| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-48592 | Hig | 0.57 | 8.8 | 0.01 | Aug 9, 2023 | A SQL injection vulnerability exists in the vendor_country parameter of the “vendor print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being… | ||
| CVE-2022-48591 | Hig | 0.57 | 8.8 | 0.01 | Aug 9, 2023 | A SQL injection vulnerability exists in the vendor_state parameter of the “vendor print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being… | ||
| CVE-2022-48590 | Hig | 0.57 | 8.8 | 0.01 | Aug 9, 2023 | A SQL injection vulnerability exists in the “admin dynamic app mib errors” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the… | ||
| CVE-2022-48589 | Hig | 0.57 | 8.8 | 0.01 | Aug 9, 2023 | A SQL injection vulnerability exists in the “reporting job editor” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | ||
| CVE-2022-48588 | Hig | 0.57 | 8.8 | 0.01 | Aug 9, 2023 | A SQL injection vulnerability exists in the “schedule editor decoupled” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the… | ||
| CVE-2022-48587 | Hig | 0.57 | 8.8 | 0.01 | Aug 9, 2023 | A SQL injection vulnerability exists in the “schedule editor” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | ||
| CVE-2022-48586 | Hig | 0.57 | 8.8 | 0.01 | Aug 9, 2023 | A SQL injection vulnerability exists in the “json walker” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | ||
| CVE-2022-48585 | Hig | 0.57 | 8.8 | 0.01 | Aug 9, 2023 | A SQL injection vulnerability exists in the “admin brand portal” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | ||
| CVE-2022-48584 | Hig | 0.57 | 8.8 | 0.01 | Aug 9, 2023 | A command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating… | ||
| CVE-2022-48583 | Hig | 0.57 | 8.8 | 0.01 | Aug 9, 2023 | A command injection vulnerability exists in the dashboard scheduler feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system. | ||
| CVE-2022-48582 | Hig | 0.57 | 8.8 | 0.01 | Aug 9, 2023 | A command injection vulnerability exists in the ticket report generate feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system. | ||
| CVE-2022-48581 | Hig | 0.57 | 8.8 | 0.01 | Aug 9, 2023 | A command injection vulnerability exists in the “dash export” feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system. | ||
| CVE-2022-48580 | Hig | 0.57 | 8.8 | 0.01 | Aug 9, 2023 | A command injection vulnerability exists in the ARP ping device tool feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system. | ||
| CVE-2023-3518 | Hig | 0.48 | 7.4 | 0.00 | Aug 9, 2023 | HashiCorp Consul and Consul Enterprise 1.16.0 when using JWT Auth for service mesh incorrectly allows/denies access regardless of service identities. Fixed in 1.16.1. | ||
| CVE-2023-33953 | Hig | 0.49 | 7.5 | 0.00 | Aug 9, 2023 | gRPC contains a vulnerability that allows hpack table accounting errors could lead to unwanted disconnects between clients and servers in exceptional cases/ Three vectors were found that allow the following DOS attacks: - Unbounded memory buffering in the HPACK parser -… | ||
| CVE-2023-32782 | Hig | 0.51 | 7.2 | 0.52 | Aug 9, 2023 | A command injection was identified in PRTG 23.2.84.1566 and earlier versions in the Dicom C-ECHO sensor where an authenticated user with write permissions could abuse the debug option to write new files that could potentially get executed by the EXE/Script sensor. The severity… | ||
| CVE-2023-32781 | Hig | 0.51 | 7.2 | 0.12 | Aug 9, 2023 | A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an authenticated user with write permissions could abuse the debug option to write new files that could potentially get executed by the EXE/Script sensor. The… | ||
| CVE-2023-31452 | Hig | 0.57 | 8.8 | 0.01 | Aug 9, 2023 | A cross-site request forgery (CSRF) token bypass was identified in PRTG 23.2.84.1566 and earlier versions that allows remote attackers to perform actions with the permissions of a victim user, provided the victim user has an active session and is induced to trigger the malicious… | ||
| CVE-2023-38212 | Hig | 0.51 | 7.8 | 0.00 | Aug 9, 2023 | Adobe Dimension version 3.4.9 is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||
| CVE-2023-38211 | Hig | 0.51 | 7.8 | 0.00 | Aug 9, 2023 | Adobe Dimension version 3.4.9 is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||
| CVE-2023-23574 | Hig | 0.57 | 8.8 | 0.01 | Aug 9, 2023 | A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the alerts_count component, allows an authenticated attacker to execute arbitrary SQL statements on the DBMS used by the web application. Authenticated users may be able… | ||
| CVE-2023-22378 | Hig | 0.57 | 8.8 | 0.01 | Aug 9, 2023 | A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the sorting parameter, allows an authenticated attacker to execute arbitrary SQL statements on the DBMS used by the web application. Authenticated users may be able to… | ||
| CVE-2023-38207 | Hig | 0.49 | 7.5 | 0.01 | Aug 9, 2023 | Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by a XML Injection (aka Blind XPath Injection) vulnerability that could lead in minor arbitrary file system read. Exploitation of this issue does not require user… | ||
| CVE-2023-24477 | Hig | 0.46 | 7.0 | 0.00 | Aug 9, 2023 | In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely invalidate the user session upon logout. Thus an authenticated local attacker may gain acces to the original user's session. | ||
| CVE-2023-37864 | Hig | 0.47 | 7.2 | 0.00 | Aug 9, 2023 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device. | ||
| CVE-2023-37863 | Hig | 0.47 | 7.2 | 0.01 | Aug 9, 2023 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device. | ||
| CVE-2023-37862 | Hig | 0.53 | 8.2 | 0.00 | Aug 9, 2023 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP API. This might cause certificate errors for SSL-connections and might result in a partial denial-of-service. | ||
| CVE-2023-37861 | Hig | 0.57 | 8.8 | 0.01 | Aug 9, 2023 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated remote attacker can execute code with root permissions with a specially crafted HTTP POST when uploading a certificate to the device. | ||
| CVE-2023-37860 | Hig | 0.49 | 7.5 | 0.01 | Aug 9, 2023 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote unauthenticated attacker can obtain the r/w community string of the SNMPv2 daemon. | ||
| CVE-2023-37859 | Hig | 0.47 | 7.2 | 0.01 | Aug 9, 2023 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 the SNMP daemon is running with root privileges allowing a remote attacker with knowledge of the SNMPv2 r/w community string to execute system commands as root. | ||
| CVE-2023-26310 | Hig | 0.48 | 7.4 | 0.01 | Aug 9, 2023 | There is a command injection problem in the old version of the mobile phone backup app. | ||
| CVE-2022-47185 | Hig | 0.49 | 7.5 | 0.01 | Aug 9, 2023 | Improper input validation vulnerability on the range header in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1. | ||
| CVE-2023-2905 | Hig | 0.00 | 8.8 | 0.01 | Aug 9, 2023 | Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability in the default configuration. Version… | ||
| CVE-2023-4243 | Hig | 0.57 | 8.8 | 0.01 | Aug 9, 2023 | The FULL - Customer plugin for WordPress is vulnerable to Arbitrary File Upload via the /install-plugin REST route in versions up to, and including, 2.2.3 due to improper authorization. This allows authenticated attackers with subscriber-level permissions and above to execute… | ||
| CVE-2023-4239 | Hig | 0.57 | 8.8 | 0.01 | Aug 9, 2023 | The Real Estate Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.2 due to insufficient restriction on the 'rem_save_profile_front' function. This makes it possible for authenticated attackers, with minimal permissions such as… | ||
| CVE-2023-39910 | Hig | 0.49 | 7.5 | 0.01 | Aug 9, 2023 | The cryptocurrency wallet entropy seeding mechanism used in Libbitcoin Explorer 3.0.0 through 3.6.0 is weak, aka the Milk Sad issue. The use of an mt19937 Mersenne Twister PRNG restricts the internal entropy to 32 bits regardless of settings. This allows remote attackers to… | ||
| CVE-2023-39214 | Hig | 0.49 | 7.6 | 0.01 | Aug 8, 2023 | Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access. | ||
| CVE-2023-39212 | Hig | 0.51 | 7.9 | 0.00 | Aug 8, 2023 | Untrusted search path in Zoom Rooms for Windows before version 5.15.5 may allow an authenticated user to enable a denial of service via local access. | ||
| CVE-2023-39211 | Hig | 0.57 | 8.8 | 0.00 | Aug 8, 2023 | Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via local access. | ||
| CVE-2023-39086 | Hig | 0.49 | 7.5 | 0.00 | Aug 8, 2023 | ASUS RT-AC66U B1 3.0.0.4.286_51665 was discovered to transmit sensitive information in cleartext. | ||
| CVE-2023-36344 | Hig | 0.51 | 7.8 | 0.00 | Aug 8, 2023 | An issue in Diebold Nixdorf Vynamic View Console v.5.3.1 and before allows a local attacker to execute arbitrary code via not restricting the search path for required DLLs and not verifying the signature. | ||
| CVE-2023-39533 | Hig | 0.42 | 7.5 | 0.01 | Aug 8, 2023 | go-libp2p is the Go implementation of the libp2p Networking Stack. Prior to versions 0.27.8, 0.28.2, and 0.29.1 malicious peer can use large RSA keys to run a resource exhaustion attack & force a node to spend time doing signature verification of the large key. This… | ||
| CVE-2023-38180 | Hig | 0.62 | 7.5 | 0.15 | KEV | Aug 8, 2023 | .NET and Visual Studio Denial of Service Vulnerability | |
| CVE-2023-36899 | Hig | 0.63 | 8.8 | 0.74 | Aug 8, 2023 | ASP.NET Elevation of Privilege Vulnerability | ||
| CVE-2023-36873 | Hig | 0.48 | 7.4 | 0.01 | Aug 8, 2023 | .NET Framework Spoofing Vulnerability | ||
| CVE-2023-38186 | Hig | 0.57 | 8.8 | 0.01 | Aug 8, 2023 | Windows Mobile Device Management Elevation of Privilege Vulnerability | ||
| CVE-2023-38185 | Hig | 0.57 | 8.8 | 0.03 | Aug 8, 2023 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2023-38184 | Hig | 0.49 | 7.5 | 0.01 | Aug 8, 2023 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | ||
| CVE-2023-38182 | Hig | 0.53 | 8.0 | 0.11 | Aug 8, 2023 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2023-38181 | Hig | 0.59 | 8.8 | 0.17 | Aug 8, 2023 | Microsoft Exchange Server Spoofing Vulnerability |
- risk 0.57cvss 8.8epss 0.01
A SQL injection vulnerability exists in the vendor_country parameter of the “vendor print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being…
- risk 0.57cvss 8.8epss 0.01
A SQL injection vulnerability exists in the vendor_state parameter of the “vendor print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being…
- risk 0.57cvss 8.8epss 0.01
A SQL injection vulnerability exists in the “admin dynamic app mib errors” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the…
- risk 0.57cvss 8.8epss 0.01
A SQL injection vulnerability exists in the “reporting job editor” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
- risk 0.57cvss 8.8epss 0.01
A SQL injection vulnerability exists in the “schedule editor decoupled” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the…
- risk 0.57cvss 8.8epss 0.01
A SQL injection vulnerability exists in the “schedule editor” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
- risk 0.57cvss 8.8epss 0.01
A SQL injection vulnerability exists in the “json walker” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
- risk 0.57cvss 8.8epss 0.01
A SQL injection vulnerability exists in the “admin brand portal” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
- risk 0.57cvss 8.8epss 0.01
A command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating…
- risk 0.57cvss 8.8epss 0.01
A command injection vulnerability exists in the dashboard scheduler feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.
- risk 0.57cvss 8.8epss 0.01
A command injection vulnerability exists in the ticket report generate feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.
- risk 0.57cvss 8.8epss 0.01
A command injection vulnerability exists in the “dash export” feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.
- risk 0.57cvss 8.8epss 0.01
A command injection vulnerability exists in the ARP ping device tool feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.
- risk 0.48cvss 7.4epss 0.00
HashiCorp Consul and Consul Enterprise 1.16.0 when using JWT Auth for service mesh incorrectly allows/denies access regardless of service identities. Fixed in 1.16.1.
- risk 0.49cvss 7.5epss 0.00
gRPC contains a vulnerability that allows hpack table accounting errors could lead to unwanted disconnects between clients and servers in exceptional cases/ Three vectors were found that allow the following DOS attacks: - Unbounded memory buffering in the HPACK parser -…
- risk 0.51cvss 7.2epss 0.52
A command injection was identified in PRTG 23.2.84.1566 and earlier versions in the Dicom C-ECHO sensor where an authenticated user with write permissions could abuse the debug option to write new files that could potentially get executed by the EXE/Script sensor. The severity…
- risk 0.51cvss 7.2epss 0.12
A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an authenticated user with write permissions could abuse the debug option to write new files that could potentially get executed by the EXE/Script sensor. The…
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery (CSRF) token bypass was identified in PRTG 23.2.84.1566 and earlier versions that allows remote attackers to perform actions with the permissions of a victim user, provided the victim user has an active session and is induced to trigger the malicious…
- risk 0.51cvss 7.8epss 0.00
Adobe Dimension version 3.4.9 is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- risk 0.51cvss 7.8epss 0.00
Adobe Dimension version 3.4.9 is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- risk 0.57cvss 8.8epss 0.01
A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the alerts_count component, allows an authenticated attacker to execute arbitrary SQL statements on the DBMS used by the web application. Authenticated users may be able…
- risk 0.57cvss 8.8epss 0.01
A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the sorting parameter, allows an authenticated attacker to execute arbitrary SQL statements on the DBMS used by the web application. Authenticated users may be able to…
- risk 0.49cvss 7.5epss 0.01
Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by a XML Injection (aka Blind XPath Injection) vulnerability that could lead in minor arbitrary file system read. Exploitation of this issue does not require user…
- risk 0.46cvss 7.0epss 0.00
In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely invalidate the user session upon logout. Thus an authenticated local attacker may gain acces to the original user's session.
- risk 0.47cvss 7.2epss 0.00
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device.
- risk 0.47cvss 7.2epss 0.01
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device.
- risk 0.53cvss 8.2epss 0.00
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP API. This might cause certificate errors for SSL-connections and might result in a partial denial-of-service.
- risk 0.57cvss 8.8epss 0.01
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated remote attacker can execute code with root permissions with a specially crafted HTTP POST when uploading a certificate to the device.
- risk 0.49cvss 7.5epss 0.01
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote unauthenticated attacker can obtain the r/w community string of the SNMPv2 daemon.
- risk 0.47cvss 7.2epss 0.01
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 the SNMP daemon is running with root privileges allowing a remote attacker with knowledge of the SNMPv2 r/w community string to execute system commands as root.
- risk 0.48cvss 7.4epss 0.01
There is a command injection problem in the old version of the mobile phone backup app.
- risk 0.49cvss 7.5epss 0.01
Improper input validation vulnerability on the range header in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.
- risk 0.00cvss 8.8epss 0.01
Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability in the default configuration. Version…
- risk 0.57cvss 8.8epss 0.01
The FULL - Customer plugin for WordPress is vulnerable to Arbitrary File Upload via the /install-plugin REST route in versions up to, and including, 2.2.3 due to improper authorization. This allows authenticated attackers with subscriber-level permissions and above to execute…
- risk 0.57cvss 8.8epss 0.01
The Real Estate Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.2 due to insufficient restriction on the 'rem_save_profile_front' function. This makes it possible for authenticated attackers, with minimal permissions such as…
- risk 0.49cvss 7.5epss 0.01
The cryptocurrency wallet entropy seeding mechanism used in Libbitcoin Explorer 3.0.0 through 3.6.0 is weak, aka the Milk Sad issue. The use of an mt19937 Mersenne Twister PRNG restricts the internal entropy to 32 bits regardless of settings. This allows remote attackers to…
- risk 0.49cvss 7.6epss 0.01
Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access.
- risk 0.51cvss 7.9epss 0.00
Untrusted search path in Zoom Rooms for Windows before version 5.15.5 may allow an authenticated user to enable a denial of service via local access.
- risk 0.57cvss 8.8epss 0.00
Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via local access.
- risk 0.49cvss 7.5epss 0.00
ASUS RT-AC66U B1 3.0.0.4.286_51665 was discovered to transmit sensitive information in cleartext.
- risk 0.51cvss 7.8epss 0.00
An issue in Diebold Nixdorf Vynamic View Console v.5.3.1 and before allows a local attacker to execute arbitrary code via not restricting the search path for required DLLs and not verifying the signature.
- risk 0.42cvss 7.5epss 0.01
go-libp2p is the Go implementation of the libp2p Networking Stack. Prior to versions 0.27.8, 0.28.2, and 0.29.1 malicious peer can use large RSA keys to run a resource exhaustion attack & force a node to spend time doing signature verification of the large key. This…
- risk 0.62cvss 7.5epss 0.15
.NET and Visual Studio Denial of Service Vulnerability
- risk 0.63cvss 8.8epss 0.74
ASP.NET Elevation of Privilege Vulnerability
- risk 0.48cvss 7.4epss 0.01
.NET Framework Spoofing Vulnerability
- risk 0.57cvss 8.8epss 0.01
Windows Mobile Device Management Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.03
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.01
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- risk 0.53cvss 8.0epss 0.11
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.59cvss 8.8epss 0.17
Microsoft Exchange Server Spoofing Vulnerability