VYPR

CVEs

114,096 total · page 953 of 2,282

  • CVE-2024-30165HigMay 28, 2024
    risk 0.46cvss 7.1epss 0.00

    Amazon AWS Client VPN before 3.9.1 on macOS has a buffer overflow that could potentially allow a local actor to execute arbitrary commands with elevated permissions, a different vulnerability than CVE-2024-30164.

  • CVE-2024-26024HigMay 28, 2024
    risk 0.55cvss 8.4epss 0.00

    SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in Substation Server.

  • CVE-2024-30212HigMay 28, 2024
    risk 0.39cvss epss 0.01

    If a SCSI READ(10) command is initiated via USB using the largest LBA (0xFFFFFFFF) with it's default block size of 512 and a count of 1, the first 512 byte of the 0x80000000 memory area is returned to the user. If the block count is increased, the full RAM can be exposed. …

  • CVE-2024-24959HigMay 28, 2024
    risk 0.53cvss 8.2epss 0.01

    Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based memory corruption. An attacker can send malicious packets to…

  • CVE-2024-24958HigMay 28, 2024
    risk 0.53cvss 8.2epss 0.01

    Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based memory corruption. An attacker can send malicious packets to…

  • CVE-2024-24957HigMay 28, 2024
    risk 0.53cvss 8.2epss 0.00

    Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based memory corruption. An attacker can send malicious packets to…

  • CVE-2024-24956HigMay 28, 2024
    risk 0.53cvss 8.2epss 0.01

    Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based memory corruption. An attacker can send malicious packets to…

  • CVE-2024-24955HigMay 28, 2024
    risk 0.53cvss 8.2epss 0.00

    Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based memory corruption. An attacker can send malicious packets to…

  • CVE-2024-24954HigMay 28, 2024
    risk 0.53cvss 8.2epss 0.01

    Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based memory corruption. An attacker can send malicious packets to…

  • CVE-2024-24947HigMay 28, 2024
    risk 0.53cvss 8.2epss 0.01

    A heap-based buffer overflow vulnerability exists in the Programming Software Connection CurrDir functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to denial of service. An attacker can send an unauthenticated packet to trigger these…

  • CVE-2024-24946HigMay 28, 2024
    risk 0.53cvss 8.2epss 0.01

    A heap-based buffer overflow vulnerability exists in the Programming Software Connection CurrDir functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to denial of service. An attacker can send an unauthenticated packet to trigger these…

  • CVE-2024-24851HigMay 28, 2024
    risk 0.49cvss 7.5epss 0.01

    A heap-based buffer overflow vulnerability exists in the Programming Software Connection FiBurn functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to a buffer overflow. An attacker can send an unauthenticated packet to trigger this…

  • CVE-2024-23315HigMay 28, 2024
    risk 0.49cvss 7.5epss 0.01

    A read-what-where vulnerability exists in the Programming Software Connection IMM 01A1 Memory Read functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to a disclosure of sensitive information. An attacker can send an unauthenticated…

  • CVE-2024-3969HigMay 28, 2024
    risk 0.51cvss 7.8epss 0.01

    XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to remote code execution by parsing untrusted XML payload

  • CVE-2024-35399HigMay 28, 2024
    risk 0.57cvss 8.8epss 0.00

    TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the password parameter in the function loginAuth

  • CVE-2024-35397HigMay 28, 2024
    risk 0.58cvss 8.8epss 0.15

    TOTOLINK CP900L v4.1.5cu.798_B20221228 weas discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2024-29072HigMay 28, 2024
    risk 0.53cvss 8.2epss 0.00

    A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of the updater executable before executing it. A low privilege user can trigger the update action which can result in unexpected…

  • CVE-2024-24686HigMay 28, 2024
    risk 0.51cvss 7.8epss 0.01

    Multiple stack-based buffer overflow vulnerabilities exist in the readOFF functionality of libigl v2.5.0. A specially crafted .off file can lead to stack-based buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability concerns the…

  • CVE-2024-24685HigMay 28, 2024
    risk 0.51cvss 7.8epss 0.01

    Multiple stack-based buffer overflow vulnerabilities exist in the readOFF functionality of libigl v2.5.0. A specially crafted .off file can lead to stack-based buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability concerns the…

  • CVE-2024-24684HigMay 28, 2024
    risk 0.51cvss 7.8epss 0.01

    Multiple stack-based buffer overflow vulnerabilities exist in the readOFF functionality of libigl v2.5.0. A specially crafted .off file can lead to stack-based buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability concerns the…

  • CVE-2024-23951HigMay 28, 2024
    risk 0.57cvss 8.8epss 0.01

    Multiple improper array index validation vulnerabilities exist in the readMSH functionality of libigl v2.5.0. A specially crafted .msh file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability concerns the…

  • CVE-2024-23950HigMay 28, 2024
    risk 0.57cvss 8.8epss 0.01

    Multiple improper array index validation vulnerabilities exist in the readMSH functionality of libigl v2.5.0. A specially crafted .msh file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability concerns the…

  • CVE-2024-23949HigMay 28, 2024
    risk 0.57cvss 8.8epss 0.01

    Multiple improper array index validation vulnerabilities exist in the readMSH functionality of libigl v2.5.0. A specially crafted .msh file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability concerns the…

  • CVE-2024-23948HigMay 28, 2024
    risk 0.57cvss 8.8epss 0.01

    Multiple improper array index validation vulnerabilities exist in the readMSH functionality of libigl v2.5.0. A specially crafted .msh file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability concerns the…

  • CVE-2024-23947HigMay 28, 2024
    risk 0.57cvss 8.8epss 0.01

    Multiple improper array index validation vulnerabilities exist in the readMSH functionality of libigl v2.5.0. A specially crafted .msh file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability concerns the…

  • CVE-2024-22181HigMay 28, 2024
    risk 0.51cvss 7.8epss 0.00

    An out-of-bounds write vulnerability exists in the readNODE functionality of libigl v2.5.0. A specially crafted .node file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2023-49600HigMay 28, 2024
    risk 0.53cvss 8.1epss 0.01

    An out-of-bounds write vulnerability exists in the PlyFile ply_cast_ascii functionality of libigl v2.5.0. A specially crafted .ply file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2023-35953HigMay 28, 2024
    risk 0.51cvss 7.8epss 0.01

    Multiple stack-based buffer overflow vulnerabilities exist in the readOFF.cpp functionality of libigl v2.4.0. A specially-crafted .off file can lead to a buffer overflow. An attacker can arbitrary code execution to trigger these vulnerabilities.This vulnerability exists within…

  • CVE-2023-35952HigMay 28, 2024
    risk 0.51cvss 7.8epss 0.01

    Multiple stack-based buffer overflow vulnerabilities exist in the readOFF.cpp functionality of libigl v2.4.0. A specially-crafted .off file can lead to a buffer overflow. An attacker can arbitrary code execution to trigger these vulnerabilities.This vulnerability exists within…

  • CVE-2023-35951HigMay 28, 2024
    risk 0.51cvss 7.8epss 0.01

    Multiple stack-based buffer overflow vulnerabilities exist in the readOFF.cpp functionality of libigl v2.4.0. A specially-crafted .off file can lead to a buffer overflow. An attacker can arbitrary code execution to trigger these vulnerabilities.This vulnerability exists within…

  • CVE-2023-35950HigMay 28, 2024
    risk 0.51cvss 7.8epss 0.01

    Multiple stack-based buffer overflow vulnerabilities exist in the readOFF.cpp functionality of libigl v2.4.0. A specially-crafted .off file can lead to a buffer overflow. An attacker can arbitrary code execution to trigger these vulnerabilities.This vulnerability exists within…

  • CVE-2023-35949HigMay 28, 2024
    risk 0.51cvss 7.8epss 0.01

    Multiple stack-based buffer overflow vulnerabilities exist in the readOFF.cpp functionality of libigl v2.4.0. A specially-crafted .off file can lead to a buffer overflow. An attacker can arbitrary code execution to trigger these vulnerabilities.This vulnerability exists within…

  • CVE-2024-5415HigMay 28, 2024
    risk 0.46cvss 7.1epss 0.00

    A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS through /phpmybackuppro/backup.php, 'comments' and 'db' parameters. This vulnerabilities could allow an attacker to create a specially crafted URL and send it…

  • CVE-2024-5414HigMay 28, 2024
    risk 0.46cvss 7.1epss 0.00

    A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS through /phpmybackuppro/get_file.php, 'view' parameter. This vulnerabilities could allow an attacker to create a specially crafted URL and send it to a victim…

  • CVE-2024-5413HigMay 28, 2024
    risk 0.46cvss 7.1epss 0.00

    A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS through /phpmybackuppro/scheduled.php, all parameters. This vulnerabilities could allow an attacker to create a specially crafted URL and send it to a victim…

  • CVE-2024-3657HigMay 28, 2024
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of service

  • CVE-2024-5411HigMay 28, 2024
    risk 0.59cvss 8.8epss 0.23

    Missing input validation and OS command integration of the input in the ORing IAP-420 web-interface allows authenticated command injection.This issue affects IAP-420 version 2.01e and below.

  • CVE-2023-52712HigMay 28, 2024
    risk 0.51cvss 7.8epss 0.00

    Various Issues Due To Exposed SMI Handler in AmdPspP2CmboxV2. The first issue can be leveraged to bypass the protections that have been put in place by previous UEFI phases to prevent direct access to the SPI flash. The second issue can be used to both leak and corrupt SMM…

  • CVE-2023-52711HigMay 28, 2024
    risk 0.51cvss 7.8epss 0.00

    Various Issues Due To Exposed SMI Handler in AmdPspP2CmboxV2. The first issue can be leveraged to bypass the protections that have been put in place by previous UEFI phases to prevent direct access to the SPI flash. The second issue can be used to both leak and corrupt SMM…

  • CVE-2023-52710HigMay 28, 2024
    risk 0.51cvss 7.8epss 0.00

    Huawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26), As the communication buffer size hasn’t been properly validated to be of the expected size, it can partially overlap with the beginning SMRAM.This can be leveraged by a malicious OS attacker to corrupt data structures stored…

  • CVE-2023-52548HigMay 28, 2024
    risk 0.51cvss 7.8epss 0.00

    Huawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26) Arbitrary Memory Corruption in SMI Handler of ThisiServicesSmm SMM module. This can be leveraged by a malicious OS attacker to corrupt arbitrary SMRAM memory and, in turn, lead to code execution in SMM

  • CVE-2023-52547HigMay 28, 2024
    risk 0.51cvss 7.8epss 0.00

    Huawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26. Memory Corruption in SMI Handler of HddPassword SMM Module. This can be leveraged by a malicious OS attacker to corrupt data structures stored at the beginning of SMRAM and can potentially lead to code execution in SMM.

  • CVE-2022-48681HigMay 28, 2024
    risk 0.47cvss 7.2epss 0.00

    Some Huawei smart speakers have a memory overflow vulnerability. Successful exploitation of this vulnerability may cause certain functions to fail.

  • CVE-2024-28886HigMay 28, 2024
    risk 0.55cvss 8.4epss 0.01

    OS command injection vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product opens a crafted UTAU project file (.ust file), an arbitrary OS command may be executed.

  • CVE-2024-29078HigMay 28, 2024
    risk 0.49cvss 7.5epss 0.00

    Incorrect permission assignment for critical resource issue exists in MosP kintai kanri V4.6.6 and earlier, which may allow a remote unauthenticated attacker with access to the product to alter the product settings.

  • CVE-2024-36428HigMay 27, 2024
    risk 0.53cvss 8.1epss 0.02

    OrangeHRM 3.3.3 allows admin/viewProjects sortOrder SQL injection.

  • CVE-2024-36426HigMay 27, 2024
    risk 0.49cvss 7.5epss 0.00

    In TARGIT Decision Suite 23.2.15007.0 before Autumn 2023, the session token is part of the URL and may be sent in a cleartext HTTP session.

  • CVE-2024-29415HigMay 27, 2024
    risk 0.46cvss 8.1epss 0.08

    The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, and ::fFFf:127.0.0.1) are improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix…

  • CVE-2024-35237HigMay 27, 2024
    risk 0.42cvss 7.5epss 0.01

    MIT IdentiBot is an open-source Discord bot written in Node.js that verifies individuals' affiliations with MIT, grants them roles in a Discord server, and stores information about them in a database backend. A vulnerability that exists prior to commit…

  • CVE-2024-35231HigMay 27, 2024
    risk 0.49cvss 8.6epss 0.01

    rack-contrib provides contributed rack middleware and utilities for Rack, a Ruby web server interface. Versions of rack-contrib prior to 2.5.0 are vulnerable to denial of service due to the fact that the user controlled data `profiler_runs` was not constrained to any limitation.…