| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-47674 | Cri | 0.64 | 9.8 | 0.01 | Nov 16, 2023 | Missing authentication for critical function vulnerability in First Corporation's DVRs allows a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB,… | ||
| CVE-2023-47213 | Cri | 0.64 | 9.8 | 0.01 | Nov 16, 2023 | First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB,… | ||
| CVE-2023-47003 | Cri | 0.64 | 9.8 | 0.01 | Nov 16, 2023 | An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafted string in DataBlock_ItemIsDeleted. | ||
| CVE-2021-35437 | Cri | 0.64 | 9.8 | 0.01 | Nov 16, 2023 | SQL injection vulnerability in LMXCMS v.1.4 allows attacker to execute arbitrary code via the TagsAction.class. | ||
| CVE-2023-48365 | Cri | 0.82 | 9.6 | 0.25 | KEV | Nov 15, 2023 | Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of HTTP headers, a remote attacker is able to elevate their privilege by tunneling HTTP requests, allowing them to execute HTTP… | |
| CVE-2023-41442 | Cri | 0.64 | 9.8 | 0.01 | Nov 15, 2023 | An issue in Kloudq Technologies Limited Tor Equip 1.0, Tor Loco Mini 1.0 through 3.1 allows a remote attacker to execute arbitrary code via a crafted request to the MQTT component. | ||
| CVE-2023-47445 | Cri | 0.64 | 9.8 | 0.01 | Nov 15, 2023 | Pre-School Enrollment version 1.0 is vulnerable to SQL Injection via the username parameter in preschool/admin/ page. | ||
| CVE-2023-47678 | Cri | 0.59 | 9.1 | 0.01 | Nov 15, 2023 | An improper access control vulnerability exists in RT-AC87U all versions. An attacker may read or write files that are not intended to be accessed by connecting to a target device via tftp. | ||
| CVE-2023-47308 | Cri | 0.64 | 9.8 | 0.01 | Nov 15, 2023 | In the module "Newsletter Popup PRO with Voucher/Coupon code" (newsletterpop) before version 2.6.1 from Active Design for PrestaShop, a guest can perform SQL injection in affected versions. The method `NewsletterpopsendVerificationModuleFrontController::checkEmailSubscription()`… | ||
| CVE-2023-43979 | Cri | 0.64 | 9.8 | 0.01 | Nov 15, 2023 | ETS Soft ybc_blog before v4.4.0 was discovered to contain a SQL injection vulnerability via the component Ybc_blogBlogModuleFrontController::getPosts(). | ||
| CVE-2023-39337 | Cri | 0.59 | 9.1 | 0.02 | Nov 15, 2023 | A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with knowledge of an enrolled device identifier to access and extract sensitive information, including device and environment configuration details, as well as secrets. This vulnerability… | ||
| CVE-2023-39335 | Cri | 0.64 | 9.8 | 0.02 | Nov 15, 2023 | A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated threat actor to impersonate any existing user during the device enrollment process. This issue poses a significant security risk, as it enables unauthorized… | ||
| CVE-2023-45616 | Cri | 0.64 | 9.8 | 0.02 | Nov 14, 2023 | There is a buffer overflow vulnerability in the underlying AirWave client service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful… | ||
| CVE-2023-45615 | Cri | 0.64 | 9.8 | 0.02 | Nov 14, 2023 | There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these… | ||
| CVE-2023-45614 | Cri | 0.64 | 9.8 | 0.02 | Nov 14, 2023 | There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these… | ||
| CVE-2023-34060 | Cri | 0.64 | 9.8 | 0.01 | Nov 14, 2023 | VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance was upgraded to 10.5 from an older version. On an upgraded version of VMware Cloud Director Appliance 10.5, a malicious actor with network access to the… | ||
| CVE-2023-31273 | Cri | 0.65 | 10.0 | 0.01 | Nov 14, 2023 | Protection mechanism failure in some Intel DCM software before version 5.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access. | ||
| CVE-2023-20596 | Cri | 0.64 | 9.8 | 0.01 | Nov 14, 2023 | Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 access potentially leading to arbitrary code execution. | ||
| CVE-2022-23821 | Cri | 0.64 | 9.8 | 0.01 | Nov 14, 2023 | Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution. | ||
| CVE-2023-36553 | Cri | 0.64 | 9.8 | 0.02 | Nov 14, 2023 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.3.3 and 5.2.5 through 5.2.8 and 5.2.1 through 5.2.2 and 5.1.0 through 5.1.3 and 5.0.0 through 5.0.1 and 4.10.0 and 4.9.0 and 4.7.2… | ||
| CVE-2023-36397 | Cri | 0.65 | 9.8 | 0.18 | Nov 14, 2023 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | ||
| CVE-2023-36028 | Cri | 0.64 | 9.8 | 0.03 | Nov 14, 2023 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | ||
| CVE-2023-34991 | Cri | 0.66 | 9.8 | 0.29 | Nov 14, 2023 | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.0 through 8.4.2 and 8.3.0 through 8.3.2 and 8.2.2 allows attacker to execute unauthorized code or commands via… | ||
| CVE-2023-6126 | Cri | 0.00 | 9.8 | 0.01 | Nov 14, 2023 | Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. | ||
| CVE-2023-46601 | Cri | 0.62 | 9.6 | 0.01 | Nov 14, 2023 | A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in making the SQLServer connection. This could allow an attacker to query the database directly to access information that the user should not have access to. | ||
| CVE-2023-44373 | Cri | 0.59 | 9.1 | 0.01 | Nov 14, 2023 | Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell. Follow-up of CVE-2022-36323. | ||
| CVE-2023-43505 | Cri | 0.62 | 9.6 | 0.01 | Nov 14, 2023 | A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in SMB shares. This could allow an attacker to access files that the user should not have access to. | ||
| CVE-2023-43504 | Cri | 0.62 | 9.6 | 0.01 | Nov 14, 2023 | A vulnerability has been identified in COMOS (All versions < V10.4.4). Ptmcast executable used for testing cache validation service in affected application is vulnerable to Structured Exception Handler (SEH) based buffer overflow. This could allow an attacker to execute… | ||
| CVE-2023-31247 | Cri | 0.59 | 9.0 | 0.02 | Nov 14, 2023 | A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability. | ||
| CVE-2023-28391 | Cri | 0.59 | 9.0 | 0.01 | Nov 14, 2023 | A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted network packets can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability. | ||
| CVE-2023-28379 | Cri | 0.59 | 9.0 | 0.02 | Nov 14, 2023 | A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability. | ||
| CVE-2023-27882 | Cri | 0.59 | 9.0 | 0.02 | Nov 14, 2023 | A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability. | ||
| CVE-2023-25181 | Cri | 0.59 | 9.0 | 0.02 | Nov 14, 2023 | A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network packets can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability. | ||
| CVE-2023-45878 | Cri | 0.69 | 9.8 | 0.63 | Nov 14, 2023 | GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication. The endpoint accepts the img, path, and gibbonPersonID parameters. The img parameter is expected to be a base64 encoded image. If the… | ||
| CVE-2023-43902 | Cri | 0.64 | 9.8 | 0.01 | Nov 14, 2023 | Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token. | ||
| CVE-2023-31403 | Cri | 0.62 | 9.6 | 0.00 | Nov 14, 2023 | SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder. As a result, any malicious user can read and write to the SMB shared folder. Additionally, the files in the folder can be executed or be used by… | ||
| CVE-2023-6097 | Cri | 0.61 | 9.4 | 0.01 | Nov 13, 2023 | A SQL injection vulnerability has been found in ICS Business Manager, affecting version 7.06.0028.7089. This vulnerability could allow a remote user to send a specially crafted SQL query and retrieve all the information stored in the database. The data could also be modified or… | ||
| CVE-2023-46850 | Cri | 0.64 | 9.8 | 0.02 | Nov 11, 2023 | Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer. | ||
| CVE-2023-4804 | Cri | 0.65 | 10.0 | 0.01 | Nov 10, 2023 | An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed. | ||
| CVE-2023-47128 | Cri | 0.52 | 9.1 | 0.01 | Nov 10, 2023 | Piccolo is an object-relational mapping and query builder which supports asyncio. Prior to version 1.1.1, the handling of named transaction `savepoints` in all database implementations is vulnerable to SQL Injection via f-strings. While the likelihood of an end developer… | ||
| CVE-2023-47800 | Cri | 0.64 | 9.8 | 0.01 | Nov 10, 2023 | Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account, allowing a threat actor to perform remote code execution, data exfiltration, or other nefarious actions such as tampering with data or… | ||
| CVE-2023-47246 | Cri | 0.90 | 9.8 | 0.99 | KEV | Nov 10, 2023 | In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023. | |
| CVE-2023-39796 | Cri | 0.64 | 9.8 | 0.06 | Nov 10, 2023 | SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the DB_RECORD_TABLE parameter. | ||
| CVE-2023-6069 | Cri | 0.57 | 9.9 | 0.01 | Nov 10, 2023 | Improper Link Resolution Before File Access in GitHub repository froxlor/froxlor prior to 2.1.0. | ||
| CVE-2023-46729 | Cri | 0.54 | 9.3 | 0.01 | Nov 10, 2023 | sentry-javascript provides Sentry SDKs for JavaScript. An unsanitized input of Next.js SDK tunnel endpoint allows sending HTTP requests to arbitrary URLs and reflecting the response back to the user. This issue only affects users who have Next.js SDK tunneling feature enabled.… | ||
| CVE-2023-47110 | Cri | 0.52 | 9.1 | 0.00 | Nov 9, 2023 | blockreassurance adds an information block aimed at offering helpful information to reassure customers that their store is trustworthy. An ajax function in module blockreassurance allows modifying any value in the configuration table. This vulnerability has been patched in… | ||
| CVE-2023-43791 | Cri | 0.57 | 9.8 | 0.01 | Nov 9, 2023 | Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained within the ORM Leak vulnerability to impersonate any account on Label Studio. An attacker could exploit these vulnerabilities to escalate… | ||
| CVE-2023-4612 | Cri | 0.64 | 9.8 | 0.01 | Nov 9, 2023 | Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions the issue will be fixed. For the date… | ||
| CVE-2023-47248 | Cri | 0.58 | 9.8 | 0.14 | Nov 9, 2023 | Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from untrusted sources (for example user-supplied input files). This… | ||
| CVE-2021-43609 | Cri | 0.65 | 9.9 | 0.02 | Nov 9, 2023 | An issue was discovered in Spiceworks Help Desk Server before 1.3.3. A Blind Boolean SQL injection vulnerability within the order_by_for_ticket function in app/models/reporting/database_query.rb allows an authenticated attacker to execute arbitrary SQL commands via the sort… |
- risk 0.64cvss 9.8epss 0.01
Missing authentication for critical function vulnerability in First Corporation's DVRs allows a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB,…
- risk 0.64cvss 9.8epss 0.01
First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB,…
- risk 0.64cvss 9.8epss 0.01
An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafted string in DataBlock_ItemIsDeleted.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in LMXCMS v.1.4 allows attacker to execute arbitrary code via the TagsAction.class.
- risk 0.82cvss 9.6epss 0.25
Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of HTTP headers, a remote attacker is able to elevate their privilege by tunneling HTTP requests, allowing them to execute HTTP…
- risk 0.64cvss 9.8epss 0.01
An issue in Kloudq Technologies Limited Tor Equip 1.0, Tor Loco Mini 1.0 through 3.1 allows a remote attacker to execute arbitrary code via a crafted request to the MQTT component.
- risk 0.64cvss 9.8epss 0.01
Pre-School Enrollment version 1.0 is vulnerable to SQL Injection via the username parameter in preschool/admin/ page.
- risk 0.59cvss 9.1epss 0.01
An improper access control vulnerability exists in RT-AC87U all versions. An attacker may read or write files that are not intended to be accessed by connecting to a target device via tftp.
- risk 0.64cvss 9.8epss 0.01
In the module "Newsletter Popup PRO with Voucher/Coupon code" (newsletterpop) before version 2.6.1 from Active Design for PrestaShop, a guest can perform SQL injection in affected versions. The method `NewsletterpopsendVerificationModuleFrontController::checkEmailSubscription()`…
- risk 0.64cvss 9.8epss 0.01
ETS Soft ybc_blog before v4.4.0 was discovered to contain a SQL injection vulnerability via the component Ybc_blogBlogModuleFrontController::getPosts().
- risk 0.59cvss 9.1epss 0.02
A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with knowledge of an enrolled device identifier to access and extract sensitive information, including device and environment configuration details, as well as secrets. This vulnerability…
- risk 0.64cvss 9.8epss 0.02
A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated threat actor to impersonate any existing user during the device enrollment process. This issue poses a significant security risk, as it enables unauthorized…
- risk 0.64cvss 9.8epss 0.02
There is a buffer overflow vulnerability in the underlying AirWave client service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful…
- risk 0.64cvss 9.8epss 0.02
There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these…
- risk 0.64cvss 9.8epss 0.02
There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these…
- risk 0.64cvss 9.8epss 0.01
VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance was upgraded to 10.5 from an older version. On an upgraded version of VMware Cloud Director Appliance 10.5, a malicious actor with network access to the…
- risk 0.65cvss 10.0epss 0.01
Protection mechanism failure in some Intel DCM software before version 5.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
- risk 0.64cvss 9.8epss 0.01
Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 access potentially leading to arbitrary code execution.
- risk 0.64cvss 9.8epss 0.01
Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.
- risk 0.64cvss 9.8epss 0.02
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.3.3 and 5.2.5 through 5.2.8 and 5.2.1 through 5.2.2 and 5.1.0 through 5.1.3 and 5.0.0 through 5.0.1 and 4.10.0 and 4.9.0 and 4.7.2…
- risk 0.65cvss 9.8epss 0.18
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.03
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
- risk 0.66cvss 9.8epss 0.29
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.0 through 8.4.2 and 8.3.0 through 8.3.2 and 8.2.2 allows attacker to execute unauthorized code or commands via…
- risk 0.00cvss 9.8epss 0.01
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
- risk 0.62cvss 9.6epss 0.01
A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in making the SQLServer connection. This could allow an attacker to query the database directly to access information that the user should not have access to.
- risk 0.59cvss 9.1epss 0.01
Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell. Follow-up of CVE-2022-36323.
- risk 0.62cvss 9.6epss 0.01
A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in SMB shares. This could allow an attacker to access files that the user should not have access to.
- risk 0.62cvss 9.6epss 0.01
A vulnerability has been identified in COMOS (All versions < V10.4.4). Ptmcast executable used for testing cache validation service in affected application is vulnerable to Structured Exception Handler (SEH) based buffer overflow. This could allow an attacker to execute…
- risk 0.59cvss 9.0epss 0.02
A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
- risk 0.59cvss 9.0epss 0.01
A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted network packets can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
- risk 0.59cvss 9.0epss 0.02
A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
- risk 0.59cvss 9.0epss 0.02
A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
- risk 0.59cvss 9.0epss 0.02
A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network packets can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.
- risk 0.69cvss 9.8epss 0.63
GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication. The endpoint accepts the img, path, and gibbonPersonID parameters. The img parameter is expected to be a base64 encoded image. If the…
- risk 0.64cvss 9.8epss 0.01
Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.
- risk 0.62cvss 9.6epss 0.00
SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder. As a result, any malicious user can read and write to the SMB shared folder. Additionally, the files in the folder can be executed or be used by…
- risk 0.61cvss 9.4epss 0.01
A SQL injection vulnerability has been found in ICS Business Manager, affecting version 7.06.0028.7089. This vulnerability could allow a remote user to send a specially crafted SQL query and retrieve all the information stored in the database. The data could also be modified or…
- risk 0.64cvss 9.8epss 0.02
Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.
- risk 0.65cvss 10.0epss 0.01
An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.
- risk 0.52cvss 9.1epss 0.01
Piccolo is an object-relational mapping and query builder which supports asyncio. Prior to version 1.1.1, the handling of named transaction `savepoints` in all database implementations is vulnerable to SQL Injection via f-strings. While the likelihood of an end developer…
- risk 0.64cvss 9.8epss 0.01
Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account, allowing a threat actor to perform remote code execution, data exfiltration, or other nefarious actions such as tampering with data or…
- risk 0.90cvss 9.8epss 0.99
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.
- risk 0.64cvss 9.8epss 0.06
SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the DB_RECORD_TABLE parameter.
- risk 0.57cvss 9.9epss 0.01
Improper Link Resolution Before File Access in GitHub repository froxlor/froxlor prior to 2.1.0.
- risk 0.54cvss 9.3epss 0.01
sentry-javascript provides Sentry SDKs for JavaScript. An unsanitized input of Next.js SDK tunnel endpoint allows sending HTTP requests to arbitrary URLs and reflecting the response back to the user. This issue only affects users who have Next.js SDK tunneling feature enabled.…
- risk 0.52cvss 9.1epss 0.00
blockreassurance adds an information block aimed at offering helpful information to reassure customers that their store is trustworthy. An ajax function in module blockreassurance allows modifying any value in the configuration table. This vulnerability has been patched in…
- risk 0.57cvss 9.8epss 0.01
Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained within the ORM Leak vulnerability to impersonate any account on Label Studio. An attacker could exploit these vulnerabilities to escalate…
- risk 0.64cvss 9.8epss 0.01
Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions the issue will be fixed. For the date…
- risk 0.58cvss 9.8epss 0.14
Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from untrusted sources (for example user-supplied input files). This…
- risk 0.65cvss 9.9epss 0.02
An issue was discovered in Spiceworks Help Desk Server before 1.3.3. A Blind Boolean SQL injection vulnerability within the order_by_for_ticket function in app/models/reporting/database_query.rb allows an authenticated attacker to execute arbitrary SQL commands via the sort…