VYPR

CVEs

115,363 total · page 883 of 2,308

  • CVE-2024-45731HigOct 14, 2024
    risk 0.52cvss 8.0epss 0.01

    In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could write a file to the Windows system root directory, which has a default location in the Windows System32 folder, when Splunk…

  • CVE-2023-50780HigOct 14, 2024
    risk 0.52cvss 8.8epss 0.17

    Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29.0, this also included the Log4J2 MBean. This MBean is not meant for exposure to non-administrative…

  • CVE-2024-48259HigOct 14, 2024
    risk 0.48cvss 7.3epss 0.01

    Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign.

  • CVE-2024-48249HigOct 14, 2024
    risk 0.00cvss 7.3epss 0.00

    Wavelog 1.8.5 allows Gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.

  • CVE-2024-7847HigOct 14, 2024
    risk 0.50cvss 7.7epss 0.00

    VULNERABILITY DETAILS Rockwell Automation used the latest versions of the CVSS scoring system to assess the following vulnerabilities. The following vulnerabilities were reported to us by Sharon Brizinov of Claroty Research - Team82. A feature in the affected products enables…

  • CVE-2024-9139HigOct 14, 2024
    risk 0.47cvss 7.2epss 0.01

    The affected product permits OS command injection through improperly restricted commands, potentially allowing attackers to execute arbitrary code.

  • CVE-2024-43701HigOct 14, 2024
    risk 0.51cvss 7.8epss 0.00

    Software installed and run as a non-privileged user may conduct GPU system calls to read and write freed physical memory from the GPU.

  • CVE-2024-38863HigOct 14, 2024
    risk 0.49cvss 7.5epss 0.00

    Exposure of CSRF tokens in query parameters on specific requests in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35 and <2.1.0p48 could lead to a leak of the token to facilitate targeted phishing attacks.

  • CVE-2024-9922HigOct 14, 2024
    risk 0.49cvss 7.5epss 0.01

    The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

  • CVE-2024-8070HigOct 13, 2024
    risk 0.55cvss 8.5epss 0.00

    CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that exposes test credentials in the firmware binary

  • CVE-2024-9916HigOct 13, 2024
    risk 0.53cvss 7.3epss 0.73

    A vulnerability, which was classified as critical, has been found in HuangDou UTCMS V9. Affected by this issue is some unknown functionality of the file app/modules/ut-cac/admin/cli.php. The manipulation of the argument o leads to os command injection. The attack may be launched…

  • CVE-2024-9915HigOct 13, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability classified as critical was found in D-Link DIR-619L B1 2.06. Affected by this vulnerability is the function formVirtualServ of the file /goform/formVirtualServ. The manipulation of the argument curTime leads to buffer overflow. The attack can be launched…

  • CVE-2024-9914HigOct 13, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability classified as critical has been found in D-Link DIR-619L B1 2.06. Affected is the function formSetWizardSelectMode of the file /goform/formSetWizardSelectMode. The manipulation of the argument curTime leads to buffer overflow. It is possible to launch the attack…

  • CVE-2024-9913HigOct 13, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability was found in D-Link DIR-619L B1 2.06. It has been rated as critical. This issue affects the function formSetRoute of the file /goform/formSetRoute. The manipulation of the argument curTime leads to buffer overflow. The attack may be initiated remotely. The…

  • CVE-2024-9912HigOct 13, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability was found in D-Link DIR-619L B1 2.06. It has been declared as critical. This vulnerability affects the function formSetQoS of the file /goform/formSetQoS. The manipulation of the argument curTime leads to buffer overflow. The attack can be initiated remotely. The…

  • CVE-2024-9911HigOct 13, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability was found in D-Link DIR-619L B1 2.06. It has been classified as critical. This affects the function formSetPortTr of the file /goform/formSetPortTr. The manipulation of the argument curTime leads to buffer overflow. It is possible to initiate the attack remotely.…

  • CVE-2024-9910HigOct 13, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability was found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this issue is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the argument curTime leads to buffer overflow. The attack may be launched remotely.…

  • CVE-2024-9909HigOct 13, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability has been found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this vulnerability is the function formSetMuti of the file /goform/formSetMuti. The manipulation of the argument curTime leads to buffer overflow. The attack can be launched…

  • CVE-2024-6959HigOct 13, 2024
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file. If an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process each character, rendering…

  • CVE-2024-49193HigOct 12, 2024
    risk 0.49cvss 7.5epss 0.01

    Zendesk before 2024-07-02 allows remote attackers to read ticket history via e-mail spoofing, because Cc fields are extracted from incoming e-mail messages and used to grant additional authorization for ticket viewing, the mechanism for detecting spoofed e-mail messages is…

  • CVE-2024-8757HigOct 12, 2024
    risk 0.40cvss 7.2epss 0.01

    The WP Post Author – Boost Your Blog's Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the linked_user_id parameter in all…

  • CVE-2024-9821HigOct 12, 2024
    risk 0.50cvss 8.8epss 0.01

    The Bot for Telegram on WooCommerce plugin for WordPress is vulnerable to sensitive information disclosure due to missing authorization checks on the 'stm_wpcfto_get_settings' AJAX action in all versions up to, and including, 1.2.7. This makes it possible for authenticated…

  • CVE-2024-45754HigOct 11, 2024
    risk 0.40cvss 7.2epss 0.01

    An issue was discovered in the centreon-bi-server component in Centreon BI Server 24.04.x before 24.04.3, 23.10.x before 23.10.8, 23.04.x before 23.04.11, and 22.10.x before 22.10.11. SQL injection can occur in the listing of configured reporting jobs. Exploitation is only…

  • CVE-2024-35522HigOct 11, 2024
    risk 0.55cvss 8.4epss 0.02

    Netgear EX3700 ' AC750 WiFi Range Extender Essentials Edition before 1.0.0.98 contains an authenticated command injection in operating_mode.cgi via the ap_mode parameter with ap_24g_manual set to 1 and ap_24g_manual_sec set to NotNone.

  • CVE-2024-35517HigOct 11, 2024
    risk 0.56cvss 8.4epss 0.15

    Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter.

  • CVE-2024-48938HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.01

    Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows DoS/ReDos via email. Parsing the content of emails where HTML code is copied from Microsoft Word could lead to high CPU usage and block the parsing process.

  • CVE-2024-48788HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in YESCAM (com.yescom.YesCam.zwave) 1.0.2 allows a remote attacker to obtain sensitive information via the firmware update process.

  • CVE-2024-46468HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.00

    A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker to obtain sensitive information, resulting in an information disclosure.

  • CVE-2024-48777HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.00

    LEDVANCE com.ledvance.smartplus.eu 2.1.10 allows a remote attacker to obtain sensitive information via the firmware update process.

  • CVE-2024-48776HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware update process

  • CVE-2024-48775HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in Plug n Play Camera com.ezset.delaney 1.2.0 allows a remote attacker to obtain sensitive information via the firmware update process.

  • CVE-2024-48774HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in Fermax Asia Pacific Pte Ltd com.fermax.vida 2.4.6 allows a remote attacker to obtain sensitve information via the firmware update process.

  • CVE-2024-48773HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in WoFit v.7.2.3 allows a remote attacker to obtain sensitive information via the firmware update process

  • CVE-2024-48771HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in almando GmbH Almando Play APP (com.almando.play) 1.8.2 allows a remote attacker to obtain sensitive information via the firmware update process

  • CVE-2024-48770HigOct 11, 2024
    risk 0.53cvss 8.2epss 0.00

    An issue in Plug n Play Camera com.wisdomcity.zwave 1.1.0 allows a remote attacker to obtain sensitive information via the firmware update process.

  • CVE-2024-48768HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in almaodo GmbH appinventor.ai_google.almando_control 2.3.1 allows a remote attacker to obtain sensitive information via the firmware update process

  • CVE-2024-38365HigOct 11, 2024
    risk 0.41cvss 7.4epss 0.01

    btcd is an alternative full node bitcoin implementation written in Go (golang). The btcd Bitcoin client (versions 0.10 to 0.24) did not correctly re-implement Bitcoin Core's "FindAndDelete()" functionality. This logic is consensus-critical: the difference in behavior with the…

  • CVE-2024-8912HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.00

    An HTTP Request Smuggling vulnerability in Looker allowed an unauthorized attacker to capture HTTP responses destined for legitimate users. There are two Looker versions that are hosted by Looker: * Looker (Google Cloud core) was found to be vulnerable. This issue has…

  • CVE-2024-48040HigOct 11, 2024
    risk 0.48cvss 8.5epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan tainacan allows SQL Injection.This issue affects Tainacan: from n/a through <= 0.21.8.

  • CVE-2024-48020HigOct 11, 2024
    risk 0.55cvss 8.5epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows SQL Injection.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.21.

  • CVE-2024-9859HigOct 11, 2024
    risk 0.57cvss 8.8epss 0.00

    Type confusion in WebAssembly in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-47877HigOct 11, 2024
    risk 0.42cvss 7.5epss 0.01

    Extract is aA Go library to extract archives in zip, tar.gz or tar.bz2 formats. A maliciously crafted archive may allow an attacker to create a symlink outside the extraction target directory. This vulnerability is fixed in 4.0.0. If you're using the Extractor.FS interface, then…

  • CVE-2024-44734HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in Mirotalk before commit 9de226 allows attackers to arbitrarily change usernames via sending a crafted roomAction request to the server.

  • CVE-2024-44414HigOct 11, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was discovered in FBM_292W-21.03.10V, which has been classified as critical. This issue affects the sub_4901E0 function in the msp_info.htm file. Manipulation of the path parameter can lead to command injection.

  • CVE-2024-44413HigOct 11, 2024
    risk 0.57cvss 8.8epss 0.03

    A vulnerability was discovered in DI_8200-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the path parameter can lead to command injection.

  • CVE-2024-42018HigOct 11, 2024
    risk 0.50cvss 7.7epss 0.00

    An issue was discovered in Atos Eviden SMC xScale before 1.6.6. During initialization of nodes, some configuration parameters are retrieved from management nodes. These parameters embed credentials whose integrity and confidentiality may be important to the security of the HPC…

  • CVE-2024-9046HigOct 11, 2024
    risk 0.51cvss 7.8epss 0.00

    A DLL hijack vulnerability was reported in Lenovo stARstudio that could allow a local attacker to execute code with elevated privileges.

  • CVE-2024-8376HigOct 11, 2024
    risk 0.00cvss 7.5epss 0.01

    In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets.

  • CVE-2024-4132HigOct 11, 2024
    risk 0.51cvss 7.8epss 0.00

    A DLL hijack vulnerability was reported in Lenovo Lock Screen that could allow a local attacker to execute code with elevated privileges.

  • CVE-2024-4131HigOct 11, 2024
    risk 0.51cvss 7.8epss 0.00

    A DLL hijack vulnerability was reported in Lenovo Emulator that could allow a local attacker to execute code with elevated privileges.