VYPR

CVEs

115,362 total · page 886 of 2,308

  • CVE-2024-45139HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Stager versions 3.0.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2024-45138HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Stager versions 3.0.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2024-45720HigOct 9, 2024
    risk 0.46cvss 8.2epss 0.01

    On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead to unexpected command line argument interpretation, including argument injection and execution of other programs, if a specially…

  • CVE-2024-28168HigOct 9, 2024
    risk 0.42cvss 7.5epss 0.01

    Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. Users are recommended to upgrade to version 2.10, which fixes the issue.

  • CVE-2024-47334HigOct 9, 2024
    risk 0.49cvss 7.6epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho Flow Zoho Flow zoho-flow allows SQL Injection.This issue affects Zoho Flow: from n/a through <= 2.7.1.

  • CVE-2024-9575HigOct 9, 2024
    risk 0.55cvss epss 0.01

    Local File Inclusion vulnerability in pretix Widget WordPress plugin pretix-widget on Windows allows PHP Local File Inclusion. This issue affects pretix Widget WordPress plugin: from 1.0.0 through 1.0.5.

  • CVE-2024-47418HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.00

    Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2024-47417HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.00

    Animate versions 23.0.7, 24.0.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2024-47416HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.00

    Animate versions 23.0.7, 24.0.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2024-47415HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.00

    Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2024-47414HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.00

    Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2024-47413HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.00

    Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2024-47412HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.00

    Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2024-47411HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.00

    Animate versions 23.0.7, 24.0.4 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2024-47410HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.00

    Animate versions 23.0.7, 24.0.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2024-45150HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.00

    Dimension versions 4.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2024-45146HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.00

    Dimension versions 4.0.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2023-37154HigOct 9, 2024
    risk 0.48cvss 8.4epss 0.00

    check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in e8810de, and as intended behavior.

  • CVE-2024-47191HigOct 9, 2024
    risk 0.39cvss 7.1epss 0.00

    pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by calling fchown in the presence of a symlink.

  • CVE-2024-45179HigOct 9, 2024
    risk 0.47cvss 7.2epss 0.03

    An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to insufficient input validation, the C-MOR web interface is vulnerable to OS command injection attacks. It was found out that different functionality is vulnerable to OS command injection…

  • CVE-2024-35288HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.00

    Nitro PDF Pro before 13.70.8.82 and 14.x before 14.26.1.0 allows Local Privilege Escalation in the MSI Installer because custom actions occur unsafely in repair mode. CertUtil is run in a conhost.exe window, and there is a mechanism allowing CTRL+o to launch cmd.exe as NT…

  • CVE-2024-9603HigOct 8, 2024
    risk 0.57cvss 8.8epss 0.00

    Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-9602HigOct 8, 2024
    risk 0.57cvss 8.8epss 0.01

    Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-9412HigOct 8, 2024
    risk 0.55cvss epss 0.00

    An improper authorization vulnerability exists in the Rockwell Automation affected products that could allow an unauthorized user to sign in. While removal of all role mappings is unlikely, it could occur in the case of unexpected or accidental removal by the administrator. If…

  • CVE-2024-47773HigOct 8, 2024
    risk 0.56cvss 8.2epss 0.02

    Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data. This issue only affects anonymous visitors of the site. This problem has been patched in the latest…

  • CVE-2024-46539HigOct 8, 2024
    risk 0.53cvss 8.2epss 0.00

    Insecure permissions in the Bluetooth Low Energy (BLE) component of Fire-Boltt Artillery Smart Watch NJ-R6E-10.3 allow attackers to cause a Denial of Service (DoS).

  • CVE-2024-43616HigOct 8, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Remote Code Execution Vulnerability

  • CVE-2024-43615HigOct 8, 2024
    risk 0.46cvss 7.1epss 0.01

    Microsoft OpenSSH for Windows Remote Code Execution Vulnerability

  • CVE-2024-43611HigOct 8, 2024
    risk 0.57cvss 8.8epss 0.02

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

  • CVE-2024-43608HigOct 8, 2024
    risk 0.57cvss 8.8epss 0.01

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

  • CVE-2024-43607HigOct 8, 2024
    risk 0.57cvss 8.8epss 0.01

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

  • CVE-2024-43601HigOct 8, 2024
    risk 0.51cvss 7.8epss 0.01

    Visual Studio Code for Linux Remote Code Execution Vulnerability

  • CVE-2024-43599HigOct 8, 2024
    risk 0.57cvss 8.8epss 0.01

    Remote Desktop Client Remote Code Execution Vulnerability

  • CVE-2024-43593HigOct 8, 2024
    risk 0.57cvss 8.8epss 0.02

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

  • CVE-2024-43592HigOct 8, 2024
    risk 0.57cvss 8.8epss 0.02

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

  • CVE-2024-43591HigOct 8, 2024
    risk 0.57cvss 8.7epss 0.02

    Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability

  • CVE-2024-43590HigOct 8, 2024
    risk 0.51cvss 7.8epss 0.00

    Visual C++ Redistributable Installer Elevation of Privilege Vulnerability

  • CVE-2024-43589HigOct 8, 2024
    risk 0.57cvss 8.8epss 0.01

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

  • CVE-2024-43584HigOct 8, 2024
    risk 0.50cvss 7.7epss 0.01

    Windows Scripting Engine Security Feature Bypass Vulnerability

  • CVE-2024-43583HigOct 8, 2024
    risk 0.51cvss 7.8epss 0.01

    Winlogon Elevation of Privilege Vulnerability

  • CVE-2024-43582HigOct 8, 2024
    risk 0.53cvss 8.1epss 0.03

    Remote Desktop Protocol Server Remote Code Execution Vulnerability

  • CVE-2024-43581HigOct 8, 2024
    risk 0.46cvss 7.1epss 0.01

    Microsoft OpenSSH for Windows Remote Code Execution Vulnerability

  • CVE-2024-43576HigOct 8, 2024
    risk 0.51cvss 7.8epss 0.00

    Microsoft Office Remote Code Execution Vulnerability

  • CVE-2024-43575HigOct 8, 2024
    risk 0.49cvss 7.5epss 0.02

    Windows Hyper-V Denial of Service Vulnerability

  • CVE-2024-43574HigOct 8, 2024
    risk 0.54cvss 8.3epss 0.01

    Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability

  • CVE-2024-43572HigKEVOct 8, 2024
    risk 0.68cvss 7.8epss 0.67

    Microsoft Management Console Remote Code Execution Vulnerability

  • CVE-2024-43567HigOct 8, 2024
    risk 0.49cvss 7.5epss 0.02

    Windows Hyper-V Denial of Service Vulnerability

  • CVE-2024-43565HigOct 8, 2024
    risk 0.49cvss 7.5epss 0.02

    Windows Network Address Translation (NAT) Denial of Service Vulnerability

  • CVE-2024-43564HigOct 8, 2024
    risk 0.57cvss 8.8epss 0.01

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

  • CVE-2024-43563HigOct 8, 2024
    risk 0.51cvss 7.8epss 0.00

    Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability