| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-3935 | Cri | 0.64 | 9.8 | 0.02 | Sep 13, 2023 | A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system. | ||
| CVE-2023-39073 | Cri | 0.64 | 9.8 | 0.01 | Sep 12, 2023 | An issue in SNMP Web Pro v.1.1 allows a remote attacker to execute arbitrary code and obtain senstive information via a crafted request. | ||
| CVE-2023-41331 | Cri | 0.64 | 9.8 | 0.01 | Sep 12, 2023 | SOFARPC is a Java RPC framework. Versions prior to 5.11.0 are vulnerable to remote command execution. Through a carefully crafted payload, an attacker can achieve JNDI injection or system command execution. In the default configuration of the SOFARPC framework, a blacklist is… | ||
| CVE-2023-3710 | Cri | 0.70 | 9.9 | 0.33 | Sep 12, 2023 | Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5… | ||
| CVE-2023-4501 | Cri | 0.64 | 9.8 | 0.01 | Sep 12, 2023 | User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), versions 7.0 patch updates 19 and 20, 8.0… | ||
| CVE-2023-40784 | Cri | 0.64 | 9.8 | 0.01 | Sep 12, 2023 | DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php. | ||
| CVE-2023-40834 | Cri | 0.64 | 9.8 | 0.01 | Sep 12, 2023 | OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated attackers to gain access to the application via a brute force attack to the password parameter. | ||
| CVE-2023-2071 | Cri | 0.65 | 9.8 | 0.11 | Sep 12, 2023 | Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets. The device has the functionality, through a CIP class, to… | ||
| CVE-2023-39150 | Cri | 0.00 | 9.8 | 0.01 | Sep 12, 2023 | ConEmu before commit 230724 does not sanitize title responses correctly for control characters, potentially leading to arbitrary code execution. This is related to an incomplete fix for CVE-2022-46387. | ||
| CVE-2023-39637 | Cri | 0.64 | 9.8 | 0.02 | Sep 12, 2023 | D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis. | ||
| CVE-2022-24093 | Cri | 0.59 | 9.1 | 0.01 | Sep 12, 2023 | Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution. | ||
| CVE-2023-40622 | Cri | 0.64 | 9.9 | 0.01 | Sep 12, 2023 | SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attacker to view sensitive information which is otherwise restricted. On successful exploitation, the attacker can completely compromise… | ||
| CVE-2023-40309 | Cri | 0.64 | 9.8 | 0.01 | Sep 12, 2023 | SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could… | ||
| CVE-2023-39069 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | An issue in StrangeBee TheHive v.5.0.8, v.4.1.21 and Cortex v.3.1.6 allows a remote attacker to gain privileges via Active Directory authentication mechanism. | ||
| CVE-2023-4897 | Cri | 0.00 | 9.8 | 0.01 | Sep 11, 2023 | Relative Path Traversal in GitHub repository mintplex-labs/anything-llm prior to 0.0.1. | ||
| CVE-2023-35681 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | In eatt_l2cap_reconfig_completed of eatt_impl.h, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-40946 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | Schoolmate 1.3 is vulnerable to SQL Injection in the variable $username from SESSION in ValidateLogin.php. | ||
| CVE-2023-40945 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails.php. | ||
| CVE-2023-40944 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | Schoolmate 1.3 is vulnerable to SQL Injection in the variable $schoolname from Database at ~\header.php. | ||
| CVE-2023-40150 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | Softneta MedDream PACS does not perform an authentication check and performs some dangerous functionality, which could result in unauthenticated remote code execution.0 | ||
| CVE-2023-41256 | Cri | 0.59 | 9.1 | 0.01 | Sep 11, 2023 | Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 are vulnerable to authentication bypass that could allow an unauthorized attacker to obtain user access. | ||
| CVE-2023-31069 | Cri | 0.67 | 9.8 | 0.02 | Sep 11, 2023 | An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML source code of the login page. | ||
| CVE-2023-31068 | Cri | 0.67 | 9.8 | 0.03 | Sep 11, 2023 | An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\UserDesktop\themes. | ||
| CVE-2023-31067 | Cri | 0.67 | 9.8 | 0.03 | Sep 11, 2023 | An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\Clients\www. | ||
| CVE-2020-19559 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | An issue in Diebold Aglis XFS for Opteva v.4.1.61.1 allows a remote attacker to execute arbitrary code via a crafted payload to the ResolveMethod() parameter. | ||
| CVE-2020-19320 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the curTime parameter on login. | ||
| CVE-2020-19319 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the FILECODE parameter on login. | ||
| CVE-2023-30058 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | novel-plus 3.6.2 is vulnerable to SQL Injection. | ||
| CVE-2023-36140 | Cri | 0.64 | 9.8 | 0.00 | Sep 11, 2023 | In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts. | ||
| CVE-2023-42471 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | The wave.ai.browser application through 1.0.35 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. It contains a manifest entry that exports the wave.ai.browser.ui.splash.SplashScreen activity. This activity uses a WebView component to… | ||
| CVE-2023-42470 | Cri | 0.64 | 9.8 | 0.02 | Sep 11, 2023 | The Imou Life com.mm.android.smartlifeiot application through 6.8.0 for Android allows Remote Code Execution via a crafted intent to an exported component. This relates to the com.mm.android.easy4ip.MainActivity activity. JavaScript execution is enabled in the WebView, and… | ||
| CVE-2023-40039 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | An issue was discovered on ARRIS TG852G, TG862G, and TG1672G devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame. | ||
| CVE-2023-42277 | — | Cri | 0.57 | 9.8 | 0.01 | Sep 8, 2023 | hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonObject.putByPath. | |
| CVE-2023-42276 | — | Cri | 0.57 | 9.8 | 0.01 | Sep 8, 2023 | hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonArray. | |
| CVE-2023-42268 | — | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2023 | Jeecg boot up to v3.5.3 was discovered to contain a SQL injection vulnerability via the component /jeecg-boot/jmreport/show. | |
| CVE-2023-39320 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2023 | The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "go" command from the module proxy, as… | ||
| CVE-2023-41615 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2023 | Zoo Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the Admin sign-in page via the username and password fields. | ||
| CVE-2023-37759 | — | Cri | 0.67 | 9.8 | 0.04 | Sep 8, 2023 | Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticated attackers to register as an Admin account via a crafted POST request. | |
| CVE-2021-27715 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2023 | An issue was discovered in MoFi Network MOFI4500-4GXeLTE-V2 3.5.6-xnet-5052 allows attackers to bypass the authentication and execute arbitrary code via crafted HTTP request. | ||
| CVE-2023-40029 | Cri | 0.57 | 9.9 | 0.01 | Sep 7, 2023 | Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively using Argo CD / kubectl apply. As a result, the full secret body is stored in`kubectl.kubernetes.io/last-applied-configuration` annotation. pull request #7139… | ||
| CVE-2023-30908 | Cri | 0.64 | 9.8 | 0.01 | Sep 7, 2023 | A remote authentication bypass issue exists in a OneView API. | ||
| CVE-2023-40942 | Cri | 0.64 | 9.8 | 0.01 | Sep 7, 2023 | Tenda AC9 V3.0BR_V15.03.06.42_multi_TD01 was discovered stack overflow via parameter 'firewall_value' at url /goform/SetFirewallCfg. | ||
| CVE-2023-39424 | Cri | 0.64 | 9.9 | 0.01 | Sep 7, 2023 | A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication… | ||
| CVE-2023-39420 | Cri | 0.64 | 9.9 | 0.01 | Sep 7, 2023 | The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL file. Once reverse-engineered, this routine can help an… | ||
| CVE-2023-40397 | Cri | 0.64 | 9.8 | 0.02 | Sep 6, 2023 | The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5. A remote attacker may be able to cause arbitrary javascript code execution. | ||
| CVE-2023-39967 | Cri | 0.65 | 10.0 | 0.01 | Sep 6, 2023 | WireMock is a tool for mocking HTTP services. When certain request URLs like “@127.0.0.1:1234" are used in WireMock Studio configuration fields, the request might be forwarded to an arbitrary service reachable from WireMock’s instance. There are 3 identified potential attack… | ||
| CVE-2020-10131 | Cri | 0.64 | 9.8 | 0.01 | Sep 6, 2023 | SearchBlox before Version 9.2.1 is vulnerable to CSV macro injection in "Featured Results" parameter. | ||
| CVE-2023-41330 | Cri | 0.57 | 9.8 | 0.02 | Sep 6, 2023 | knplabs/knp-snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. ## Issue On March 17th the vulnerability CVE-2023-28115 was disclosed, allowing an attacker to gain remote code execution through PHAR deserialization. Version 1.4.2… | ||
| CVE-2023-20238 | Cri | 0.66 | 10.0 | 0.15 | Sep 6, 2023 | A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to forge the credentials required to access an affected system. This… | ||
| CVE-2023-0925 | Cri | 0.64 | 9.8 | 0.01 | Sep 6, 2023 | Version 10.11 of webMethods OneData runs an embedded instance of Azul Zulu Java 11.0.15 which hosts a Java RMI registry (listening on TCP port 2099 by default) and two RMI interfaces (listening on a single, dynamically assigned TCP high port). Port 2099 serves as a Java… |
- risk 0.64cvss 9.8epss 0.02
A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.
- risk 0.64cvss 9.8epss 0.01
An issue in SNMP Web Pro v.1.1 allows a remote attacker to execute arbitrary code and obtain senstive information via a crafted request.
- risk 0.64cvss 9.8epss 0.01
SOFARPC is a Java RPC framework. Versions prior to 5.11.0 are vulnerable to remote command execution. Through a carefully crafted payload, an attacker can achieve JNDI injection or system command execution. In the default configuration of the SOFARPC framework, a blacklist is…
- risk 0.70cvss 9.9epss 0.33
Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5…
- risk 0.64cvss 9.8epss 0.01
User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), versions 7.0 patch updates 19 and 20, 8.0…
- risk 0.64cvss 9.8epss 0.01
DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.
- risk 0.64cvss 9.8epss 0.01
OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated attackers to gain access to the application via a brute force attack to the password parameter.
- risk 0.65cvss 9.8epss 0.11
Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets. The device has the functionality, through a CIP class, to…
- risk 0.00cvss 9.8epss 0.01
ConEmu before commit 230724 does not sanitize title responses correctly for control characters, potentially leading to arbitrary code execution. This is related to an incomplete fix for CVE-2022-46387.
- risk 0.64cvss 9.8epss 0.02
D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis.
- risk 0.59cvss 9.1epss 0.01
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.
- risk 0.64cvss 9.9epss 0.01
SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attacker to view sensitive information which is otherwise restricted. On successful exploitation, the attacker can completely compromise…
- risk 0.64cvss 9.8epss 0.01
SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could…
- risk 0.64cvss 9.8epss 0.01
An issue in StrangeBee TheHive v.5.0.8, v.4.1.21 and Cortex v.3.1.6 allows a remote attacker to gain privileges via Active Directory authentication mechanism.
- risk 0.00cvss 9.8epss 0.01
Relative Path Traversal in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.
- risk 0.64cvss 9.8epss 0.01
In eatt_l2cap_reconfig_completed of eatt_impl.h, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.64cvss 9.8epss 0.01
Schoolmate 1.3 is vulnerable to SQL Injection in the variable $username from SESSION in ValidateLogin.php.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails.php.
- risk 0.64cvss 9.8epss 0.01
Schoolmate 1.3 is vulnerable to SQL Injection in the variable $schoolname from Database at ~\header.php.
- risk 0.64cvss 9.8epss 0.01
Softneta MedDream PACS does not perform an authentication check and performs some dangerous functionality, which could result in unauthenticated remote code execution.0
- risk 0.59cvss 9.1epss 0.01
Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 are vulnerable to authentication bypass that could allow an unauthorized attacker to obtain user access.
- risk 0.67cvss 9.8epss 0.02
An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML source code of the login page.
- risk 0.67cvss 9.8epss 0.03
An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\UserDesktop\themes.
- risk 0.67cvss 9.8epss 0.03
An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\Clients\www.
- risk 0.64cvss 9.8epss 0.01
An issue in Diebold Aglis XFS for Opteva v.4.1.61.1 allows a remote attacker to execute arbitrary code via a crafted payload to the ResolveMethod() parameter.
- risk 0.64cvss 9.8epss 0.01
Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the curTime parameter on login.
- risk 0.64cvss 9.8epss 0.01
Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the FILECODE parameter on login.
- risk 0.64cvss 9.8epss 0.01
novel-plus 3.6.2 is vulnerable to SQL Injection.
- risk 0.64cvss 9.8epss 0.00
In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts.
- risk 0.64cvss 9.8epss 0.01
The wave.ai.browser application through 1.0.35 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. It contains a manifest entry that exports the wave.ai.browser.ui.splash.SplashScreen activity. This activity uses a WebView component to…
- risk 0.64cvss 9.8epss 0.02
The Imou Life com.mm.android.smartlifeiot application through 6.8.0 for Android allows Remote Code Execution via a crafted intent to an exported component. This relates to the com.mm.android.easy4ip.MainActivity activity. JavaScript execution is enabled in the WebView, and…
- risk 0.64cvss 9.8epss 0.01
An issue was discovered on ARRIS TG852G, TG862G, and TG1672G devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame.
- risk 0.57cvss 9.8epss 0.01
hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonObject.putByPath.
- risk 0.57cvss 9.8epss 0.01
hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonArray.
- risk 0.64cvss 9.8epss 0.01
Jeecg boot up to v3.5.3 was discovered to contain a SQL injection vulnerability via the component /jeecg-boot/jmreport/show.
- risk 0.64cvss 9.8epss 0.01
The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "go" command from the module proxy, as…
- risk 0.64cvss 9.8epss 0.01
Zoo Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the Admin sign-in page via the username and password fields.
- risk 0.67cvss 9.8epss 0.04
Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticated attackers to register as an Admin account via a crafted POST request.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in MoFi Network MOFI4500-4GXeLTE-V2 3.5.6-xnet-5052 allows attackers to bypass the authentication and execute arbitrary code via crafted HTTP request.
- risk 0.57cvss 9.9epss 0.01
Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively using Argo CD / kubectl apply. As a result, the full secret body is stored in`kubectl.kubernetes.io/last-applied-configuration` annotation. pull request #7139…
- risk 0.64cvss 9.8epss 0.01
A remote authentication bypass issue exists in a OneView API.
- risk 0.64cvss 9.8epss 0.01
Tenda AC9 V3.0BR_V15.03.06.42_multi_TD01 was discovered stack overflow via parameter 'firewall_value' at url /goform/SetFirewallCfg.
- risk 0.64cvss 9.9epss 0.01
A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication…
- risk 0.64cvss 9.9epss 0.01
The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL file. Once reverse-engineered, this routine can help an…
- risk 0.64cvss 9.8epss 0.02
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5. A remote attacker may be able to cause arbitrary javascript code execution.
- risk 0.65cvss 10.0epss 0.01
WireMock is a tool for mocking HTTP services. When certain request URLs like “@127.0.0.1:1234" are used in WireMock Studio configuration fields, the request might be forwarded to an arbitrary service reachable from WireMock’s instance. There are 3 identified potential attack…
- risk 0.64cvss 9.8epss 0.01
SearchBlox before Version 9.2.1 is vulnerable to CSV macro injection in "Featured Results" parameter.
- risk 0.57cvss 9.8epss 0.02
knplabs/knp-snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. ## Issue On March 17th the vulnerability CVE-2023-28115 was disclosed, allowing an attacker to gain remote code execution through PHAR deserialization. Version 1.4.2…
- risk 0.66cvss 10.0epss 0.15
A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to forge the credentials required to access an affected system. This…
- risk 0.64cvss 9.8epss 0.01
Version 10.11 of webMethods OneData runs an embedded instance of Azul Zulu Java 11.0.15 which hosts a Java RMI registry (listening on TCP port 2099 by default) and two RMI interfaces (listening on a single, dynamically assigned TCP high port). Port 2099 serves as a Java…