| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-30264 | Cri | 0.64 | 9.8 | 0.01 | May 4, 2023 | CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via application/admin/controller/Template.php:update. | ||
| CVE-2023-23059 | Cri | 0.64 | 9.8 | 0.01 | May 4, 2023 | An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions within the default installation and allows attackers to execute arbitrary code and gain escalated privileges. | ||
| CVE-2023-20126 | Cri | 0.67 | 9.8 | 0.38 | May 4, 2023 | A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to a missing authentication process within the firmware upgrade… | ||
| CVE-2023-30203 | Cri | 0.64 | 9.8 | 0.01 | May 4, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the event_id parameter at /php-jms/result_sheet.php. | ||
| CVE-2023-29827 | Cri | 0.64 | 9.8 | 0.06 | May 4, 2023 | ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter. NOTE: this is disputed by the vendor because the render function is not intended… | ||
| CVE-2023-22651 | Cri | 0.64 | 9.9 | 0.01 | May 4, 2023 | Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook may lead to the misconfiguration of the Webhook. This component enforces validation rules and security checks before resources… | ||
| CVE-2023-30331 | — | Cri | 0.64 | 9.8 | 0.01 | May 4, 2023 | An issue in the render function of beetl v3.15.0 allows attackers to execute server-side template injection (SSTI) via a crafted payload. | |
| CVE-2023-30077 | Cri | 0.64 | 9.8 | 0.01 | May 4, 2023 | Judging Management System v1.0 by oretnom23 was discovered to vulnerable to SQL injection via /php-jms/review_result.php?mainevent_id=, mainevent_id. | ||
| CVE-2022-47757 | Cri | 0.64 | 9.8 | 0.01 | May 4, 2023 | In imo.im 2022.11.1051, a path traversal vulnerability delivered via an unsanitized deeplink can force the application to write a file into the application's data directory. This may allow an attacker to save a shared library under a special directory which the app uses to… | ||
| CVE-2023-30204 | Cri | 0.64 | 9.8 | 0.01 | May 3, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the judge_id parameter at /php-jms/edit_judge.php. | ||
| CVE-2023-25826 | Cri | 0.63 | 9.8 | 0.36 | May 3, 2023 | Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameters and execute malicious code on the OpenTSDB host system. This exploit exists due to an incomplete fix that was made when this… | ||
| CVE-2023-29778 | Cri | 0.65 | 9.8 | 0.16 | May 2, 2023 | GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread. | ||
| CVE-2023-26089 | Cri | 0.64 | 9.8 | 0.01 | May 2, 2023 | European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5. | ||
| CVE-2023-2479 | Cri | 0.58 | 9.8 | 0.22 | May 2, 2023 | OS Command Injection in GitHub repository appium/appium-desktop prior to v1.22.3-4. | ||
| CVE-2023-29856 | Cri | 0.64 | 9.8 | 0.01 | May 2, 2023 | D-Link DIR-868L Hardware version A1, firmware version 1.12 is vulnerable to Buffer Overflow. The vulnerability is in scandir.sgi binary. | ||
| CVE-2023-30869 | Cri | 0.64 | 9.8 | 0.03 | May 2, 2023 | Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue affects Easy Digital Downloads: from 3.1 through 3.1.1.4.1. | ||
| CVE-2023-1730 | Cri | 0.67 | 9.8 | 0.41 | May 2, 2023 | The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks | ||
| CVE-2022-35898 | Cri | 0.64 | 9.8 | 0.01 | May 1, 2023 | OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows any authenticated user to change the password of any other user, including the Administrator account. | ||
| CVE-2023-29635 | Cri | 0.64 | 9.8 | 0.01 | May 1, 2023 | File upload vulnerability in Antabot White-Jotter v0.2.2, allows remote attackers to execute malicious code via the file parameter to function coversUpload. | ||
| CVE-2022-46365 | Cri | 0.52 | 9.1 | 0.01 | May 1, 2023 | Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a parameter, but not verified whether the user name is the currently logged user and whether the user is legal, This will allow… | ||
| CVE-2022-45802 | Cri | 0.57 | 9.8 | 0.01 | May 1, 2023 | Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to Apache StreamPark… | ||
| CVE-2023-2429 | — | Cri | 0.57 | 9.8 | 0.01 | Apr 30, 2023 | Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.13. | |
| CVE-2023-31470 | Cri | 0.00 | 9.8 | 0.01 | Apr 28, 2023 | SmartDNS through 41 before 56d0332 allows an out-of-bounds write because of a stack-based buffer overflow in the _dns_encode_domain function in the dns.c file, via a crafted DNS request. | ||
| CVE-2023-26813 | — | Cri | 0.64 | 9.8 | 0.01 | Apr 28, 2023 | SQL injection vulnerability in com.xnx3.wangmarket.plugin.dataDictionary.controller.DataDictionaryPluginController.java in wangmarket CMS 4.10 allows remote attackers to run arbitrary SQL commands via the TableName parameter to /plugin/dataDictionary/tableView.do. | |
| CVE-2023-26781 | Cri | 0.64 | 9.8 | 0.01 | Apr 28, 2023 | SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search. | ||
| CVE-2023-1968 | Cri | 0.65 | 10.0 | 0.02 | Apr 28, 2023 | Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remote communications. | ||
| CVE-2023-27973 | Cri | 0.64 | 9.8 | 0.01 | Apr 28, 2023 | Certain HP LaserJet Pro print products are potentially vulnerable to Heap Overflow and/or Remote Code Execution. | ||
| CVE-2023-27972 | Cri | 0.64 | 9.8 | 0.01 | Apr 28, 2023 | Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Remote Code Execution. | ||
| CVE-2023-27971 | Cri | 0.64 | 9.8 | 0.01 | Apr 28, 2023 | Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Elevation of Privilege. | ||
| CVE-2022-41400 | Cri | 0.64 | 9.8 | 0.01 | Apr 28, 2023 | Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings stored in ISAM database files in the shared data directory. This issue could allow attackers to decrypt user passwords and SQL connection strings. | ||
| CVE-2022-41397 | Cri | 0.64 | 9.8 | 0.01 | Apr 28, 2023 | The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKey") to encrypt and decrypt secrets stored in configuration files and in database tables. | ||
| CVE-2023-30466 | Cri | 0.64 | 9.8 | 0.01 | Apr 28, 2023 | This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface. A remote attacker could exploit this… | ||
| CVE-2023-1967 | Cri | 0.64 | 9.8 | 0.01 | Apr 27, 2023 | Keysight N8844A Data Analytics Web Service deserializes untrusted data without sufficiently verifying the resulting data will be valid. | ||
| CVE-2023-2158 | Cri | 0.64 | 9.8 | 0.01 | Apr 27, 2023 | Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain access to another user's account by crafting a custom "Remember Me" token. This is possible due to the use of a hard-coded cipher which was used when generating… | ||
| CVE-2023-30349 | — | Cri | 0.64 | 9.8 | 0.02 | Apr 27, 2023 | JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function. | |
| CVE-2023-1778 | Cri | 0.65 | 10.0 | 0.01 | Apr 27, 2023 | This vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 (except v4.21) due to insecure default credentials which allows remote attacker to login as superuser by using default username/password via web-based management interface and/or… | ||
| CVE-2023-28769 | Cri | 0.67 | 9.8 | 0.05 | Apr 27, 2023 | The buffer overflow vulnerability in the library “libclinkc.so” of the web server “zhttpd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated attacker to execute some OS commands or to cause denial-of-service (DoS)… | ||
| CVE-2023-28697 | Cri | 0.64 | 9.8 | 0.01 | Apr 27, 2023 | Moxa MiiNePort E1 has a vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to perform arbitrary system operation or disrupt service. | ||
| CVE-2023-20853 | Cri | 0.64 | 9.8 | 0.01 | Apr 27, 2023 | aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message process. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or… | ||
| CVE-2023-20852 | Cri | 0.64 | 9.8 | 0.01 | Apr 27, 2023 | aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or disrupt service. | ||
| CVE-2022-47758 | Cri | 0.64 | 9.8 | 0.01 | Apr 27, 2023 | Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack. | ||
| CVE-2023-2297 | Cri | 0.64 | 9.8 | 0.01 | Apr 27, 2023 | The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 3.9.0. This is due to the plugin using native password reset functionality, with insufficient validation on the… | ||
| CVE-2023-30846 | Cri | 0.52 | 9.1 | 0.02 | Apr 26, 2023 | typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScript. Users of the typed-rest-client library version 1.7.3 or lower are vulnerable to leak authentication data to 3rd parties. The flow of the vulnerability is as follows: First, send… | ||
| CVE-2023-30363 | — | Cri | 0.57 | 9.8 | 0.01 | Apr 26, 2023 | vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts. | |
| CVE-2023-30280 | Cri | 0.64 | 9.8 | 0.01 | Apr 26, 2023 | Buffer Overflow vulnerability found in Netgear R6900 v.1.0.2.26, R6700v3 v.1.0.4.128, R6700 v.1.0.0.26 allows a remote attacker to execute arbitrary code and cause a denial ofservice via the getInputData parameter of the fwSchedule.cgi page. | ||
| CVE-2020-36070 | — | Cri | 0.57 | 9.8 | 0.01 | Apr 26, 2023 | Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code via a crafted .php file to the media component. | |
| CVE-2023-30546 | Cri | 0.00 | 9.8 | 0.01 | Apr 26, 2023 | Contiki-NG is an operating system for Internet of Things devices. An off-by-one error can be triggered in the Antelope database management system in the Contiki-NG operating system in versions 4.8 and prior. The problem exists in the Contiki File System (CFS) backend for the… | ||
| CVE-2023-29268 | Cri | 0.64 | 9.8 | 0.01 | Apr 26, 2023 | The Splus Server component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that allows an unauthenticated remote attacker to upload or modify arbitrary files within the web server directory on the affected system. Affected releases are TIBCO… | ||
| CVE-2023-30211 | Cri | 0.64 | 9.8 | 0.01 | Apr 26, 2023 | OURPHP <= 7.2.0 is vulnerable to SQL Injection. | ||
| CVE-2022-39989 | Cri | 0.64 | 9.8 | 0.01 | Apr 26, 2023 | An issue was discovered in Fighting Cock Information System 1.0, which uses default credentials, but does not force nor prompt the administrators to change the credentials. |
- risk 0.64cvss 9.8epss 0.01
CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via application/admin/controller/Template.php:update.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions within the default installation and allows attackers to execute arbitrary code and gain escalated privileges.
- risk 0.67cvss 9.8epss 0.38
A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to a missing authentication process within the firmware upgrade…
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the event_id parameter at /php-jms/result_sheet.php.
- risk 0.64cvss 9.8epss 0.06
ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter. NOTE: this is disputed by the vendor because the render function is not intended…
- risk 0.64cvss 9.9epss 0.01
Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook may lead to the misconfiguration of the Webhook. This component enforces validation rules and security checks before resources…
- risk 0.64cvss 9.8epss 0.01
An issue in the render function of beetl v3.15.0 allows attackers to execute server-side template injection (SSTI) via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 by oretnom23 was discovered to vulnerable to SQL injection via /php-jms/review_result.php?mainevent_id=, mainevent_id.
- risk 0.64cvss 9.8epss 0.01
In imo.im 2022.11.1051, a path traversal vulnerability delivered via an unsanitized deeplink can force the application to write a file into the application's data directory. This may allow an attacker to save a shared library under a special directory which the app uses to…
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the judge_id parameter at /php-jms/edit_judge.php.
- risk 0.63cvss 9.8epss 0.36
Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameters and execute malicious code on the OpenTSDB host system. This exploit exists due to an incomplete fix that was made when this…
- risk 0.65cvss 9.8epss 0.16
GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.
- risk 0.64cvss 9.8epss 0.01
European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5.
- risk 0.58cvss 9.8epss 0.22
OS Command Injection in GitHub repository appium/appium-desktop prior to v1.22.3-4.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-868L Hardware version A1, firmware version 1.12 is vulnerable to Buffer Overflow. The vulnerability is in scandir.sgi binary.
- risk 0.64cvss 9.8epss 0.03
Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue affects Easy Digital Downloads: from 3.1 through 3.1.1.4.1.
- risk 0.67cvss 9.8epss 0.41
The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks
- risk 0.64cvss 9.8epss 0.01
OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows any authenticated user to change the password of any other user, including the Administrator account.
- risk 0.64cvss 9.8epss 0.01
File upload vulnerability in Antabot White-Jotter v0.2.2, allows remote attackers to execute malicious code via the file parameter to function coversUpload.
- risk 0.52cvss 9.1epss 0.01
Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a parameter, but not verified whether the user name is the currently logged user and whether the user is legal, This will allow…
- risk 0.57cvss 9.8epss 0.01
Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to Apache StreamPark…
- risk 0.57cvss 9.8epss 0.01
Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.13.
- risk 0.00cvss 9.8epss 0.01
SmartDNS through 41 before 56d0332 allows an out-of-bounds write because of a stack-based buffer overflow in the _dns_encode_domain function in the dns.c file, via a crafted DNS request.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in com.xnx3.wangmarket.plugin.dataDictionary.controller.DataDictionaryPluginController.java in wangmarket CMS 4.10 allows remote attackers to run arbitrary SQL commands via the TableName parameter to /plugin/dataDictionary/tableView.do.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search.
- risk 0.65cvss 10.0epss 0.02
Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remote communications.
- risk 0.64cvss 9.8epss 0.01
Certain HP LaserJet Pro print products are potentially vulnerable to Heap Overflow and/or Remote Code Execution.
- risk 0.64cvss 9.8epss 0.01
Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Remote Code Execution.
- risk 0.64cvss 9.8epss 0.01
Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Elevation of Privilege.
- risk 0.64cvss 9.8epss 0.01
Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings stored in ISAM database files in the shared data directory. This issue could allow attackers to decrypt user passwords and SQL connection strings.
- risk 0.64cvss 9.8epss 0.01
The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKey") to encrypt and decrypt secrets stored in configuration files and in database tables.
- risk 0.64cvss 9.8epss 0.01
This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface. A remote attacker could exploit this…
- risk 0.64cvss 9.8epss 0.01
Keysight N8844A Data Analytics Web Service deserializes untrusted data without sufficiently verifying the resulting data will be valid.
- risk 0.64cvss 9.8epss 0.01
Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain access to another user's account by crafting a custom "Remember Me" token. This is possible due to the use of a hard-coded cipher which was used when generating…
- risk 0.64cvss 9.8epss 0.02
JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function.
- risk 0.65cvss 10.0epss 0.01
This vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 (except v4.21) due to insecure default credentials which allows remote attacker to login as superuser by using default username/password via web-based management interface and/or…
- risk 0.67cvss 9.8epss 0.05
The buffer overflow vulnerability in the library “libclinkc.so” of the web server “zhttpd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated attacker to execute some OS commands or to cause denial-of-service (DoS)…
- risk 0.64cvss 9.8epss 0.01
Moxa MiiNePort E1 has a vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to perform arbitrary system operation or disrupt service.
- risk 0.64cvss 9.8epss 0.01
aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message process. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or…
- risk 0.64cvss 9.8epss 0.01
aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or disrupt service.
- risk 0.64cvss 9.8epss 0.01
Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack.
- risk 0.64cvss 9.8epss 0.01
The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 3.9.0. This is due to the plugin using native password reset functionality, with insufficient validation on the…
- risk 0.52cvss 9.1epss 0.02
typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScript. Users of the typed-rest-client library version 1.7.3 or lower are vulnerable to leak authentication data to 3rd parties. The flow of the vulnerability is as follows: First, send…
- risk 0.57cvss 9.8epss 0.01
vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts.
- risk 0.64cvss 9.8epss 0.01
Buffer Overflow vulnerability found in Netgear R6900 v.1.0.2.26, R6700v3 v.1.0.4.128, R6700 v.1.0.0.26 allows a remote attacker to execute arbitrary code and cause a denial ofservice via the getInputData parameter of the fwSchedule.cgi page.
- risk 0.57cvss 9.8epss 0.01
Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code via a crafted .php file to the media component.
- risk 0.00cvss 9.8epss 0.01
Contiki-NG is an operating system for Internet of Things devices. An off-by-one error can be triggered in the Antelope database management system in the Contiki-NG operating system in versions 4.8 and prior. The problem exists in the Contiki File System (CFS) backend for the…
- risk 0.64cvss 9.8epss 0.01
The Splus Server component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that allows an unauthenticated remote attacker to upload or modify arbitrary files within the web server directory on the affected system. Affected releases are TIBCO…
- risk 0.64cvss 9.8epss 0.01
OURPHP <= 7.2.0 is vulnerable to SQL Injection.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Fighting Cock Information System 1.0, which uses default credentials, but does not force nor prompt the administrators to change the credentials.