VYPR

CVEs

114,169 total · page 933 of 2,284

  • CVE-2024-6250HigJun 27, 2024
    risk 0.49cvss 7.5epss 0.02

    An absolute path traversal vulnerability exists in parisneo/lollms-webui v9.6, specifically in the `open_file` endpoint of `lollms_advanced.py`. The `sanitize_path` function with `allow_absolute_path=True` allows an attacker to access arbitrary files and directories on a Windows…

  • CVE-2024-6139HigJun 27, 2024
    risk 0.47cvss 7.3epss 0.01

    A path traversal vulnerability exists in the XTTS server of the parisneo/lollms package version v9.6. This vulnerability allows an attacker to write audio files to arbitrary locations on the system and enumerate file paths. The issue arises from improper validation of…

  • CVE-2024-6090HigJun 27, 2024
    risk 0.00cvss 7.5epss 0.01

    A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to delete any files ending in `.json` on the target system, leading to a denial of service as…

  • CVE-2024-6085HigJun 27, 2024
    risk 0.56cvss 8.6epss 0.01

    A path traversal vulnerability exists in the XTTS server included in the lollms package, version v9.6. This vulnerability arises from the ability to perform an unauthenticated root folder settings change. Although the read file endpoint is protected against path traversals, this…

  • CVE-2024-6038HigJun 27, 2024
    risk 0.00cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability is located in the filter_history function within the utils.py module. This function takes a user-provided keyword and attempts to match it…

  • CVE-2024-5979HigJun 27, 2024
    risk 0.42cvss 7.5epss 0.01

    In h2oai/h2o-3 version 3.46.0, the `run_tool` command in the `rapids` component allows the `main` function of any class under the `water.tools` namespace to be called. One such class, `MojoConvertTool`, crashes the server when invoked with an invalid argument, causing a denial…

  • CVE-2024-5885HigJun 27, 2024
    risk 0.56cvss 8.6epss 0.01

    stangirard/quivr version 0.0.236 contains a Server-Side Request Forgery (SSRF) vulnerability. The application does not provide sufficient controls when crawling a website, allowing an attacker to access applications on the local network. This vulnerability could allow a…

  • CVE-2024-5824HigJun 27, 2024
    risk 0.41cvss 7.4epss 0.00

    A path traversal vulnerability in the `/set_personality_config` endpoint of parisneo/lollms version 9.4.0 allows an attacker to overwrite the `configs/config.yaml` file. This can lead to remote code execution by changing server configuration properties such as…

  • CVE-2024-5820HigJun 27, 2024
    risk 0.57cvss 8.8epss 0.01

    An unprotected WebSocket connection in the latest version of stitionai/devika (commit ecee79f) allows a malicious website to connect to the backend and issue commands on behalf of the user. The backend serves all listeners on the given socket, enabling any such malicious website…

  • CVE-2024-4578HigJun 27, 2024
    risk 0.55cvss 8.4epss 0.00

    This Advisory describes an issue that impacts Arista Wireless Access Points. Any entity with the ability to authenticate via SSH to an affected AP as the “config” user is able to cause a privilege escalation via spawning a bash shell. The SSH CLI session does not require…

  • CVE-2024-3043HigJun 27, 2024
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated IEEE 802.15.4 'co-ordinator realignment' packet can be used to force Zigbee nodes to change their network identifier (pan ID), leading to a denial of service. This packet type is not useful in production and should be used only for PHY qualification.

  • CVE-2023-38370HigJun 27, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious packages. IBM X-Force ID: 261197.

  • CVE-2023-30998HigJun 27, 2024
    risk 0.51cvss 7.8epss 0.00

    IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254649.

  • CVE-2023-30997HigJun 27, 2024
    risk 0.51cvss 7.8epss 0.00

    IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254638.

  • CVE-2024-5548HigJun 27, 2024
    risk 0.00cvss 7.5epss 0.01

    A directory traversal vulnerability exists in the stitionai/devika repository, specifically within the /api/download-project endpoint. Attackers can exploit this vulnerability by manipulating the 'project_name' parameter in a GET request to download arbitrary files from the…

  • CVE-2024-5547HigJun 27, 2024
    risk 0.00cvss 7.5epss 0.01

    A directory traversal vulnerability exists in the /api/download-project-pdf endpoint of the stitionai/devika repository, affecting the latest version. The vulnerability arises due to insufficient sanitization of the 'project_name' parameter in the download_project_pdf function.…

  • CVE-2024-5334HigJun 27, 2024
    risk 0.00cvss 7.5epss 0.02

    A local file read vulnerability exists in the stitionai/devika repository, affecting the latest version. The vulnerability is due to improper handling of the 'snapshot_path' parameter in the '/api/get-browser-snapshot' endpoint. An attacker can exploit this vulnerability by…

  • CVE-2024-35260HigJun 27, 2024
    risk 0.52cvss 8.0epss 0.01

    An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.

  • CVE-2024-31916HigJun 27, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unauthorized actor that bypasses authentication channels. IBM X-ForceID: 290026.

  • CVE-2024-24792HigJun 27, 2024
    risk 0.42cvss 7.5epss 0.01

    Parsing a corrupt or malicious image with invalid color indices can cause a panic.

  • CVE-2024-39373HigJun 27, 2024
    risk 0.47cvss 7.2epss 0.01

    TELSAT marKoni FM Transmitters are vulnerable to a command injection vulnerability through the manipulation of settings and could allow an attacker to gain unauthorized access to the system with administrative privileges.

  • CVE-2024-39158HigJun 27, 2024
    risk 0.57cvss 8.8epss 0.00

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/userSys_deal.php?mudi=infoSet.

  • CVE-2024-39154HigJun 27, 2024
    risk 0.57cvss 8.8epss 0.00

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=del&dataType=word&dataTypeCN.

  • CVE-2024-6373HigJun 27, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in itsourcecode Online Food Ordering System up to 1.0 and classified as critical. This vulnerability affects unknown code of the file /addproduct.php. The manipulation of the argument photo leads to unrestricted upload. The attack can be initiated…

  • CVE-2024-6371HigJun 27, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in itsourcecode Pool of Bethesda Online Reservation System 1.0. Affected by this issue is some unknown functionality of the file controller.php. The manipulation of the argument rmtype_id leads to sql injection.…

  • CVE-2024-22232HigJun 27, 2024
    risk 0.43cvss 7.7epss 0.01

    A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary file from a Salt master’s filesystem.

  • CVE-2024-6054HigJun 27, 2024
    risk 0.57cvss 8.8epss 0.01

    The Auto Featured Image plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'create_post_attachment_from_url' function in all versions up to, and including, 1.2. This makes it possible for authenticated attackers, with…

  • CVE-2024-6323HigJun 27, 2024
    risk 0.49cvss 7.5epss 0.01

    Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to 17.1.1 allows an attacker leak content of a private repository in a public project.

  • CVE-2024-4901HigJun 27, 2024
    risk 0.59cvss 8.7epss 0.33

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit notes.

  • CVE-2024-28984HigJun 26, 2024
    risk 0.57cvss 8.8epss 0.00

    Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface.

  • CVE-2024-28983HigJun 26, 2024
    risk 0.57cvss 8.8epss 0.00

    Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface.

  • CVE-2024-28982HigJun 26, 2024
    risk 0.46cvss 7.1epss 0.00

    Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference.

  • CVE-2024-36829HigJun 26, 2024
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in Teldat M1 v11.00.05.50.01 allows attackers to obtain sensitive information via a crafted query string.

  • CVE-2024-23767HigJun 26, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered on HMS Anybus X-Gateway AB7832-F firmware version 3. The HICP protocol allows unauthenticated changes to a device's network configurations.

  • CVE-2024-23766HigJun 26, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes a web interface on port 80. An unauthenticated GET request to a specific URL triggers the reboot of the Anybus gateway (or at least most of its modules). An attacker can use this feature to…

  • CVE-2024-33329HigJun 26, 2024
    risk 0.49cvss 7.5epss 0.01

    A hardcoded privileged ID within Lumisxp v15.0.x to v16.1.x allows attackers to bypass authentication and access internal pages and other sensitive information.

  • CVE-2024-6354HigJun 26, 2024
    risk 0.47cvss 7.2epss 0.01

    Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user to bypass the execute permission via the use of the PAM dashboard.

  • CVE-2024-4758HigJun 26, 2024
    risk 0.49cvss 7.6epss 0.00

    The Muslim Prayer Time BD WordPress plugin through 2.4 does not have CSRF check in place when reseting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack

  • CVE-2024-34581HigJun 26, 2024
    risk 0.47cvss 7.3epss 0.00

    The W3C XML Signature Syntax and Processing (XMLDsig) specification, starting with 1.0, was originally published with a "RetrievalMethod is a URI ... that may be used to obtain key and/or certificate information" statement and no accompanying information about SSRF risks, and…

  • CVE-2024-37140HigJun 26, 2024
    risk 0.57cvss 8.8epss 0.01

    Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an OS command injection vulnerability in an admin operation. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS…

  • CVE-2024-29176HigJun 26, 2024
    risk 0.57cvss 8.8epss 0.01

    Dell PowerProtect DD, version(s) 8.0, 7.13.1.0, 7.10.1.30, 7.7.5.40, contain(s) an Out-of-bounds Write vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.

  • CVE-2024-5460HigJun 26, 2024
    risk 0.53cvss 8.1epss 0.01

    A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric OS versions before v9.0.0 could allow an authenticated, remote attacker to read data from an affected device via SNMP. The vulnerability is due to…

  • CVE-2024-4869HigJun 26, 2024
    risk 0.47cvss 7.2epss 0.00

    The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Client-IP’ header in all versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2024-38526HigJun 26, 2024
    risk 0.40cvss 7.2epss 0.04

    pdoc provides API Documentation for Python Projects. Documentation generated with `pdoc --math` linked to JavaScript files from polyfill.io. The polyfill.io CDN has been sold and now serves malicious code. This issue has been fixed in pdoc 14.5.1.

  • CVE-2024-37742HigJun 25, 2024
    risk 0.53cvss 8.2epss 0.01

    Insecure Access Control in Safe Exam Browser (SEB) = 3.5.0 on Windows. The vulnerability allows an attacker to share clipboard data between the SEB kiosk mode and the underlying system, compromising exam integrity. By exploiting this flaw, an attacker can bypass exam controls…

  • CVE-2024-5016HigJun 25, 2024
    risk 0.49cvss 7.2epss 0.22

    In WhatsUp Gold versions released before 2023.1.3, Distributed Edition installations can be exploited by using a deserialization tool to achieve a Remote Code Execution as SYSTEM.  The vulnerability exists in the main message processing routines NmDistributed.DistributedServic…

  • CVE-2024-5015HigJun 25, 2024
    risk 0.46cvss 7.1epss 0.01

    In WhatsUp Gold versions released before 2023.1.3, an authenticated SSRF vulnerability in Wug.UI.Areas.Wug.Controllers.SessionControler.Update allows a low privileged user to chain this SSRF with an Improper Access Control vulnerability. This can be used to escalate privileges…

  • CVE-2024-5014HigJun 25, 2024
    risk 0.46cvss 7.1epss 0.00

    In WhatsUp Gold versions released before 2023.1.3, a Server Side Request Forgery vulnerability exists in the GetASPReport feature. This allows any authenticated user to retrieve ASP reports from an HTML form.

  • CVE-2024-5013HigJun 25, 2024
    risk 0.49cvss 7.5epss 0.01

    In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Denial of Service vulnerability was identified. An unauthenticated attacker can put the application into the SetAdminPassword installation step, which renders the application non-accessible.

  • CVE-2024-5012HigJun 25, 2024
    risk 0.56cvss 8.6epss 0.00

    In WhatsUp Gold versions released before 2023.1.3, there is a missing authentication vulnerability in WUGDataAccess.Credentials. This vulnerability allows unauthenticated attackers to disclose Windows Credentials stored in the product Credential Library.