VYPR

CVEs

115,065 total · page 901 of 2,302

  • CVE-2024-30073HigSep 10, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Security Zone Mapping Security Feature Bypass Vulnerability

  • CVE-2024-26191HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

  • CVE-2024-26186HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

  • CVE-2024-21416HigSep 10, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows TCP/IP Remote Code Execution Vulnerability

  • CVE-2023-6841HigSep 10, 2024
    risk 0.49cvss 7.5epss 0.01

    A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP requests could cause a resource exhaustion when the application send back rows with long attribute values.

  • CVE-2024-45592HigSep 10, 2024
    risk 0.46cvss 8.2epss 0.00

    auditor-bundle, formerly known as DoctrineAuditBundle, integrates auditor library into any Symfony 3.4+ application. Prior to version 5.2.6, there is an unescaped entity property enabling Javascript injection. This is possible because `%source_label%` in twig macro is not…

  • CVE-2024-45590HigSep 10, 2024
    risk 0.42cvss 7.5epss 0.01

    body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. This…

  • CVE-2024-31960HigSep 10, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 1480, Exynos 2400. The xclipse amdgpu driver has a reference count bug. This can lead to a use after free.

  • CVE-2023-37233HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.00

    Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.

  • CVE-2023-37232HigSep 10, 2024
    risk 0.49cvss 7.5epss 0.00

    Loftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor.

  • CVE-2024-45044HigSep 10, 2024
    risk 0.50cvss 8.8epss 0.01

    Bareos is open source software for backup, archiving, and recovery of data for operating systems. When a command ACL is in place and a user executes a command in bconsole using an abbreviation (i.e. "w" for "whoami") the ACL check did not apply to the full form (i.e. "whoami")…

  • CVE-2024-33508HigSep 10, 2024
    risk 0.48cvss 7.3epss 0.01

    An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to execute limited and temporary operations on the underlying…

  • CVE-2024-23185HigSep 10, 2024
    risk 0.49cvss 7.5epss 0.01

    Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. However, when it feeds them to message-header-parser, it starts building up "full_value" buffer out of the smaller chunks. The…

  • CVE-2024-44867HigSep 10, 2024
    risk 0.49cvss 7.5epss 0.01

    phpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php.

  • CVE-2024-37728HigSep 10, 2024
    risk 0.49cvss 7.5epss 0.02

    Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via the "Pic/Indexes" interface

  • CVE-2023-37230HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.00

    Loftware Spectrum (testDeviceConnection) before 5.1 allows SSRF.

  • CVE-2023-37229HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.00

    Loftware Spectrum before 5.1 allows SSRF.

  • CVE-2024-7770HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.01

    The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload' function in all versions up to, and including, 6.5.5. This makes it…

  • CVE-2024-44087HigSep 10, 2024
    risk 0.57cvss 8.6epss 0.11

    A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6.0 (All versions < V6.0 SP12 Upd3), Automation License Manager V6.2 (All versions < V6.2 Upd3). Affected applications do not properly validate certain fields in…

  • CVE-2024-43647HigSep 10, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0) (All versions), SIMATIC S7-200 SMART CPU CR60 (6ES7288-1CR60-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR20 (6ES7288-1SR20-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR20…

  • CVE-2024-41171HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.00

    A vulnerability has been identified in SINUMERIK 828D V4 (All versions), SINUMERIK 828D V5 (All versions < V5.24), SINUMERIK 840D sl V4 (All versions), SINUMERIK ONE (All versions < V6.24). Affected devices do not properly enforce access restrictions to scripts that are…

  • CVE-2024-41170HigSep 10, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0015), Tecnomatix Plant Simulation V2404 (All versions < V2404.0004). The affected applications contain a stack based overflow vulnerability while parsing specially crafted SPP files.…

  • CVE-2024-8258HigSep 10, 2024
    risk 0.51cvss 7.8epss 0.00

    Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to execute arbitrary code via insecure Electron Fuses configuration.

  • CVE-2024-7699HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.01

    An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data.

  • CVE-2024-43393HigSep 10, 2024
    risk 0.53cvss 8.1epss 0.01

    A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP FW_RULESETS.FROM_IP…

  • CVE-2024-43392HigSep 10, 2024
    risk 0.53cvss 8.1epss 0.01

    A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP environment variable…

  • CVE-2024-43391HigSep 10, 2024
    risk 0.53cvss 8.1epss 0.01

    A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_PORTFORWARDING.SRC_IP environment variable which can lead to a DoS.

  • CVE-2024-43390HigSep 10, 2024
    risk 0.53cvss 8.1epss 0.01

    A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding or NAT through the FW_NAT.IN_IP environment variable which can lead to a DoS.

  • CVE-2024-43389HigSep 10, 2024
    risk 0.53cvss 8.1epss 0.01

    A low privileged remote attacker can perform configuration changes of the ospf service through OSPF_INTERFACE.SIMPLE_KEY, OSPF_INTERFACE.DIGEST_KEY environment variables which can lead to a DoS.

  • CVE-2024-43388HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.01

    A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.

  • CVE-2024-43387HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.01

    A low privileged remote attacker can read and write files as root due to improper neutralization of special elements in the variable EMAIL_RELAY_PASSWORD in mGuard devices.

  • CVE-2024-43386HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.01

    A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable EMAIL_NOTIFICATION.TO in mGuard devices.

  • CVE-2024-43385HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.01

    A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable PROXY_HTTP_PORT in mGuard devices.

  • CVE-2024-39583HigSep 10, 2024
    risk 0.53cvss 8.1epss 0.00

    Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2024-39581HigSep 10, 2024
    risk 0.47cvss 7.3epss 0.00

    Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a File or Directories Accessible to External Parties vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to read, modify, and delete arbitrary files.

  • CVE-2024-42427HigSep 10, 2024
    risk 0.49cvss 7.6epss 0.01

    Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2024-8478HigSep 10, 2024
    risk 0.48cvss 7.3epss 0.01

    The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.5.3. This is due to the software allowing users to supply arbitrary shortcodes in comments when the 'Parse comments' option is enabled.…

  • CVE-2024-8268HigSep 10, 2024
    risk 0.50cvss 8.8epss 0.01

    The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering on callable methods/functions via the ajax_request() function in all versions up to, and including, 2.2.4. This makes it possible for authenticated attackers,…

  • CVE-2024-6796HigSep 9, 2024
    risk 0.53cvss 8.2epss 0.00

    In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that could allow an unauthenticated attacker to gain unauthorized access to Connex portal's database and/or modify content.

  • CVE-2024-44725HigSep 9, 2024
    risk 0.47cvss 7.2epss 0.00

    AutoCMS v5.4 was discovered to contain a SQL injection vulnerability via the sidebar parameter at /admin/robot.php.

  • CVE-2024-44724HigSep 9, 2024
    risk 0.47cvss 7.2epss 0.01

    AutoCMS v5.4 was discovered to contain a PHP code injection vulnerability via the txtsite_url parameter at /admin/site_add.php. This vulnerability allows attackers to execute arbitrary PHP code via injecting a crafted value.

  • CVE-2024-7341HigSep 9, 2024
    risk 0.39cvss 7.1epss 0.01

    A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an attacker who hijacks the current session…

  • CVE-2024-45411HigSep 9, 2024
    risk 0.48cvss 8.5epss 0.01

    Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0.

  • CVE-2024-45296HigSep 9, 2024
    risk 0.42cvss 7.5epss 0.01

    path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance…

  • CVE-2024-44335HigSep 9, 2024
    risk 0.58cvss 8.8epss 0.12

    D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution (RCE) via version_upgrade.asp.

  • CVE-2024-44334HigSep 9, 2024
    risk 0.60cvss 8.8epss 0.32

    D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution due to insufficient parameter filtering in the CGI handling function of…

  • CVE-2024-44333HigSep 9, 2024
    risk 0.58cvss 8.8epss 0.12

    D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution. An attacker can achieve arbitrary command execution by sending a carefully…

  • CVE-2024-44720HigSep 9, 2024
    risk 0.49cvss 7.5epss 0.01

    SeaCMS v13.1 was discovered to an arbitrary file read vulnerability via the component admin_safe.php.

  • CVE-2024-45041HigSep 9, 2024
    risk 0.47cvss 8.3epss 0.01

    External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secrets has a deployment called default-external-secrets-cert-controller, which is bound with a same-name ClusterRole. This ClusterRole has "get/list" verbs of…

  • CVE-2024-44375HigSep 9, 2024
    risk 0.49cvss 7.5epss 0.01

    D-Link DI-8100 v16.07.26A1 has a stack overflow vulnerability in the dbsrv_asp function.