VYPR

CVEs

113,612 total · page 992 of 2,273

  • CVE-2024-3067HigApr 16, 2024
    risk 0.47cvss 7.2epss 0.01

    The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 2.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. …

  • CVE-2024-32631HigApr 16, 2024
    risk 0.47cvss 7.2epss 0.00

    Out-of-Bounds read in ciCCIOTOPT in ASR180X will cause incorrect computations.

  • CVE-2024-22262HigApr 16, 2024
    risk 0.53cvss 8.1epss 0.01

    Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a…

  • CVE-2024-3574HigApr 16, 2024
    risk 0.42cvss 7.5epss 0.01

    In scrapy version 2.10.1, an issue was identified where the Authorization header, containing credentials for server authentication, is leaked to a third-party site during a cross-domain redirect. This vulnerability arises from the failure to remove the Authorization header when…

  • CVE-2024-3572HigApr 16, 2024
    risk 0.42cvss 7.5epss 0.01

    The scrapy/scrapy project is vulnerable to XML External Entity (XXE) attacks due to the use of lxml.etree.fromstring for parsing untrusted XML data without proper validation. This vulnerability allows attackers to perform denial of service attacks, access local files, generate…

  • CVE-2024-3571HigApr 16, 2024
    risk 0.50cvss 8.8epss 0.02

    langchain-ai/langchain is vulnerable to path traversal due to improper limitation of a pathname to a restricted directory ('Path Traversal') in its LocalFileStore functionality. An attacker can leverage this vulnerability to read or write files anywhere on the filesystem,…

  • CVE-2024-3029HigApr 16, 2024
    risk 0.00cvss 8.0epss 0.01

    In mintplex-labs/anything-llm, an attacker can exploit improper input validation by sending a malformed JSON payload to the '/system/enable-multi-user' endpoint. This triggers an error that is caught by a catch block, which in turn deletes all users and disables the…

  • CVE-2024-3028HigApr 16, 2024
    risk 0.00cvss 7.2epss 0.01

    mintplex-labs/anything-llm is vulnerable to improper input validation, allowing attackers to read and delete arbitrary files on the server. By manipulating the 'logo_filename' parameter in the 'system-preferences' API endpoint, an attacker can construct requests to read…

  • CVE-2024-1961HigApr 16, 2024
    risk 0.57cvss 8.8epss 0.01

    vertaai/modeldb is vulnerable to a path traversal attack due to improper sanitization of user-supplied file paths in its file upload functionality. Attackers can exploit this vulnerability to write arbitrary files anywhere in the file system by manipulating the 'artifact_path'…

  • CVE-2024-1738HigApr 16, 2024
    risk 0.49cvss 7.5epss 0.01

    An incorrect authorization vulnerability exists in the lunary-ai/lunary repository, specifically within the evaluations.get route in the evaluations API endpoint. This vulnerability allows unauthorized users to retrieve the results of any organization's evaluation by simply…

  • CVE-2024-1646HigApr 16, 2024
    risk 0.00cvss 8.2epss 0.01

    parisneo/lollms-webui is vulnerable to authentication bypass due to insufficient protection over sensitive endpoints. The application checks if the host parameter is not '0.0.0.0' to restrict access, which is inadequate when the application is bound to a specific interface,…

  • CVE-2024-1626HigApr 16, 2024
    risk 0.53cvss 8.1epss 0.00

    An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary repository, version 0.3.0, within the project update endpoint. The vulnerability allows authenticated users to modify the name of any project within the system without proper authorization…

  • CVE-2024-1594HigApr 16, 2024
    risk 0.49cvss 7.5epss 0.01

    A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the `artifact_location` parameter when creating an experiment. Attackers can exploit this vulnerability by using a fragment component `#` in the artifact location URI to…

  • CVE-2024-1593HigApr 16, 2024
    risk 0.49cvss 7.5epss 0.01

    A path traversal vulnerability exists in the mlflow/mlflow repository due to improper handling of URL parameters. By smuggling path traversal sequences using the ';' character in URLs, attackers can manipulate the 'params' portion of the URL to gain unauthorized access to files…

  • CVE-2024-1569HigApr 16, 2024
    risk 0.00cvss 7.5epss 0.01

    parisneo/lollms-webui is vulnerable to a denial of service (DoS) attack due to uncontrolled resource consumption. Attackers can exploit the `/open_code_in_vs_code` and similar endpoints without authentication by sending repeated HTTP POST requests, leading to the opening of…

  • CVE-2024-1561HigApr 16, 2024
    risk 0.42cvss 7.5epss 0.09

    An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of any method on a `Component` class with attacker-controlled arguments. Specifically, by exploiting the `move_resource_to_block_cache()` method of the `Block`…

  • CVE-2024-1560HigApr 16, 2024
    risk 0.53cvss 8.1epss 0.01

    A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the artifact deletion functionality. Attackers can bypass path validation by exploiting the double decoding process in the `_delete_artifact_mlflow_artifacts` handler and…

  • CVE-2024-1558HigApr 16, 2024
    risk 0.49cvss 7.5epss 0.01

    A path traversal vulnerability exists in the `_create_model_version()` function within `server/handlers.py` of the mlflow/mlflow repository, due to improper validation of the `source` parameter. Attackers can exploit this vulnerability by crafting a `source` parameter that…

  • CVE-2024-1483HigApr 16, 2024
    risk 0.49cvss 7.5epss 0.03

    A path traversal vulnerability exists in mlflow/mlflow version 2.9.2, allowing attackers to access arbitrary files on the server. By crafting a series of HTTP POST requests with specially crafted 'artifact_location' and 'source' parameters, using a local URI with '#' instead of…

  • CVE-2024-1456HigApr 16, 2024
    risk 0.46cvss 7.1epss 0.00

    An S3 bucket takeover vulnerability was identified in the h2oai/h2o-3 repository. The issue involves the S3 bucket 'http://s3.amazonaws.com/h2o-training', which was found to be vulnerable to unauthorized takeover.

  • CVE-2024-1135HigApr 16, 2024
    risk 0.42cvss 7.5epss 0.03

    Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due…

  • CVE-2024-0549HigApr 16, 2024
    risk 0.00cvss 8.1epss 0.01

    mintplex-labs/anything-llm is vulnerable to a relative path traversal attack, allowing unauthorized attackers with a default role account to delete files and folders within the filesystem, including critical database files such as 'anythingllm.db'. The vulnerability stems from…

  • CVE-2023-33806HigApr 15, 2024
    risk 0.51cvss 7.8epss 0.00

    Insecure default configurations in Hikvision Interactive Tablet DS-D5B86RB/B V2.3.0 build220119, allows attackers to execute arbitrary commands.

  • CVE-2024-3493HigApr 15, 2024
    risk 0.56cvss 8.6epss 0.01

    A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Automation's ControlLogix 5580, Guard Logix 5580, CompactLogix 5380, and…

  • CVE-2024-30656HigApr 15, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in Fireboltt Dream Wristphone BSW202_FB_AAC_v2.0_20240110-20240110-1956 allows attackers to cause a Denial of Service (DoS) via a crafted deauth frame.

  • CVE-2024-2424HigApr 15, 2024
    risk 0.49cvss 7.5epss 0.03

    An input validation vulnerability exists in the Rockwell Automation 5015-AENFTXT that causes the secondary adapter to result in a major nonrecoverable fault (MNRF) when malicious input is entered. If exploited, the availability of the device will be impacted, and a manual…

  • CVE-2020-22539HigApr 15, 2024
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file upload vulnerability in the Add Category function of Codoforum v4.9 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-28558HigApr 15, 2024
    risk 0.57cvss 8.8epss 0.01

    SQL Injection vulnerability in sourcecodester Petrol pump management software v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to admin/app/web_crud.php.

  • CVE-2024-24485HigApr 15, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to obtain sensitive information via the GET EEP_DATA command.

  • CVE-2024-2659HigApr 15, 2024
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing a specific administrative function.

  • CVE-2024-22014HigApr 15, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue discovered in 360 Total Security Antivirus through 11.0.0.1061 for Windows allows attackers to gain escalated privileges via Symbolic Link Follow to Arbitrary File Delete.

  • CVE-2023-4857HigApr 15, 2024
    risk 0.49cvss 7.5epss 0.01

    An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute certain IPMI calls that could lead to exposure of limited system information.

  • CVE-2023-4856HigApr 15, 2024
    risk 0.57cvss 8.8epss 0.01

    A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbitrary commands on a specific API endpoint.

  • CVE-2023-4855HigApr 15, 2024
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute unauthorized commands via IPMI.

  • CVE-2023-48709HigApr 15, 2024
    risk 0.00cvss 8.0epss 0.01

    iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious formulas that may be imported into Excel. As Excel 2016 does **not** prevent Remote Code Execution by default, uninformed users…

  • CVE-2023-47626HigApr 15, 2024
    risk 0.57cvss 8.8epss 0.00

    iTop is an IT service management platform. When displaying/editing the user's personal tokens, XSS attacks are possible. This vulnerability is fixed in 3.1.1.

  • CVE-2023-47622HigApr 15, 2024
    risk 0.00cvss 8.8epss 0.00

    iTop is an IT service management platform. When dashlet are refreshed, XSS attacks are possible. This vulnerability is fixed in 3.0.4 and 3.1.1.

  • CVE-2023-47123HigApr 15, 2024
    risk 0.00cvss 8.7epss 0.00

    iTop is an IT service management platform. By filling malicious code in an object friendlyname / complementary name, an XSS attack can be performed when this object will displayed as an n:n relation item in another object. This vulnerability is fixed in 3.1.1 and 3.2.0.

  • CVE-2024-3783HigApr 15, 2024
    risk 0.50cvss 7.7epss 0.01

    The Backup Agents section in WBSAirback 21.02.04 is affected by a Path Traversal vulnerability, allowing a user with low privileges to download files from the system.

  • CVE-2024-3782HigApr 15, 2024
    risk 0.57cvss 8.8epss 0.00

    Cross-Site Request Forgery vulnerability in WBSAirback 21.02.04, which could allow an attacker to create a manipulated HTML form to perform privileged actions once it is executed by a privileged user.

  • CVE-2024-3780HigApr 15, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability of Information Exposure has been found on Technicolor CGA2121 affecting the version 1.01, this vulnerability allows a local attacker to obtain sensitive information stored on the device such as wifi network's SSID and their respective passwords.

  • CVE-2024-30220HigApr 15, 2024
    risk 0.57cvss 8.8epss 0.01

    Command injection vulnerability in PLANEX COMMUNICATIONS wireless LAN routers allows a network-adjacent unauthenticated attacker to execute an arbitrary command by sending a specially crafted request to a certain port. Note that MZK-MF300N is no longer supported, therefore the…

  • CVE-2024-29219HigApr 15, 2024
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read vulnerability exists in KV STUDIO Ver.11.64 and earlier and KV REPLAY VIEWER Ver.2.64 and earlier, and VT5-WX15/WX12 Ver.6.02 and earlier, which may lead to information disclosure or arbitrary code execution by having a user of the affected product open a…

  • CVE-2024-29218HigApr 15, 2024
    risk 0.57cvss 8.8epss 0.01

    Out-of-bounds write vulnerability exists in KV STUDIO Ver.11.64 and earlier, KV REPLAY VIEWER Ver.2.64 and earlier, and VT5-WX15/WX12 Ver.6.02 and earlier, which may lead to information disclosure or arbitrary code execution by having a user of the affected product open a…

  • CVE-2024-28099HigApr 15, 2024
    risk 0.51cvss 7.8epss 0.00

    VT STUDIO Ver.8.32 and earlier contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running application.

  • CVE-2024-23911HigApr 15, 2024
    risk 0.49cvss 7.5epss 0.01

    Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 NDP packets exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet.

  • CVE-2024-31424HigApr 15, 2024
    risk 0.57cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.6.93.

  • CVE-2024-22437HigApr 15, 2024
    risk 0.47cvss 7.3epss 0.00

    A potential security vulnerability has been identified in VSS Provider and CAPI Proxy software for certain HPE MSA storage products. This vulnerability could be exploited to gain elevated privilege on the system.

  • CVE-2024-22435HigApr 15, 2024
    risk 0.54cvss 8.3epss 0.00

    A potential security vulnerability has been identified in Web ViewPoint Enterprise software. This vulnerability could be exploited to allow unauthorized users to access some resources on a NonStop system.

  • CVE-2024-32139HigApr 15, 2024
    risk 0.55cvss 8.5epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.12.