VYPR

CVEs

113,626 total · page 978 of 2,273

  • CVE-2023-27323HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Parallels Desktop Updater Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code…

  • CVE-2023-27322HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Parallels Desktop Service Improper Initialization Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code…

  • CVE-2024-34402HigMay 3, 2024
    risk 0.00cvss 8.6epss 0.01

    An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.

  • CVE-2024-34033HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    Delta Electronics DIAEnergie has insufficient input validation which makes it possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the original file will be overwritten.…

  • CVE-2024-34032HigMay 3, 2024
    risk 0.58cvss 8.8epss 0.09

    Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the GetDIACloudList endpoint. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed.

  • CVE-2024-34031HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the script Handler_CFG.ashx. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed.

  • CVE-2024-30306HigMay 2, 2024
    risk 0.51cvss 7.8epss 0.01

    Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute…

  • CVE-2024-30305HigMay 2, 2024
    risk 0.51cvss 7.8epss 0.01

    Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2024-30304HigMay 2, 2024
    risk 0.51cvss 7.8epss 0.01

    Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2024-30303HigMay 2, 2024
    risk 0.51cvss 7.8epss 0.01

    Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2024-30301HigMay 2, 2024
    risk 0.51cvss 7.8epss 0.01

    Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2024-25047HigMay 2, 2024
    risk 0.56cvss 8.6epss 0.01

    IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection attacks in application logging by not sanitizing user provided data. This could lead to further attacks against the system. IBM X-Force ID: 282956.

  • CVE-2024-4140HigMay 2, 2024
    risk 0.00cvss 7.5epss 0.01

    An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts.

  • CVE-2024-34394HigMay 2, 2024
    risk 0.53cvss 8.1epss 0.01

    libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespaces() function (which invokes XmlNode::get_local_namespaces()) on a grand-child of a node that refers to an entity. This vulnerability can lead to denial of…

  • CVE-2024-34393HigMay 2, 2024
    risk 0.53cvss 8.1epss 0.01

    libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking a function on the result of attrs() that was called on a parsed node. This vulnerability might lead to denial of service (on both 32-bit systems and 64-bit systems),…

  • CVE-2024-34392HigMay 2, 2024
    risk 0.53cvss 8.1epss 0.01

    libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespaces() function (which invokes _wrap__xmlNode_nsDef_get()) on a grand-child of a node that refers to an entity. This vulnerability can lead to denial of service…

  • CVE-2024-34391HigMay 2, 2024
    risk 0.53cvss 8.1epss 0.01

    libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking a function on the result of attrs() that was called on a parsed node. This vulnerability might lead to denial of service (on both 32-bit systems and 64-bit systems), data…

  • CVE-2024-33396HigMay 2, 2024
    risk 0.55cvss 8.4epss 0.00

    An issue in karmada-io karmada v1.9.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

  • CVE-2024-4216HigMay 2, 2024
    risk 0.41cvss 7.4epss 0.00

    pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end.

  • CVE-2024-4215HigMay 2, 2024
    risk 0.41cvss 7.4epss 0.01

    pgAdmin <= 8.5 is affected by a multi-factor authentication bypass vulnerability. This vulnerability allows an attacker with knowledge of a legitimate account’s username and password may authenticate to the application and perform sensitive actions within the application, such…

  • CVE-2024-4097HigMay 2, 2024
    risk 0.47cvss 7.2epss 0.01

    The Cost Calculator Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature in all versions up to, and including, 3.1.67 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

  • CVE-2024-4033HigMay 2, 2024
    risk 0.57cvss 8.8epss 0.02

    The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the aiovg_create_attachment_from_external_image_url function in all versions up to, and including, 3.6.4. This makes it possible for authenticated…

  • CVE-2024-3895HigMay 2, 2024
    risk 0.50cvss 8.8epss 0.01

    The WP Datepicker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpdp_add_new_datepicker_ajax() function in all versions up to, and including, 2.1.0. This makes it possible for authenticated attackers, with …

  • CVE-2024-3849HigMay 2, 2024
    risk 0.57cvss 8.8epss 0.02

    The Click to Chat – HoliThemes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.35. This makes it possible for authenticated attackers, with contributor access or above, to include and execute arbitrary files on the server,…

  • CVE-2024-3715HigMay 2, 2024
    risk 0.47cvss 7.2epss 0.01

    The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

  • CVE-2024-3500HigMay 2, 2024
    risk 0.57cvss 8.8epss 0.01

    The ElementsKit Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.0 via the Price Menu, Hotspot, and Advanced Toggle widgets. This makes it possible for authenticated attackers, with contributor-level access and above, to…

  • CVE-2024-3499HigMay 2, 2024
    risk 0.50cvss 8.8epss 0.01

    The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the generate_navigation_markup function of the Onepage Scroll module. This makes it possible for authenticated attackers, with…

  • CVE-2024-3047HigMay 2, 2024
    risk 0.40cvss 7.2epss 0.00

    The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.8.0 via the transform() function. This can allow unauthenticated attackers to make web requests to arbitrary locations…

  • CVE-2024-3045HigMay 2, 2024
    risk 0.40cvss 7.2epss 0.01

    The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2024-2831HigMay 2, 2024
    risk 0.57cvss 8.8epss 0.01

    The Calendar plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcodes in all versions up to, and including, 1.3.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…

  • CVE-2024-2661HigMay 2, 2024
    risk 0.57cvss 8.8epss 0.01

    The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. plugin for WordPress is vulnerable to blind SQL Injection via the ‘currentIds’ parameter in all versions up to, and including, 1.5.4 due to insufficient…

  • CVE-2024-2417HigMay 2, 2024
    risk 0.50cvss 8.8epss 0.01

    The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the form_save_action() function in all versions up to, and including, 3.1.5. This…

  • CVE-2024-2082HigMay 2, 2024
    risk 0.47cvss 7.2epss 0.00

    The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 2.9.9.7 due to insufficient input sanitization and output escaping. This makes…

  • CVE-2024-25290HigMay 2, 2024
    risk 0.52cvss 8.0epss 0.01

    An issue in Casa Systems NL1901ACV R6B032 allows a remote attacker to execute arbitrary code via the userName parameter of the add function.

  • CVE-2024-1945HigMay 2, 2024
    risk 0.46cvss 7.1epss 0.00

    The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'arflite_remove_preview_data' function in all versions up to, and including, 1.6.4. This…

  • CVE-2024-1897HigMay 2, 2024
    risk 0.49cvss 7.5epss 0.01

    The Grid Gallery – Photo Image Grid Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.3 via deserialization via shortcode of untrusted input from the awl_gg_settings_ meta value. This makes it possible for…

  • CVE-2024-1896HigMay 2, 2024
    risk 0.49cvss 7.5epss 0.01

    The Photo Gallery – Responsive Photo Gallery, Image Gallery, Portfolio Gallery, Logo Gallery And Team Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.2 via deserialization via shortcode of untrusted input from the…

  • CVE-2024-1797HigMay 2, 2024
    risk 0.57cvss 8.8epss 0.01

    The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to SQL Injection via the 'status' and 'id' attributes of the 'wp_ulike_counter' and 'wp_ulike' shortcodes in all versions up to, and including, 4.6.9 due to insufficient escaping on the…

  • CVE-2024-1567HigMay 2, 2024
    risk 0.46cvss 8.2epss 0.01

    The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_validity' function in all versions up to, and including, 1.3.94. This makes it possible for unauthenticated attackers to upload…

  • CVE-2024-1173HigMay 2, 2024
    risk 0.40cvss 7.2epss 0.01

    The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all versions up to, and including, 1.13.1 due to insufficient escaping on the user supplied…

  • CVE-2023-7064HigMay 2, 2024
    risk 0.42cvss 7.5epss 0.01

    The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.17.5 via deserialization of untrusted input from the vulnerable 'id' parameter in the 'auxin_template_control_importer' function.…

  • CVE-2023-6961HigMay 2, 2024
    risk 0.47cvss 7.2epss 0.00

    The WP Meta SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Referer’ header in all versions up to, and including, 4.5.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

  • CVE-2023-6214HigMay 2, 2024
    risk 0.42cvss 7.5epss 0.01

    The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.6 via the purchased_products function. This makes it possible for unauthenticatied attackers to extract sensitive data…

  • CVE-2024-33530HigMay 2, 2024
    risk 0.49cvss 7.5epss 0.01

    In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the disclosure of the meeting password when a user is invited to a call after waiting in the lobby.

  • CVE-2024-31964HigMay 2, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an unauthenticated attacker to conduct an authentication bypass attack due to improper authentication…

  • CVE-2024-29309HigMay 2, 2024
    risk 0.50cvss 7.7epss 0.01

    An issue in Alfresco Content Services v.23.3.0.7 allows a remote attacker to execute arbitrary code via the Transfer Service.

  • CVE-2023-50685HigMay 2, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in Hipcam Cameras RealServer v.1.0 allows a remote attacker to cause a denial of service via a crafted script to the client_port parameter.

  • CVE-2024-3544HigMay 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated attackers can perform actions, using SSH private keys, by knowing the IP address and having access to the same network of one of the machines in the HA or Cluster group. This vulnerability has been closed by enhancing LoadMaster partner communications to require…

  • CVE-2024-34145HigMay 2, 2024
    risk 0.57cvss 8.8epss 0.01

    A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to…

  • CVE-2024-33303HigMay 2, 2024
    risk 0.53cvss 8.2epss 0.01

    SourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" under Add Users.