VYPR

CVEs

114,852 total · page 920 of 2,298

  • CVE-2024-7498HigAug 6, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been classified as critical. Affected is the function login/login2 of the file /admin/login.php of the component Admin Login Page. The manipulation of the argument username leads to sql injection.…

  • CVE-2024-5828HigAug 6, 2024
    risk 0.56cvss 8.6epss 0.00

    Expression Language Injection vulnerability in Hitachi Tuning Manager on Windows, Linux, Solaris allows Code Injection.This issue affects Hitachi Tuning Manager: before 8.8.7-00.

  • CVE-2024-7485HigAug 6, 2024
    risk 0.47cvss 7.2epss 0.00

    The Traffic Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page' parameter in the 'UserWebStat' AJAX function in all versions up to, and including, 1.4.5 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2024-7484HigAug 6, 2024
    risk 0.40cvss 7.2epss 0.01

    The CRM Perks Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'handle_uploaded_files' function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with administrator-level…

  • CVE-2024-6315HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.01

    The Blox Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handleUploadFile' function in all versions up to, and including, 1.0.65. This makes it possible for authenticated attackers, with contributor-level and…

  • CVE-2023-5000HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.01

    The Horizontal scrolling announcements plugin for WordPress is vulnerable to SQL Injection via the plugin's 'hsas-shortcode' shortcode in versions up to, and including, 2.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…

  • CVE-2024-7547HigAug 6, 2024
    risk 0.51cvss 7.8epss 0.00

    oFono SMS Decoder Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to…

  • CVE-2024-7546HigAug 6, 2024
    risk 0.51cvss 7.8epss 0.00

    oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to…

  • CVE-2024-7545HigAug 6, 2024
    risk 0.51cvss 7.8epss 0.00

    oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to…

  • CVE-2024-7544HigAug 6, 2024
    risk 0.51cvss 7.8epss 0.00

    oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to…

  • CVE-2024-7543HigAug 6, 2024
    risk 0.51cvss 7.8epss 0.00

    oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to…

  • CVE-2024-7539HigAug 6, 2024
    risk 0.51cvss 7.8epss 0.00

    oFono CUSD Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this…

  • CVE-2024-7538HigAug 6, 2024
    risk 0.51cvss 7.8epss 0.00

    oFono CUSD AT Command Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to…

  • CVE-2024-42352HigAug 5, 2024
    risk 0.49cvss 8.6epss 0.01

    Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. `nuxt/icon` provides an API to allow client side icon lookup. This endpoint is at `/api/_nuxt_icon/[name]`. The proxied request path is improperly parsed, allowing an…

  • CVE-2024-34344HigAug 5, 2024
    risk 0.57cvss 8.8epss 0.01

    Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Due to the insufficient validation of the `path` parameter in the NuxtTestComponentWrapper, an attacker can execute arbitrary JavaScript on the server side, which allows them…

  • CVE-2024-23657HigAug 5, 2024
    risk 0.57cvss 8.8epss 0.01

    Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Nuxt Devtools is missing authentication on the `getTextAssetContent` RPC function which is vulnerable to path traversal. Combined with a lack of Origin checks on the…

  • CVE-2024-41959HigAug 5, 2024
    risk 0.00cvss 7.6epss 0.00

    mailcow: dockerized is an open source groupware/email suite based on docker. An unauthenticated attacker can inject a JavaScript payload into the API logs. This payload is executed whenever the API logs page is viewed, potentially allowing an attacker to run malicious scripts in…

  • CVE-2024-42010HigAug 5, 2024
    risk 0.46cvss 7.5epss 0.53

    mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail messages, allowing a remote attacker to obtain sensitive information.

  • CVE-2024-41376HigAug 5, 2024
    risk 0.57cvss 8.8epss 0.01

    dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.

  • CVE-2024-40531HigAug 5, 2024
    risk 0.57cvss 8.8epss 0.00

    A mass assignment vulnerability exists in Pantera CRM versions 401.152 and 402.072. This flaw allows authenticated users to modify any user attribute, including roles, by injecting additional parameters via profile management functions.

  • CVE-2024-40530HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in Pantera CRM versions 401.152 and 402.072 allows unauthorized attackers to bypass IP-based access controls by manipulating the X-Forwarded-For header.

  • CVE-2024-21980HigAug 5, 2024
    risk 0.51cvss 7.9epss 0.00

    Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity.

  • CVE-2024-33034HigAug 5, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time.

  • CVE-2024-33028HigAug 5, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.

  • CVE-2024-33027HigAug 5, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.

  • CVE-2024-33026HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp.

  • CVE-2024-33025HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.

  • CVE-2024-33024HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE length.

  • CVE-2024-33023HigAug 5, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.

  • CVE-2024-33022HigAug 5, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption while allocating memory in HGSL driver.

  • CVE-2024-33021HigAug 5, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption while processing IOCTL call to set metainfo.

  • CVE-2024-33020HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing TID-to-link mapping IE elements.

  • CVE-2024-33019HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing the received TID-to-link mapping action frame.

  • CVE-2024-33018HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame.

  • CVE-2024-33015HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report.

  • CVE-2024-33014HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing ESP IE from beacon/probe response frame.

  • CVE-2024-33013HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length.

  • CVE-2024-33012HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.

  • CVE-2024-33011HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.

  • CVE-2024-33010HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing fragments of MBSSID IE from beacon frame.

  • CVE-2024-23384HigAug 5, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker.

  • CVE-2024-23383HigAug 5, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption when kernel driver attempts to trigger hardware fences.

  • CVE-2024-23382HigAug 5, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption while processing graphics kernel driver request to create DMA fence.

  • CVE-2024-23381HigAug 5, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption when memory mapped in a VBO is not unmapped by the GPU SMMU.

  • CVE-2024-23356HigAug 5, 2024
    risk 0.51cvss 7.8epss 0.00

    Memory corruption during session sign renewal request calls in HLOS.

  • CVE-2024-23355HigAug 5, 2024
    risk 0.51cvss 7.8epss 0.00

    Memory corruption when keymaster operation imports a shared key.

  • CVE-2024-23353HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.

  • CVE-2024-23352HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.

  • CVE-2024-21481HigAug 5, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.

  • CVE-2024-21479HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS during music playback of ALAC content.