| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-36023 | Cri | 0.59 | 9.1 | 0.02 | Sep 6, 2023 | Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution. | ||
| CVE-2023-41149 | Cri | 0.64 | 9.8 | 0.01 | Sep 6, 2023 | F-RevoCRM version7.3.7 and version7.3.8 contains an OS command injection vulnerability. If this vulnerability is exploited, an attacker who can access the product may execute an arbitrary OS command on the server where the product is running. | ||
| CVE-2023-4589 | Cri | 0.59 | 9.1 | 0.00 | Sep 6, 2023 | Insufficient verification of data authenticity vulnerability in Delinea Secret Server, in its v10.9.000002 version. An attacker with an administrator account could perform software updates without proper integrity verification mechanisms. In this scenario, the update process… | ||
| CVE-2023-4634 | Cri | 0.73 | 9.8 | 0.83 | Sep 6, 2023 | The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the… | ||
| CVE-2023-4485 | Cri | 0.64 | 9.8 | 0.01 | Sep 6, 2023 | ARDEREG Sistema SCADA Central versions 2.203 and prior login page are vulnerable to an unauthenticated blind SQL injection attack. An attacker could manipulate the application's SQL query logic to extract sensitive information or perform unauthorized actions within the… | ||
| CVE-2023-41507 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | Super Store Finder v3.6 was discovered to contain multiple SQL injection vulnerabilities in the store locator component via the products, distance, lat, and lng parameters. | ||
| CVE-2023-4310 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious HTTP request. Successful exploitation of this vulnerability can allow an unauthenticated remote… | ||
| CVE-2023-41508 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | A hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel. | ||
| CVE-2023-39361 | Cri | 0.71 | 9.8 | 0.88 | Sep 5, 2023 | Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an… | ||
| CVE-2023-41009 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | File Upload vulnerability in adlered bolo-solo v.2.6 allows a remote attacker to execute arbitrary code via a crafted script to the authorization field in the header. | ||
| CVE-2023-39654 | — | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | abupy up to v0.4.0 was discovered to contain a SQL injection vulnerability via the component abupy.MarketBu.ABuSymbol.search_to_symbol_dict. | |
| CVE-2023-4531 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestav Software E-commerce Software allows SQL Injection. This issue affects E-commerce Software: before 20230901 . | ||
| CVE-2023-4178 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | Authentication Bypass by Spoofing vulnerability in Neutron Neutron Smart VMS allows Authentication Bypass. This issue affects Neutron Smart VMS: before b1130.1.0.1. | ||
| CVE-2023-4034 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digita Information Technology Smartrise Document Management System allows SQL Injection. This issue affects Smartrise Document Management System: before Hvl-2.0. | ||
| CVE-2023-3616 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mava Software Hotel Management System allows SQL Injection. This issue affects Hotel Management System: before 2.0. | ||
| CVE-2023-39681 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at /Configuration.php. This vulnerability is triggered via a crafted payload. | ||
| CVE-2023-35072 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Coyav Travel Proagent allows SQL Injection. This issue affects Proagent: before 20230904 . | ||
| CVE-2023-35068 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BMA Personnel Tracking System allows SQL Injection. This issue affects Personnel Tracking System: before 20230904. | ||
| CVE-2023-35065 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Osoft Paint Production Management allows SQL Injection. This issue affects Paint Production Management: before 2.1. | ||
| CVE-2017-9453 | Cri | 0.59 | 9.0 | 0.01 | Sep 5, 2023 | BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass. | ||
| CVE-2023-3374 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | Incomplete List of Disallowed Inputs vulnerability in Unisign Bookreen allows Privilege Escalation. This issue affects Bookreen: before 3.0.0. | ||
| CVE-2023-41012 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the authentication mechanism. | ||
| CVE-2023-36361 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter. | ||
| CVE-2023-40743 | Cri | 0.57 | 9.8 | 0.03 | Sep 5, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allows potentially dangerous lookup mechanisms such as LDAP. When passing untrusted input to this API… | ||
| CVE-2023-41910 | Cri | 0.00 | 9.8 | 0.01 | Sep 5, 2023 | An issue was discovered in lldpd before 1.0.17. By crafting a CDP PDU packet with specific CDP_TLV_ADDRESSES TLVs, a malicious actor can remotely force the lldpd daemon to perform an out-of-bounds read on heap memory. This occurs in cdp_decode in daemon/protocols/cdp.c. | ||
| CVE-2023-28581 | Cri | 0.64 | 9.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN Firmware while parsing receieved GTK Keys in GTK KDE. | ||
| CVE-2023-28562 | Cri | 0.64 | 9.8 | 0.00 | Sep 5, 2023 | Memory corruption while handling payloads from remote ESL. | ||
| CVE-2023-4614 | Cri | 0.64 | 9.8 | 0.02 | Sep 4, 2023 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/installation/setThumbnailRc endpoint. The issue results from… | ||
| CVE-2023-4613 | Cri | 0.64 | 9.8 | 0.02 | Sep 4, 2023 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/settings/upload endpoint. The issue results from the lack of… | ||
| CVE-2023-4744 | Cri | 0.64 | 9.8 | 0.02 | Sep 4, 2023 | A vulnerability was found in Tenda AC8 16.03.34.06_cn_TDC01. It has been declared as critical. Affected by this vulnerability is the function formSetDeviceName. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been… | ||
| CVE-2023-3703 | Cri | 0.65 | 10.0 | 0.01 | Sep 3, 2023 | Proscend Advice ICR Series routers FW version 1.76 - CWE-1392: Use of Default Credentials | ||
| CVE-2023-39979 | Cri | 0.64 | 9.8 | 0.01 | Sep 2, 2023 | There is a vulnerability in MXsecurity versions prior to 1.0.1 that can be exploited to bypass authentication. A remote attacker might access the system if the web service authenticator has insufficient random values. | ||
| CVE-2023-1523 | Cri | 0.00 | 10.0 | 0.01 | Sep 1, 2023 | Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary commands to be executed outside of the snap sandbox after the snap exits. Graphical terminal emulators like xterm,… | ||
| CVE-2023-40980 | Cri | 0.64 | 9.8 | 0.01 | Sep 1, 2023 | File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and savveFile in the action/UploadAction.java file. | ||
| CVE-2023-39631 | — | Cri | 0.57 | 9.8 | 0.01 | Sep 1, 2023 | An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library. | |
| CVE-2023-36328 | Cri | 0.00 | 9.8 | 0.01 | Sep 1, 2023 | Integer Overflow vulnerability in mp_grow in libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, allows attackers to execute arbitrary code and cause a denial of service (DoS). | ||
| CVE-2023-36327 | Cri | 0.00 | 9.8 | 0.01 | Sep 1, 2023 | Integer Overflow vulnerability in RELIC before commit 421f2e91cf2ba42473d4d54daf24e295679e290e, allows attackers to execute arbitrary code and cause a denial of service in pos argument in bn_get_prime function. | ||
| CVE-2023-36326 | Cri | 0.00 | 9.8 | 0.01 | Sep 1, 2023 | Integer Overflow vulnerability in RELIC before commit 34580d840469361ba9b5f001361cad659687b9ab, allows attackers to execute arbitrary code, cause a denial of service, and escalate privileges when calling realloc function in bn_grow function. | ||
| CVE-2023-36187 | Cri | 0.64 | 9.8 | 0.01 | Sep 1, 2023 | Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd. | ||
| CVE-2023-36100 | Cri | 0.64 | 9.8 | 0.01 | Sep 1, 2023 | An issue was discovered in IceCMS version 2.0.1, allows attackers to escalate privileges and gain sensitive information via UserID parameter in api/User/ChangeUser. | ||
| CVE-2023-36076 | Cri | 0.64 | 9.8 | 0.02 | Sep 1, 2023 | SQL Injection vulnerability in smanga version 3.1.9 and earlier, allows remote attackers to execute arbitrary code and gain sensitive information via mediaId, mangaId, and userId parameters in php/history/add.php. | ||
| CVE-2020-22612 | Cri | 0.64 | 9.8 | 0.01 | Sep 1, 2023 | Installer RCE on settings file write in MyBB before 1.8.22. | ||
| CVE-2023-41364 | Cri | 0.64 | 9.8 | 0.01 | Sep 1, 2023 | In tine through 2023.01.14.325, the sort parameter of the /index.php endpoint allows SQL Injection. | ||
| CVE-2023-4696 | — | Cri | 0.57 | 9.8 | 0.01 | Sep 1, 2023 | Improper Access Control in GitHub repository usememos/memos prior to 0.13.2. | |
| CVE-2023-4299 | Cri | 0.59 | 9.0 | 0.01 | Aug 31, 2023 | Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment. | ||
| CVE-2023-41748 | Cri | 0.64 | 9.8 | 0.01 | Aug 31, 2023 | Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.23089.203. | ||
| CVE-2023-41746 | Cri | 0.64 | 9.8 | 0.01 | Aug 31, 2023 | Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.23089.203. | ||
| CVE-2023-41637 | Cri | 0.64 | 9.8 | 0.01 | Aug 31, 2023 | An arbitrary file upload vulnerability in the Carica immagine function of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code via uploading a crafted HTML file. | ||
| CVE-2023-41636 | Cri | 0.64 | 9.8 | 0.01 | Aug 31, 2023 | A SQL injection vulnerability in the Data Richiesta dal parameter of GruppoSCAI RealGimm v1.1.37p38 allows attackers to access the database and execute arbitrary commands via a crafted SQL query. | ||
| CVE-2023-28801 | Cri | 0.62 | 9.6 | 0.00 | Aug 31, 2023 | An Improper Verification of Cryptographic Signature in the SAML authentication of the Zscaler Admin UI allows a Privilege Escalation.This issue affects Admin UI: from 6.2 before 6.2r. |
- risk 0.59cvss 9.1epss 0.02
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.
- risk 0.64cvss 9.8epss 0.01
F-RevoCRM version7.3.7 and version7.3.8 contains an OS command injection vulnerability. If this vulnerability is exploited, an attacker who can access the product may execute an arbitrary OS command on the server where the product is running.
- risk 0.59cvss 9.1epss 0.00
Insufficient verification of data authenticity vulnerability in Delinea Secret Server, in its v10.9.000002 version. An attacker with an administrator account could perform software updates without proper integrity verification mechanisms. In this scenario, the update process…
- risk 0.73cvss 9.8epss 0.83
The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the…
- risk 0.64cvss 9.8epss 0.01
ARDEREG Sistema SCADA Central versions 2.203 and prior login page are vulnerable to an unauthenticated blind SQL injection attack. An attacker could manipulate the application's SQL query logic to extract sensitive information or perform unauthorized actions within the…
- risk 0.64cvss 9.8epss 0.01
Super Store Finder v3.6 was discovered to contain multiple SQL injection vulnerabilities in the store locator component via the products, distance, lat, and lng parameters.
- risk 0.64cvss 9.8epss 0.01
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious HTTP request. Successful exploitation of this vulnerability can allow an unauthenticated remote…
- risk 0.64cvss 9.8epss 0.01
A hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel.
- risk 0.71cvss 9.8epss 0.88
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an…
- risk 0.64cvss 9.8epss 0.01
File Upload vulnerability in adlered bolo-solo v.2.6 allows a remote attacker to execute arbitrary code via a crafted script to the authorization field in the header.
- risk 0.64cvss 9.8epss 0.01
abupy up to v0.4.0 was discovered to contain a SQL injection vulnerability via the component abupy.MarketBu.ABuSymbol.search_to_symbol_dict.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestav Software E-commerce Software allows SQL Injection. This issue affects E-commerce Software: before 20230901 .
- risk 0.64cvss 9.8epss 0.01
Authentication Bypass by Spoofing vulnerability in Neutron Neutron Smart VMS allows Authentication Bypass. This issue affects Neutron Smart VMS: before b1130.1.0.1.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digita Information Technology Smartrise Document Management System allows SQL Injection. This issue affects Smartrise Document Management System: before Hvl-2.0.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mava Software Hotel Management System allows SQL Injection. This issue affects Hotel Management System: before 2.0.
- risk 0.64cvss 9.8epss 0.01
Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at /Configuration.php. This vulnerability is triggered via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Coyav Travel Proagent allows SQL Injection. This issue affects Proagent: before 20230904 .
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BMA Personnel Tracking System allows SQL Injection. This issue affects Personnel Tracking System: before 20230904.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Osoft Paint Production Management allows SQL Injection. This issue affects Paint Production Management: before 2.1.
- risk 0.59cvss 9.0epss 0.01
BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass.
- risk 0.64cvss 9.8epss 0.01
Incomplete List of Disallowed Inputs vulnerability in Unisign Bookreen allows Privilege Escalation. This issue affects Bookreen: before 3.0.0.
- risk 0.64cvss 9.8epss 0.01
An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the authentication mechanism.
- risk 0.64cvss 9.8epss 0.01
Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter.
- risk 0.57cvss 9.8epss 0.03
** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allows potentially dangerous lookup mechanisms such as LDAP. When passing untrusted input to this API…
- risk 0.00cvss 9.8epss 0.01
An issue was discovered in lldpd before 1.0.17. By crafting a CDP PDU packet with specific CDP_TLV_ADDRESSES TLVs, a malicious actor can remotely force the lldpd daemon to perform an out-of-bounds read on heap memory. This occurs in cdp_decode in daemon/protocols/cdp.c.
- risk 0.64cvss 9.8epss 0.00
Memory corruption in WLAN Firmware while parsing receieved GTK Keys in GTK KDE.
- risk 0.64cvss 9.8epss 0.00
Memory corruption while handling payloads from remote ESL.
- risk 0.64cvss 9.8epss 0.02
This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/installation/setThumbnailRc endpoint. The issue results from…
- risk 0.64cvss 9.8epss 0.02
This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/settings/upload endpoint. The issue results from the lack of…
- risk 0.64cvss 9.8epss 0.02
A vulnerability was found in Tenda AC8 16.03.34.06_cn_TDC01. It has been declared as critical. Affected by this vulnerability is the function formSetDeviceName. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been…
- risk 0.65cvss 10.0epss 0.01
Proscend Advice ICR Series routers FW version 1.76 - CWE-1392: Use of Default Credentials
- risk 0.64cvss 9.8epss 0.01
There is a vulnerability in MXsecurity versions prior to 1.0.1 that can be exploited to bypass authentication. A remote attacker might access the system if the web service authenticator has insufficient random values.
- risk 0.00cvss 10.0epss 0.01
Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary commands to be executed outside of the snap sandbox after the snap exits. Graphical terminal emulators like xterm,…
- risk 0.64cvss 9.8epss 0.01
File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and savveFile in the action/UploadAction.java file.
- risk 0.57cvss 9.8epss 0.01
An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library.
- risk 0.00cvss 9.8epss 0.01
Integer Overflow vulnerability in mp_grow in libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, allows attackers to execute arbitrary code and cause a denial of service (DoS).
- risk 0.00cvss 9.8epss 0.01
Integer Overflow vulnerability in RELIC before commit 421f2e91cf2ba42473d4d54daf24e295679e290e, allows attackers to execute arbitrary code and cause a denial of service in pos argument in bn_get_prime function.
- risk 0.00cvss 9.8epss 0.01
Integer Overflow vulnerability in RELIC before commit 34580d840469361ba9b5f001361cad659687b9ab, allows attackers to execute arbitrary code, cause a denial of service, and escalate privileges when calling realloc function in bn_grow function.
- risk 0.64cvss 9.8epss 0.01
Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in IceCMS version 2.0.1, allows attackers to escalate privileges and gain sensitive information via UserID parameter in api/User/ChangeUser.
- risk 0.64cvss 9.8epss 0.02
SQL Injection vulnerability in smanga version 3.1.9 and earlier, allows remote attackers to execute arbitrary code and gain sensitive information via mediaId, mangaId, and userId parameters in php/history/add.php.
- risk 0.64cvss 9.8epss 0.01
Installer RCE on settings file write in MyBB before 1.8.22.
- risk 0.64cvss 9.8epss 0.01
In tine through 2023.01.14.325, the sort parameter of the /index.php endpoint allows SQL Injection.
- risk 0.57cvss 9.8epss 0.01
Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.
- risk 0.59cvss 9.0epss 0.01
Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment.
- risk 0.64cvss 9.8epss 0.01
Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.23089.203.
- risk 0.64cvss 9.8epss 0.01
Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.23089.203.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the Carica immagine function of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code via uploading a crafted HTML file.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in the Data Richiesta dal parameter of GruppoSCAI RealGimm v1.1.37p38 allows attackers to access the database and execute arbitrary commands via a crafted SQL query.
- risk 0.62cvss 9.6epss 0.00
An Improper Verification of Cryptographic Signature in the SAML authentication of the Zscaler Admin UI allows a Privilege Escalation.This issue affects Admin UI: from 6.2 before 6.2r.