VYPR

CVEs

114,971 total · page 905 of 2,300

  • CVE-2024-8194HigAug 28, 2024
    risk 0.57cvss 8.8epss 0.00

    Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-8193HigAug 28, 2024
    risk 0.57cvss 8.8epss 0.00

    Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-45059HigAug 28, 2024
    risk 0.00cvss 8.8epss 0.01

    i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. A SQL Injection vulnerability was found prior to the 2.9 branch in the `ieducar/intranet/funcionario_vinculo_det.php` file, which creates…

  • CVE-2024-45058HigAug 28, 2024
    risk 0.00cvss 8.1epss 0.01

    i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. Prior to the 2.9 branch, an attacker with only minimal viewing privileges in the settings section is able to change their user type to…

  • CVE-2024-45048HigAug 28, 2024
    risk 0.50cvss 8.8epss 0.01

    PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions are subject to a bypassing of a filter which allows for an XXE-attack. This in turn allows attacker to obtain contents of local files, even if error reporting is muted. This…

  • CVE-2024-44760HigAug 28, 2024
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the component /servlet/SnoopServlet of Shenzhou News Union Enterprise Management System v5.0 through v18.8 allows attackers to access sensitive information regarding the server.

  • CVE-2024-43805HigAug 28, 2024
    risk 0.42cvss 7.6epss 0.00

    jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. This vulnerability depends on user interaction by opening a malicious notebook with Markdown cells, or Markdown file using JupyterLab preview feature.…

  • CVE-2024-42793HigAug 28, 2024
    risk 0.52cvss 8.0epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via a crafted request to the /music/ajax.php?action=save_user page.

  • CVE-2024-41236HigAug 28, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL injection vulnerability in /smsa/admin_login.php in Kashipara Responsive School Management System v3.2.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter of the Admin Login Page

  • CVE-2024-20446HigAug 28, 2024
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the DHCPv6 relay agent of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of specific fields in a DHCPv6 RELAY-REPLY…

  • CVE-2024-5546HigAug 28, 2024
    risk 0.54cvss 8.3epss 0.03

    Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option.

  • CVE-2023-26324HigAug 28, 2024
    risk 0.57cvss 8.8epss 0.01

    A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.

  • CVE-2023-26323HigAug 28, 2024
    risk 0.49cvss 7.6epss 0.01

    A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code.

  • CVE-2023-26322HigAug 28, 2024
    risk 0.57cvss 8.8epss 0.01

    A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.

  • CVE-2024-6311HigAug 28, 2024
    risk 0.47cvss 7.2epss 0.01

    The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'af2_add_font' function in all versions up to, and including, 3.7.3.2. This makes it possible for authenticated attackers, with administrator-level and…

  • CVE-2024-4555HigAug 28, 2024
    risk 0.50cvss 7.7epss 0.00

    Improper Privilege Management vulnerability in OpenText NetIQ Access Manager allows user account impersonation in specific scenario. This issue affects NetIQ Access Manager before 5.0.4.1 and before 5.1

  • CVE-2024-4554HigAug 28, 2024
    risk 0.47cvss 7.3epss 0.00

    Improper Input Validation vulnerability in OpenText NetIQ Access Manager leads to Cross-Site Scripting (XSS) attack. This issue affects Access Manager before 5.0.4.1 and 5.1.

  • CVE-2024-45346HigAug 28, 2024
    risk 0.57cvss 8.8epss 0.00

    The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend Micro Zero Day Initiative! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security…

  • CVE-2021-38121HigAug 28, 2024
    risk 0.54cvss 8.3epss 0.00

    Insufficient or weak TLS protocol version identified in Advance authentication client server communication when specific service is accessed between devices.  This issue affects NetIQ Advance Authentication versions before 6.3.5.1

  • CVE-2021-22530HigAug 28, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability identified in NetIQ Advance Authentication that doesn't enforce account lockout when brute force attack is performed on API based login. This issue may lead to user account compromise if successful or may impact server performance. This issue impacts all NetIQ…

  • CVE-2021-22509HigAug 28, 2024
    risk 0.53cvss 8.1epss 0.00

    A vulnerability identified in storing and reusing information in Advance Authentication. This issue can lead to leakage of sensitive data to unauthorized user. The issue affects NetIQ Advance Authentication before 6.3.5.1

  • CVE-2024-39584HigAug 28, 2024
    risk 0.53cvss 8.2epss 0.00

    Dell Client Platform BIOS contains a Use of Default Cryptographic Key Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Secure Boot bypass and arbitrary code execution.

  • CVE-2023-45896HigAug 28, 2024
    risk 0.39cvss 7.1epss 0.00

    ntfs3 in the Linux kernel through 6.8.0 allows a physically proximate attacker to read kernel memory by mounting a filesystem (e.g., if a Linux distribution is configured to allow unprivileged mounts of removable media) and then leveraging local access to trigger an…

  • CVE-2024-8231HigAug 28, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical has been found in Tenda O6 1.0.0.7(2054). Affected is the function fromVirtualSet of the file /goform/setPortForward. The manipulation of the argument ip/localPort/publicPort/app leads to stack-based buffer overflow. It is possible to…

  • CVE-2024-8230HigAug 28, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda O6 1.0.0.7(2054). It has been rated as critical. This issue affects the function fromSafeSetMacFilter of the file /goform/setMacFilterList. The manipulation of the argument remark/type/time leads to stack-based buffer overflow. The attack may…

  • CVE-2024-8229HigAug 28, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda O6 1.0.0.7(2054). It has been declared as critical. This vulnerability affects the function frommacFilterModify of the file /goform/operateMacFilter. The manipulation of the argument mac leads to stack-based buffer overflow. The attack can be…

  • CVE-2024-8228HigAug 28, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda O5 1.0.0.8(5017). It has been classified as critical. This affects the function fromSafeSetMacFilter of the file /goform/setMacFilterList. The manipulation of the argument remark/type/time leads to stack-based buffer overflow. It is possible to…

  • CVE-2024-8227HigAug 28, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda O1 1.0.0.7(10648) and classified as critical. Affected by this issue is the function fromDhcpSetSer of the file /goform/DhcpSetSer. The manipulation of the argument dhcpStartIp/dhcpEndIp/dhcpGw/dhcpMask/dhcpLeaseTime/dhcpDns1/dhcpDns2 leads to…

  • CVE-2024-8226HigAug 28, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been found in Tenda O1 1.0.0.7(10648) and classified as critical. Affected by this vulnerability is the function formSetCfm of the file /goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack can be launched…

  • CVE-2024-8225HigAug 27, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability, which was classified as critical, was found in Tenda G3 15.11.0.20. Affected is the function formSetSysTime of the file /goform/SetSysTimeCfg. The manipulation of the argument sysTimePolicy leads to stack-based buffer overflow. It is possible to launch the…

  • CVE-2024-8224HigAug 27, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability, which was classified as critical, has been found in Tenda G3 15.11.0.20. This issue affects the function formSetDebugCfg of the file /goform/setDebugCfg. The manipulation of the argument enable/level/module leads to stack-based buffer overflow. The attack may be…

  • CVE-2024-8219HigAug 27, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in code-projects Responsive Hotel Site 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. The manipulation of the argument name/phone/email leads to sql injection. It is possible to launch the attack…

  • CVE-2024-8218HigAug 27, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in code-projects Online Quiz Site 1.0 and classified as critical. This issue affects some unknown processing of the file index.php. The manipulation of the argument loginid leads to sql injection. The attack may be initiated remotely. The exploit has…

  • CVE-2024-8217HigAug 27, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in SourceCodester E-Commerce Website 1.0 and classified as critical. This vulnerability affects unknown code of the file /Admin/registration.php. The manipulation of the argument fname leads to sql injection. The attack can be initiated remotely.…

  • CVE-2024-45049HigAug 27, 2024
    risk 0.00cvss 7.5epss 0.01

    Hydra is a Continuous Integration service for Nix based projects. It is possible to trigger evaluations in Hydra without any authentication. Depending on the size of evaluations, this can impact the availability of systems. The problem can be fixed by applying…

  • CVE-2024-45038HigAug 27, 2024
    risk 0.49cvss 7.5epss 0.01

    Meshtastic device firmware is a firmware for meshtastic devices to run an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. Meshtastic device firmware is subject to a denial of serivce vulnerability in MQTT handling, fixed in…

  • CVE-2024-5991HigAug 27, 2024
    risk 0.00cvss 7.5epss 0.01

    In function MatchDomainName(), input param str is treated as a NULL terminated string despite being user provided and unchecked. Specifically, the function X509_check_host() takes in a pointer and length to check against, with no requirements that it be NULL terminated. If a…

  • CVE-2022-39997HigAug 27, 2024
    risk 0.52cvss 8.0epss 0.00

    A weak password requirement issue was discovered in Teldats Router RS123, RS123w allows a remote attacker to escalate privileges

  • CVE-2024-43783HigAug 27, 2024
    risk 0.42cvss 7.5epss 0.01

    The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of the Apollo Router running versions >=1.21.0 and < 1.52.1 are impacted by a denial of service vulnerability if _all_…

  • CVE-2024-43414HigAug 27, 2024
    risk 0.42cvss 7.5epss 0.01

    Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them to deliver autonomously and incrementally. Instances of @apollo/query-planner >=2.0.0 and <2.8.5 are impacted by…

  • CVE-2024-42851HigAug 27, 2024
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the paresetag function.

  • CVE-2024-45264HigAug 27, 2024
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to add a new administrator, leading to escalation of privileges.

  • CVE-2024-44340HigAug 27, 2024
    risk 0.57cvss 8.8epss 0.02

    D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via keys smartqos_express_devices and smartqos_normal_devices in SetSmartQoSSettings.

  • CVE-2024-6632HigAug 27, 2024
    risk 0.47cvss 7.2epss 0.01

    A vulnerability exists in FileCatalyst Workflow whereby a field accessible to the super admin can be used to perform an SQL injection attack which can lead to a loss of confidentiality, integrity, and availability.

  • CVE-2024-8182HigAug 27, 2024
    risk 0.50cvss 7.5epss 0.14

    An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulnerable version due to improper handling of user supplied input to the “/api/v1/get-upload-file” api endpoint.

  • CVE-2024-7940HigAug 27, 2024
    risk 0.54cvss 8.3epss 0.01

    The product exposes a service that is intended for local only to all network interfaces without any authentication.

  • CVE-2024-3982HigAug 27, 2024
    risk 0.53cvss 8.2epss 0.00

    An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already established session. By default, the session logging level is not enabled and only users…

  • CVE-2024-41176HigAug 27, 2024
    risk 0.47cvss 7.3epss 0.00

    The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local attacker to induce a Denial-of-Service (DoS) condition on the daemon and execute code in the context of user “root” via a crafted HTTP request.

  • CVE-2024-41174HigAug 27, 2024
    risk 0.47cvss 7.3epss 0.00

    The IPC-Diagnostics package in TwinCAT/BSD is susceptible to improper input neutralization by a low-privileged local attacker.

  • CVE-2024-41173HigAug 27, 2024
    risk 0.51cvss 7.8epss 0.00

    The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local authentication bypass by a low privileged attacker.