| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-35839 | — | Cri | 0.64 | 9.8 | 0.01 | Jun 19, 2023 | A bypass in the component sofa-hessian of Solon before v2.3.3 allows attackers to execute arbitrary code via providing crafted payload. | |
| CVE-2023-35813 | Cri | 0.71 | 9.8 | 0.87 | Jun 17, 2023 | Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3. | ||
| CVE-2014-125106 | Cri | 0.57 | 9.8 | 0.01 | Jun 17, 2023 | Nanopb before 0.3.1 allows size_t overflows in pb_dec_bytes and pb_dec_string. | ||
| CVE-2023-35784 | Cri | 0.00 | 9.8 | 0.01 | Jun 16, 2023 | A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected. | ||
| CVE-2023-34832 | Cri | 0.64 | 9.8 | 0.01 | Jun 16, 2023 | TP-Link Archer AX10(EU)_V1.2_230220 was discovered to contain a buffer overflow via the function FUN_131e8 - 0x132B4. | ||
| CVE-2023-34659 | — | Cri | 0.65 | 9.8 | 0.12 | Jun 16, 2023 | jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface. | |
| CVE-2023-25366 | Cri | 0.64 | 9.8 | 0.00 | Jun 16, 2023 | In Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS, insecure SCPI interface discloses web password. | ||
| CVE-2023-34548 | Cri | 0.64 | 9.8 | 0.01 | Jun 16, 2023 | Simple Customer Relationship Management 1.0 is vulnerable to SQL Injection via the email parameter. | ||
| CVE-2022-48472 | Cri | 0.64 | 9.8 | 0.01 | Jun 16, 2023 | A Huawei printer has a system command injection vulnerability. Successful exploitation could lead to remote code execution. Affected product versions include:BiSheng-WNM versions OTA-BiSheng-FW-2.0.0.211-beta,BiSheng-WNM FW 3.0.0.325,BiSheng-WNM FW 2.0.0.211. | ||
| CVE-2023-34157 | Cri | 0.65 | 10.0 | 0.00 | Jun 16, 2023 | Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app. | ||
| CVE-2023-35708 | Cri | 0.71 | 9.8 | 0.97 | Jun 16, 2023 | In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain… | ||
| CVE-2023-32754 | Cri | 0.64 | 9.8 | 0.01 | Jun 16, 2023 | Thinking Software Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify or delete database. | ||
| CVE-2023-32753 | Cri | 0.64 | 9.8 | 0.01 | Jun 16, 2023 | OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service. | ||
| CVE-2023-32752 | Cri | 0.64 | 9.8 | 0.01 | Jun 16, 2023 | L7 Networks InstantScan IS-8000 & InstantQoS IQ-8000’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system… | ||
| CVE-2023-34800 | Cri | 0.66 | 9.8 | 0.29 | Jun 15, 2023 | D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main. | ||
| CVE-2023-34852 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2023 | PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions. | ||
| CVE-2023-31672 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2023 | In the PrestaShop < 2.4.3 module "Length, weight or volume sell" (ailinear) there is a SQL injection vulnerability. | ||
| CVE-2023-2686 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2023 | Buffer overflow in Wi-Fi Commissioning MicriumOS example in Silicon Labs Gecko SDK v4.2.3 or earlier allows connected device to write payload onto the stack. | ||
| CVE-2023-29297 | Cri | 0.59 | 9.1 | 0.01 | Jun 15, 2023 | Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could lead to arbitrary code execution by an admin-privilege authenticated… | ||
| CVE-2023-21130 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2023 | In btm_ble_periodic_adv_sync_lost of btm_ble_gap.cc, there is a possible remote code execution due to a buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2021-0945 | Cri | 0.64 | 9.8 | 0.00 | Jun 15, 2023 | In _PMRCreate of the PowerVR kernel driver, a missing bounds check means it is possible to overwrite heap memory via PhysmemNewRamBackedPMR. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2021-0701 | Cri | 0.64 | 9.8 | 0.00 | Jun 15, 2023 | In PVRSRVBridgeSyncPrimOpCreate of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed. User… | ||
| CVE-2023-34880 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2023 | cmseasy v7.7.7.7 20230520 was discovered to contain a path traversal vulnerability via the add_action method at lib/admin/language_admin.php. This vulnerability allows attackers to execute arbitrary code and perform a local file inclusion. | ||
| CVE-2023-34251 | Cri | 0.58 | 9.9 | 0.02 | Jun 14, 2023 | Grav is a flat-file content management system. Versions prior to 1.7.42 are vulnerable to server side template injection. Remote code execution is possible by embedding malicious PHP code on the administrator screen by a user with page editing privileges. Version 1.7.42 contains… | ||
| CVE-2023-31746 | Cri | 0.64 | 9.8 | 0.03 | Jun 14, 2023 | There is a command injection vulnerability in the adslr VW2100 router with firmware version M1DV1.0. An unauthenticated attacker can exploit the vulnerability to execute system commands as the root user. | ||
| CVE-2023-30150 | Cri | 0.64 | 9.8 | 0.04 | Jun 14, 2023 | PrestaShop leocustomajax 1.0 and 1.0.0 are vulnerable to SQL Injection via modules/leocustomajax/leoajax.php. | ||
| CVE-2023-1329 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2023 | A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Buffer Overflow and/or Remote Code Execution when running HP Workpath solutions on potentially affected products. | ||
| CVE-2023-31671 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2023 | PrestaShop postfinance <= 17.1.13 is vulnerable to SQL Injection via PostfinanceValidationModuleFrontController::postProcess(). | ||
| CVE-2023-34095 | Cri | 0.00 | 9.8 | 0.02 | Jun 14, 2023 | cpdb-libs provides frontend and backend libraries for the Common Printing Dialog Backends (CPDB) project. In versions 1.0 through 2.0b4, cpdb-libs is vulnerable to buffer overflows via improper use of `scanf(3)`. cpdb-libs uses the `fscanf()` and `scanf()` functions to parse… | ||
| CVE-2023-25367 | Cri | 0.64 | 9.8 | 0.02 | Jun 14, 2023 | Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS allows unfiltered user input resulting in Remote Code Execution (RCE) with SCPI interface or web server. | ||
| CVE-2023-34540 | Cri | 0.57 | 9.8 | 0.02 | Jun 14, 2023 | Langchain before v0.0.225 was discovered to contain a remote code execution (RCE) vulnerability in the component JiraAPIWrapper (aka the JIRA API wrapper). This vulnerability allows attackers to execute arbitrary code via crafted input. As noted in the "releases/tag" reference,… | ||
| CVE-2023-34865 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2023 | Directory traversal vulnerability in ujcms 6.0.2 allows attackers to move files via the rename feature. | ||
| CVE-2023-34756 | Cri | 0.64 | 9.8 | 0.04 | Jun 14, 2023 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit. | ||
| CVE-2023-34755 | Cri | 0.64 | 9.8 | 0.04 | Jun 14, 2023 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit. | ||
| CVE-2023-34754 | Cri | 0.64 | 9.8 | 0.03 | Jun 14, 2023 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit. | ||
| CVE-2023-34753 | Cri | 0.64 | 9.8 | 0.04 | Jun 14, 2023 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit. | ||
| CVE-2023-34752 | Cri | 0.64 | 9.8 | 0.04 | Jun 14, 2023 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit. | ||
| CVE-2023-34751 | Cri | 0.64 | 9.8 | 0.04 | Jun 14, 2023 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit. | ||
| CVE-2023-34750 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2023 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=projects&action=edit. | ||
| CVE-2023-34747 | Cri | 0.65 | 9.8 | 0.20 | Jun 14, 2023 | File upload vulnerability in ujcms 6.0.2 via /api/backend/core/web-file-upload/upload. | ||
| CVE-2023-32015 | Cri | 0.64 | 9.8 | 0.02 | Jun 14, 2023 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | ||
| CVE-2023-32014 | Cri | 0.64 | 9.8 | 0.02 | Jun 14, 2023 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | ||
| CVE-2023-29363 | Cri | 0.64 | 9.8 | 0.02 | Jun 14, 2023 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | ||
| CVE-2023-29357 | Cri | 0.93 | 9.8 | 1.00 | KEV | Jun 14, 2023 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | |
| CVE-2023-24470 | Cri | 0.59 | 9.1 | 0.01 | Jun 13, 2023 | Potential XML External Entity Injection in ArcSight Logger versions prior to 7.3.0. | ||
| CVE-2023-34944 | Cri | 0.64 | 9.8 | 0.01 | Jun 13, 2023 | An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary code via uploading a crafted SVG file. | ||
| CVE-2023-29562 | Cri | 0.64 | 9.8 | 0.01 | Jun 13, 2023 | TP-Link TL-WPA7510 (EU)_V2_190125 was discovered to contain a stack overflow via the operation parameter at /admin/locale. | ||
| CVE-2022-28550 | Cri | 0.00 | 9.8 | 0.01 | Jun 13, 2023 | Matthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer Overflow via shellescape(), jhead.c, jhead. jhead copies strings to a stack buffer when it detects a &i or &o. However, jhead does not check the boundary of the stack buffer. As a result, there will be a stack buffer… | ||
| CVE-2023-27836 | Cri | 0.64 | 9.8 | 0.02 | Jun 13, 2023 | TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the devicePwd parameter in the function sub_ 40A80C. | ||
| CVE-2022-43684 | Cri | 0.64 | 9.9 | 0.02 | Jun 13, 2023 | ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is present in the following supported ServiceNow releases: * Quebec prior to Patch 10 Hot Fix 8b * … |
- risk 0.64cvss 9.8epss 0.01
A bypass in the component sofa-hessian of Solon before v2.3.3 allows attackers to execute arbitrary code via providing crafted payload.
- risk 0.71cvss 9.8epss 0.87
Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.
- risk 0.57cvss 9.8epss 0.01
Nanopb before 0.3.1 allows size_t overflows in pb_dec_bytes and pb_dec_string.
- risk 0.00cvss 9.8epss 0.01
A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected.
- risk 0.64cvss 9.8epss 0.01
TP-Link Archer AX10(EU)_V1.2_230220 was discovered to contain a buffer overflow via the function FUN_131e8 - 0x132B4.
- risk 0.65cvss 9.8epss 0.12
jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.
- risk 0.64cvss 9.8epss 0.00
In Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS, insecure SCPI interface discloses web password.
- risk 0.64cvss 9.8epss 0.01
Simple Customer Relationship Management 1.0 is vulnerable to SQL Injection via the email parameter.
- risk 0.64cvss 9.8epss 0.01
A Huawei printer has a system command injection vulnerability. Successful exploitation could lead to remote code execution. Affected product versions include:BiSheng-WNM versions OTA-BiSheng-FW-2.0.0.211-beta,BiSheng-WNM FW 3.0.0.325,BiSheng-WNM FW 2.0.0.211.
- risk 0.65cvss 10.0epss 0.00
Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app.
- risk 0.71cvss 9.8epss 0.97
In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain…
- risk 0.64cvss 9.8epss 0.01
Thinking Software Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify or delete database.
- risk 0.64cvss 9.8epss 0.01
OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service.
- risk 0.64cvss 9.8epss 0.01
L7 Networks InstantScan IS-8000 & InstantQoS IQ-8000’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system…
- risk 0.66cvss 9.8epss 0.29
D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main.
- risk 0.64cvss 9.8epss 0.01
PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.
- risk 0.64cvss 9.8epss 0.01
In the PrestaShop < 2.4.3 module "Length, weight or volume sell" (ailinear) there is a SQL injection vulnerability.
- risk 0.64cvss 9.8epss 0.01
Buffer overflow in Wi-Fi Commissioning MicriumOS example in Silicon Labs Gecko SDK v4.2.3 or earlier allows connected device to write payload onto the stack.
- risk 0.59cvss 9.1epss 0.01
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could lead to arbitrary code execution by an admin-privilege authenticated…
- risk 0.64cvss 9.8epss 0.01
In btm_ble_periodic_adv_sync_lost of btm_ble_gap.cc, there is a possible remote code execution due to a buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.64cvss 9.8epss 0.00
In _PMRCreate of the PowerVR kernel driver, a missing bounds check means it is possible to overwrite heap memory via PhysmemNewRamBackedPMR. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.64cvss 9.8epss 0.00
In PVRSRVBridgeSyncPrimOpCreate of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed. User…
- risk 0.64cvss 9.8epss 0.01
cmseasy v7.7.7.7 20230520 was discovered to contain a path traversal vulnerability via the add_action method at lib/admin/language_admin.php. This vulnerability allows attackers to execute arbitrary code and perform a local file inclusion.
- risk 0.58cvss 9.9epss 0.02
Grav is a flat-file content management system. Versions prior to 1.7.42 are vulnerable to server side template injection. Remote code execution is possible by embedding malicious PHP code on the administrator screen by a user with page editing privileges. Version 1.7.42 contains…
- risk 0.64cvss 9.8epss 0.03
There is a command injection vulnerability in the adslr VW2100 router with firmware version M1DV1.0. An unauthenticated attacker can exploit the vulnerability to execute system commands as the root user.
- risk 0.64cvss 9.8epss 0.04
PrestaShop leocustomajax 1.0 and 1.0.0 are vulnerable to SQL Injection via modules/leocustomajax/leoajax.php.
- risk 0.64cvss 9.8epss 0.01
A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Buffer Overflow and/or Remote Code Execution when running HP Workpath solutions on potentially affected products.
- risk 0.64cvss 9.8epss 0.01
PrestaShop postfinance <= 17.1.13 is vulnerable to SQL Injection via PostfinanceValidationModuleFrontController::postProcess().
- risk 0.00cvss 9.8epss 0.02
cpdb-libs provides frontend and backend libraries for the Common Printing Dialog Backends (CPDB) project. In versions 1.0 through 2.0b4, cpdb-libs is vulnerable to buffer overflows via improper use of `scanf(3)`. cpdb-libs uses the `fscanf()` and `scanf()` functions to parse…
- risk 0.64cvss 9.8epss 0.02
Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS allows unfiltered user input resulting in Remote Code Execution (RCE) with SCPI interface or web server.
- risk 0.57cvss 9.8epss 0.02
Langchain before v0.0.225 was discovered to contain a remote code execution (RCE) vulnerability in the component JiraAPIWrapper (aka the JIRA API wrapper). This vulnerability allows attackers to execute arbitrary code via crafted input. As noted in the "releases/tag" reference,…
- risk 0.64cvss 9.8epss 0.01
Directory traversal vulnerability in ujcms 6.0.2 allows attackers to move files via the rename feature.
- risk 0.64cvss 9.8epss 0.04
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit.
- risk 0.64cvss 9.8epss 0.04
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit.
- risk 0.64cvss 9.8epss 0.03
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit.
- risk 0.64cvss 9.8epss 0.04
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit.
- risk 0.64cvss 9.8epss 0.04
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.
- risk 0.64cvss 9.8epss 0.04
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit.
- risk 0.64cvss 9.8epss 0.01
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=projects&action=edit.
- risk 0.65cvss 9.8epss 0.20
File upload vulnerability in ujcms 6.0.2 via /api/backend/core/web-file-upload/upload.
- risk 0.64cvss 9.8epss 0.02
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- risk 0.93cvss 9.8epss 1.00
Microsoft SharePoint Server Elevation of Privilege Vulnerability
- risk 0.59cvss 9.1epss 0.01
Potential XML External Entity Injection in ArcSight Logger versions prior to 7.3.0.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary code via uploading a crafted SVG file.
- risk 0.64cvss 9.8epss 0.01
TP-Link TL-WPA7510 (EU)_V2_190125 was discovered to contain a stack overflow via the operation parameter at /admin/locale.
- risk 0.00cvss 9.8epss 0.01
Matthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer Overflow via shellescape(), jhead.c, jhead. jhead copies strings to a stack buffer when it detects a &i or &o. However, jhead does not check the boundary of the stack buffer. As a result, there will be a stack buffer…
- risk 0.64cvss 9.8epss 0.02
TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the devicePwd parameter in the function sub_ 40A80C.
- risk 0.64cvss 9.9epss 0.02
ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is present in the following supported ServiceNow releases: * Quebec prior to Patch 10 Hot Fix 8b * …