| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-32724 | Cri | 0.59 | 9.1 | 0.01 | Oct 12, 2023 | Memory pointer is in a property of the Ducktape object. This leads to multiple vulnerabilities related to direct memory access and manipulation. | ||
| CVE-2023-32722 | Cri | 0.62 | 9.6 | 0.01 | Oct 12, 2023 | The zabbix/src/libs/zbxjson module is vulnerable to a buffer overflow when parsing JSON files via zbx_json_open. | ||
| CVE-2023-40833 | Cri | 0.64 | 9.8 | 0.01 | Oct 12, 2023 | An issue in Thecosy IceCMS v.1.0.0 allows a remote attacker to gain privileges via the Id and key parameters in getCosSetting. | ||
| CVE-2023-29453 | Cri | 0.64 | 9.8 | 0.01 | Oct 12, 2023 | Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the… | ||
| CVE-2023-45132 | Cri | 0.00 | 9.1 | 0.01 | Oct 11, 2023 | NAXSI is an open-source maintenance web application firewall (WAF) for NGINX. An issue present starting in version 1.3 and prior to version 1.6 allows someone to bypass the WAF when a malicious `X-Forwarded-For` IP matches `IgnoreIP` `IgnoreCIDR` rules. This old code was… | ||
| CVE-2023-35662 | Cri | 0.64 | 9.8 | 0.00 | Oct 11, 2023 | there is a possible out of bounds write due to buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-35648 | Cri | 0.64 | 9.8 | 0.00 | Oct 11, 2023 | In ProtocolMiscLceIndAdapter::GetConfLevel() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed for… | ||
| CVE-2023-35647 | Cri | 0.64 | 9.8 | 0.00 | Oct 11, 2023 | In ProtocolEmbmsGlobalCellIdAdapter::Init() of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed for… | ||
| CVE-2023-35646 | Cri | 0.64 | 9.8 | 0.00 | Oct 11, 2023 | In TBD of TBD, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-35968 | Cri | 0.64 | 9.8 | 0.01 | Oct 11, 2023 | Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these… | ||
| CVE-2023-35967 | Cri | 0.64 | 9.8 | 0.01 | Oct 11, 2023 | Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these… | ||
| CVE-2023-35966 | Cri | 0.64 | 9.8 | 0.01 | Oct 11, 2023 | Two heap-based buffer overflow vulnerabilities exist in the httpd manage_post functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer… | ||
| CVE-2023-35965 | Cri | 0.64 | 9.8 | 0.01 | Oct 11, 2023 | Two heap-based buffer overflow vulnerabilities exist in the httpd manage_post functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer… | ||
| CVE-2023-34426 | Cri | 0.64 | 9.8 | 0.01 | Oct 11, 2023 | A stack-based buffer overflow vulnerability exists in the httpd manage_request functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to stack-based buffer overflow. An attacker can send a network request to trigger this vulnerability. | ||
| CVE-2023-34365 | Cri | 0.64 | 9.8 | 0.01 | Oct 11, 2023 | A stack-based buffer overflow vulnerability exists in the libutils.so nvram_restore functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a buffer overflow. An attacker can send a network request to trigger this vulnerability. | ||
| CVE-2023-34346 | Cri | 0.64 | 9.8 | 0.01 | Oct 11, 2023 | A stack-based buffer overflow vulnerability exists in the httpd gwcfg.cgi get functionality of Yifan YF325 v1.0_20221108. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. | ||
| CVE-2023-32645 | Cri | 0.68 | 9.8 | 0.54 | Oct 11, 2023 | A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to authentication bypass. An attacker can send a network request to trigger this vulnerability. | ||
| CVE-2023-24479 | Cri | 0.64 | 9.8 | 0.02 | Oct 11, 2023 | An authentication bypass vulnerability exists in the httpd nvram.cgi functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger this vulnerability. | ||
| CVE-2023-44118 | Cri | 0.59 | 9.1 | 0.00 | Oct 11, 2023 | Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnerability will affect availability and confidentiality. | ||
| CVE-2023-44116 | Cri | 0.64 | 9.8 | 0.00 | Oct 11, 2023 | Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful exploitation of this vulnerability may cause some apps to run without being authorized. | ||
| CVE-2023-44107 | Cri | 0.59 | 9.1 | 0.00 | Oct 11, 2023 | Vulnerability of defects introduced in the design process in the screen projection module.Successful exploitation of this vulnerability may affect service availability and integrity. | ||
| CVE-2023-44105 | Cri | 0.64 | 9.8 | 0.00 | Oct 11, 2023 | Vulnerability of permissions not being strictly verified in the window management module.Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2023-37538 | Cri | 0.60 | 9.3 | 0.00 | Oct 11, 2023 | HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site). | ||
| CVE-2023-5521 | Cri | 0.00 | 9.8 | 0.01 | Oct 11, 2023 | Incorrect Authorization in GitHub repository tiann/kernelsu prior to v0.6.9. | ||
| CVE-2023-44981 | Cri | 0.59 | 9.1 | 0.02 | Oct 11, 2023 | Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication ID is listed in… | ||
| CVE-2023-44106 | Cri | 0.64 | 9.8 | 0.00 | Oct 11, 2023 | API permission management vulnerability in the Fwk-Display module.Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2023-4309 | Cri | 0.65 | 10.0 | 0.01 | Oct 10, 2023 | Election Services Co. (ESC) Internet Election Service is vulnerable to SQL injection in multiple pages and parameters. These vulnerabilities allow an unauthenticated, remote attacker to read or modify data for any elections that share the same backend database. ESC deactivated… | ||
| CVE-2023-36434 | Cri | 0.64 | 9.8 | 0.02 | Oct 10, 2023 | Windows IIS Server Elevation of Privilege Vulnerability | ||
| CVE-2023-35349 | Cri | 0.64 | 9.8 | 0.03 | Oct 10, 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||
| CVE-2023-36550 | Cri | 0.64 | 9.8 | 0.02 | Oct 10, 2023 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters. | ||
| CVE-2023-36548 | Cri | 0.64 | 9.8 | 0.02 | Oct 10, 2023 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters. | ||
| CVE-2023-36547 | Cri | 0.64 | 9.8 | 0.02 | Oct 10, 2023 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters. | ||
| CVE-2023-34993 | Cri | 0.65 | 9.8 | 0.18 | Oct 10, 2023 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters. | ||
| CVE-2023-34992 | Cri | 0.70 | 10.0 | 0.80 | Oct 10, 2023 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests. | ||
| CVE-2020-27636 | Cri | 0.59 | 9.1 | 0.01 | Oct 10, 2023 | In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random. | ||
| CVE-2020-27635 | Cri | 0.59 | 9.1 | 0.01 | Oct 10, 2023 | In PicoTCP 1.7.0, TCP ISNs are improperly random. | ||
| CVE-2020-27634 | Cri | 0.59 | 9.1 | 0.02 | Oct 10, 2023 | In Contiki 4.5, TCP ISNs are improperly random. | ||
| CVE-2020-27633 | Cri | 0.59 | 9.1 | 0.01 | Oct 10, 2023 | In FNET 4.6.3, TCP ISNs are improperly random. | ||
| CVE-2020-27631 | Cri | 0.64 | 9.8 | 0.01 | Oct 10, 2023 | In Oryx CycloneTCP 1.9.6, TCP ISNs are improperly random. | ||
| CVE-2020-27630 | Cri | 0.64 | 9.8 | 0.01 | Oct 10, 2023 | In Silicon Labs uC/TCP-IP 3.6.0, TCP ISNs are improperly random. | ||
| CVE-2023-30806 | Cri | 0.69 | 9.8 | 0.66 | Oct 10, 2023 | The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /cgi-bin/login.cgi endpoint. This… | ||
| CVE-2023-30805 | Cri | 0.69 | 9.8 | 0.66 | Oct 10, 2023 | The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /LogInOut.php endpoint. This is… | ||
| CVE-2023-30803 | Cri | 0.65 | 9.8 | 0.18 | Oct 10, 2023 | The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can bypass authentication and access administrative functionality by sending HTTP requests using a crafted Y-forwarded-for… | ||
| CVE-2023-4966 | Cri | 0.90 | 9.4 | 1.00 | KEV | Oct 10, 2023 | Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. | |
| CVE-2023-30801 | Cri | 0.64 | 9.8 | 0.01 | Oct 10, 2023 | All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use the default credentials… | ||
| CVE-2023-41373 | Cri | 0.65 | 9.9 | 0.02 | Oct 10, 2023 | A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BIG-IP system. For BIG-IP system running in Appliance mode, a successful exploit can allow the attacker to cross a security… | ||
| CVE-2023-43625 | Cri | 0.64 | 9.8 | 0.01 | Oct 10, 2023 | A vulnerability has been identified in Simcenter Amesim (All versions < V2021.1). The affected application contains a SOAP endpoint that could allow an unauthenticated remote attacker to perform DLL injection and execute arbitrary code in the context of the affected application… | ||
| CVE-2023-36380 | Cri | 0.64 | 9.8 | 0.00 | Oct 10, 2023 | A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.11 (only with activated debug support)), CP-8050 MASTER MODULE (All versions < CPCI85 V05.11 (only with activated debug support)). The affected devices contain a hard-coded ID in the SSH… | ||
| CVE-2023-43899 | Cri | 0.64 | 9.8 | 0.01 | Oct 9, 2023 | hansun CMS v1.0 was discovered to contain a SQL injection vulnerability via the component /ajax/ajax_login.ashx. | ||
| CVE-2023-43271 | — | Cri | 0.59 | 9.1 | 0.01 | Oct 9, 2023 | Incorrect access control in 70mai a500s v1.2.119 allows attackers to directly access and delete the video files of the driving recorder through ftp and other protocols. |
- risk 0.59cvss 9.1epss 0.01
Memory pointer is in a property of the Ducktape object. This leads to multiple vulnerabilities related to direct memory access and manipulation.
- risk 0.62cvss 9.6epss 0.01
The zabbix/src/libs/zbxjson module is vulnerable to a buffer overflow when parsing JSON files via zbx_json_open.
- risk 0.64cvss 9.8epss 0.01
An issue in Thecosy IceCMS v.1.0.0 allows a remote attacker to gain privileges via the Id and key parameters in getCosSetting.
- risk 0.64cvss 9.8epss 0.01
Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the…
- risk 0.00cvss 9.1epss 0.01
NAXSI is an open-source maintenance web application firewall (WAF) for NGINX. An issue present starting in version 1.3 and prior to version 1.6 allows someone to bypass the WAF when a malicious `X-Forwarded-For` IP matches `IgnoreIP` `IgnoreCIDR` rules. This old code was…
- risk 0.64cvss 9.8epss 0.00
there is a possible out of bounds write due to buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.64cvss 9.8epss 0.00
In ProtocolMiscLceIndAdapter::GetConfLevel() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed for…
- risk 0.64cvss 9.8epss 0.00
In ProtocolEmbmsGlobalCellIdAdapter::Init() of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed for…
- risk 0.64cvss 9.8epss 0.00
In TBD of TBD, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.64cvss 9.8epss 0.01
Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these…
- risk 0.64cvss 9.8epss 0.01
Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these…
- risk 0.64cvss 9.8epss 0.01
Two heap-based buffer overflow vulnerabilities exist in the httpd manage_post functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer…
- risk 0.64cvss 9.8epss 0.01
Two heap-based buffer overflow vulnerabilities exist in the httpd manage_post functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer…
- risk 0.64cvss 9.8epss 0.01
A stack-based buffer overflow vulnerability exists in the httpd manage_request functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to stack-based buffer overflow. An attacker can send a network request to trigger this vulnerability.
- risk 0.64cvss 9.8epss 0.01
A stack-based buffer overflow vulnerability exists in the libutils.so nvram_restore functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a buffer overflow. An attacker can send a network request to trigger this vulnerability.
- risk 0.64cvss 9.8epss 0.01
A stack-based buffer overflow vulnerability exists in the httpd gwcfg.cgi get functionality of Yifan YF325 v1.0_20221108. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability.
- risk 0.68cvss 9.8epss 0.54
A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to authentication bypass. An attacker can send a network request to trigger this vulnerability.
- risk 0.64cvss 9.8epss 0.02
An authentication bypass vulnerability exists in the httpd nvram.cgi functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger this vulnerability.
- risk 0.59cvss 9.1epss 0.00
Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnerability will affect availability and confidentiality.
- risk 0.64cvss 9.8epss 0.00
Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful exploitation of this vulnerability may cause some apps to run without being authorized.
- risk 0.59cvss 9.1epss 0.00
Vulnerability of defects introduced in the design process in the screen projection module.Successful exploitation of this vulnerability may affect service availability and integrity.
- risk 0.64cvss 9.8epss 0.00
Vulnerability of permissions not being strictly verified in the window management module.Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.60cvss 9.3epss 0.00
HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).
- risk 0.00cvss 9.8epss 0.01
Incorrect Authorization in GitHub repository tiann/kernelsu prior to v0.6.9.
- risk 0.59cvss 9.1epss 0.02
Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication ID is listed in…
- risk 0.64cvss 9.8epss 0.00
API permission management vulnerability in the Fwk-Display module.Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.65cvss 10.0epss 0.01
Election Services Co. (ESC) Internet Election Service is vulnerable to SQL injection in multiple pages and parameters. These vulnerabilities allow an unauthenticated, remote attacker to read or modify data for any elections that share the same backend database. ESC deactivated…
- risk 0.64cvss 9.8epss 0.02
Windows IIS Server Elevation of Privilege Vulnerability
- risk 0.64cvss 9.8epss 0.03
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.
- risk 0.64cvss 9.8epss 0.02
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.
- risk 0.64cvss 9.8epss 0.02
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.
- risk 0.65cvss 9.8epss 0.18
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.
- risk 0.70cvss 10.0epss 0.80
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests.
- risk 0.59cvss 9.1epss 0.01
In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random.
- risk 0.59cvss 9.1epss 0.01
In PicoTCP 1.7.0, TCP ISNs are improperly random.
- risk 0.59cvss 9.1epss 0.02
In Contiki 4.5, TCP ISNs are improperly random.
- risk 0.59cvss 9.1epss 0.01
In FNET 4.6.3, TCP ISNs are improperly random.
- risk 0.64cvss 9.8epss 0.01
In Oryx CycloneTCP 1.9.6, TCP ISNs are improperly random.
- risk 0.64cvss 9.8epss 0.01
In Silicon Labs uC/TCP-IP 3.6.0, TCP ISNs are improperly random.
- risk 0.69cvss 9.8epss 0.66
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /cgi-bin/login.cgi endpoint. This…
- risk 0.69cvss 9.8epss 0.66
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /LogInOut.php endpoint. This is…
- risk 0.65cvss 9.8epss 0.18
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can bypass authentication and access administrative functionality by sending HTTP requests using a crafted Y-forwarded-for…
- risk 0.90cvss 9.4epss 1.00
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
- risk 0.64cvss 9.8epss 0.01
All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use the default credentials…
- risk 0.65cvss 9.9epss 0.02
A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BIG-IP system. For BIG-IP system running in Appliance mode, a successful exploit can allow the attacker to cross a security…
- risk 0.64cvss 9.8epss 0.01
A vulnerability has been identified in Simcenter Amesim (All versions < V2021.1). The affected application contains a SOAP endpoint that could allow an unauthenticated remote attacker to perform DLL injection and execute arbitrary code in the context of the affected application…
- risk 0.64cvss 9.8epss 0.00
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.11 (only with activated debug support)), CP-8050 MASTER MODULE (All versions < CPCI85 V05.11 (only with activated debug support)). The affected devices contain a hard-coded ID in the SSH…
- risk 0.64cvss 9.8epss 0.01
hansun CMS v1.0 was discovered to contain a SQL injection vulnerability via the component /ajax/ajax_login.ashx.
- risk 0.59cvss 9.1epss 0.01
Incorrect access control in 70mai a500s v1.2.119 allows attackers to directly access and delete the video files of the driving recorder through ftp and other protocols.