VYPR

CVEs

113,625 total · page 987 of 2,273

  • CVE-2024-32694HigApr 22, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Creative interactive media 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook WordPress Plugin allows Reflected XSS.This issue affects 3D FlipBook, PDF Viewer, PDF…

  • CVE-2024-32693HigApr 22, 2024
    risk 0.49cvss 7.6epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in ValvePress Automatic.This issue affects Automatic: from n/a before 3.93.0.

  • CVE-2024-4020HigApr 20, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability was found in Tenda FH1206 1.2.0.8(8155) and classified as critical. This issue affects the function fromAddressNat of the file /goform/addressNat. The manipulation of the argument entrys leads to buffer overflow. The attack may be initiated remotely. The exploit…

  • CVE-2024-1480HigApr 19, 2024
    risk 0.49cvss 7.5epss 0.01

    Unitronics Vision Standard line of controllers allow the Information Mode password to be retrieved without authentication.

  • CVE-2024-4018HigApr 19, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (local appliance api modules) allows Privilege Escalation.This issue affects U-Series Appliance: from 3.4 before 4.0.3.

  • CVE-2024-4017HigApr 19, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (filesystem modules) allows DLL Side-Loading.This issue affects U-Series Appliance: from 3.4 before 4.0.3.

  • CVE-2024-32391HigApr 19, 2024
    risk 0.48cvss 7.3epss 0.01

    Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.

  • CVE-2024-30974HigApr 19, 2024
    risk 0.47cvss 7.3epss 0.00

    SQL Injection vulnerability in autoexpress v.1.3.0 allows attackers to run arbitrary SQL commands via the carId parameter.

  • CVE-2024-22905HigApr 19, 2024
    risk 0.46cvss 7.0epss 0.00

    Buffer Overflow vulnerability in ARM mbed-os v.6.17.0 allows a remote attacker to execute arbitrary code via a crafted script to the hciTrSerialRxIncoming function.

  • CVE-2024-32652HigApr 19, 2024
    risk 0.42cvss 7.5epss 0.01

    The adapter @hono/node-server allows you to run your Hono application on Node.js. Prior to 1.10.1, the application hangs when receiving a Host header with a value that `@hono/node-server` can't handle well. Invalid values are those that cannot be parsed by the `URL` as a…

  • CVE-2024-31552HigApr 19, 2024
    risk 0.46cvss 7.1epss 0.00

    CuteHttpFileServer v.3.1 version has an arbitrary file download vulnerability, which allows attackers to download arbitrary files on the server and obtain sensitive information.

  • CVE-2023-51798HigApr 19, 2024
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via a floating point exception (FPE) error at libavfilter/vf_minterpolate.c:1078:60 in interpolate.

  • CVE-2023-51795HigApr 19, 2024
    risk 0.52cvss 8.0epss 0.00

    Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showspectrum.c:1789:52 component in showspectrumpic_request_frame

  • CVE-2023-51793HigApr 19, 2024
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavutil/imgutils.c:353:9 in image_copy_plane.

  • CVE-2023-51791HigApr 19, 2024
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulenrability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavcodec/jpegxl_parser.c in gen_alias_map.

  • CVE-2023-50010HigApr 19, 2024
    risk 0.00cvss 7.8epss 0.00

    FFmpeg v.n6.1-3-g466799d4f5 allows a buffer over-read at ff_gradfun_blur_line_movdqa_sse2, as demonstrated by a call to the set_encoder_id function in /fftools/ffmpeg_enc.c component.

  • CVE-2023-50009HigApr 19, 2024
    risk 0.00cvss 8.0epss 0.00

    FFmpeg v.n6.1-3-g466799d4f5 allows a heap-based buffer overflow via the ff_gaussian_blur_8 function in libavfilter/edge_template.c:116:5 component.

  • CVE-2023-50008HigApr 19, 2024
    risk 0.00cvss 7.8epss 0.00

    FFmpeg v.n6.1-3-g466799d4f5 allows memory consumption when using the colorcorrect filter, in the av_malloc function in libavutil/mem.c:105:9 component.

  • CVE-2023-49963HigApr 19, 2024
    risk 0.57cvss 8.8epss 0.00

    DYMO LabelWriter Print Server through 2.366 contains a backdoor hard-coded password that could allow an attacker to take control.

  • CVE-2023-49502HigApr 19, 2024
    risk 0.50cvss 8.8epss 0.02

    Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the ff_bwdif_filter_intra_c function in the libavfilter/bwdifdsp.c:125:5 component.

  • CVE-2023-49501HigApr 19, 2024
    risk 0.52cvss 8.0epss 0.00

    Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component.

  • CVE-2024-32650HigApr 19, 2024
    risk 0.42cvss 7.5epss 0.01

    Rustls is a modern TLS library written in Rust. `rustls::ConnectionCommon::complete_io` could fall into an infinite loop based on network input. When using a blocking rustls server, if a client send a `close_notify` message immediately after `client_hello`, the server's…

  • CVE-2024-32409HigApr 19, 2024
    risk 0.46cvss 7.1epss 0.00

    An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script.

  • CVE-2024-31846HigApr 19, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

  • CVE-2024-31841HigApr 19, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthenticated attackers to read arbitrary files on the filesystem.

  • CVE-2024-22640HigApr 19, 2024
    risk 0.42cvss 7.5epss 0.01

    TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color.

  • CVE-2024-3684HigApr 19, 2024
    risk 0.52cvss 8.0epss 0.01

    A server side request forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin access to the appliance when configuring the Artifacts & Logs and Migrations Storage. Exploitation of this…

  • CVE-2024-3646HigApr 19, 2024
    risk 0.52cvss 8.0epss 0.02

    A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the instance when configuring the chat integration. Exploitation of this vulnerability required access…

  • CVE-2023-50260HigApr 19, 2024
    risk 0.60cvss 8.8epss 0.41

    Wazuh is a free and open source platform used for threat prevention, detection, and response. A wrong validation in the `host_deny` script allows to write any string in the `hosts.deny` file, which can end in an arbitrary command execution on the target system. This…

  • CVE-2024-32166HigApr 19, 2024
    risk 0.57cvss 8.8epss 0.01

    Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an auction that is suspended (horizontal privilege escalation).

  • CVE-2023-37400HigApr 19, 2024
    risk 0.51cvss 7.8epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to escalate their privileges due to insecure credential storage. IBM X-Force ID: 259677.

  • CVE-2024-31744HigApr 19, 2024
    risk 0.42cvss 7.5epss 0.01

    In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerability, allowing attackers to cause a denial of service attack through a specific image file.

  • CVE-2024-29969HigApr 19, 2024
    risk 0.49cvss 7.5epss 0.00

    When a Brocade SANnav installation is upgraded from Brocade SANnav v2.2.2 to Brocade SANnav 2.3.0, TLS/SSL weak message authentication code ciphers are added by default for port 18082.

  • CVE-2024-29968HigApr 19, 2024
    risk 0.50cvss 7.7epss 0.00

    An information disclosure vulnerability exists in Brocade SANnav before v2.3.1 and v2.3.0a when Brocade SANnav instances are configured in disaster recovery mode. SQL Table names, column names, and SQL queries are collected in DR standby Supportsave. This could allow…

  • CVE-2024-29966HigApr 19, 2024
    risk 0.49cvss 7.5epss 0.01

    Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appliance's root password. The vulnerability could allow an unauthenticated attacker full access to the Brocade SANnav appliance.

  • CVE-2024-29961HigApr 19, 2024
    risk 0.53cvss 8.2epss 0.01

    A vulnerability affects Brocade SANnav before v2.3.1 and v2.3.0a. It allows a Brocade SANnav service to send ping commands in the background at regular intervals to gridgain.com to check if updates are available for the Component. This could make an unauthenticated, remote…

  • CVE-2024-29959HigApr 19, 2024
    risk 0.56cvss 8.6epss 0.00

    A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints Brocade Fabric OS switch encrypted passwords in the Brocade SANnav Standby node's support save.

  • CVE-2024-29958HigApr 19, 2024
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the encryption key in the console when a privileged user executes the script to replace the Brocade SANnav Management Portal standby node. This could provide attackers an additional, less protected path to…

  • CVE-2024-29957HigApr 19, 2024
    risk 0.49cvss 7.5epss 0.00

    When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode, the encryption key is stored in the DR log files. This could provide attackers with an additional, less-protected path to acquiring the encryption key.

  • CVE-2024-3600HigApr 19, 2024
    risk 0.47cvss 7.2epss 0.00

    The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check on the ays_poll_maker_quick_start AJAX action in addition to insufficient escaping and sanitization in all versions up to, and…

  • CVE-2024-27984HigApr 19, 2024
    risk 0.46cvss 7.1epss 0.02

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to delete specific type of files and/or cause denial of service.

  • CVE-2024-27977HigApr 19, 2024
    risk 0.53cvss 8.1epss 0.02

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to delete arbitrary files, thereby leading to Denial-of-Service.

  • CVE-2024-27976HigApr 19, 2024
    risk 0.57cvss 8.8epss 0.03

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

  • CVE-2024-27975HigApr 19, 2024
    risk 0.57cvss 8.8epss 0.03

    An Use-after-free vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

  • CVE-2024-25000HigApr 19, 2024
    risk 0.57cvss 8.8epss 0.03

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

  • CVE-2024-24999HigApr 19, 2024
    risk 0.57cvss 8.8epss 0.03

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

  • CVE-2024-24998HigApr 19, 2024
    risk 0.57cvss 8.8epss 0.03

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

  • CVE-2024-24997HigApr 19, 2024
    risk 0.57cvss 8.8epss 0.03

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

  • CVE-2024-24995HigApr 19, 2024
    risk 0.49cvss 7.5epss 0.02

    A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

  • CVE-2024-24994HigApr 19, 2024
    risk 0.63cvss 8.8epss 0.68

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.