VYPR

CVEs

114,016 total · page 969 of 2,281

  • CVE-2024-34818HigMay 14, 2024
    risk 0.39cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress.This issue affects WebinarPress: from n/a through 1.33.17.

  • CVE-2024-34707HigMay 14, 2024
    risk 0.42cvss 7.5epss 0.01

    Nautobot is a Network Source of Truth and Network Automation Platform. A Nautobot user with admin privileges can modify the `BANNER_TOP`, `BANNER_BOTTOM`, and `BANNER_LOGIN` configuration settings via the `/admin/constance/config/` endpoint. Normally these settings are used to…

  • CVE-2024-34697HigMay 14, 2024
    risk 0.00cvss 7.6epss 0.01

    FreeScout is a free, self-hosted help desk and shared mailbox. A stored HTML Injection vulnerability has been identified in the Email Receival Module of the Freescout Application. The vulnerability allows attackers to inject malicious HTML content into emails sent to the…

  • CVE-2024-34559HigMay 14, 2024
    risk 0.49cvss 7.5epss 0.01

    Insertion of Sensitive Information into Log File vulnerability in Ghost Foundation Ghost.This issue affects Ghost: from n/a through 1.4.0.

  • CVE-2024-34459HigMay 14, 2024
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer over-read in xmlHTMLPrintFileContext in xmllint.c.

  • CVE-2024-34431HigMay 14, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP-etracker WP etracker allows Reflected XSS.This issue affects WP etracker: from n/a through 1.0.2.

  • CVE-2024-34360HigMay 14, 2024
    risk 0.46cvss 8.2epss 0.01

    go-spacemesh is a Go implementation of the Spacemesh protocol full node. Nodes can publish activations transactions (ATXs) which reference the incorrect previous ATX of the Smesher that created the ATX. ATXs are expected to form a single chain from the newest to the first ATX…

  • CVE-2024-34351HigMay 14, 2024
    risk 0.42cvss 7.5epss 0.05

    Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Actions. If the `Host` header is modified, and the below conditions are also met, an attacker may be able…

  • CVE-2024-34350HigMay 14, 2024
    risk 0.42cvss 7.5epss 0.01

    Next.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsistent interpretation of a crafted HTTP request meant that requests are treated as both a single request, and two separate requests by Next.js, leading to…

  • CVE-2024-34345HigMay 14, 2024
    risk 0.46cvss 8.1epss 0.01

    The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML External entity injections were possible, when running the provided XML Validator on arbitrary input. This issue was fixed in version 6.7.1.

  • CVE-2024-34338HigMay 14, 2024
    risk 0.47cvss 7.2epss 0.03

    Tenda O3V2 with firmware versions V1.0.0.10 and V1.0.0.12 was discovered to contain a Blind Command Injection via dest parameter in /goform/getTraceroute. This vulnerability allows attackers to execute arbitrary commands with root privileges. Authentication is required to…

  • CVE-2024-34310HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    Jin Fang Times Content Management System v3.2.3 was discovered to contain a SQL injection vulnerability via the id parameter.

  • CVE-2024-34308HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the function urldecode.

  • CVE-2024-34231HigMay 14, 2024
    risk 0.46cvss 7.1epss 0.00

    A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the System Short Name parameter.

  • CVE-2024-34224HigMay 14, 2024
    risk 0.48cvss 7.3epss 0.01

    Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the firstname, middlename, lastname parameters.

  • CVE-2024-34221HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.

  • CVE-2024-34220HigMay 14, 2024
    risk 0.49cvss 7.5epss 0.01

    Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the 'leave' parameter.

  • CVE-2024-34219HigMay 14, 2024
    risk 0.58cvss 8.6epss 0.21

    TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allows attackers to log in through telnet.

  • CVE-2024-34217HigMay 14, 2024
    risk 0.50cvss 7.7epss 0.01

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the addWlProfileClientMode function.

  • CVE-2024-34215HigMay 14, 2024
    risk 0.47cvss 7.3epss 0.01

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setUrlFilterRules function.

  • CVE-2024-34212HigMay 14, 2024
    risk 0.47cvss 7.3epss 0.01

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the CloudACMunualUpdate function.

  • CVE-2024-34211HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.

  • CVE-2024-34210HigMay 14, 2024
    risk 0.48cvss 7.3epss 0.01

    TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the CloudACMunualUpdate function via the FileName parameter.

  • CVE-2024-34207HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setStaticDhcpConfig function.

  • CVE-2024-34205HigMay 14, 2024
    risk 0.48cvss 7.3epss 0.01

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the download_firmware function.

  • CVE-2024-34201HigMay 14, 2024
    risk 0.47cvss 7.3epss 0.01

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the getSaveConfig function.

  • CVE-2024-34200HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    TOTOLINK CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpQosRules function.

  • CVE-2024-34199HigMay 14, 2024
    risk 0.00cvss 8.6epss 0.01

    TinyWeb 1.94 and below allows unauthenticated remote attackers to cause a denial of service (Buffer Overflow) when sending excessively large elements in the request line.

  • CVE-2024-34196HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    Totolink AC1200 Wireless Dual Band Gigabit Router A3002RU_V3 Firmware V3.0.0-B20230809.1615 is vulnerable to Buffer Overflow. The "boa" program allows attackers to modify the value of the "vwlan_idx" field via "formMultiAP". This can lead to a stack overflow through the…

  • CVE-2024-34077HigMay 14, 2024
    risk 0.41cvss 7.3epss 0.01

    MantisBT (Mantis Bug Tracker) is an open source issue tracker. Insufficient access control in the registration and password reset process allows an attacker to reset another user's password and takeover their account, if the victim has an incomplete request pending. The exploit…

  • CVE-2024-33877HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5T__conv_struct_opt in H5Tconv.c.

  • CVE-2024-33873HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5D__scatter_mem in H5Dscatgath.c.

  • CVE-2024-33818HigMay 14, 2024
    risk 0.49cvss 7.5epss 0.01

    Globitel KSA SpeechLog v8.1 was discovered to contain an Insecure Direct Object Reference (IDOR) via the userID parameter.

  • CVE-2024-33250HigMay 14, 2024
    risk 0.47cvss 7.2epss 0.01

    An issue in Open-Source Technology Committee SRS real-time video server RS/4.0.268(Leo) and SRS/4.0.195(Leo) allows a remote attacker to execute arbitrary code via a crafted request.

  • CVE-2024-32997HigMay 14, 2024
    risk 0.55cvss 8.4epss 0.00

    Race condition vulnerability in the binder driver module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-32992HigMay 14, 2024
    risk 0.49cvss 7.5epss 0.01

    Insufficient verification vulnerability in the baseband module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-32991HigMay 14, 2024
    risk 0.49cvss 7.5epss 0.01

    Permission verification vulnerability in the wpa_supplicant module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-32739HigMay 14, 2024
    risk 0.49cvss 7.5epss 0.05

    A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_verbose" function within MCUDBHelper.

  • CVE-2024-32738HigMay 14, 2024
    risk 0.49cvss 7.5epss 0.05

    A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_lean" function within MCUDBHelper.

  • CVE-2024-32737HigMay 14, 2024
    risk 0.49cvss 7.5epss 0.05

    A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_contract_result" function within MCUDBHelper.

  • CVE-2024-32736HigMay 14, 2024
    risk 0.49cvss 7.5epss 0.05

    A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_utask_verbose" function within MCUDBHelper.

  • CVE-2024-32724HigMay 14, 2024
    risk 0.49cvss 7.5epss 0.01

    Missing Authorization vulnerability in Woo product importer Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy.This issue affects Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy: from n/a through 2.1.1.

  • CVE-2024-32712HigMay 14, 2024
    risk 0.42cvss 7.5epss 0.00

    Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.14.

  • CVE-2024-32655HigMay 14, 2024
    risk 0.46cvss 8.1epss 0.02

    Npgsql is the .NET data provider for PostgreSQL. The `WriteBind()` method in `src/Npgsql/Internal/NpgsqlConnector.FrontendMessages.cs` uses `int` variables to store the message length and the sum of parameter lengths. Both variables overflow when the sum of parameter lengths…

  • CVE-2024-32624HigMay 14, 2024
    risk 0.48cvss 7.4epss 0.01

    HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__ref_mem_setnull in H5Tref.c (called from H5T__conv_ref in H5Tconv.c), resulting in the corruption of the instruction pointer.

  • CVE-2024-32623HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5VM_array_fill in H5VM.c (called from H5S_select_elements in H5Spoint.c).

  • CVE-2024-32620HigMay 14, 2024
    risk 0.48cvss 7.4epss 0.00

    HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c, resulting in the corruption of the instruction pointer.

  • CVE-2024-32619HigMay 14, 2024
    risk 0.48cvss 7.4epss 0.00

    HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T_copy_reopen in H5T.c, resulting in the corruption of the instruction pointer.

  • CVE-2024-32618HigMay 14, 2024
    risk 0.48cvss 7.4epss 0.00

    HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__get_native_type in H5Tnative.c, resulting in the corruption of the instruction pointer.

  • CVE-2024-32617HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdup in H5MM_xstrdup in H5MM.c (called from H5G__ent_to_link in H5Glink.c).