VYPR

CVEs

113,625 total · page 982 of 2,273

  • CVE-2024-1895HigApr 30, 2024
    risk 0.42cvss 7.5epss 0.01

    The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.9 via deserialization via shortcode of untrusted input from a custom meta value. This makes it possible…

  • CVE-2024-4225HigApr 30, 2024
    risk 0.49cvss 7.6epss 0.00

    Multiple security vulnerabilities has been discovered in web interface of NetGuardian DIN Remote Telemetry Unit (RTU), by DPS Telecom. Attackers can exploit those security vulnerabilities to perform critical actions such as escalate user's privilege, steal user's credential,…

  • CVE-2024-31837HigApr 30, 2024
    risk 0.48cvss 8.4epss 0.00

    DMitry (Deepmagic Information Gathering Tool) 1.3a has a format-string vulnerability, with a threat model similar to CVE-2017-7938.

  • CVE-2024-34050HigApr 30, 2024
    risk 0.49cvss 7.5epss 0.01

    Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return uint64(b[2])<<16 | uint64(b[1])<<8 | uint64(b[0])" in reader.go.

  • CVE-2024-34049HigApr 30, 2024
    risk 0.49cvss 7.5epss 0.01

    Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return plmnIdString[0:3], plmnIdString[3:]" in reader.go.

  • CVE-2024-34046HigApr 30, 2024
    risk 0.49cvss 7.5epss 0.01

    The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->sctpParams->e2tCounters[IN_SUCC][MSG_COUNTER][ProcedureCode_id_RICsubscription]->Increment().

  • CVE-2024-34045HigApr 30, 2024
    risk 0.49cvss 7.5epss 0.01

    The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->counters[IN_INITI][MSG_COUNTER][ProcedureCode_id_E2setup]->Increment().

  • CVE-2023-52727HigApr 30, 2024
    risk 0.53cvss 8.1epss 0.01

    Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 allows an index out-of-range condition in parseAlignBits.

  • CVE-2023-52724HigApr 30, 2024
    risk 0.53cvss 8.1epss 0.01

    Open Networking Foundation SD-RAN onos-kpimon 0.4.7 allows out-of-bounds array access in the processIndicationFormat1 function.

  • CVE-2024-27518HigApr 29, 2024
    risk 0.51cvss 7.8epss 0.01

    An issue in SUPERAntiSyware Professional X 10.0.1262 and 10.0.1264 allows unprivileged attackers to escalate privileges via a restore of a crafted DLL file into the C:\Program Files\SUPERAntiSpyware folder.

  • CVE-2023-46960HigApr 29, 2024
    risk 0.56cvss 8.6epss 0.01

    Buffer Overflow vulnerability in PyPXE v.1.8.4 allows a remote attacker to cause a denial of service via the handle function in the tftp module.

  • CVE-2023-46566HigApr 29, 2024
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability in msoulier tftpy commit 467017b844bf6e31745138a30e2509145b0c529c allows a remote attacker to cause a denial of service via the parse function in the TftpPacketFactory class.

  • CVE-2024-33271HigApr 29, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in FME Modules eventsmanager before 4.4.0 allows an attacker to obtain sensitive information from the ps_customer component.

  • CVE-2024-31801HigApr 29, 2024
    risk 0.49cvss 7.5epss 0.01

    Directory Traversal vulnerability in NEXSYS-ONE before v.Rev.15320 allows a remote attacker to obtain sensitive information via a crafted request.

  • CVE-2023-46565HigApr 29, 2024
    risk 0.42cvss 7.5epss 0.01

    Buffer Overflow vulnerability in osrg gobgp commit 419c50dfac578daa4d11256904d0dc182f1a9b22 allows a remote attacker to cause a denial of service via the handlingError function in pkg/server/fsm.go.

  • CVE-2024-0840HigApr 29, 2024
    risk 0.57cvss 8.8epss 0.01

    The Grandstream UCM Series IP PBX before firmware version 1.0.20.52 is affected by a parameter injection vulnerability in the HTTP interface. A remote and authenticated attacker can execute arbitrary code by sending a crafted HTTP request. Authentication may be possible using a…

  • CVE-2024-33443HigApr 29, 2024
    risk 0.46cvss 7.1epss 0.01

    An issue in onethink v.1.1 allows a remote attacker to execute arbitrary code via a crafted script to the AddonsController.class.php component.

  • CVE-2024-33438HigApr 29, 2024
    risk 0.00cvss 8.0epss 0.01

    File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file.

  • CVE-2024-33338HigApr 29, 2024
    risk 0.48cvss 7.3epss 0.01

    Cross Site Scripting vulnerability in jizhicms v.2.5.4 allows a remote attacker to obtain sensitive information via a crafted article publication request.

  • CVE-2024-31823HigApr 29, 2024
    risk 0.00cvss 8.8epss 0.02

    An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the removeSecondaryImage method of the Publish.php component.

  • CVE-2024-31821HigApr 29, 2024
    risk 0.00cvss 8.0epss 0.01

    SQL Injection vulnerability in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the manageQuantitiesAndProcurement method of the Orders_model.php component.

  • CVE-2024-28320HigApr 29, 2024
    risk 0.49cvss 7.6epss 0.01

    Insecure Direct Object References (IDOR) vulnerability in Hospital Management System 1.0 allows attackers to manipulate user parameters for unauthorized access and modifications via crafted POST request to /patient/edit-user.php.

  • CVE-2023-52080HigApr 29, 2024
    risk 0.50cvss 7.7epss 0.00

    IEIT NF5280M6 UEFI firmware through 8.4 has a pool overflow vulnerability, caused by improper use of the gRT->GetVariable() function. Attackers with access to local NVRAM variables can exploit this by modifying these variables on SPI Flash, resulting in memory data being…

  • CVE-2024-32493HigApr 29, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Znuny LTS 6.5.1 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in agent is able to inject SQL in the draft form ID parameter of an AJAX request.

  • CVE-2024-32492HigApr 29, 2024
    risk 0.46cvss 7.1epss 0.01

    An issue was discovered in Znuny 7.0.1 through 7.0.16 where the ticket detail view in the customer front allows the execution of external JavaScript.

  • CVE-2024-32269HigApr 29, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in Yonganda YAD-LOJ V3.0.561 allows a remote attacker to cause a denial of service via a crafted packet.

  • CVE-2024-31621HigApr 29, 2024
    risk 0.50cvss 7.6epss 0.60

    An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component.

  • CVE-2024-34010HigApr 29, 2024
    risk 0.53cvss 8.2epss 0.00

    Local privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 37758, Acronis Cyber Protect 16 (Windows) before build 38690, Acronis True Image (Windows) before build 42386,…

  • CVE-2023-48684HigApr 29, 2024
    risk 0.46cvss 7.1epss 0.00

    Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 37758, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186.

  • CVE-2023-48683HigApr 29, 2024
    risk 0.46cvss 7.1epss 0.00

    Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 37758, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39169.

  • CVE-2024-1969HigApr 29, 2024
    risk 0.53cvss 8.2epss 0.00

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Secomea GateManager (webserver modules) allows crash of GateManager.This issue affects GateManager: from 9.7 before 11.2.624095033.

  • CVE-2024-1579HigApr 29, 2024
    risk 0.53cvss 8.1epss 0.01

    Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Secomea GateManager (Webserver modules) allows Session Hijacking.This issue affects GateManager: before 11.2.624071020.

  • CVE-2024-4309HigApr 29, 2024
    risk 0.53cvss 8.1epss 0.00

    SQL injection vulnerability in HubBank affecting version 1.0.2. This vulnerability could allow an attacker to send a specially crafted SQL query to the database through different endpoints (/user/transaction.php?id=1, /user/credit-debit_transaction.php?id=1,/user/view_transaction…

  • CVE-2024-4308HigApr 29, 2024
    risk 0.53cvss 8.1epss 0.00

    SQL injection vulnerability in HubBank affecting version 1.0.2. This vulnerability could allow an attacker to send a specially crafted SQL query to the database through different endpoints (/admin/view_users.php?id=1,/admin/viewloan-trans.php?id=1,/admin/view-deposit.php?id=1,/ad…

  • CVE-2024-4307HigApr 29, 2024
    risk 0.53cvss 8.1epss 0.00

    SQL injection vulnerability in HubBank affecting version 1.0.2. This vulnerability could allow an attacker to send a specially crafted SQL query to the database through different endpoints (/accounts/activities.php?id=1, /accounts/view-deposit.php?id=1, /accounts/view_cards.…

  • CVE-2024-27322HigApr 29, 2024
    risk 0.59cvss 8.8epss 0.24

    Deserialization of untrusted data can occur in the R statistical programming language, on any version starting at 1.4.0 up to and not including 4.4.0, enabling a maliciously crafted RDS (R Data Serialization) formatted file or R package to run arbitrary code on an end user’s…

  • CVE-2024-33594HigApr 29, 2024
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in Leaky Paywall.This issue affects Leaky Paywall: from n/a through 4.20.8.

  • CVE-2024-33591HigApr 29, 2024
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in Tips and Tricks HQ Easy Accept Payments.This issue affects Easy Accept Payments: from n/a through 4.9.10.

  • CVE-2024-33635HigApr 29, 2024
    risk 0.49cvss 7.5epss 0.01

    Missing Authorization vulnerability in Piotnet Piotnet Addons For Elementor Pro.This issue affects Piotnet Addons For Elementor Pro: from n/a through 7.1.17.

  • CVE-2024-33597HigApr 29, 2024
    risk 0.49cvss 7.5epss 0.01

    Missing Authorization vulnerability in ProFaceOff SSU.This issue affects SSU: from n/a through 1.5.0.

  • CVE-2024-33637HigApr 29, 2024
    risk 0.49cvss 7.5epss 0.01

    Insertion of Sensitive Information into Log File vulnerability in Solid Plugins Solid Affiliate.This issue affects Solid Affiliate: from n/a through 1.9.1.

  • CVE-2024-3193HigApr 29, 2024
    risk 0.00cvss 8.8epss 0.04

    A vulnerability has been found in MailCleaner up to 2023.03.14 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Admin Endpoints. The manipulation leads to os command injection. The attack can be launched remotely. The…

  • CVE-2024-4303HigApr 29, 2024
    risk 0.57cvss 8.8epss 0.01

    ArmorX Android APP's multi-factor authentication (MFA) for the login function is not properly implemented. Remote attackers who obtain user credentials can bypass MFA, allowing them to successfully log into the APP.

  • CVE-2024-33904HigApr 29, 2024
    risk 0.39cvss 7.0epss 0.00

    In plugins/HookSystem.cpp in Hyprland through 0.39.1 (before 28c8561), through a race condition, a local attacker can cause execution of arbitrary assembly code by writing to a predictable temporary file.

  • CVE-2024-33681HigApr 29, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Sandor Kovacs Regenerate post permalink allows Cross-Site Scripting (XSS).This issue affects Regenerate post permalink: from n/a through 1.0.3.

  • CVE-2024-33571HigApr 29, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Infomaniak Network VOD Infomaniak vod-infomaniak.This issue affects VOD Infomaniak: from n/a through <= 1.5.6.

  • CVE-2024-33562HigApr 29, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore allows Reflected XSS.This issue affects XStore: from n/a through 9.3.5.

  • CVE-2024-33554HigApr 29, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core allows Reflected XSS.This issue affects XStore Core: from n/a through 5.3.5.

  • CVE-2024-33548HigApr 29, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team WZone allows Reflected XSS.This issue affects WZone: from n/a through 14.0.10.

  • CVE-2024-2505HigApr 29, 2024
    risk 0.53cvss 8.1epss 0.01

    The GamiPress WordPress plugin before 6.8.9's access control mechanism fails to properly restrict access to its settings, permitting Authors to manipulate requests and extend access to lower privileged users, like Subscribers, despite initial settings prohibiting such access.…