VYPR

Dvc

by Trcore

CVEs (8)

  • CVE-2024-11315Nov 18, 2024
    risk 0.01cvss epss 0.07

    The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.

  • CVE-2024-11314Nov 18, 2024
    risk 0.01cvss epss 0.07

    The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.

  • CVE-2024-11313Nov 18, 2024
    risk 0.01cvss epss 0.07

    The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.

  • CVE-2024-11312Nov 18, 2024
    risk 0.01cvss epss 0.07

    The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.

  • CVE-2024-11311Nov 18, 2024
    risk 0.01cvss epss 0.07

    The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.

  • CVE-2024-11310Nov 18, 2024
    risk 0.00cvss epss 0.00

    The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

  • CVE-2024-11309Nov 18, 2024
    risk 0.00cvss epss 0.00

    The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

  • CVE-2024-11308Nov 18, 2024
    risk 0.00cvss epss 0.00

    The DVC from TRCore encrypts files using a hardcoded key. Attackers can use this key to decrypt the files and restore the original content.