| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36089 | Cri | 0.64 | 9.8 | 0.01 | Jul 31, 2023 | Authentication Bypass vulnerability in D-Link DIR-645 firmware version 1.03 allows remote attackers to gain escalated privileges via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | ||
| CVE-2023-34842 | Cri | 0.64 | 9.8 | 0.01 | Jul 31, 2023 | Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php. | ||
| CVE-2023-34644 | Cri | 0.64 | 9.8 | 0.02 | Jul 31, 2023 | Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW_3.0(1)B11P204, RG-NBS and RG-S1930 series switches SWITCH_3.0(1)B11P218, RG-EG series business VPN routers EG_3.0(1)B11P216, EAP and RAP series wireless access points… | ||
| CVE-2023-34635 | Cri | 0.67 | 9.8 | 0.04 | Jul 31, 2023 | Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not validating or sanitizing the user input in the username field of the login page. | ||
| CVE-2020-21662 | Cri | 0.64 | 9.8 | 0.01 | Jul 31, 2023 | SQL injection vulnerability in yunyecms 2.0.2 allows remote attackers to run arbitrary SQL commands via XFF. | ||
| CVE-2023-37647 | Cri | 0.64 | 9.8 | 0.01 | Jul 31, 2023 | SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php. | ||
| CVE-2023-35861 | Cri | 0.64 | 9.8 | 0.02 | Jul 31, 2023 | A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute arbitrary commands as root on the BMC. | ||
| CVE-2023-4006 | — | Cri | 0.57 | 9.8 | 0.01 | Jul 31, 2023 | Improper Neutralization of Formula Elements in a CSV File in GitHub repository thorsten/phpmyfaq prior to 3.1.16. | |
| CVE-2023-4005 | Cri | 0.00 | 9.8 | 0.00 | Jul 31, 2023 | Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5. | ||
| CVE-2023-37214 | Cri | 0.64 | 9.8 | 0.01 | Jul 30, 2023 | Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025. | ||
| CVE-2023-32227 | Cri | 0.64 | 9.8 | 0.01 | Jul 30, 2023 | Synel SYnergy Fingerprint Terminals - CWE-798: Use of Hard-coded Credentials | ||
| CVE-2023-32225 | Cri | 0.64 | 9.8 | 0.01 | Jul 30, 2023 | Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type - A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method. | ||
| CVE-2022-4924 | Cri | 0.62 | 9.6 | 0.01 | Jul 29, 2023 | Use after free in WebRTC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2022-4920 | Cri | 0.62 | 9.6 | 0.01 | Jul 29, 2023 | Heap buffer overflow in Blink in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2023-39023 | Cri | 0.64 | 9.8 | 0.01 | Jul 28, 2023 | university compass v2.2.0 and below was discovered to contain a code injection vulnerability in the component org.compass.core.executor.DefaultExecutorManager.configure. This vulnerability is exploited via passing an unchecked argument. | ||
| CVE-2023-39022 | — | Cri | 0.64 | 9.8 | 0.01 | Jul 28, 2023 | oscore v2.2.6 and below was discovered to contain a code injection vulnerability in the component com.opensymphony.util.EJBUtils.createStateless. This vulnerability is exploited via passing an unchecked argument. | |
| CVE-2023-39021 | — | Cri | 0.64 | 9.8 | 0.01 | Jul 28, 2023 | wix-embedded-mysql v4.6.1 and below was discovered to contain a code injection vulnerability in the component com.wix.mysql.distribution.Setup.apply. This vulnerability is exploited via passing an unchecked argument. | |
| CVE-2023-39020 | — | Cri | 0.57 | 9.8 | 0.01 | Jul 28, 2023 | stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford.nlp.io.getBZip2PipedInputStream. This vulnerability is exploited via passing an unchecked argument. | |
| CVE-2023-39018 | Cri | 0.64 | 9.8 | 0.01 | Jul 28, 2023 | FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple third parties because there are no… | ||
| CVE-2023-39017 | Cri | 0.64 | 9.8 | 0.01 | Jul 28, 2023 | quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessageJob.execute. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple parties because it is… | ||
| CVE-2023-39016 | Cri | 0.64 | 9.8 | 0.01 | Jul 28, 2023 | bboss-persistent v6.0.9 and below was discovered to contain a code injection vulnerability in the component com.frameworkset.common.poolman.util.SQLManager.createPool. This vulnerability is exploited via passing an unchecked argument. | ||
| CVE-2023-39015 | — | Cri | 0.64 | 9.8 | 0.01 | Jul 28, 2023 | webmagic-extension v0.9.0 and below was discovered to contain a code injection vulnerability via the component us.codecraft.webmagic.downloader.PhantomJSDownloader. | |
| CVE-2023-39013 | — | Cri | 0.64 | 9.8 | 0.01 | Jul 28, 2023 | Duke v1.2 and below was discovered to contain a code injection vulnerability via the component no.priv.garshol.duke.server.CommonJTimer.init. | |
| CVE-2023-39010 | — | Cri | 0.57 | 9.8 | 0.01 | Jul 28, 2023 | BoofCV 0.42 was discovered to contain a code injection vulnerability via the component boofcv.io.calibration.CalibrationIO.load. This vulnerability is exploited by loading a crafted camera calibration file. | |
| CVE-2023-38992 | — | Cri | 0.62 | 9.8 | 0.72 | Jul 28, 2023 | jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData. | |
| CVE-2023-37754 | Cri | 0.66 | 9.8 | 0.27 | Jul 28, 2023 | PowerJob v4.3.3 was discovered to contain a remote command execution (RCE) vulnerability via the instanceId parameter at /instance/detail. | ||
| CVE-2023-38604 | Cri | 0.64 | 9.8 | 0.01 | Jul 28, 2023 | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in watchOS 9.6, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Monterey 12.6.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute… | ||
| CVE-2023-38598 | Cri | 0.64 | 9.8 | 0.01 | Jul 28, 2023 | A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.6, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Monterey 12.6.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute arbitrary… | ||
| CVE-2023-37285 | Cri | 0.64 | 9.8 | 0.01 | Jul 28, 2023 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, macOS Big Sur 11.7.9, macOS Monterey 12.6.8, macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges. | ||
| CVE-2023-36495 | Cri | 0.64 | 9.8 | 0.01 | Jul 28, 2023 | An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.6, macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges. | ||
| CVE-2023-34425 | Cri | 0.64 | 9.8 | 0.01 | Jul 28, 2023 | The issue was addressed with improved memory handling. This issue is fixed in watchOS 9.6, macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, macOS Big Sur 11.7.9, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges. | ||
| CVE-2023-33745 | Cri | 0.64 | 9.8 | 0.01 | Jul 27, 2023 | TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Privilege Management: from the shell available after an adb connection, simply entering the su command provides root access (without requiring a password). | ||
| CVE-2023-33744 | Cri | 0.64 | 9.8 | 0.01 | Jul 27, 2023 | TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671. | ||
| CVE-2023-33743 | Cri | 0.64 | 9.8 | 0.01 | Jul 27, 2023 | TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Access Control; specifically, Android Debug Bridge (adb) is available. | ||
| CVE-2023-3975 | Cri | 0.00 | 9.8 | 0.02 | Jul 27, 2023 | OS Command Injection in GitHub repository jgraph/drawio prior to 21.5.0. | ||
| CVE-2023-3974 | Cri | 0.00 | 9.8 | 0.01 | Jul 27, 2023 | OS Command Injection in GitHub repository jgraph/drawio prior to 21.4.0. | ||
| CVE-2023-3956 | Cri | 0.57 | 9.8 | 0.01 | Jul 27, 2023 | The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of data due to a missing capability check on the 'events_receiver' function in versions up to, and including, 0.0.9.18. This makes it possible for unauthenticated… | ||
| CVE-2023-31465 | Cri | 0.67 | 9.8 | 0.44 | Jul 26, 2023 | An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper streams, it is possible to find the getsamplebacklog call. Some query parameters are passed directly in the URL and named arg[x], with x an integer starting from… | ||
| CVE-2023-33308 | Cri | 0.64 | 9.8 | 0.02 | Jul 26, 2023 | A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remote unauthenticated attacker to execute arbitrary code or command via crafted… | ||
| CVE-2023-26859 | Cri | 0.64 | 9.8 | 0.01 | Jul 26, 2023 | SQL injection vulnerability found in PrestaShop sendinblue v.4.0.15 and before allow a remote attacker to gain privileges via the ajaxOrderTracking.php component. | ||
| CVE-2023-38673 | Cri | 0.56 | 9.6 | 0.02 | Jul 26, 2023 | PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands on the operating system. | ||
| CVE-2023-38647 | Cri | 0.57 | 9.8 | 0.02 | Jul 26, 2023 | An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.ScriptEngineManager to load code using that ClassLoader. This unbounded deserialization can likely lead to remote code… | ||
| CVE-2023-37677 | Cri | 0.64 | 9.8 | 0.01 | Jul 25, 2023 | Pligg CMS v2.0.2 (also known as Kliqqi) was discovered to contain a remote code execution (RCE) vulnerability in the component admin_editor.php. | ||
| CVE-2023-34798 | Cri | 0.64 | 9.8 | 0.01 | Jul 25, 2023 | An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a crafted file. | ||
| CVE-2022-46898 | Cri | 0.64 | 9.8 | 0.01 | Jul 25, 2023 | An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal via the "restore SQL data" filename. The Vocera Report Console contains a websocket function that allows for the restoration of the database from a ZIP archive that expects… | ||
| CVE-2023-35982 | Cri | 0.64 | 9.8 | 0.02 | Jul 25, 2023 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of… | ||
| CVE-2023-35981 | Cri | 0.64 | 9.8 | 0.02 | Jul 25, 2023 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of… | ||
| CVE-2023-35980 | Cri | 0.64 | 9.8 | 0.02 | Jul 25, 2023 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of… | ||
| CVE-2023-37895 | — | Cri | 0.64 | 9.8 | 0.03 | Jul 25, 2023 | Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (including) 2.20.10 (stable branch) and 2.21.17 (unstable branch) use the component "commons-beanutils", which contains a class that… | |
| CVE-2023-35088 | Cri | 0.57 | 9.8 | 0.02 | Jul 25, 2023 | Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. In the toAuditCkSql method, the groupId, streamId, auditId, and dt are… |
- risk 0.64cvss 9.8epss 0.01
Authentication Bypass vulnerability in D-Link DIR-645 firmware version 1.03 allows remote attackers to gain escalated privileges via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
- risk 0.64cvss 9.8epss 0.01
Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php.
- risk 0.64cvss 9.8epss 0.02
Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW_3.0(1)B11P204, RG-NBS and RG-S1930 series switches SWITCH_3.0(1)B11P218, RG-EG series business VPN routers EG_3.0(1)B11P216, EAP and RAP series wireless access points…
- risk 0.67cvss 9.8epss 0.04
Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not validating or sanitizing the user input in the username field of the login page.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in yunyecms 2.0.2 allows remote attackers to run arbitrary SQL commands via XFF.
- risk 0.64cvss 9.8epss 0.01
SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.
- risk 0.64cvss 9.8epss 0.02
A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute arbitrary commands as root on the BMC.
- risk 0.57cvss 9.8epss 0.01
Improper Neutralization of Formula Elements in a CSV File in GitHub repository thorsten/phpmyfaq prior to 3.1.16.
- risk 0.00cvss 9.8epss 0.00
Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5.
- risk 0.64cvss 9.8epss 0.01
Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025.
- risk 0.64cvss 9.8epss 0.01
Synel SYnergy Fingerprint Terminals - CWE-798: Use of Hard-coded Credentials
- risk 0.64cvss 9.8epss 0.01
Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type - A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method.
- risk 0.62cvss 9.6epss 0.01
Use after free in WebRTC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- risk 0.62cvss 9.6epss 0.01
Heap buffer overflow in Blink in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- risk 0.64cvss 9.8epss 0.01
university compass v2.2.0 and below was discovered to contain a code injection vulnerability in the component org.compass.core.executor.DefaultExecutorManager.configure. This vulnerability is exploited via passing an unchecked argument.
- risk 0.64cvss 9.8epss 0.01
oscore v2.2.6 and below was discovered to contain a code injection vulnerability in the component com.opensymphony.util.EJBUtils.createStateless. This vulnerability is exploited via passing an unchecked argument.
- risk 0.64cvss 9.8epss 0.01
wix-embedded-mysql v4.6.1 and below was discovered to contain a code injection vulnerability in the component com.wix.mysql.distribution.Setup.apply. This vulnerability is exploited via passing an unchecked argument.
- risk 0.57cvss 9.8epss 0.01
stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford.nlp.io.getBZip2PipedInputStream. This vulnerability is exploited via passing an unchecked argument.
- risk 0.64cvss 9.8epss 0.01
FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple third parties because there are no…
- risk 0.64cvss 9.8epss 0.01
quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessageJob.execute. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple parties because it is…
- risk 0.64cvss 9.8epss 0.01
bboss-persistent v6.0.9 and below was discovered to contain a code injection vulnerability in the component com.frameworkset.common.poolman.util.SQLManager.createPool. This vulnerability is exploited via passing an unchecked argument.
- risk 0.64cvss 9.8epss 0.01
webmagic-extension v0.9.0 and below was discovered to contain a code injection vulnerability via the component us.codecraft.webmagic.downloader.PhantomJSDownloader.
- risk 0.64cvss 9.8epss 0.01
Duke v1.2 and below was discovered to contain a code injection vulnerability via the component no.priv.garshol.duke.server.CommonJTimer.init.
- risk 0.57cvss 9.8epss 0.01
BoofCV 0.42 was discovered to contain a code injection vulnerability via the component boofcv.io.calibration.CalibrationIO.load. This vulnerability is exploited by loading a crafted camera calibration file.
- risk 0.62cvss 9.8epss 0.72
jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData.
- risk 0.66cvss 9.8epss 0.27
PowerJob v4.3.3 was discovered to contain a remote command execution (RCE) vulnerability via the instanceId parameter at /instance/detail.
- risk 0.64cvss 9.8epss 0.01
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in watchOS 9.6, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Monterey 12.6.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute…
- risk 0.64cvss 9.8epss 0.01
A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.6, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Monterey 12.6.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute arbitrary…
- risk 0.64cvss 9.8epss 0.01
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, macOS Big Sur 11.7.9, macOS Monterey 12.6.8, macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges.
- risk 0.64cvss 9.8epss 0.01
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.6, macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges.
- risk 0.64cvss 9.8epss 0.01
The issue was addressed with improved memory handling. This issue is fixed in watchOS 9.6, macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, macOS Big Sur 11.7.9, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges.
- risk 0.64cvss 9.8epss 0.01
TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Privilege Management: from the shell available after an adb connection, simply entering the su command provides root access (without requiring a password).
- risk 0.64cvss 9.8epss 0.01
TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671.
- risk 0.64cvss 9.8epss 0.01
TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Access Control; specifically, Android Debug Bridge (adb) is available.
- risk 0.00cvss 9.8epss 0.02
OS Command Injection in GitHub repository jgraph/drawio prior to 21.5.0.
- risk 0.00cvss 9.8epss 0.01
OS Command Injection in GitHub repository jgraph/drawio prior to 21.4.0.
- risk 0.57cvss 9.8epss 0.01
The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of data due to a missing capability check on the 'events_receiver' function in versions up to, and including, 0.0.9.18. This makes it possible for unauthenticated…
- risk 0.67cvss 9.8epss 0.44
An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper streams, it is possible to find the getsamplebacklog call. Some query parameters are passed directly in the URL and named arg[x], with x an integer starting from…
- risk 0.64cvss 9.8epss 0.02
A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remote unauthenticated attacker to execute arbitrary code or command via crafted…
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability found in PrestaShop sendinblue v.4.0.15 and before allow a remote attacker to gain privileges via the ajaxOrderTracking.php component.
- risk 0.56cvss 9.6epss 0.02
PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands on the operating system.
- risk 0.57cvss 9.8epss 0.02
An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.ScriptEngineManager to load code using that ClassLoader. This unbounded deserialization can likely lead to remote code…
- risk 0.64cvss 9.8epss 0.01
Pligg CMS v2.0.2 (also known as Kliqqi) was discovered to contain a remote code execution (RCE) vulnerability in the component admin_editor.php.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a crafted file.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal via the "restore SQL data" filename. The Vocera Report Console contains a websocket function that allows for the restoration of the database from a ZIP archive that expects…
- risk 0.64cvss 9.8epss 0.02
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…
- risk 0.64cvss 9.8epss 0.02
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…
- risk 0.64cvss 9.8epss 0.02
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…
- risk 0.64cvss 9.8epss 0.03
Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (including) 2.20.10 (stable branch) and 2.21.17 (unstable branch) use the component "commons-beanutils", which contains a class that…
- risk 0.57cvss 9.8epss 0.02
Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. In the toAuditCkSql method, the groupId, streamId, auditId, and dt are…