| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-33378 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2023 | Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication protocol, enabling attackers to execute arbitrary OS commands on devices. | ||
| CVE-2023-33377 | Cri | 0.64 | 9.8 | 0.02 | Aug 4, 2023 | Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its communication protocol, enabling attackers to execute arbitrary OS commands on devices. | ||
| CVE-2023-33376 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2023 | Connected IO v2.1.0 and prior has an argument injection vulnerability in its iptables command message in its communication protocol, enabling attackers to execute arbitrary OS commands on devices. | ||
| CVE-2023-33375 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2023 | Connected IO v2.1.0 and prior has a stack-based buffer overflow vulnerability in its communication protocol, enabling attackers to take control over devices. | ||
| CVE-2023-33374 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2023 | Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to specify arbitrary OS commands for devices to execute. Attackers abusing this dangerous functionality may issue all devices OS commands to execute, resulting in… | ||
| CVE-2023-33373 | Cri | 0.64 | 9.8 | 0.00 | Aug 4, 2023 | Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and use them to impersonate the devices. | ||
| CVE-2023-33372 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2023 | Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for device communication using MQTT. An attacker who gained access to these credentials is able to connect to the MQTT broker and send messages on behalf of devices,… | ||
| CVE-2023-39143 | Cri | 0.70 | 9.8 | 0.78 | Aug 4, 2023 | PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration). | ||
| CVE-2023-38686 | Cri | 0.53 | 9.3 | 0.00 | Aug 4, 2023 | Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured to send emails using TLS, Sydent does not verify SMTP servers' certificates. This makes Sydent's emails vulnerable to interception via a man-in-the-middle (MITM) attack.… | ||
| CVE-2023-37470 | Cri | 0.65 | 10.0 | 0.01 | Aug 4, 2023 | Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3, 1.45.4.3, and 1.46.6.4, a vulnerability could potentially allow remote code execution on one's Metabase server. The core issue… | ||
| CVE-2023-36480 | Cri | 0.57 | 9.8 | 0.02 | Aug 4, 2023 | The Aerospike Java client is a Java application that implements a network protocol to communicate with an Aerospike server. Prior to versions 7.0.0, 6.2.0, 5.2.0, and 4.5.0 some of the messages received from the server contain Java objects that the client deserializes when it… | ||
| CVE-2023-29689 | Cri | 0.70 | 9.8 | 0.41 | Aug 4, 2023 | PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system. | ||
| CVE-2023-38941 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2023 | django-sspanel v2022.2.2 was discovered to contain a remote command execution (RCE) vulnerability via the component sspanel/admin_view.py -> GoodsCreateView._post. | ||
| CVE-2023-36139 | Cri | 0.64 | 9.8 | 0.00 | Aug 4, 2023 | In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts. | ||
| CVE-2023-36134 | Cri | 0.64 | 9.8 | 0.00 | Aug 4, 2023 | In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts. | ||
| CVE-2023-36133 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2023 | PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change. | ||
| CVE-2023-36132 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2023 | PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control. | ||
| CVE-2023-36131 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2023 | PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation of password parameter. | ||
| CVE-2023-33665 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2023 | ai-dev aitable before v0.2.2 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php. | ||
| CVE-2023-38951 | Cri | 0.64 | 9.8 | 0.03 | Aug 3, 2023 | ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server via crafted requests to /base/sftpsetting/ endpoints that abuse a path traversal issue in the Username field and a lack of input… | ||
| CVE-2023-20214 | Cri | 0.59 | 9.1 | 0.01 | Aug 3, 2023 | A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance. … | ||
| CVE-2023-33666 | Cri | 0.64 | 9.8 | 0.01 | Aug 3, 2023 | ai-dev aioptimizedcombinations before v0.1.3 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php. | ||
| CVE-2023-38942 | — | Cri | 0.64 | 9.8 | 0.02 | Aug 3, 2023 | Dango-Translator v4.5.5 was discovered to contain a remote command execution (RCE) vulnerability via the component app/config/cloud_config.json. | |
| CVE-2023-36217 | Cri | 0.59 | 9.0 | 0.01 | Aug 3, 2023 | Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image manager function. | ||
| CVE-2023-36213 | Cri | 0.64 | 9.8 | 0.01 | Aug 3, 2023 | SQL injection vulnerability in MotoCMS v.3.4.3 allows a remote attacker to gain privileges via the keyword parameter of the search function. | ||
| CVE-2023-3346 | Cri | 0.64 | 9.8 | 0.02 | Aug 3, 2023 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in MITSUBSHI CNC Series allows a remote unauthenticated attacker to cause Denial of Service (DoS) condition and execute arbitrary code on the product by sending specially crafted packets. In… | ||
| CVE-2023-37679 | Cri | 0.74 | 9.8 | 0.99 | Aug 3, 2023 | A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server. | ||
| CVE-2023-37364 | Cri | 0.59 | 9.1 | 0.01 | Aug 3, 2023 | In WS-Inc J WBEM Server 4.7.4 before 4.7.5, the CIM-XML protocol adapter does not disable entity resolution. This allows context-dependent attackers to read arbitrary files or cause a denial of service, a similar issue to CVE-2013-4152. | ||
| CVE-2023-38954 | Cri | 0.64 | 9.8 | 0.01 | Aug 3, 2023 | ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability. | ||
| CVE-2023-36082 | Cri | 0.64 | 9.8 | 0.01 | Aug 3, 2023 | An isssue in GatesAIr Flexiva FM Transmitter/Exiter Fax 150W allows a remote attacker to gain privileges via the LDAP and SMTP credentials. | ||
| CVE-2023-33371 | Cri | 0.64 | 9.8 | 0.01 | Aug 3, 2023 | Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication. | ||
| CVE-2023-33369 | Cri | 0.59 | 9.1 | 0.01 | Aug 3, 2023 | A path traversal vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to delete arbitrary files on IDSecure filesystem, causing a denial of service. | ||
| CVE-2023-1935 | Cri | 0.61 | 9.4 | 0.01 | Aug 2, 2023 | ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized access to data or control of the device and cause a denial-of-service condition. | ||
| CVE-2023-1437 | Cri | 0.64 | 9.8 | 0.03 | Aug 2, 2023 | All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the remote file system and the… | ||
| CVE-2023-33562 | Cri | 0.64 | 9.8 | 0.01 | Aug 1, 2023 | User enumeration is found in in PHP Jabbers Time Slots Booking Calendar v3.3. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | ||
| CVE-2023-33561 | Cri | 0.64 | 9.8 | 0.01 | Aug 1, 2023 | Improper input validation of password parameter in PHP Jabbers Time Slots Booking Calendar v 3.3 results in insecure passwords. | ||
| CVE-2023-36210 | Cri | 0.66 | 9.8 | 0.29 | Aug 1, 2023 | MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter. | ||
| CVE-2023-33493 | Cri | 0.64 | 9.8 | 0.01 | Aug 1, 2023 | An Unrestricted Upload of File with Dangerous Type vulnerability in the Ajaxmanager File and Database explorer (ajaxmanager) module for PrestaShop through 2.3.0, allows remote attackers to upload dangerous files without restrictions. | ||
| CVE-2023-4058 | Cri | 0.64 | 9.8 | 0.01 | Aug 1, 2023 | Memory safety bugs present in Firefox 115. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116. | ||
| CVE-2023-4057 | Cri | 0.64 | 9.8 | 0.01 | Aug 1, 2023 | Memory safety bugs present in Firefox 115, Firefox ESR 115.0, and Thunderbird 115.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox <… | ||
| CVE-2023-4056 | Cri | 0.64 | 9.8 | 0.01 | Aug 1, 2023 | Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary… | ||
| CVE-2023-31710 | Cri | 0.64 | 9.8 | 0.01 | Aug 1, 2023 | TP-Link Archer AX21(US)_V3_1.1.4 Build 20230219 and AX21(US)_V3.6_1.1.4 Build 20230219 are vulnerable to Buffer Overflow. | ||
| CVE-2022-39986 | — | Cri | 0.04 | 9.8 | 0.99 | Aug 1, 2023 | A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpncfg.php and /ajax/openvpn/del_ovpncfg.php. | |
| CVE-2023-34960 | Cri | 0.75 | 9.8 | 0.99 | Aug 1, 2023 | A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name. | ||
| CVE-2023-39122 | Cri | 0.64 | 9.8 | 0.01 | Jul 31, 2023 | BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. This is fixed in 9.0.21 (and is also fixed by a patch for 9.0.20.200). | ||
| CVE-2022-42183 | Cri | 0.59 | 9.1 | 0.01 | Jul 31, 2023 | Precisely Spectrum Spatial Analyst 20.01 is vulnerable to Server-Side Request Forgery (SSRF). | ||
| CVE-2023-37771 | Cri | 0.64 | 9.8 | 0.01 | Jul 31, 2023 | Art Gallery Management System v1.0 contains a SQL injection vulnerability via the cid parameter at /agms/product.php. | ||
| CVE-2023-36092 | Cri | 0.64 | 9.8 | 0.01 | Jul 31, 2023 | Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via via phpcgi_main. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | ||
| CVE-2023-36091 | Cri | 0.64 | 9.8 | 0.01 | Jul 31, 2023 | Authentication Bypass vulnerability in D-Link DIR-895 FW102b07 allows remote attackers to gain escalated privileges via via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | ||
| CVE-2023-36090 | Cri | 0.64 | 9.8 | 0.01 | Jul 31, 2023 | Authentication Bypass vulnerability in D-Link DIR-885L FW102b01 allows remote attackers to gain escalated privileges via phpcgi. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. |
- risk 0.64cvss 9.8epss 0.01
Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication protocol, enabling attackers to execute arbitrary OS commands on devices.
- risk 0.64cvss 9.8epss 0.02
Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its communication protocol, enabling attackers to execute arbitrary OS commands on devices.
- risk 0.64cvss 9.8epss 0.01
Connected IO v2.1.0 and prior has an argument injection vulnerability in its iptables command message in its communication protocol, enabling attackers to execute arbitrary OS commands on devices.
- risk 0.64cvss 9.8epss 0.01
Connected IO v2.1.0 and prior has a stack-based buffer overflow vulnerability in its communication protocol, enabling attackers to take control over devices.
- risk 0.64cvss 9.8epss 0.01
Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to specify arbitrary OS commands for devices to execute. Attackers abusing this dangerous functionality may issue all devices OS commands to execute, resulting in…
- risk 0.64cvss 9.8epss 0.00
Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and use them to impersonate the devices.
- risk 0.64cvss 9.8epss 0.01
Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for device communication using MQTT. An attacker who gained access to these credentials is able to connect to the MQTT broker and send messages on behalf of devices,…
- risk 0.70cvss 9.8epss 0.78
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).
- risk 0.53cvss 9.3epss 0.00
Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured to send emails using TLS, Sydent does not verify SMTP servers' certificates. This makes Sydent's emails vulnerable to interception via a man-in-the-middle (MITM) attack.…
- risk 0.65cvss 10.0epss 0.01
Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3, 1.45.4.3, and 1.46.6.4, a vulnerability could potentially allow remote code execution on one's Metabase server. The core issue…
- risk 0.57cvss 9.8epss 0.02
The Aerospike Java client is a Java application that implements a network protocol to communicate with an Aerospike server. Prior to versions 7.0.0, 6.2.0, 5.2.0, and 4.5.0 some of the messages received from the server contain Java objects that the client deserializes when it…
- risk 0.70cvss 9.8epss 0.41
PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system.
- risk 0.64cvss 9.8epss 0.01
django-sspanel v2022.2.2 was discovered to contain a remote command execution (RCE) vulnerability via the component sspanel/admin_view.py -> GoodsCreateView._post.
- risk 0.64cvss 9.8epss 0.00
In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
- risk 0.64cvss 9.8epss 0.00
In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
- risk 0.64cvss 9.8epss 0.01
PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change.
- risk 0.64cvss 9.8epss 0.01
PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control.
- risk 0.64cvss 9.8epss 0.01
PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation of password parameter.
- risk 0.64cvss 9.8epss 0.01
ai-dev aitable before v0.2.2 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php.
- risk 0.64cvss 9.8epss 0.03
ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server via crafted requests to /base/sftpsetting/ endpoints that abuse a path traversal issue in the Username field and a lack of input…
- risk 0.59cvss 9.1epss 0.01
A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance. …
- risk 0.64cvss 9.8epss 0.01
ai-dev aioptimizedcombinations before v0.1.3 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php.
- risk 0.64cvss 9.8epss 0.02
Dango-Translator v4.5.5 was discovered to contain a remote command execution (RCE) vulnerability via the component app/config/cloud_config.json.
- risk 0.59cvss 9.0epss 0.01
Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image manager function.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in MotoCMS v.3.4.3 allows a remote attacker to gain privileges via the keyword parameter of the search function.
- risk 0.64cvss 9.8epss 0.02
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in MITSUBSHI CNC Series allows a remote unauthenticated attacker to cause Denial of Service (DoS) condition and execute arbitrary code on the product by sending specially crafted packets. In…
- risk 0.74cvss 9.8epss 0.99
A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.
- risk 0.59cvss 9.1epss 0.01
In WS-Inc J WBEM Server 4.7.4 before 4.7.5, the CIM-XML protocol adapter does not disable entity resolution. This allows context-dependent attackers to read arbitrary files or cause a denial of service, a similar issue to CVE-2013-4152.
- risk 0.64cvss 9.8epss 0.01
ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability.
- risk 0.64cvss 9.8epss 0.01
An isssue in GatesAIr Flexiva FM Transmitter/Exiter Fax 150W allows a remote attacker to gain privileges via the LDAP and SMTP credentials.
- risk 0.64cvss 9.8epss 0.01
Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication.
- risk 0.59cvss 9.1epss 0.01
A path traversal vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to delete arbitrary files on IDSecure filesystem, causing a denial of service.
- risk 0.61cvss 9.4epss 0.01
ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized access to data or control of the device and cause a denial-of-service condition.
- risk 0.64cvss 9.8epss 0.03
All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the remote file system and the…
- risk 0.64cvss 9.8epss 0.01
User enumeration is found in in PHP Jabbers Time Slots Booking Calendar v3.3. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
- risk 0.64cvss 9.8epss 0.01
Improper input validation of password parameter in PHP Jabbers Time Slots Booking Calendar v 3.3 results in insecure passwords.
- risk 0.66cvss 9.8epss 0.29
MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter.
- risk 0.64cvss 9.8epss 0.01
An Unrestricted Upload of File with Dangerous Type vulnerability in the Ajaxmanager File and Database explorer (ajaxmanager) module for PrestaShop through 2.3.0, allows remote attackers to upload dangerous files without restrictions.
- risk 0.64cvss 9.8epss 0.01
Memory safety bugs present in Firefox 115. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116.
- risk 0.64cvss 9.8epss 0.01
Memory safety bugs present in Firefox 115, Firefox ESR 115.0, and Thunderbird 115.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox <…
- risk 0.64cvss 9.8epss 0.01
Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary…
- risk 0.64cvss 9.8epss 0.01
TP-Link Archer AX21(US)_V3_1.1.4 Build 20230219 and AX21(US)_V3.6_1.1.4 Build 20230219 are vulnerable to Buffer Overflow.
- risk 0.04cvss 9.8epss 0.99
A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpncfg.php and /ajax/openvpn/del_ovpncfg.php.
- risk 0.75cvss 9.8epss 0.99
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.
- risk 0.64cvss 9.8epss 0.01
BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. This is fixed in 9.0.21 (and is also fixed by a patch for 9.0.20.200).
- risk 0.59cvss 9.1epss 0.01
Precisely Spectrum Spatial Analyst 20.01 is vulnerable to Server-Side Request Forgery (SSRF).
- risk 0.64cvss 9.8epss 0.01
Art Gallery Management System v1.0 contains a SQL injection vulnerability via the cid parameter at /agms/product.php.
- risk 0.64cvss 9.8epss 0.01
Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via via phpcgi_main. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
- risk 0.64cvss 9.8epss 0.01
Authentication Bypass vulnerability in D-Link DIR-895 FW102b07 allows remote attackers to gain escalated privileges via via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
- risk 0.64cvss 9.8epss 0.01
Authentication Bypass vulnerability in D-Link DIR-885L FW102b01 allows remote attackers to gain escalated privileges via phpcgi. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.