| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-30690 | Hig | 0.55 | 8.5 | 0.00 | Oct 4, 2023 | Improper input validation vulnerability in Duo prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities. | ||
| CVE-2023-43176 | Hig | 0.57 | 8.8 | 0.01 | Oct 3, 2023 | A deserialization vulnerability in Afterlogic Aurora Files v9.7.3 allows attackers to execute arbitrary code via supplying a crafted .sabredav file. | ||
| CVE-2023-43976 | Hig | 0.53 | 8.1 | 0.01 | Oct 3, 2023 | An issue in CatoNetworks CatoClient before v.5.4.0 allows attackers to escalate privileges and winning the race condition (TOCTOU) via the PrivilegedHelperTool component. | ||
| CVE-2023-4911 | Hig | 0.65 | 7.8 | 0.81 | KEV | Oct 3, 2023 | A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID… | |
| CVE-2023-4817 | Hig | 0.47 | 7.2 | 0.01 | Oct 3, 2023 | This vulnerability allows an authenticated attacker to upload malicious files by bypassing the restrictions of the upload functionality, compromising the entire device. | ||
| CVE-2023-4883 | Hig | 0.49 | 7.5 | 0.01 | Oct 3, 2023 | Invalid pointer release vulnerability. Exploitation of this vulnerability could allow an attacker to interrupt the correct operation of the service by sending a specially crafted json string to the VNF (Virtual Network Function), and triggering the ogs_sbi_message_free… | ||
| CVE-2023-4882 | Hig | 0.49 | 7.5 | 0.01 | Oct 3, 2023 | DOS vulnerability that could allow an attacker to register a new VNF (Virtual Network Function) value. This action could trigger the args_assets() function defined in the arg-log.php file, which would then execute the args-abort.c file, causing the service to crash. | ||
| CVE-2023-3350 | Hig | 0.53 | 8.2 | 0.00 | Oct 3, 2023 | A Cryptographic Issue vulnerability has been found on IBERMATICA RPS, affecting version 2019. By firstly downloading the log file, an attacker could retrieve the SQL query sent to the application in plaint text. This log file contains the password hashes coded with AES-CBC-128… | ||
| CVE-2023-3349 | Hig | 0.53 | 8.2 | 0.00 | Oct 3, 2023 | Information exposure vulnerability in IBERMATICA RPS 2019, which exploitation could allow an unauthenticated user to retrieve sensitive information, such as usernames, IP addresses or SQL queries sent to the application. By accessing the URL /RPS2019Service/status.html, the… | ||
| CVE-2023-0506 | Hig | 0.57 | 8.8 | 0.01 | Oct 3, 2023 | The web service of ByDemes Group Airspace CCTV Web Service in its 2.616.BY00.11 version, contains a privilege escalation vulnerability, detected in the Camera Control Panel, whose exploitation could allow a low-privileged attacker to gain administrator access. | ||
| CVE-2023-2681 | Hig | 0.57 | 8.8 | 0.01 | Oct 3, 2023 | An SQL Injection vulnerability has been found on Jorani version 1.0.0. This vulnerability allows an authenticated remote user, with low privileges, to send queries with malicious SQL code on the "/leaves/validate" path and the “id” parameter, managing to extract arbritary… | ||
| CVE-2023-4103 | Hig | 0.57 | 8.8 | 0.00 | Oct 3, 2023 | QSige statistics are affected by a remote SQLi vulnerability. It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prerequisite, it is necessary to log into the application. | ||
| CVE-2023-4102 | Hig | 0.57 | 8.8 | 0.01 | Oct 3, 2023 | QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application. | ||
| CVE-2023-4101 | Hig | 0.57 | 8.8 | 0.00 | Oct 3, 2023 | The QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application. | ||
| CVE-2023-4099 | Hig | 0.49 | 7.6 | 0.00 | Oct 3, 2023 | The QSige Monitor application does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application. | ||
| CVE-2023-4098 | Hig | 0.57 | 8.8 | 0.00 | Oct 3, 2023 | It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prerequisite, it is necessary to log into the application. | ||
| CVE-2022-47891 | Hig | 0.53 | 8.1 | 0.01 | Oct 3, 2023 | All versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device to reset the administrator password via the legitimate recovery function. | ||
| CVE-2023-4097 | Hig | 0.57 | 8.8 | 0.01 | Oct 3, 2023 | The file upload functionality is not implemented correctly and allows uploading of any type of file. As a prerequisite, it is necessary for the attacker to log into the application with a valid username. | ||
| CVE-2023-44218 | Hig | 0.57 | 8.8 | 0.00 | Oct 3, 2023 | A flaw within the SonicWall NetExtender Pre-Logon feature enables an unauthorized user to gain access to the host Windows operating system with 'SYSTEM' level privileges, leading to a local privilege escalation (LPE) vulnerability. | ||
| CVE-2023-44217 | Hig | 0.51 | 7.8 | 0.00 | Oct 3, 2023 | A local privilege escalation vulnerability in SonicWall Net Extender MSI client for Windows 10.2.336 and earlier versions allows a local low-privileged user to gain system privileges through running repair functionality. | ||
| CVE-2023-3655 | Hig | 0.49 | 7.5 | 0.00 | Oct 3, 2023 | cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by a dangerous methods, that allows to leak the database (system settings, user accounts,...). This vulnerability can be triggered by an HTTP… | ||
| CVE-2023-33039 | Hig | 0.55 | 8.4 | 0.00 | Oct 3, 2023 | Memory corruption in Automotive Display while destroying the image handle created using connected display driver. | ||
| CVE-2023-33035 | Hig | 0.51 | 7.8 | 0.00 | Oct 3, 2023 | Memory corruption while invoking callback function of AFE from ADSP. | ||
| CVE-2023-33034 | Hig | 0.51 | 7.8 | 0.00 | Oct 3, 2023 | Memory corruption while parsing the ADSP response command. | ||
| CVE-2023-33029 | Hig | 0.55 | 8.4 | 0.00 | Oct 3, 2023 | Memory corruption in DSP Service during a remote call from HLOS to DSP. | ||
| CVE-2023-33027 | Hig | 0.49 | 7.5 | 0.00 | Oct 3, 2023 | Transient DOS in WLAN Firmware while parsing rsn ies. | ||
| CVE-2023-33026 | Hig | 0.49 | 7.5 | 0.00 | Oct 3, 2023 | Transient DOS in WLAN Firmware while parsing a NAN management frame. | ||
| CVE-2023-24853 | Hig | 0.55 | 8.4 | 0.00 | Oct 3, 2023 | Memory Corruption in HLOS while registering for key provisioning notify. | ||
| CVE-2023-24850 | Hig | 0.51 | 7.8 | 0.00 | Oct 3, 2023 | Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application. | ||
| CVE-2023-24849 | Hig | 0.53 | 8.2 | 0.00 | Oct 3, 2023 | Information Disclosure in data Modem while parsing an FMTP line in an SDP message. | ||
| CVE-2023-24848 | Hig | 0.53 | 8.2 | 0.00 | Oct 3, 2023 | Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value. | ||
| CVE-2023-24847 | Hig | 0.49 | 7.5 | 0.00 | Oct 3, 2023 | Transient DOS in Modem while allocating DSM items. | ||
| CVE-2023-24844 | Hig | 0.55 | 8.4 | 0.00 | Oct 3, 2023 | Memory Corruption in Core while invoking a call to Access Control core library with hardware protected address range. | ||
| CVE-2023-24843 | Hig | 0.49 | 7.5 | 0.00 | Oct 3, 2023 | Transient DOS in Modem while triggering a camping on an 5G cell. | ||
| CVE-2023-22385 | Hig | 0.53 | 8.2 | 0.00 | Oct 3, 2023 | Memory Corruption in Data Modem while making a MO call or MT VOLTE call. | ||
| CVE-2023-22382 | Hig | 0.48 | 7.4 | 0.00 | Oct 3, 2023 | Weak configuration in Automotive while VM is processing a listener request from TEE. | ||
| CVE-2023-21673 | Hig | 0.57 | 8.7 | 0.00 | Oct 3, 2023 | Improper Access to the VM resource manager can lead to Memory Corruption. | ||
| CVE-2023-26152 | Hig | 0.49 | 7.5 | 0.01 | Oct 3, 2023 | All versions of the package static-server are vulnerable to Directory Traversal due to improper input sanitization passed via the validPath function of server.js. | ||
| CVE-2023-5345 | Hig | 0.00 | 7.8 | 0.00 | Oct 3, 2023 | A use-after-free vulnerability in the Linux kernel's fs/smb/client component can be exploited to achieve local privilege escalation. In case of an error in smb3_fs_context_parse_param, ctx->password was freed but the field was not set to NULL which could lead to double free. … | ||
| CVE-2023-3440 | Hig | 0.55 | 8.4 | 0.00 | Oct 3, 2023 | Incorrect Default Permissions vulnerability in Hitachi JP1/Performance Management on Windows allows File Manipulation.This issue affects JP1/Performance Management - Manager: from 09-00 before 12-50-07; JP1/Performance Management - Base: from 09-00 through 10-50-*;… | ||
| CVE-2023-42771 | Hig | 0.57 | 8.8 | 0.00 | Oct 3, 2023 | Authentication bypass vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier allows a network-adjacent unauthenticated attacker who can access the affected product to download configuration files and/or log files, and upload… | ||
| CVE-2023-41086 | Hig | 0.57 | 8.8 | 0.00 | Oct 3, 2023 | Cross-site request forgery (CSRF) vulnerability exists in FURUNO SYSTEMS wireless LAN access point devices. If a user views a malicious page while logged in, unintended operations may be performed. Affected products and versions are as follows: ACERA 1210 firmware ver.02.36 and… | ||
| CVE-2023-39222 | Hig | 0.57 | 8.8 | 0.01 | Oct 3, 2023 | OS command injection vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to execute an arbitrary OS command that is not intended to be executed from the web interface by sending a specially crafted request. Affected products and… | ||
| CVE-2023-36628 | Hig | 0.57 | 8.8 | 0.00 | Oct 3, 2023 | A flaw exists in VASA which allows users with access to a vSphere/ESXi VMware admin on a FlashArray to gain root access through privilege escalation. | ||
| CVE-2023-36627 | Hig | 0.50 | 7.7 | 0.00 | Oct 2, 2023 | A flaw exists in FlashBlade Purity whereby a user with access to an administrative account on a FlashBlade that is configured with timezone-dependent snapshot schedules can configure a timezone to prevent the schedule from functioning properly. | ||
| CVE-2023-31042 | Hig | 0.50 | 7.7 | 0.00 | Oct 2, 2023 | A flaw exists in FlashBlade Purity whereby an authenticated user with access to FlashBlade’s object store protocol can impact the availability of the system’s data access and replication protocols. | ||
| CVE-2023-43361 | Hig | 0.51 | 7.8 | 0.00 | Oct 2, 2023 | Buffer Overflow vulnerability in Vorbis-tools v.1.4.2 allows a local attacker to execute arbitrary code and cause a denial of service during the conversion of wav files to ogg files. | ||
| CVE-2023-43268 | Hig | 0.57 | 8.8 | 0.01 | Oct 2, 2023 | Deyue Remote Vehicle Management System v1.1 was discovered to contain a deserialization vulnerability. | ||
| CVE-2023-5344 | Hig | 0.00 | 7.5 | 0.01 | Oct 2, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969. | ||
| CVE-2023-43890 | Hig | 0.57 | 8.8 | 0.03 | Oct 2, 2023 | Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the diagnostic tools page. This vulnerability is exploited via a crafted HTTP request. |
- risk 0.55cvss 8.5epss 0.00
Improper input validation vulnerability in Duo prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.
- risk 0.57cvss 8.8epss 0.01
A deserialization vulnerability in Afterlogic Aurora Files v9.7.3 allows attackers to execute arbitrary code via supplying a crafted .sabredav file.
- risk 0.53cvss 8.1epss 0.01
An issue in CatoNetworks CatoClient before v.5.4.0 allows attackers to escalate privileges and winning the race condition (TOCTOU) via the PrivilegedHelperTool component.
- risk 0.65cvss 7.8epss 0.81
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID…
- risk 0.47cvss 7.2epss 0.01
This vulnerability allows an authenticated attacker to upload malicious files by bypassing the restrictions of the upload functionality, compromising the entire device.
- risk 0.49cvss 7.5epss 0.01
Invalid pointer release vulnerability. Exploitation of this vulnerability could allow an attacker to interrupt the correct operation of the service by sending a specially crafted json string to the VNF (Virtual Network Function), and triggering the ogs_sbi_message_free…
- risk 0.49cvss 7.5epss 0.01
DOS vulnerability that could allow an attacker to register a new VNF (Virtual Network Function) value. This action could trigger the args_assets() function defined in the arg-log.php file, which would then execute the args-abort.c file, causing the service to crash.
- risk 0.53cvss 8.2epss 0.00
A Cryptographic Issue vulnerability has been found on IBERMATICA RPS, affecting version 2019. By firstly downloading the log file, an attacker could retrieve the SQL query sent to the application in plaint text. This log file contains the password hashes coded with AES-CBC-128…
- risk 0.53cvss 8.2epss 0.00
Information exposure vulnerability in IBERMATICA RPS 2019, which exploitation could allow an unauthenticated user to retrieve sensitive information, such as usernames, IP addresses or SQL queries sent to the application. By accessing the URL /RPS2019Service/status.html, the…
- risk 0.57cvss 8.8epss 0.01
The web service of ByDemes Group Airspace CCTV Web Service in its 2.616.BY00.11 version, contains a privilege escalation vulnerability, detected in the Camera Control Panel, whose exploitation could allow a low-privileged attacker to gain administrator access.
- risk 0.57cvss 8.8epss 0.01
An SQL Injection vulnerability has been found on Jorani version 1.0.0. This vulnerability allows an authenticated remote user, with low privileges, to send queries with malicious SQL code on the "/leaves/validate" path and the “id” parameter, managing to extract arbritary…
- risk 0.57cvss 8.8epss 0.00
QSige statistics are affected by a remote SQLi vulnerability. It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prerequisite, it is necessary to log into the application.
- risk 0.57cvss 8.8epss 0.01
QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application.
- risk 0.57cvss 8.8epss 0.00
The QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application.
- risk 0.49cvss 7.6epss 0.00
The QSige Monitor application does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application.
- risk 0.57cvss 8.8epss 0.00
It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prerequisite, it is necessary to log into the application.
- risk 0.53cvss 8.1epss 0.01
All versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device to reset the administrator password via the legitimate recovery function.
- risk 0.57cvss 8.8epss 0.01
The file upload functionality is not implemented correctly and allows uploading of any type of file. As a prerequisite, it is necessary for the attacker to log into the application with a valid username.
- risk 0.57cvss 8.8epss 0.00
A flaw within the SonicWall NetExtender Pre-Logon feature enables an unauthorized user to gain access to the host Windows operating system with 'SYSTEM' level privileges, leading to a local privilege escalation (LPE) vulnerability.
- risk 0.51cvss 7.8epss 0.00
A local privilege escalation vulnerability in SonicWall Net Extender MSI client for Windows 10.2.336 and earlier versions allows a local low-privileged user to gain system privileges through running repair functionality.
- risk 0.49cvss 7.5epss 0.00
cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by a dangerous methods, that allows to leak the database (system settings, user accounts,...). This vulnerability can be triggered by an HTTP…
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Automotive Display while destroying the image handle created using connected display driver.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while invoking callback function of AFE from ADSP.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while parsing the ADSP response command.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in DSP Service during a remote call from HLOS to DSP.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while parsing rsn ies.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while parsing a NAN management frame.
- risk 0.55cvss 8.4epss 0.00
Memory Corruption in HLOS while registering for key provisioning notify.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application.
- risk 0.53cvss 8.2epss 0.00
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
- risk 0.53cvss 8.2epss 0.00
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in Modem while allocating DSM items.
- risk 0.55cvss 8.4epss 0.00
Memory Corruption in Core while invoking a call to Access Control core library with hardware protected address range.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in Modem while triggering a camping on an 5G cell.
- risk 0.53cvss 8.2epss 0.00
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
- risk 0.48cvss 7.4epss 0.00
Weak configuration in Automotive while VM is processing a listener request from TEE.
- risk 0.57cvss 8.7epss 0.00
Improper Access to the VM resource manager can lead to Memory Corruption.
- risk 0.49cvss 7.5epss 0.01
All versions of the package static-server are vulnerable to Directory Traversal due to improper input sanitization passed via the validPath function of server.js.
- risk 0.00cvss 7.8epss 0.00
A use-after-free vulnerability in the Linux kernel's fs/smb/client component can be exploited to achieve local privilege escalation. In case of an error in smb3_fs_context_parse_param, ctx->password was freed but the field was not set to NULL which could lead to double free. …
- risk 0.55cvss 8.4epss 0.00
Incorrect Default Permissions vulnerability in Hitachi JP1/Performance Management on Windows allows File Manipulation.This issue affects JP1/Performance Management - Manager: from 09-00 before 12-50-07; JP1/Performance Management - Base: from 09-00 through 10-50-*;…
- risk 0.57cvss 8.8epss 0.00
Authentication bypass vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier allows a network-adjacent unauthenticated attacker who can access the affected product to download configuration files and/or log files, and upload…
- risk 0.57cvss 8.8epss 0.00
Cross-site request forgery (CSRF) vulnerability exists in FURUNO SYSTEMS wireless LAN access point devices. If a user views a malicious page while logged in, unintended operations may be performed. Affected products and versions are as follows: ACERA 1210 firmware ver.02.36 and…
- risk 0.57cvss 8.8epss 0.01
OS command injection vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to execute an arbitrary OS command that is not intended to be executed from the web interface by sending a specially crafted request. Affected products and…
- risk 0.57cvss 8.8epss 0.00
A flaw exists in VASA which allows users with access to a vSphere/ESXi VMware admin on a FlashArray to gain root access through privilege escalation.
- risk 0.50cvss 7.7epss 0.00
A flaw exists in FlashBlade Purity whereby a user with access to an administrative account on a FlashBlade that is configured with timezone-dependent snapshot schedules can configure a timezone to prevent the schedule from functioning properly.
- risk 0.50cvss 7.7epss 0.00
A flaw exists in FlashBlade Purity whereby an authenticated user with access to FlashBlade’s object store protocol can impact the availability of the system’s data access and replication protocols.
- risk 0.51cvss 7.8epss 0.00
Buffer Overflow vulnerability in Vorbis-tools v.1.4.2 allows a local attacker to execute arbitrary code and cause a denial of service during the conversion of wav files to ogg files.
- risk 0.57cvss 8.8epss 0.01
Deyue Remote Vehicle Management System v1.1 was discovered to contain a deserialization vulnerability.
- risk 0.00cvss 7.5epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.
- risk 0.57cvss 8.8epss 0.03
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the diagnostic tools page. This vulnerability is exploited via a crafted HTTP request.