| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-45225 | Cri | 0.64 | 9.8 | 0.01 | Nov 8, 2023 | Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While parsing certain XML elements from incoming network requests, the… | ||
| CVE-2023-43755 | Cri | 0.64 | 9.8 | 0.01 | Nov 8, 2023 | Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. During the processing and parsing of certain fields in XML elements from… | ||
| CVE-2023-3959 | Cri | 0.67 | 9.8 | 0.40 | Nov 8, 2023 | Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While processing XML elements from incoming network requests, the product… | ||
| CVE-2023-29974 | Cri | 0.64 | 9.8 | 0.02 | Nov 8, 2023 | An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements. | ||
| CVE-2023-47397 | Cri | 0.64 | 9.8 | 0.01 | Nov 8, 2023 | WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php. | ||
| CVE-2023-45849 | Cri | 0.59 | 9.0 | 0.01 | Nov 8, 2023 | An arbitrary code execution which results in privilege escalation was discovered in Helix Core versions prior to 2023.2. Reported by Jason Geffner. | ||
| CVE-2023-5941 | Cri | 0.64 | 9.8 | 0.01 | Nov 8, 2023 | In versions of FreeBSD 12.4-RELEASE prior to 12.4-RELEASE-p7 and FreeBSD 13.2-RELEASE prior to 13.2-RELEASE-p5 the __sflush() stdio function in libc does not correctly update FILE objects' write space members for write-buffered streams when the write(2) system call returns an… | ||
| CVE-2023-5801 | Cri | 0.59 | 9.1 | 0.00 | Nov 8, 2023 | Vulnerability of identity verification being bypassed in the face unlock module. Successful exploitation of this vulnerability will affect integrity and confidentiality. | ||
| CVE-2023-46800 | Cri | 0.64 | 9.8 | 0.01 | Nov 7, 2023 | Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the view_profile.php resource does not validate the characters received and they are sent unfiltered to the database. | ||
| CVE-2023-46793 | Cri | 0.64 | 9.8 | 0.01 | Nov 7, 2023 | Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'day' parameter in the 'register()' function of the functions.php resource does not validate the characters received and they are sent unfiltered to the database. | ||
| CVE-2023-46789 | Cri | 0.64 | 9.8 | 0.01 | Nov 7, 2023 | Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'filename' attribute of the 'pic1' multipart parameter of the functions.php resource does not validate the characters received and they are sent unfiltered to the… | ||
| CVE-2023-46788 | Cri | 0.64 | 9.8 | 0.01 | Nov 7, 2023 | Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter in the 'uploadphoto()' function of the functions.php resource does not validate the characters received and they are sent unfiltered to the database. | ||
| CVE-2023-46787 | Cri | 0.64 | 9.8 | 0.01 | Nov 7, 2023 | Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the auth/auth.php resource does not validate the characters received and they are sent unfiltered to the database. | ||
| CVE-2023-46785 | Cri | 0.64 | 9.8 | 0.01 | Nov 7, 2023 | Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the partner_preference.php resource does not validate the characters received and they are sent unfiltered to the database. | ||
| CVE-2023-46679 | Cri | 0.64 | 9.8 | 0.01 | Nov 7, 2023 | Online Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txt_uname_email' parameter of the index.php resource does not validate the characters received and they are sent unfiltered to the database. | ||
| CVE-2023-46677 | Cri | 0.64 | 9.8 | 0.01 | Nov 7, 2023 | Online Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txt_uname' parameter of the sign-up.php resource does not validate the characters received and they are sent unfiltered to the database. | ||
| CVE-2023-46243 | Cri | 0.57 | 9.9 | 0.01 | Nov 7, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for a user to execute any content with the right of an existing document's content author, provided the user have edit right on it. A… | ||
| CVE-2023-46253 | Cri | 0.59 | 9.1 | 0.02 | Nov 7, 2023 | Squidex is an open source headless CMS and content management hub. Affected versions are subject to an arbitrary file write vulnerability in the backup restore feature which allows an authenticated attacker to gain remote code execution (RCE). Squidex allows users with the… | ||
| CVE-2023-46244 | Cri | 0.52 | 9.1 | 0.01 | Nov 7, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for a user to write a script in which any velocity content is executed with the right of any other document content author. Since this API… | ||
| CVE-2023-46242 | Cri | 0.55 | 9.6 | 0.00 | Nov 7, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to execute a content with the right of any user via a crafted URL. A user must have `programming` privileges in order to exploit this… | ||
| CVE-2023-46501 | Cri | 0.59 | 9.1 | 0.01 | Nov 7, 2023 | An issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view and change admin password function. | ||
| CVE-2023-47359 | Cri | 0.64 | 9.8 | 0.01 | Nov 7, 2023 | Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results in a memory corruption. | ||
| CVE-2023-42659 | Cri | 0.59 | 9.1 | 0.01 | Nov 7, 2023 | In WS_FTP Server versions prior to 8.7.6 and 8.8.4, an unrestricted file upload flaw has been identified. An authenticated Ad Hoc Transfer user has the ability to craft an API call which allows them to upload a file to a specified location on the underlying operating system… | ||
| CVE-2023-47456 | Cri | 0.59 | 9.1 | 0.01 | Nov 7, 2023 | Tenda AX1806 V1.0.0.1 contains a stack overflow vulnerability in function sub_455D4, called by function fromSetWirelessRepeat. | ||
| CVE-2023-47455 | Cri | 0.59 | 9.1 | 0.01 | Nov 7, 2023 | Tenda AX1806 V1.0.0.1 contains a heap overflow vulnerability in setSchedWifi function, in which the src and v12 are directly obtained from http request parameter schedStartTime and schedEndTime without checking their size. | ||
| CVE-2023-33481 | Cri | 0.64 | 9.8 | 0.01 | Nov 7, 2023 | RemoteClinic 2.0 is vulnerable to a time-based blind SQL injection attack in the 'start' GET parameter of patients/index.php. | ||
| CVE-2023-33479 | Cri | 0.64 | 9.8 | 0.01 | Nov 7, 2023 | RemoteClinic version 2.0 contains a SQL injection vulnerability in the /staff/edit.php file. | ||
| CVE-2023-33478 | Cri | 0.64 | 9.8 | 0.01 | Nov 7, 2023 | RemoteClinic 2.0 has a SQL injection vulnerability in the ID parameter of /medicines/stocks.php. | ||
| CVE-2023-42284 | Cri | 0.64 | 9.8 | 0.01 | Nov 7, 2023 | Blind SQL injection in api_version parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query. | ||
| CVE-2023-42283 | Cri | 0.64 | 9.8 | 0.01 | Nov 7, 2023 | Blind SQL injection in api_id parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query. | ||
| CVE-2023-38547 | Cri | 0.65 | 9.8 | 0.19 | Nov 7, 2023 | A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configuration database. This may lead to remote code execution on the SQL server hosting the Veeam ONE configuration database. | ||
| CVE-2023-33045 | Cri | 0.64 | 9.8 | 0.00 | Nov 7, 2023 | Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute. | ||
| CVE-2023-28574 | Cri | 0.59 | 9.0 | 0.00 | Nov 7, 2023 | Memory corruption in core services when Diag handler receives a command to configure event listeners. | ||
| CVE-2023-22388 | Cri | 0.64 | 9.8 | 0.00 | Nov 7, 2023 | Memory Corruption in Multi-mode Call Processor while processing bit mask API. | ||
| CVE-2023-21671 | Cri | 0.60 | 9.3 | 0.00 | Nov 7, 2023 | Memory Corruption in Core during syscall for Sectools Fuse comparison feature. | ||
| CVE-2023-2675 | Cri | 0.00 | 9.8 | 0.01 | Nov 7, 2023 | Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 2023.Q1.1223. | ||
| CVE-2023-5601 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2023 | The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated users to upload arbitrary files to the server, leading to RCE. | ||
| CVE-2023-5777 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2023 | Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the crash report transmission is finished, the private key is exposed to the public, which could result in obtaining remote control of the crash report server. | ||
| CVE-2023-46732 | Cri | 0.56 | 9.6 | 0.02 | Nov 6, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to reflected cross-site scripting (RXSS) via the `rev` parameter that is used in the content of the content menu without escaping. If an attacker can… | ||
| CVE-2023-46731 | Cri | 0.00 | 10.0 | 0.89 | Nov 6, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki doesn't properly escape the section URL parameter that is used in the code for displaying administration sections. This allows any user with read access to the document… | ||
| CVE-2023-5964 | — | Cri | 0.64 | 9.9 | 0.01 | Nov 6, 2023 | The 1E-Exchange-DisplayMessageinstruction that is part of the End-User Interaction product pack available on the 1E Exchange does not properly validate the Caption or Message parameters, which allows for a specially crafted input to perform arbitrary code execution with SYSTEM… | |
| CVE-2023-45163 | — | Cri | 0.64 | 9.9 | 0.01 | Nov 6, 2023 | The 1E-Exchange-CommandLinePing instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the input parameter, which allows for a specially crafted input to perform arbitrary code execution with SYSTEM permissions. This… | |
| CVE-2023-45161 | — | Cri | 0.64 | 9.9 | 0.01 | Nov 6, 2023 | The 1E-Exchange-URLResponseTime instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the URL parameter, which allows for a specially crafted input to perform arbitrary code execution with SYSTEM permissions. This… | |
| CVE-2023-38382 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daniel Söderström / Sidney van de Stouwe Subscribe to Category allows SQL Injection.This issue affects Subscribe to Category: from n/a through 2.7.4. | ||
| CVE-2023-4699 | Cri | 0.65 | 10.0 | 0.01 | Nov 6, 2023 | Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC-F Series CPU modules, MELSEC iQ-F Series, MELSEC iQ-R series CPU modules, MELSEC iQ-R series, MELSEC iQ-L series, MELSEC Q series, MELSEC-L series, Mitsubishi Electric CNC… | ||
| CVE-2023-47253 | Cri | 0.65 | 9.8 | 0.14 | Nov 6, 2023 | Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php gridValoresPopHidden parameter. | ||
| CVE-2023-38406 | Cri | 0.00 | 9.8 | 0.01 | Nov 6, 2023 | bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow." | ||
| CVE-2023-46981 | Cri | 0.64 | 9.8 | 0.01 | Nov 5, 2023 | SQL injection vulnerability in Novel-Plus v.4.2.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /common/log/list. | ||
| CVE-2023-40922 | Cri | 0.64 | 9.8 | 0.01 | Nov 4, 2023 | kerawen before v2.5.1 was discovered to contain a SQL injection vulnerability via the ocs_id_cart parameter at KerawenDeliveryModuleFrontController::initContent(). | ||
| CVE-2023-36529 | Cri | 0.64 | 9.9 | 0.01 | Nov 3, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez - Real Estate WordPress Theme allows SQL Injection.This issue affects Houzez - Real Estate WordPress Theme: from n/a through 1.3.4. |
- risk 0.64cvss 9.8epss 0.01
Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While parsing certain XML elements from incoming network requests, the…
- risk 0.64cvss 9.8epss 0.01
Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. During the processing and parsing of certain fields in XML elements from…
- risk 0.67cvss 9.8epss 0.40
Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While processing XML elements from incoming network requests, the product…
- risk 0.64cvss 9.8epss 0.02
An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.
- risk 0.64cvss 9.8epss 0.01
WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.
- risk 0.59cvss 9.0epss 0.01
An arbitrary code execution which results in privilege escalation was discovered in Helix Core versions prior to 2023.2. Reported by Jason Geffner.
- risk 0.64cvss 9.8epss 0.01
In versions of FreeBSD 12.4-RELEASE prior to 12.4-RELEASE-p7 and FreeBSD 13.2-RELEASE prior to 13.2-RELEASE-p5 the __sflush() stdio function in libc does not correctly update FILE objects' write space members for write-buffered streams when the write(2) system call returns an…
- risk 0.59cvss 9.1epss 0.00
Vulnerability of identity verification being bypassed in the face unlock module. Successful exploitation of this vulnerability will affect integrity and confidentiality.
- risk 0.64cvss 9.8epss 0.01
Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the view_profile.php resource does not validate the characters received and they are sent unfiltered to the database.
- risk 0.64cvss 9.8epss 0.01
Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'day' parameter in the 'register()' function of the functions.php resource does not validate the characters received and they are sent unfiltered to the database.
- risk 0.64cvss 9.8epss 0.01
Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'filename' attribute of the 'pic1' multipart parameter of the functions.php resource does not validate the characters received and they are sent unfiltered to the…
- risk 0.64cvss 9.8epss 0.01
Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter in the 'uploadphoto()' function of the functions.php resource does not validate the characters received and they are sent unfiltered to the database.
- risk 0.64cvss 9.8epss 0.01
Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the auth/auth.php resource does not validate the characters received and they are sent unfiltered to the database.
- risk 0.64cvss 9.8epss 0.01
Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the partner_preference.php resource does not validate the characters received and they are sent unfiltered to the database.
- risk 0.64cvss 9.8epss 0.01
Online Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txt_uname_email' parameter of the index.php resource does not validate the characters received and they are sent unfiltered to the database.
- risk 0.64cvss 9.8epss 0.01
Online Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txt_uname' parameter of the sign-up.php resource does not validate the characters received and they are sent unfiltered to the database.
- risk 0.57cvss 9.9epss 0.01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for a user to execute any content with the right of an existing document's content author, provided the user have edit right on it. A…
- risk 0.59cvss 9.1epss 0.02
Squidex is an open source headless CMS and content management hub. Affected versions are subject to an arbitrary file write vulnerability in the backup restore feature which allows an authenticated attacker to gain remote code execution (RCE). Squidex allows users with the…
- risk 0.52cvss 9.1epss 0.01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for a user to write a script in which any velocity content is executed with the right of any other document content author. Since this API…
- risk 0.55cvss 9.6epss 0.00
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to execute a content with the right of any user via a crafted URL. A user must have `programming` privileges in order to exploit this…
- risk 0.59cvss 9.1epss 0.01
An issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view and change admin password function.
- risk 0.64cvss 9.8epss 0.01
Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results in a memory corruption.
- risk 0.59cvss 9.1epss 0.01
In WS_FTP Server versions prior to 8.7.6 and 8.8.4, an unrestricted file upload flaw has been identified. An authenticated Ad Hoc Transfer user has the ability to craft an API call which allows them to upload a file to a specified location on the underlying operating system…
- risk 0.59cvss 9.1epss 0.01
Tenda AX1806 V1.0.0.1 contains a stack overflow vulnerability in function sub_455D4, called by function fromSetWirelessRepeat.
- risk 0.59cvss 9.1epss 0.01
Tenda AX1806 V1.0.0.1 contains a heap overflow vulnerability in setSchedWifi function, in which the src and v12 are directly obtained from http request parameter schedStartTime and schedEndTime without checking their size.
- risk 0.64cvss 9.8epss 0.01
RemoteClinic 2.0 is vulnerable to a time-based blind SQL injection attack in the 'start' GET parameter of patients/index.php.
- risk 0.64cvss 9.8epss 0.01
RemoteClinic version 2.0 contains a SQL injection vulnerability in the /staff/edit.php file.
- risk 0.64cvss 9.8epss 0.01
RemoteClinic 2.0 has a SQL injection vulnerability in the ID parameter of /medicines/stocks.php.
- risk 0.64cvss 9.8epss 0.01
Blind SQL injection in api_version parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query.
- risk 0.64cvss 9.8epss 0.01
Blind SQL injection in api_id parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query.
- risk 0.65cvss 9.8epss 0.19
A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configuration database. This may lead to remote code execution on the SQL server hosting the Veeam ONE configuration database.
- risk 0.64cvss 9.8epss 0.00
Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute.
- risk 0.59cvss 9.0epss 0.00
Memory corruption in core services when Diag handler receives a command to configure event listeners.
- risk 0.64cvss 9.8epss 0.00
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
- risk 0.60cvss 9.3epss 0.00
Memory Corruption in Core during syscall for Sectools Fuse comparison feature.
- risk 0.00cvss 9.8epss 0.01
Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 2023.Q1.1223.
- risk 0.64cvss 9.8epss 0.01
The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated users to upload arbitrary files to the server, leading to RCE.
- risk 0.64cvss 9.8epss 0.01
Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the crash report transmission is finished, the private key is exposed to the public, which could result in obtaining remote control of the crash report server.
- risk 0.56cvss 9.6epss 0.02
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to reflected cross-site scripting (RXSS) via the `rev` parameter that is used in the content of the content menu without escaping. If an attacker can…
- risk 0.00cvss 10.0epss 0.89
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki doesn't properly escape the section URL parameter that is used in the code for displaying administration sections. This allows any user with read access to the document…
- risk 0.64cvss 9.9epss 0.01
The 1E-Exchange-DisplayMessageinstruction that is part of the End-User Interaction product pack available on the 1E Exchange does not properly validate the Caption or Message parameters, which allows for a specially crafted input to perform arbitrary code execution with SYSTEM…
- risk 0.64cvss 9.9epss 0.01
The 1E-Exchange-CommandLinePing instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the input parameter, which allows for a specially crafted input to perform arbitrary code execution with SYSTEM permissions. This…
- risk 0.64cvss 9.9epss 0.01
The 1E-Exchange-URLResponseTime instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the URL parameter, which allows for a specially crafted input to perform arbitrary code execution with SYSTEM permissions. This…
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daniel Söderström / Sidney van de Stouwe Subscribe to Category allows SQL Injection.This issue affects Subscribe to Category: from n/a through 2.7.4.
- risk 0.65cvss 10.0epss 0.01
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC-F Series CPU modules, MELSEC iQ-F Series, MELSEC iQ-R series CPU modules, MELSEC iQ-R series, MELSEC iQ-L series, MELSEC Q series, MELSEC-L series, Mitsubishi Electric CNC…
- risk 0.65cvss 9.8epss 0.14
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php gridValoresPopHidden parameter.
- risk 0.00cvss 9.8epss 0.01
bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in Novel-Plus v.4.2.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /common/log/list.
- risk 0.64cvss 9.8epss 0.01
kerawen before v2.5.1 was discovered to contain a SQL injection vulnerability via the ocs_id_cart parameter at KerawenDeliveryModuleFrontController::initContent().
- risk 0.64cvss 9.9epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez - Real Estate WordPress Theme allows SQL Injection.This issue affects Houzez - Real Estate WordPress Theme: from n/a through 1.3.4.