| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-24757 | Hig | 0.49 | 7.6 | 0.01 | Feb 2, 2024 | open-irs is an issue response robot that reponds to issues in the installed repository. The `.env` file was accidentally uploaded when working with git actions. This problem is fixed in 1.0.1. Discontinuing all sensitive keys and turning into secrets. | ||
| CVE-2024-24470 | Hig | 0.57 | 8.8 | 0.01 | Feb 2, 2024 | Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the update_post.php component. | ||
| CVE-2024-24161 | Hig | 0.49 | 7.5 | 0.01 | Feb 2, 2024 | MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not filtered. | ||
| CVE-2024-23831 | Hig | 0.00 | 7.5 | 0.00 | Feb 2, 2024 | LedgerSMB is a free web-based double-entry accounting system. When a LedgerSMB database administrator has an active session in /setup.pl, an attacker can trick the admin into clicking on a link which automatically submits a request to setup.pl without the admin's consent. This… | ||
| CVE-2024-22107 | Hig | 0.47 | 7.2 | 0.03 | Feb 2, 2024 | An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at /opt/webapp/src/AppBundle/Controller/React/SystemSettingsController.php is vulnerable to command injection via the /old/react/v1/api/system/dns/data endpoint. An… | ||
| CVE-2023-6387 | Hig | 0.49 | 7.5 | 0.01 | Feb 2, 2024 | A potential buffer overflow exists in the Bluetooth LE HCI CPC sample application in the Gecko SDK which may result in a denial of service or remote code execution | ||
| CVE-2023-51838 | Hig | 0.49 | 7.5 | 0.01 | Feb 2, 2024 | Ylianst MeshCentral 1.1.16 suffers from Use of a Broken or Risky Cryptographic Algorithm. | ||
| CVE-2023-47568 | Hig | 0.57 | 8.8 | 0.01 | Feb 2, 2024 | A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QTS… | ||
| CVE-2023-47564 | Hig | 0.52 | 8.0 | 0.01 | Feb 2, 2024 | An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network. We have already fixed the vulnerability in the… | ||
| CVE-2023-47562 | Hig | 0.48 | 7.4 | 0.01 | Feb 2, 2024 | An OS command injection vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: Photo Station 6.4.2 ( 2023/12/15… | ||
| CVE-2023-39297 | Hig | 0.57 | 8.8 | 0.01 | Feb 2, 2024 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS… | ||
| CVE-2020-29504 | Hig | 0.48 | 7.4 | 0.00 | Feb 2, 2024 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain a Missing Required Cryptographic Step Vulnerability. | ||
| CVE-2023-38273 | Hig | 0.49 | 7.5 | 0.01 | Feb 2, 2024 | IBM Cloud Pak System 2.3.1.1, 2.3.2.0, and 2.3.3.7 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 260733. | ||
| CVE-2023-47142 | Hig | 0.49 | 7.5 | 0.00 | Feb 2, 2024 | IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 could allow an attacker on the organization's local network to escalate their privileges due to unauthorized API access. IBM X-Force ID: 270267. | ||
| CVE-2024-0269 | Hig | 0.54 | 8.3 | 0.05 | Feb 2, 2024 | ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in File-Summary DrillDown. This issue has been fixed and released in version 7271. | ||
| CVE-2024-0253 | Hig | 0.54 | 8.3 | 0.05 | Feb 2, 2024 | ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in home Graph-Data. | ||
| CVE-2023-6676 | Hig | 0.57 | 8.8 | 0.00 | Feb 2, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in National Keep Cyber Security Services CyberMath allows Cross Site Request Forgery. This issue affects CyberMath: from v1.4 before v1.5. | ||
| CVE-2024-1201 | Hig | 0.51 | 7.8 | 0.00 | Feb 2, 2024 | Search path or unquoted item vulnerability in HDD Health affecting versions 4.2.0.112 and earlier. This vulnerability could allow a local attacker to store a malicious executable file within the unquoted search path, resulting in privilege escalation. | ||
| CVE-2024-23895 | Hig | 0.53 | 8.2 | 0.01 | Feb 2, 2024 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/locationcreate.php, in the locationid parameter.… | ||
| CVE-2024-0338 | Hig | 0.47 | 7.3 | 0.00 | Feb 2, 2024 | A buffer overflow vulnerability has been found in XAMPP affecting version 8.2.4 and earlier. An attacker could execute arbitrary code through a long file debug argument that controls the Structured Exception Handler (SEH). | ||
| CVE-2023-39611 | Hig | 0.49 | 7.5 | 0.01 | Feb 2, 2024 | An issue in Software FX Chart FX 7 version 7.0.4962.20829 allows attackers to enumerate and read files from the local filesystem by sending crafted web requests. | ||
| CVE-2024-22851 | Hig | 0.49 | 7.5 | 0.01 | Feb 2, 2024 | Directory Traversal Vulnerability in LiveConfig before v.2.5.2 allows a remote attacker to obtain sensitive information via a crafted request to the /static/ endpoint. | ||
| CVE-2023-48645 | Hig | 0.51 | 7.8 | 0.00 | Feb 2, 2024 | An issue was discovered in the Archibus app 4.0.3 for iOS. It uses a local database that is synchronized with a Web central server instance every time the application is opened, or when the refresh button is used. There is a SQL injection in the search work request feature in… | ||
| CVE-2024-24524 | Hig | 0.57 | 8.8 | 0.01 | Feb 2, 2024 | Cross Site Request Forgery (CSRF) vulnerability in flusity-CMS v.2.33, allows remote attackers to execute arbitrary code via the add_menu.php component. | ||
| CVE-2020-24682 | Hig | 0.47 | 7.2 | 0.00 | Feb 2, 2024 | Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio, B&R Industrial Automation NET/PVI allows Target Programs with Elevated Privileges.This issue affects Automation Studio: from 4.0 through 4.6, from 4.7.0 before 4.7.7 SP, from 4.8.0… | ||
| CVE-2024-21860 | Hig | 0.53 | 8.2 | 0.00 | Feb 2, 2024 | in OpenHarmony v4.0.0 and prior versions allow an adjacent attacker arbitrary code execution in any apps through use after free. | ||
| CVE-2024-21780 | Hig | 0.49 | 7.5 | 0.01 | Feb 2, 2024 | Stack-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. Processing a specially crafted command may result in a denial of service (DoS) condition. Note that the affected products are no longer supported. | ||
| CVE-2021-22282 | Hig | 0.54 | 8.3 | 0.00 | Feb 2, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in B&R Industrial Automation Automation Studio allows Local Execution of Code.This issue affects Automation Studio: from 4.0 through 4.12. | ||
| CVE-2020-24681 | Hig | 0.53 | 8.2 | 0.00 | Feb 2, 2024 | Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allows Privilege Escalation.This issue affects Automation Studio: from 4.6.0 through 4.6.X, from 4.7.0 before 4.7.7 SP, from 4.8.0 before 4.8.6 SP, from 4.9.0… | ||
| CVE-2023-46045 | Hig | 0.51 | 7.8 | 0.01 | Feb 2, 2024 | Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically owned by root. | ||
| CVE-2023-38019 | Hig | 0.53 | 8.1 | 0.01 | Feb 2, 2024 | IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 260575. | ||
| CVE-2024-22319 | Hig | 0.59 | 8.1 | 0.76 | Feb 2, 2024 | IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 279145. | ||
| CVE-2024-22903 | Hig | 0.57 | 8.8 | 0.02 | Feb 2, 2024 | Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function. | ||
| CVE-2024-22900 | Hig | 0.57 | 8.8 | 0.02 | Feb 2, 2024 | Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function. | ||
| CVE-2024-22899 | Hig | 0.57 | 8.8 | 0.02 | Feb 2, 2024 | Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function. | ||
| CVE-2024-22779 | Hig | 0.00 | 8.8 | 0.02 | Feb 2, 2024 | Directory Traversal vulnerability in Kihron ServerRPExposer v.1.0.2 and before allows a remote attacker to execute arbitrary code via the loadServerPack in ServerResourcePackProviderMixin.java. | ||
| CVE-2024-21399 | Hig | 0.54 | 8.3 | 0.01 | Feb 2, 2024 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | ||
| CVE-2023-50326 | Hig | 0.49 | 7.5 | 0.01 | Feb 2, 2024 | IBM PowerSC 1.3, 2.0, and 2.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 275107. | ||
| CVE-2024-22016 | Hig | 0.51 | 7.8 | 0.00 | Feb 2, 2024 | In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an authorized user can write directly to the Scada directory. This may allow privilege escalation. | ||
| CVE-2024-24756 | Hig | 0.00 | 7.5 | 0.01 | Feb 1, 2024 | Crafatar serves Minecraft avatars based on the skin for use in external applications. Files outside of the `lib/public/` directory can be requested from the server. Instances running behind Cloudflare (including crafatar.com) are not affected. Instances using the Docker… | ||
| CVE-2024-21852 | Hig | 0.57 | 8.8 | 0.01 | Feb 1, 2024 | In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can supply a malicious configuration file by utilizing a Zip Slip vulnerability in the unpacking routine to achieve remote code execution. | ||
| CVE-2023-6221 | Hig | 0.50 | 7.7 | 0.01 | Feb 1, 2024 | The cloud provider MachineSense uses for integration and deployment for multiple MachineSense devices, such as the programmable logic controller (PLC), PumpSense, PowerAnalyzer, FeverWarn, and others is insufficiently protected against unauthorized access. An attacker with… | ||
| CVE-2023-49610 | Hig | 0.53 | 8.1 | 0.00 | Feb 1, 2024 | MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which could allow an attacker on an adjacent network to send a message running commands or could overflow the stack. | ||
| CVE-2023-49115 | Hig | 0.49 | 7.5 | 0.01 | Feb 1, 2024 | MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote viewing of sensor data by users. | ||
| CVE-2023-47867 | Hig | 0.57 | 8.8 | 0.00 | Feb 1, 2024 | MachineSense FeverWarn devices are configured as Wi-Fi hosts in a way that attackers within range could connect to the device's web services and compromise the device. | ||
| CVE-2023-36496 | Hig | 0.50 | 7.7 | 0.01 | Feb 1, 2024 | Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server. | ||
| CVE-2023-47257 | Hig | 0.53 | 8.1 | 0.01 | Feb 1, 2024 | ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages. | ||
| CVE-2024-24570 | Hig | 0.46 | 8.2 | 0.01 | Feb 1, 2024 | Statamic is a Laravel and Git powered CMS. HTML files crafted to look like jpg files are able to be uploaded, allowing for XSS. This affects the front-end forms with asset fields without any mime type validation, asset fields in the control panel, and asset browser in the… | ||
| CVE-2023-6078 | Hig | 0.57 | 8.8 | 0.02 | Feb 1, 2024 | An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023. Upload of a specially crafted perl script can lead to arbitrary command execution. | ||
| CVE-2023-51509 | Hig | 0.46 | 7.1 | 0.00 | Feb 1, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login allows Reflected XSS.This issue affects RegistrationMagic – Custom… |
- risk 0.49cvss 7.6epss 0.01
open-irs is an issue response robot that reponds to issues in the installed repository. The `.env` file was accidentally uploaded when working with git actions. This problem is fixed in 1.0.1. Discontinuing all sensitive keys and turning into secrets.
- risk 0.57cvss 8.8epss 0.01
Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the update_post.php component.
- risk 0.49cvss 7.5epss 0.01
MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not filtered.
- risk 0.00cvss 7.5epss 0.00
LedgerSMB is a free web-based double-entry accounting system. When a LedgerSMB database administrator has an active session in /setup.pl, an attacker can trick the admin into clicking on a link which automatically submits a request to setup.pl without the admin's consent. This…
- risk 0.47cvss 7.2epss 0.03
An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at /opt/webapp/src/AppBundle/Controller/React/SystemSettingsController.php is vulnerable to command injection via the /old/react/v1/api/system/dns/data endpoint. An…
- risk 0.49cvss 7.5epss 0.01
A potential buffer overflow exists in the Bluetooth LE HCI CPC sample application in the Gecko SDK which may result in a denial of service or remote code execution
- risk 0.49cvss 7.5epss 0.01
Ylianst MeshCentral 1.1.16 suffers from Use of a Broken or Risky Cryptographic Algorithm.
- risk 0.57cvss 8.8epss 0.01
A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QTS…
- risk 0.52cvss 8.0epss 0.01
An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network. We have already fixed the vulnerability in the…
- risk 0.48cvss 7.4epss 0.01
An OS command injection vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: Photo Station 6.4.2 ( 2023/12/15…
- risk 0.57cvss 8.8epss 0.01
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS…
- risk 0.48cvss 7.4epss 0.00
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain a Missing Required Cryptographic Step Vulnerability.
- risk 0.49cvss 7.5epss 0.01
IBM Cloud Pak System 2.3.1.1, 2.3.2.0, and 2.3.3.7 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 260733.
- risk 0.49cvss 7.5epss 0.00
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 could allow an attacker on the organization's local network to escalate their privileges due to unauthorized API access. IBM X-Force ID: 270267.
- risk 0.54cvss 8.3epss 0.05
ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in File-Summary DrillDown. This issue has been fixed and released in version 7271.
- risk 0.54cvss 8.3epss 0.05
ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in home Graph-Data.
- risk 0.57cvss 8.8epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in National Keep Cyber Security Services CyberMath allows Cross Site Request Forgery. This issue affects CyberMath: from v1.4 before v1.5.
- risk 0.51cvss 7.8epss 0.00
Search path or unquoted item vulnerability in HDD Health affecting versions 4.2.0.112 and earlier. This vulnerability could allow a local attacker to store a malicious executable file within the unquoted search path, resulting in privilege escalation.
- risk 0.53cvss 8.2epss 0.01
A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/locationcreate.php, in the locationid parameter.…
- risk 0.47cvss 7.3epss 0.00
A buffer overflow vulnerability has been found in XAMPP affecting version 8.2.4 and earlier. An attacker could execute arbitrary code through a long file debug argument that controls the Structured Exception Handler (SEH).
- risk 0.49cvss 7.5epss 0.01
An issue in Software FX Chart FX 7 version 7.0.4962.20829 allows attackers to enumerate and read files from the local filesystem by sending crafted web requests.
- risk 0.49cvss 7.5epss 0.01
Directory Traversal Vulnerability in LiveConfig before v.2.5.2 allows a remote attacker to obtain sensitive information via a crafted request to the /static/ endpoint.
- risk 0.51cvss 7.8epss 0.00
An issue was discovered in the Archibus app 4.0.3 for iOS. It uses a local database that is synchronized with a Web central server instance every time the application is opened, or when the refresh button is used. There is a SQL injection in the search work request feature in…
- risk 0.57cvss 8.8epss 0.01
Cross Site Request Forgery (CSRF) vulnerability in flusity-CMS v.2.33, allows remote attackers to execute arbitrary code via the add_menu.php component.
- risk 0.47cvss 7.2epss 0.00
Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio, B&R Industrial Automation NET/PVI allows Target Programs with Elevated Privileges.This issue affects Automation Studio: from 4.0 through 4.6, from 4.7.0 before 4.7.7 SP, from 4.8.0…
- risk 0.53cvss 8.2epss 0.00
in OpenHarmony v4.0.0 and prior versions allow an adjacent attacker arbitrary code execution in any apps through use after free.
- risk 0.49cvss 7.5epss 0.01
Stack-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. Processing a specially crafted command may result in a denial of service (DoS) condition. Note that the affected products are no longer supported.
- risk 0.54cvss 8.3epss 0.00
Improper Control of Generation of Code ('Code Injection') vulnerability in B&R Industrial Automation Automation Studio allows Local Execution of Code.This issue affects Automation Studio: from 4.0 through 4.12.
- risk 0.53cvss 8.2epss 0.00
Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allows Privilege Escalation.This issue affects Automation Studio: from 4.6.0 through 4.6.X, from 4.7.0 before 4.7.7 SP, from 4.8.0 before 4.8.6 SP, from 4.9.0…
- risk 0.51cvss 7.8epss 0.01
Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically owned by root.
- risk 0.53cvss 8.1epss 0.01
IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 260575.
- risk 0.59cvss 8.1epss 0.76
IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 279145.
- risk 0.57cvss 8.8epss 0.02
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.
- risk 0.57cvss 8.8epss 0.02
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function.
- risk 0.57cvss 8.8epss 0.02
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.
- risk 0.00cvss 8.8epss 0.02
Directory Traversal vulnerability in Kihron ServerRPExposer v.1.0.2 and before allows a remote attacker to execute arbitrary code via the loadServerPack in ServerResourcePackProviderMixin.java.
- risk 0.54cvss 8.3epss 0.01
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.01
IBM PowerSC 1.3, 2.0, and 2.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 275107.
- risk 0.51cvss 7.8epss 0.00
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an authorized user can write directly to the Scada directory. This may allow privilege escalation.
- risk 0.00cvss 7.5epss 0.01
Crafatar serves Minecraft avatars based on the skin for use in external applications. Files outside of the `lib/public/` directory can be requested from the server. Instances running behind Cloudflare (including crafatar.com) are not affected. Instances using the Docker…
- risk 0.57cvss 8.8epss 0.01
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can supply a malicious configuration file by utilizing a Zip Slip vulnerability in the unpacking routine to achieve remote code execution.
- risk 0.50cvss 7.7epss 0.01
The cloud provider MachineSense uses for integration and deployment for multiple MachineSense devices, such as the programmable logic controller (PLC), PumpSense, PowerAnalyzer, FeverWarn, and others is insufficiently protected against unauthorized access. An attacker with…
- risk 0.53cvss 8.1epss 0.00
MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which could allow an attacker on an adjacent network to send a message running commands or could overflow the stack.
- risk 0.49cvss 7.5epss 0.01
MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote viewing of sensor data by users.
- risk 0.57cvss 8.8epss 0.00
MachineSense FeverWarn devices are configured as Wi-Fi hosts in a way that attackers within range could connect to the device's web services and compromise the device.
- risk 0.50cvss 7.7epss 0.01
Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server.
- risk 0.53cvss 8.1epss 0.01
ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.
- risk 0.46cvss 8.2epss 0.01
Statamic is a Laravel and Git powered CMS. HTML files crafted to look like jpg files are able to be uploaded, allowing for XSS. This affects the front-end forms with asset fields without any mime type validation, asset fields in the control panel, and asset browser in the…
- risk 0.57cvss 8.8epss 0.02
An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023. Upload of a specially crafted perl script can lead to arbitrary command execution.
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login allows Reflected XSS.This issue affects RegistrationMagic – Custom…