VYPR

CVEs

114,131 total · page 940 of 2,283

  • CVE-2024-38467HigJun 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized user information retrieval via the queryUser API.

  • CVE-2024-38461HigJun 16, 2024
    risk 0.49cvss 7.5epss 0.00

    irodsServerMonPerf in iRODS before 4.3.2 attempts to proceed with use of a path even if it is not a directory.

  • CVE-2024-38459HigJun 16, 2024
    risk 0.44cvss 7.8epss 0.00

    langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an opt-in step. NOTE; this issue exists because of an incomplete fix for CVE-2024-27444.

  • CVE-2024-38458HigJun 16, 2024
    risk 0.57cvss 8.8epss 0.01

    Xenforo before 2.2.16 allows code injection.

  • CVE-2024-38457HigJun 16, 2024
    risk 0.58cvss 8.8epss 0.07

    Xenforo before 2.2.16 allows CSRF.

  • CVE-2024-38440HigJun 16, 2024
    risk 0.49cvss 7.5epss 0.01

    Netatalk before 3.2.1 has an off-by-one error, and resultant heap-based buffer overflow and segmentation violation, because of incorrectly using FPLoginExt in BN_bin2bn in etc/uams/uams_dhx_pam.c. The original issue 1097 report stated: 'The latest version of Netatalk (v3.2.0)…

  • CVE-2024-38427HigJun 16, 2024
    risk 0.57cvss 8.8epss 0.01

    In International Color Consortium DemoIccMAX before 85ce74e, a logic flaw in CIccTagXmlProfileSequenceId::ParseXml in IccXML/IccLibXML/IccTagXml.cpp results in unconditionally returning false.

  • CVE-2024-27275HigJun 15, 2024
    risk 0.48cvss 7.4epss 0.00

    IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority requirement. A local user without administrator privilege can configure a physical file trigger to execute with the privileges of a user socially engineered to…

  • CVE-2024-6000HigJun 15, 2024
    risk 0.46cvss 7.1epss 0.01

    The FooEvents for WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability setting on the 'display_ticket_themes_page' function in versions up to, and including, 1.19.20. This makes it possible for authenticated…

  • CVE-2024-3813HigJun 15, 2024
    risk 0.57cvss 8.8epss 0.01

    The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8 via the 'td_block_title' shortcode 'block_template_id' attribute. This makes it possible for authenticated attackers, with contributor-level and above…

  • CVE-2024-2544HigJun 15, 2024
    risk 0.48cvss 7.4epss 0.00

    The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on all AJAX actions. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform multiple…

  • CVE-2023-6696HigJun 15, 2024
    risk 0.46cvss 8.1epss 0.00

    The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in all versions up to, and including, 4.3.1. While some functions…

  • CVE-2024-6003HigJun 14, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Guangdong Baolun Electronics IP Network Broadcasting Service Platform 2.0. It has been classified as critical. Affected is an unknown function of the file /api/v2/maps. The manipulation of the argument orderColumn leads to sql injection. It is…

  • CVE-2024-36600HigJun 14, 2024
    risk 0.00cvss 8.4epss 0.00

    Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a crafted ISO 9660 image file.

  • CVE-2024-36598HigJun 14, 2024
    risk 0.53cvss 8.1epss 0.01

    An arbitrary file upload vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary code via uploading a crafted image file.

  • CVE-2024-36597HigJun 14, 2024
    risk 0.57cvss 8.8epss 0.02

    Aegon Life v1.0 was discovered to contain a SQL injection vulnerability via the client_id parameter at clientStatus.php.

  • CVE-2024-24320HigJun 14, 2024
    risk 0.58cvss 8.8epss 0.04

    Directory Traversal vulnerability in Mgt-commerce CloudPanel v.2.0.0 thru v.2.4.0 allows a remote attacker to obtain sensitive information and execute arbitrary code via the service parameter of the load-logfiles function.

  • CVE-2024-37369HigJun 14, 2024
    risk 0.57cvss 8.8epss 0.00

    A privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edit scripts, bypassing Access Control Lists, and potentially gaining further access within the system.

  • CVE-2024-37882HigJun 14, 2024
    risk 0.00cvss 8.1epss 0.01

    Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions could reshare the item with more permissions. It is recommended that the Nextcloud Server is upgraded to 26.0.13 or 27.1.8 or 28.0.4 and that the Nextcloud Enterprise…

  • CVE-2024-37645HigJun 14, 2024
    risk 0.57cvss 8.8epss 0.01

    TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow vulnerability via the submit-url parameter at /formSysLog .

  • CVE-2024-37643HigJun 14, 2024
    risk 0.57cvss 8.8epss 0.01

    TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow vulnerability via the submit-url parameter at /formPasswordAuth .

  • CVE-2024-37641HigJun 14, 2024
    risk 0.57cvss 8.8epss 0.01

    TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow via the submit-url parameter at /formNewSchedule

  • CVE-2024-37644HigJun 14, 2024
    risk 0.57cvss 8.8epss 0.00

    TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.

  • CVE-2024-37368HigJun 14, 2024
    risk 0.49cvss 7.5epss 0.01

    A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. Due to the lack of proper authentication, this…

  • CVE-2024-37367HigJun 14, 2024
    risk 0.49cvss 7.5epss 0.01

    A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. This action is allowed without proper…

  • CVE-2024-37313HigJun 14, 2024
    risk 0.00cvss 7.3epss 0.00

    Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second factor of 2FA after successfully providing the user credentials. It is recommended that the Nextcloud Server is upgraded to 26.0.13, 27.1.8 or 28.0.4 and…

  • CVE-2024-34694HigJun 14, 2024
    risk 0.46cvss 8.1epss 0.01

    LNbits is a Lightning wallet and accounts system. Paying invoices in Eclair that do not get settled within the internal timeout (about 30s) lead to a payment being considered failed, even though it may still be in flight. This vulnerability can lead to a total loss of funds for…

  • CVE-2024-33377HigJun 14, 2024
    risk 0.53cvss 8.1epss 0.00

    LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attackers can cause victim users to perform arbitrary operations via interaction with crafted elements on the web page.

  • CVE-2024-37640HigJun 14, 2024
    risk 0.57cvss 8.8epss 0.01

    TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWiFiEasyGuestCfg.

  • CVE-2024-37639HigJun 14, 2024
    risk 0.57cvss 8.8epss 0.01

    TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via eport in the function setIpPortFilterRules.

  • CVE-2024-2024HigJun 14, 2024
    risk 0.57cvss 8.8epss 0.03

    The Folders Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_folders_file_upload' function in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with author access and…

  • CVE-2024-36459HigJun 14, 2024
    risk 0.55cvss epss 0.00

    A CRLF cross-site scripting vulnerability has been identified in certain configurations of the SiteMinder Web Agent for IIS Web Server and SiteMinder Web Agent for Domino Web Server. As a result, an attacker can execute arbitrary Javascript code in a client browser.

  • CVE-2024-5685HigJun 14, 2024
    risk 0.42cvss 7.6epss 0.00

    Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects snipe-it: from v4.6.17 through v6.4.1.

  • CVE-2024-5995HigJun 14, 2024
    risk 0.57cvss 8.8epss 0.00

    The notification emails sent by Soar Cloud HR Portal contain a link with a embedded session. The expiration of the session is not properly configured, remaining valid for more than 7 days and can be reused.

  • CVE-2024-36503HigJun 14, 2024
    risk 0.47cvss 7.3epss 0.00

    Memory management vulnerability in the Gralloc module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-36502HigJun 14, 2024
    risk 0.51cvss 7.9epss 0.00

    Out-of-bounds read vulnerability in the audio module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-36500HigJun 14, 2024
    risk 0.51cvss 7.8epss 0.00

    Privilege escalation vulnerability in the AMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-31163HigJun 14, 2024
    risk 0.47cvss 7.2epss 0.01

    ASUS Download Master has a buffer overflow vulnerability. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the device.

  • CVE-2024-31162HigJun 14, 2024
    risk 0.47cvss 7.2epss 0.01

    The specific function parameter of ASUS Download Master does not properly filter user input. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the device.

  • CVE-2024-5551HigJun 14, 2024
    risk 0.49cvss 7.5epss 0.00

    The WP STAGING Pro WordPress Backup Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6.0. This is due to missing or incorrect nonce validation on the 'sub' parameter called from the WP STAGING WordPress Backup Plugin…

  • CVE-2024-4404HigJun 14, 2024
    risk 0.55cvss 8.5epss 0.00

    The ElementsKit PRO plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.6.2 via the 'render_raw' function. This can allow authenticated attackers, with contributor-level permissions and above, to make web requests to arbitrary…

  • CVE-2024-3498HigJun 14, 2024
    risk 0.51cvss 7.8epss 0.00

    Attackers can then execute malicious files by enabling certain services of the printer via the web configuration page and elevate its privileges to root. As for the affected products/models/versions, see the reference URL.

  • CVE-2024-3497HigJun 14, 2024
    risk 0.57cvss 8.8epss 0.01

    Path traversal vulnerability in the web server of the Toshiba printer enables attacker to overwrite orginal files or add new ones to the printer. As for the affected products/models/versions, see the reference URL.

  • CVE-2024-3496HigJun 14, 2024
    risk 0.57cvss 8.8epss 0.01

    Attackers can bypass the web login authentication process to gain access to the printer's system information and upload malicious drivers to the printer. As for the affected products/models/versions, see the reference URL.

  • CVE-2024-1094HigJun 14, 2024
    risk 0.40cvss 7.3epss 0.01

    The Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the make_staff() function in all versions up to, and including,…

  • CVE-2024-31161HigJun 14, 2024
    risk 0.47cvss 7.2epss 0.01

    The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrative privilege can exploit this vulnerability to upload any file to any location. They may even upload malicious web page files to the website directory,…

  • CVE-2024-27178HigJun 14, 2024
    risk 0.47cvss 7.2epss 0.01

    An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying file name variable. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability…

  • CVE-2024-27177HigJun 14, 2024
    risk 0.47cvss 7.2epss 0.01

    An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying package name variable. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this…

  • CVE-2024-27176HigJun 14, 2024
    risk 0.47cvss 7.2epss 0.01

    An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying session ID variable. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability…

  • CVE-2024-27171HigJun 14, 2024
    risk 0.48cvss 7.4epss 0.01

    A remote attacker using the insecure upload functionality will be able to overwrite any Python file and get Remote Code Execution. As for the affected products/models/versions, see the reference URL.