VYPR

CVEs

114,854 total · page 919 of 2,298

  • CVE-2024-28739HigAug 6, 2024
    risk 0.48cvss 7.2epss 0.19

    An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.

  • CVE-2024-42347HigAug 6, 2024
    risk 0.43cvss 7.7epss 0.00

    matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages…

  • CVE-2024-7502HigAug 6, 2024
    risk 0.51cvss 7.8epss 0.00

    A crafted DPA file could force Delta Electronics DIAScreen to overflow a stack-based buffer, which could allow an attacker to execute arbitrary code.

  • CVE-2024-7000HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.01

    Use after free in CSS in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-6998HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.01

    Use after free in User Education in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-6997HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.01

    Use after free in Tabs in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-6994HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.01

    Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-6991HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.01

    Use after free in Dawn in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-6989HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.01

    Use after free in Loader in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-6988HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.01

    Use after free in Downloads in Google Chrome on iOS prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-6720HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.00

    The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

  • CVE-2024-23483HigAug 6, 2024
    risk 0.46cvss 7.0epss 0.01

    An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue affects Zscaler Client Connector on MacOS <4.2.

  • CVE-2024-23464HigAug 6, 2024
    risk 0.47cvss 7.2epss 0.00

    In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Zscaler Client Connector on Windows <4.2.1

  • CVE-2024-23458HigAug 6, 2024
    risk 0.47cvss 7.3epss 0.00

    While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks, potentially leading to a local privilege escalation. This issue affects Zscaler Client Connector on Windows <4.2.0.190.

  • CVE-2024-23456HigAug 6, 2024
    risk 0.51cvss 7.8epss 0.00

    Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connector <4.2.0.190 with anti-tampering enabled.

  • CVE-2024-41913HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly sanitize User input.

  • CVE-2024-41226HigAug 6, 2024
    risk 0.51cvss 7.8epss 0.01

    A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted payload. NOTE: Automation Anywhere disputes this report, arguing the attacker executes everything from the client side and does not attack…

  • CVE-2024-7530HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.00

    Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129.

  • CVE-2024-7528HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.01

    Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.

  • CVE-2024-7527HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.01

    Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

  • CVE-2024-7525HigAug 6, 2024
    risk 0.53cvss 8.1epss 0.01

    It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and…

  • CVE-2024-7523HigAug 6, 2024
    risk 0.53cvss 8.1epss 0.00

    A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. *This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 129.

  • CVE-2024-7522HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.01

    Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

  • CVE-2024-7521HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.01

    Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

  • CVE-2024-7520HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.01

    A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.

  • CVE-2024-43114HigAug 6, 2024
    risk 0.49cvss 7.5epss 0.00

    In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions

  • CVE-2024-33994HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' parameter in '/event/index.php'.

  • CVE-2024-33993HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' parameter in /candidate/index.php'.

  • CVE-2024-33992HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in…

  • CVE-2024-33991HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in…

  • CVE-2024-33990HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user and partially take over their browser session via the 'id'…

  • CVE-2024-33989HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user and partially take over their browser session via…

  • CVE-2024-33988HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance',…

  • CVE-2024-33987HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance',…

  • CVE-2024-33986HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'View' parameter…

  • CVE-2024-33985HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'View' parameter…

  • CVE-2024-33984HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance',…

  • CVE-2024-33983HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance',…

  • CVE-2024-33982HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'StudentID'…

  • CVE-2024-33981HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'start' parameter in…

  • CVE-2024-33980HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'start' parameter in…

  • CVE-2024-33979HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'q', 'arrival', 'departure' and…

  • CVE-2024-33978HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session cookie details via 'category' parameter in '/index.php'.

  • CVE-2024-33977HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session cookie details via 'view' parameter in /admin/orders/index.php'.

  • CVE-2024-33976HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an authenticated user and partially take over their browser session via 'id' parameter in…

  • CVE-2024-33975HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an authenticated user and partially take over their browser session via 'view' parameter in…

  • CVE-2024-41995HigAug 6, 2024
    risk 0.49cvss 7.5epss 0.01

    Initialization of a resource with an insecure default vulnerability exists in JavaTM Platform Ver.12.89 and earlier. If this vulnerability is exploited, the product may be affected by some known TLS1.0 and TLS1.1 vulnerabilities. As for the specific products/models/versions of…

  • CVE-2024-6203HigAug 6, 2024
    risk 0.54cvss 8.3epss 0.00

    HaloITSM versions up to 2.146.1 are affected by a Password Reset Poisoning vulnerability. Poisoned password reset links can be sent to existing HaloITSM users (given their email address is known). When these poisoned links get accessed (e.g. manually by the victim or…

  • CVE-2024-6200HigAug 6, 2024
    risk 0.52cvss 8.0epss 0.00

    HaloITSM versions up to 2.146.1 are affected by a Stored Cross-Site Scripting (XSS) vulnerability. The injected JavaScript code can execute arbitrary action on behalf of the user accessing a ticket. HaloITSM versions past 2.146.1 (and patches starting from 2.143.61 ) fix the…

  • CVE-2024-5709HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.01

    The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.7 via the 'layout_name' parameter. This makes it possible for authenticated attackers, with Author-level access and above, and with post permissions…