| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-32292 | Cri | 0.64 | 9.8 | 0.01 | Aug 22, 2023 | An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit. | ||
| CVE-2023-25915 | Cri | 0.64 | 9.9 | 0.01 | Aug 21, 2023 | Due to improper input validation, an authenticated remote attacker could execute arbitrary commands on the target system. | ||
| CVE-2023-4373 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2023 | Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 and earlier permits a user to initiate a connection without proper execution rights via the remote tools feature. | ||
| CVE-2023-39660 | — | Cri | 0.57 | 9.8 | 0.01 | Aug 21, 2023 | An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt function. | |
| CVE-2023-38961 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2023 | Buffer Overflwo vulnerability in JerryScript Project jerryscript v.3.0.0 allows a remote attacker to execute arbitrary code via the scanner_is_context_needed component in js-scanner-until.c. | ||
| CVE-2023-38035 | Cri | 0.93 | 9.8 | 1.00 | KEV | Aug 21, 2023 | A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration. | |
| CVE-2023-32002 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2023 | The use of `Module._load()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. Please note… | ||
| CVE-2023-31447 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2023 | user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers to send a crafted payload to modify the content of the code segment, insert shellcode, and execute arbitrary code. | ||
| CVE-2020-28715 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2023 | An issue was discovered in kdmserver service in LeEco LeTV X43 version V2401RCN02C080080B04121S, allows attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS). | ||
| CVE-2023-39939 | Cri | 0.59 | 9.1 | 0.01 | Aug 21, 2023 | SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute arbitrary queries against the database and obtain or alter the information in it. | ||
| CVE-2023-39751 | Cri | 0.64 | 9.8 | 0.08 | Aug 21, 2023 | TP-Link TL-WR941ND V6 were discovered to contain a buffer overflow via the pSize parameter at /userRpm/PingIframeRpm. | ||
| CVE-2023-39750 | Cri | 0.65 | 9.8 | 0.13 | Aug 21, 2023 | D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the f_ipv6_enable parameter at /bsc_ipv6. This vulnerability is exploited via a crafted POST request. | ||
| CVE-2023-39749 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2023 | D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the component /adv_resource. This vulnerability is exploited via a crafted GET request. | ||
| CVE-2023-39747 | Cri | 0.64 | 9.8 | 0.08 | Aug 21, 2023 | TP-Link WR841N V8, TP-Link TL-WR940N V2, and TL-WR941ND V5 were discovered to contain a buffer overflow via the radiusSecret parameter at /userRpm/WlanSecurityRpm. | ||
| CVE-2023-39618 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2023 | TOTOLINK X5000R B20210419 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg interface. | ||
| CVE-2023-39617 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2023 | TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contain a remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function. | ||
| CVE-2023-39809 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2023 | N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain an OS command injection vulnerability via shell metacharacters in the system_hostname parameter at /manage/network-basic.php. | ||
| CVE-2023-39808 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2023 | N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password that allows attackers to login with root privileges via the SSH service. The cleartext password corresponding to the $1$4Tmm01jl$7HRvcW.bz7uGmX9hiQWvR hash was not determined by the… | ||
| CVE-2023-39807 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2023 | N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a SQL injection vulnerability via the a_passwd parameter at /portal/user-register.php. | ||
| CVE-2022-24989 | Cri | 0.69 | 9.8 | 0.32 | Aug 20, 2023 | TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?mobile/createRaid URI. (Shell metacharacters can be placed in raidtype because popen is used… | ||
| CVE-2023-40069 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | OS command injection vulnerability in ELECOM wireless LAN routers allows an attacker who can access the product to execute an arbitrary OS command by sending a specially crafted request. Affected products and versions are as follows: WRC-F1167ACF all versions, WRC-1750GHBK all… | ||
| CVE-2023-39454 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | Buffer overflow vulnerability exists in ELECOM wireless LAN routers, which may allow an unauthenticated attacker to execute arbitrary code. | ||
| CVE-2023-35991 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | Hidden functionality vulnerability in LOGITEC wireless LAN routers allows an unauthenticated attacker to log in to the product's certain management console and execute arbitrary OS commands. Affected products and versions are as follows: LAN-W300N/DR all versions, LAN-WH300N/DR… | ||
| CVE-2023-32626 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | Hidden functionality vulnerability in LAN-W300N/RS all versions, and LAN-W300N/PR5 all versions allows an unauthenticated attacker to log in to the product's certain management console and execute arbitrary OS commands. | ||
| CVE-2023-39674 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | D-Link DIR-880 A1_FW107WWb08 was discovered to contain a buffer overflow via the function fgets. | ||
| CVE-2023-39673 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | Tenda AC15 V1.0BR_V15.03.05.18_multi_TD01 was discovered to contain a buffer overflow via the function FUN_00010e34(). | ||
| CVE-2023-39672 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | Tenda WH450 v1.0.0.18 was discovered to contain a buffer overflow via the function fgets. | ||
| CVE-2023-39671 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | D-Link DIR-880 A1_FW107WWb08 was discovered to contain a buffer overflow via the function FUN_0001be68. | ||
| CVE-2023-39670 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | Tenda AC6 _US_AC6V1.0BR_V15.03.05.16 was discovered to contain a buffer overflow via the function fgets. | ||
| CVE-2023-39668 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the inet_ntoa() function. | ||
| CVE-2023-39667 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the FUN_0000acb4 function. | ||
| CVE-2023-39666 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | D-Link DIR-842 fw_revA_1-02_eu_multi_20151008 was discovered to contain multiple buffer overflows in the fgets function via the acStack_120 and acStack_220 parameters. | ||
| CVE-2023-39665 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the acStack_50 parameter. | ||
| CVE-2023-40171 | Cri | 0.00 | 9.1 | 0.01 | Aug 17, 2023 | Dispatch is an open source security incident management tool. The server response includes the JWT Secret Key used for signing JWT tokens in error message when the `Dispatch Plugin - Basic Authentication Provider` plugin encounters an error when attempting to decode a JWT token.… | ||
| CVE-2023-39970 | Cri | 0.64 | 9.8 | 0.01 | Aug 17, 2023 | Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. It allows remote code execution. | ||
| CVE-2023-36845 | Cri | 0.86 | 9.8 | 0.94 | KEV | Aug 17, 2023 | A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code. Using a crafted request which sets the variable PHPRC an attacker is able to… | |
| CVE-2023-26469 | Cri | 0.73 | 9.8 | 0.82 | Aug 17, 2023 | In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server. | ||
| CVE-2023-37914 | Cri | 0.57 | 9.9 | 0.02 | Aug 17, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can view `Invitation.WebHome` can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read… | ||
| CVE-2023-2917 | Cri | 0.72 | 9.8 | 0.69 | Aug 17, 2023 | The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability. Due to an improper input validation, a path traversal vulnerability exists, via the filename field, when the ThinManager processes a certain function. If exploited, an… | ||
| CVE-2023-39846 | Cri | 0.64 | 9.8 | 0.01 | Aug 16, 2023 | An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token. | ||
| CVE-2023-38894 | — | Cri | 0.57 | 9.8 | 0.01 | Aug 16, 2023 | A Prototype Pollution issue in Cronvel Tree-kit v.0.7.4 and before allows a remote attacker to execute arbitrary code via the extend function. | |
| CVE-2023-35893 | Cri | 0.64 | 9.9 | 0.01 | Aug 16, 2023 | IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 258824. | ||
| CVE-2023-39115 | Cri | 0.67 | 9.8 | 0.05 | Aug 16, 2023 | install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document. | ||
| CVE-2023-33663 | Cri | 0.64 | 9.8 | 0.01 | Aug 16, 2023 | In the module “Customization fields fee for your store” (aicustomfee) from ai-dev module for PrestaShop, an attacker can perform SQL injection up to 0.2.0. Release 0.2.1 fixed this security issue. | ||
| CVE-2020-26037 | Cri | 0.64 | 9.8 | 0.02 | Aug 16, 2023 | Directory Traversal vulnerability in Server functionalty in Even Balance Punkbuster version 1.902 before 1.905 allows remote attackers to execute arbitrary code. | ||
| CVE-2023-39851 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | webchess v1.0 was discovered to contain a SQL injection vulnerability via the $playerID parameter at mainmenu.php. NOTE: this is disputed by a third party who indicates that the playerID is a session variable controlled by the server, and thus cannot be used for exploitation. | ||
| CVE-2023-39850 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | Schoolmate v1.3 was discovered to contain multiple SQL injection vulnerabilities via the $courseid and $teacherid parameters at DeleteFunctions.php. | ||
| CVE-2023-39852 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | Doctormms v1.0 was discovered to contain a SQL injection vulnerability via the $userid parameter at myAppoinment.php. NOTE: this is disputed by a third party who claims that the userid is a session variable controlled by the server, and thus cannot be used for exploitation. The… | ||
| CVE-2023-38866 | Cri | 0.64 | 9.8 | 0.02 | Aug 15, 2023 | COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter interface and display_name. | ||
| CVE-2023-38864 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protal_delete_picname parameter in the sub_41171C function at bin/webmgnt. |
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit.
- risk 0.64cvss 9.9epss 0.01
Due to improper input validation, an authenticated remote attacker could execute arbitrary commands on the target system.
- risk 0.64cvss 9.8epss 0.01
Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 and earlier permits a user to initiate a connection without proper execution rights via the remote tools feature.
- risk 0.57cvss 9.8epss 0.01
An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt function.
- risk 0.64cvss 9.8epss 0.01
Buffer Overflwo vulnerability in JerryScript Project jerryscript v.3.0.0 allows a remote attacker to execute arbitrary code via the scanner_is_context_needed component in js-scanner-until.c.
- risk 0.93cvss 9.8epss 1.00
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.
- risk 0.64cvss 9.8epss 0.01
The use of `Module._load()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. Please note…
- risk 0.64cvss 9.8epss 0.01
user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers to send a crafted payload to modify the content of the code segment, insert shellcode, and execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in kdmserver service in LeEco LeTV X43 version V2401RCN02C080080B04121S, allows attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS).
- risk 0.59cvss 9.1epss 0.01
SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute arbitrary queries against the database and obtain or alter the information in it.
- risk 0.64cvss 9.8epss 0.08
TP-Link TL-WR941ND V6 were discovered to contain a buffer overflow via the pSize parameter at /userRpm/PingIframeRpm.
- risk 0.65cvss 9.8epss 0.13
D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the f_ipv6_enable parameter at /bsc_ipv6. This vulnerability is exploited via a crafted POST request.
- risk 0.64cvss 9.8epss 0.01
D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the component /adv_resource. This vulnerability is exploited via a crafted GET request.
- risk 0.64cvss 9.8epss 0.08
TP-Link WR841N V8, TP-Link TL-WR940N V2, and TL-WR941ND V5 were discovered to contain a buffer overflow via the radiusSecret parameter at /userRpm/WlanSecurityRpm.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK X5000R B20210419 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg interface.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contain a remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.
- risk 0.64cvss 9.8epss 0.01
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain an OS command injection vulnerability via shell metacharacters in the system_hostname parameter at /manage/network-basic.php.
- risk 0.64cvss 9.8epss 0.01
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password that allows attackers to login with root privileges via the SSH service. The cleartext password corresponding to the $1$4Tmm01jl$7HRvcW.bz7uGmX9hiQWvR hash was not determined by the…
- risk 0.64cvss 9.8epss 0.01
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a SQL injection vulnerability via the a_passwd parameter at /portal/user-register.php.
- risk 0.69cvss 9.8epss 0.32
TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?mobile/createRaid URI. (Shell metacharacters can be placed in raidtype because popen is used…
- risk 0.64cvss 9.8epss 0.01
OS command injection vulnerability in ELECOM wireless LAN routers allows an attacker who can access the product to execute an arbitrary OS command by sending a specially crafted request. Affected products and versions are as follows: WRC-F1167ACF all versions, WRC-1750GHBK all…
- risk 0.64cvss 9.8epss 0.01
Buffer overflow vulnerability exists in ELECOM wireless LAN routers, which may allow an unauthenticated attacker to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
Hidden functionality vulnerability in LOGITEC wireless LAN routers allows an unauthenticated attacker to log in to the product's certain management console and execute arbitrary OS commands. Affected products and versions are as follows: LAN-W300N/DR all versions, LAN-WH300N/DR…
- risk 0.64cvss 9.8epss 0.01
Hidden functionality vulnerability in LAN-W300N/RS all versions, and LAN-W300N/PR5 all versions allows an unauthenticated attacker to log in to the product's certain management console and execute arbitrary OS commands.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-880 A1_FW107WWb08 was discovered to contain a buffer overflow via the function fgets.
- risk 0.64cvss 9.8epss 0.01
Tenda AC15 V1.0BR_V15.03.05.18_multi_TD01 was discovered to contain a buffer overflow via the function FUN_00010e34().
- risk 0.64cvss 9.8epss 0.01
Tenda WH450 v1.0.0.18 was discovered to contain a buffer overflow via the function fgets.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-880 A1_FW107WWb08 was discovered to contain a buffer overflow via the function FUN_0001be68.
- risk 0.64cvss 9.8epss 0.01
Tenda AC6 _US_AC6V1.0BR_V15.03.05.16 was discovered to contain a buffer overflow via the function fgets.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the inet_ntoa() function.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the FUN_0000acb4 function.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-842 fw_revA_1-02_eu_multi_20151008 was discovered to contain multiple buffer overflows in the fgets function via the acStack_120 and acStack_220 parameters.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the acStack_50 parameter.
- risk 0.00cvss 9.1epss 0.01
Dispatch is an open source security incident management tool. The server response includes the JWT Secret Key used for signing JWT tokens in error message when the `Dispatch Plugin - Basic Authentication Provider` plugin encounters an error when attempting to decode a JWT token.…
- risk 0.64cvss 9.8epss 0.01
Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. It allows remote code execution.
- risk 0.86cvss 9.8epss 0.94
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code. Using a crafted request which sets the variable PHPRC an attacker is able to…
- risk 0.73cvss 9.8epss 0.82
In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.
- risk 0.57cvss 9.9epss 0.02
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can view `Invitation.WebHome` can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read…
- risk 0.72cvss 9.8epss 0.69
The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability. Due to an improper input validation, a path traversal vulnerability exists, via the filename field, when the ThinManager processes a certain function. If exploited, an…
- risk 0.64cvss 9.8epss 0.01
An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token.
- risk 0.57cvss 9.8epss 0.01
A Prototype Pollution issue in Cronvel Tree-kit v.0.7.4 and before allows a remote attacker to execute arbitrary code via the extend function.
- risk 0.64cvss 9.9epss 0.01
IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 258824.
- risk 0.67cvss 9.8epss 0.05
install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document.
- risk 0.64cvss 9.8epss 0.01
In the module “Customization fields fee for your store” (aicustomfee) from ai-dev module for PrestaShop, an attacker can perform SQL injection up to 0.2.0. Release 0.2.1 fixed this security issue.
- risk 0.64cvss 9.8epss 0.02
Directory Traversal vulnerability in Server functionalty in Even Balance Punkbuster version 1.902 before 1.905 allows remote attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
webchess v1.0 was discovered to contain a SQL injection vulnerability via the $playerID parameter at mainmenu.php. NOTE: this is disputed by a third party who indicates that the playerID is a session variable controlled by the server, and thus cannot be used for exploitation.
- risk 0.64cvss 9.8epss 0.01
Schoolmate v1.3 was discovered to contain multiple SQL injection vulnerabilities via the $courseid and $teacherid parameters at DeleteFunctions.php.
- risk 0.64cvss 9.8epss 0.01
Doctormms v1.0 was discovered to contain a SQL injection vulnerability via the $userid parameter at myAppoinment.php. NOTE: this is disputed by a third party who claims that the userid is a session variable controlled by the server, and thus cannot be used for exploitation. The…
- risk 0.64cvss 9.8epss 0.02
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter interface and display_name.
- risk 0.64cvss 9.8epss 0.01
An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protal_delete_picname parameter in the sub_41171C function at bin/webmgnt.