VYPR

CVEs

114,985 total · page 904 of 2,300

  • CVE-2024-33048HigSep 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.

  • CVE-2024-33047HigSep 2, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption when the captureRead QDCM command is invoked from user-space.

  • CVE-2024-33045HigSep 2, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption when BTFM client sends new messages over Slimbus to ADSP.

  • CVE-2024-33042HigSep 2, 2024
    risk 0.51cvss 7.8epss 0.00

    Memory corruption when Alternative Frequency offset value is set to 255.

  • CVE-2024-33038HigSep 2, 2024
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while passing untrusted/corrupted pointers from DSP to EVA.

  • CVE-2024-33035HigSep 2, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients.

  • CVE-2024-23365HigSep 2, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption while releasing shared resources in MinkSocket listener thread.

  • CVE-2024-23364HigSep 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA).

  • CVE-2024-23362HigSep 2, 2024
    risk 0.46cvss 7.1epss 0.00

    Cryptographic issue while parsing RSA keys in COBR format.

  • CVE-2024-23359HigSep 2, 2024
    risk 0.53cvss 8.2epss 0.00

    Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.

  • CVE-2024-23358HigSep 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.

  • CVE-2024-7871HigSep 2, 2024
    risk 0.57cvss 8.8epss 0.01

    SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the word parameter.

  • CVE-2024-43776HigSep 2, 2024
    risk 0.57cvss 8.8epss 0.00

    SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the qlevel parameter.

  • CVE-2024-43775HigSep 2, 2024
    risk 0.57cvss 8.8epss 0.00

    SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the search parameter.

  • CVE-2024-43774HigSep 2, 2024
    risk 0.57cvss 8.8epss 0.00

    SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the uid parameter.

  • CVE-2024-41160HigSep 2, 2024
    risk 0.57cvss 8.8epss 0.00

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.

  • CVE-2024-41157HigSep 2, 2024
    risk 0.57cvss 8.8epss 0.00

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.

  • CVE-2024-39816HigSep 2, 2024
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

  • CVE-2024-38386HigSep 2, 2024
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

  • CVE-2024-20089HigSep 2, 2024
    risk 0.49cvss 7.5epss 0.00

    In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08861558; Issue ID: MSV-1526.

  • CVE-2024-8368HigSep 1, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in code-projects Hospital Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php of the component Login. The manipulation of the argument username leads to sql injection. The…

  • CVE-2024-44946HigAug 31, 2024
    risk 0.51cvss 7.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: kcm: Serialise kcm_sendmsg() for the same socket. syzkaller reported UAF in kcm_release(). [0] The scenario is 1. Thread A builds a skb with MSG_MORE and sets kcm->seq_skb. 2. Thread A resumes building…

  • CVE-2024-7717HigAug 31, 2024
    risk 0.57cvss 8.8epss 0.01

    The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 2.1.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…

  • CVE-2024-44945HigAug 31, 2024
    risk 0.46cvss 7.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink: Initialise extack before use in ACKs Add missing extack initialisation when ACKing BATCH_BEGIN and BATCH_END.

  • CVE-2024-7435HigAug 31, 2024
    risk 0.57cvss 8.8epss 0.01

    The Attire theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known…

  • CVE-2024-39747HigAug 31, 2024
    risk 0.53cvss 8.1epss 0.01

    IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality.

  • CVE-2024-6586HigAug 30, 2024
    risk 0.41cvss 7.3epss 0.02

    Lightdash version 0.1024.6 allows users with the necessary permissions, such as Administrator or Editor, to create and share dashboards. A dashboard that contains HTML elements which point to a threat actor controlled source can trigger an SSRF request when exported, via a POST…

  • CVE-2024-38868HigAug 30, 2024
    risk 0.49cvss 7.6epss 0.01

    Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.This issue affects Endpoint Central: before 11.3.2406.08 and before 11.3.2400.15

  • CVE-2024-6204HigAug 30, 2024
    risk 0.54cvss 8.3epss 0.02

    Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module.

  • CVE-2024-8343HigAug 30, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in SourceCodester Sentiment Based Movie Rating System 1.0. Affected is an unknown function of the file /classes/Users.php?f=save_client of the component User Registration Handler. The manipulation of the argument email…

  • CVE-2024-44916HigAug 30, 2024
    risk 0.47cvss 7.2epss 0.01

    Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php file and could result in arbitrary command execution.

  • CVE-2024-8340HigAug 30, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Electric Billing Management System 1.0. This affects an unknown part of the file /Actions.php?a=login. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack…

  • CVE-2024-8252HigAug 30, 2024
    risk 0.57cvss 8.8epss 0.03

    The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute of the clean-login-register shortcode. This makes it possible for authenticated attackers, with Contributor-level access and…

  • CVE-2024-2694HigAug 30, 2024
    risk 0.57cvss 8.8epss 0.01

    The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via deserialization of untrusted input of the 'mfn-page-items' post meta value. This makes it possible for authenticated attackers, with contributor-level access…

  • CVE-2024-5784HigAug 30, 2024
    risk 0.46cvss 7.1epss 0.00

    The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing capability checks on multiple functions like treport_quiz_atttempt_delete and tutor_gc_class_action in all versions up to, and including, 2.7.2. This makes it…

  • CVE-2024-8330HigAug 30, 2024
    risk 0.57cvss 8.8epss 0.01

    6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload web shell scripts and use them to execute arbitrary system commands on the server.

  • CVE-2024-8329HigAug 30, 2024
    risk 0.57cvss 8.8epss 0.01

    6SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers with regular privilege to inject SQL command to read, modify, and delete database contents.

  • CVE-2024-8327HigAug 30, 2024
    risk 0.57cvss 8.8epss 0.01

    Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitrary SQL commands to read, modify, and delete database contents.

  • CVE-2024-45490HigAug 30, 2024
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.

  • CVE-2024-8234HigAug 30, 2024
    risk 0.49cvss 7.5epss 0.04

    ** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the functions formSysCmd(), formUpgradeCert(), and formDelcert() in the Zyxel NWA1100-N firmware version 1.00(AACE.1)C0 could allow an unauthenticated attacker to execute some OS commands to access system files…

  • CVE-2024-6672HigAug 29, 2024
    risk 0.57cvss 8.8epss 0.01

    In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an authenticated low-privileged attacker to achieve privilege escalation by modifying a privileged user's password.

  • CVE-2024-34019HigAug 29, 2024
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 4569.

  • CVE-2024-34017HigAug 29, 2024
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 4569.

  • CVE-2024-43921HigAug 29, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Magic Post Thumbnail allows Reflected XSS.This issue affects Magic Post Thumbnail: from n/a through 5.2.9.

  • CVE-2024-43963HigAug 29, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WaspThemes YellowPencil Visual CSS Style Editor allows Reflected XSS.This issue affects YellowPencil Visual CSS Style Editor: from n/a through 7.6.1.

  • CVE-2024-43958HigAug 29, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gianni Porto IntoTheDark allows Reflected XSS.This issue affects IntoTheDark: from n/a through 1.0.5.

  • CVE-2024-43950HigAug 29, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Nextbricks Brickscore allows Stored XSS.This issue affects Brickscore: from n/a through 1.4.2.5.

  • CVE-2024-43948HigAug 29, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dinesh Karki WP Armour Extended.This issue affects WP Armour Extended: from n/a through 1.26.

  • CVE-2024-43926HigAug 29, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder allows Reflected XSS.This issue affects Beaver Builder: from n/a through 2.8.3.2.

  • CVE-2024-43804HigAug 29, 2024
    risk 0.57cvss 8.8epss 0.03

    Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. An OS Command Injection vulnerability allows any authenticated user on the application to execute arbitrary code on the web application server via port scanning functionality. User-supplied…