VYPR

CVEs

113,602 total · page 999 of 2,273

  • CVE-2023-49074HigApr 9, 2024
    risk 0.49cvss 7.4epss 0.13

    A denial of service vulnerability exists in the TDDP functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of network requests can lead to reset to factory settings. An attacker can send a sequence of…

  • CVE-2023-48724HigApr 9, 2024
    risk 0.49cvss 7.5epss 0.01

    A memory corruption vulnerability exists in the web interface functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted HTTP POST request can lead to denial of service of the device's web interface. An attacker…

  • CVE-2023-41677HigApr 9, 2024
    risk 0.49cvss 7.5epss 0.01

    A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12,…

  • CVE-2023-6317HigApr 9, 2024
    risk 0.47cvss 7.2epss 0.01

    A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without asking the user for the security PIN.  Full versions and TV models affected: webOS 4.9.7 - 5.30.40 running on LG43UM7000PLA …

  • CVE-2024-2224HigApr 9, 2024
    risk 0.53cvss 8.1epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects the following products that include…

  • CVE-2024-2223HigApr 9, 2024
    risk 0.53cvss 8.1epss 0.01

    An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. This issue affects the following products that include the vulnerable component:  Bitdefender Endpoint…

  • CVE-2024-3046HigApr 9, 2024
    risk 0.49cvss 7.5epss 0.01

    In Eclipse Kura LogServlet component included in versions 5.0.0 to 5.4.1, a specifically crafted request to the servlet can allow an unauthenticated user to retrieve the device logs. Also, downloaded logs may be used by an attacker to perform privilege escalation by using the…

  • CVE-2024-31978HigApr 9, 2024
    risk 0.49cvss 7.6epss 0.00

    A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP2). Affected devices allow authenticated users to export monitoring data. The corresponding API endpoint is susceptible to path traversal and could allow an authenticated attacker to download files from the…

  • CVE-2024-31370HigApr 9, 2024
    risk 0.55cvss 8.5epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CodeIsAwesome AIKit aikit-wordpress-ai-writing-assistant-using-gpt3.This issue affects AIKit: from n/a through <= 4.14.1.

  • CVE-2024-31367HigApr 9, 2024
    risk 0.46cvss 7.1epss 0.00

    Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2.

  • CVE-2024-30191HigApr 9, 2024
    risk 0.55cvss 8.4epss 0.00

    A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0), SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0), SCALANCE W1788-2 EEC M12 (6GK5788-2GY01-0TA0), SCALANCE W1788-2 M12 (6GK5788-2GY01-0AA0), SCALANCE W1788-2IA…

  • CVE-2024-26275HigApr 9, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Parasolid V36.0 (All versions < V36.0.207), Parasolid V36.1 (All versions < V36.1.147), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), Teamcenter…

  • CVE-2023-1082HigApr 9, 2024
    risk 0.57cvss 8.8epss 0.01

    An remote attacker with low privileges can perform a command injection which can lead to root access.

  • CVE-2024-31366HigApr 9, 2024
    risk 0.46cvss 7.1epss 0.00

    Missing Authorization vulnerability in Themify Post Type Builder (PTB).This issue affects Post Type Builder (PTB): from n/a through 2.0.8.

  • CVE-2024-31365HigApr 9, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Post Type Builder (PTB) allows Reflected XSS.This issue affects Post Type Builder (PTB): from n/a before 2.1.1.

  • CVE-2024-1233HigApr 9, 2024
    risk 0.41cvss 7.3epss 0.01

    A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or other filtering behavior is performed on the destination URL address, which may result in a server-side request…

  • CVE-2024-2975HigApr 9, 2024
    risk 0.57cvss 8.8epss 0.00

    A race condition was identified through which privilege escalation was possible in certain configurations.

  • CVE-2024-27983HigApr 9, 2024
    risk 0.60cvss 8.2epss 0.87

    An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave some data in nghttp2 memory after reset when headers with HTTP/2 CONTINUATION frame are sent to the…

  • CVE-2024-27901HigApr 9, 2024
    risk 0.47cvss 7.2epss 0.01

    SAP Asset Accounting could allow a high privileged attacker to exploit insufficient validation of path information provided by the users and pass it through to the file API's. Thus, causing a considerable impact on confidentiality, integrity and availability of the application.

  • CVE-2024-27899HigApr 9, 2024
    risk 0.57cvss 8.8epss 0.00

    Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the newly defined security answer. This can be leveraged by an attacker to cause profound impact on confidentiality and…

  • CVE-2024-25646HigApr 9, 2024
    risk 0.50cvss 7.7epss 0.00

    Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confidentiality of the application.

  • CVE-2024-23084HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.01

    Apfloat v1.10.1 was discovered to contain an ArrayIndexOutOfBoundsException via the component org.apfloat.internal.DoubleCRTMath::add(double[], double[]). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of…

  • CVE-2024-27632HigApr 8, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in the form_header() function.

  • CVE-2024-0082HigApr 8, 2024
    risk 0.53cvss 8.2epss 0.00

    NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause improper privilege management by sending open file requests to the application. A successful exploit of this vulnerability might lead to local escalation of privileges, information…

  • CVE-2024-27630HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.01

    Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the trackers_data_delete_file function.

  • CVE-2024-24279HigApr 8, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated privileges via vsVerifyPassword and vsSetFingerPrintPower functions.

  • CVE-2024-23085HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.01

    Apfloat v1.10.1 was discovered to contain a NullPointerException via the component org.apfloat.internal.DoubleScramble::scramble(double[], int, int[]). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a…

  • CVE-2024-28270HigApr 8, 2024
    risk 0.53cvss 8.1epss 0.00

    An issue discovered in web-flash v3.0 allows attackers to reset passwords for arbitrary users via crafted POST request to /prod-api/user/resetPassword.

  • CVE-2023-7164HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.02

    The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database.

  • CVE-2024-31442HigApr 8, 2024
    risk 0.00cvss 8.8epss 0.01

    Redon Hub is a Roblox Product Delivery Bot, also known as a Hub. In all hubs before version 1.0.2, all commands are capable of being ran by all users, including admin commands. This allows users to receive products for free and delete/create/update products/tags/etc. The only…

  • CVE-2024-28732HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in OFPMatch in parser.py in Faucet SDN Ryu version 4.34, allows remote attackers to cause a denial of service (DoS) (infinite loop).

  • CVE-2024-31817HigApr 8, 2024
    risk 0.53cvss 7.5epss 0.55

    In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg.

  • CVE-2024-31816HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.03

    In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getEasyWizardCfg.

  • CVE-2024-31814HigApr 8, 2024
    risk 0.58cvss 8.8epss 0.09

    TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to bypass login through the Form_Login function.

  • CVE-2024-31813HigApr 8, 2024
    risk 0.55cvss 8.4epss 0.00

    TOTOLINK EX200 V4.0.3c.7646_B20201211 does not contain an authentication mechanism by default.

  • CVE-2024-31811HigApr 8, 2024
    risk 0.52cvss 8.0epss 0.01

    TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLanguageCfg function.

  • CVE-2024-31809HigApr 8, 2024
    risk 0.57cvss 8.8epss 0.01

    TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in the setUpgradeFW function.

  • CVE-2024-31808HigApr 8, 2024
    risk 0.57cvss 8.8epss 0.01

    TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in the setWebWlanIdx function.

  • CVE-2024-2834HigApr 8, 2024
    risk 0.57cvss 8.7epss 0.01

    A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited.

  • CVE-2024-28066HigApr 8, 2024
    risk 0.57cvss 8.8epss 0.00

    In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).

  • CVE-2024-3439HigApr 8, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Prison Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /Account/login.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has…

  • CVE-2024-26574HigApr 8, 2024
    risk 0.51cvss 7.8epss 0.00

    Insecure Permissions vulnerability in Wondershare Filmora v.13.0.51 allows a local attacker to execute arbitrary code via a crafted script to the WSNativePushService.exe

  • CVE-2024-3438HigApr 8, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Prison Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /Admin/login.php. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been…

  • CVE-2024-27897HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Input verification vulnerability in the call module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-27896HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Input verification vulnerability in the log module. Impact: Successful exploitation of this vulnerability can affect integrity.

  • CVE-2024-27895HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2023-52386HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Out-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-52553HigApr 8, 2024
    risk 0.48cvss 7.4epss 0.00

    Race condition vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-52552HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Input verification vulnerability in the power module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-52550HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.