| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-24796 | Cri | 0.64 | 9.8 | 0.02 | Apr 26, 2023 | Password vulnerability found in Vinga WR-AC1200 81.102.1.4370 and before allows a remote attacker to execute arbitrary code via the password parameter at the /goform/sysTools and /adm/systools.asp endpoints. | ||
| CVE-2023-30404 | Cri | 0.64 | 9.8 | 0.02 | Apr 26, 2023 | Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability via the sysCmd parameter in the formSysCmd function. This vulnerability is exploited via a crafted HTTP request. | ||
| CVE-2023-27843 | Cri | 0.64 | 9.8 | 0.01 | Apr 26, 2023 | SQL injection vulnerability found in PrestaShop askforaquote v.5.4.2 and before allow a remote attacker to gain privileges via the QuotesProduct::deleteProduct component. | ||
| CVE-2012-5872 | Cri | 0.57 | 9.8 | 0.01 | Apr 26, 2023 | ARC (aka ARC2) through 2011-12-01 allows blind SQL Injection in getTriplePatternSQL in ARC2_StoreSelectQueryHandler.php via comments in a SPARQL WHERE clause. | ||
| CVE-2023-30839 | Cri | 0.57 | 9.9 | 0.02 | Apr 25, 2023 | PrestaShop is an Open Source e-commerce web application. Versions prior to 8.0.4 and 1.7.8.9 contain a SQL filtering vulnerability. A BO user can write, update, and delete in the database, even without having specific rights. PrestaShop 8.0.4 and 1.7.8.9 contain a patch for this… | ||
| CVE-2021-44547 | Cri | 0.59 | 9.1 | 0.01 | Apr 25, 2023 | A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading to privilege escalation. | ||
| CVE-2023-25313 | — | Cri | 0.57 | 9.8 | 0.01 | Apr 25, 2023 | OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbitrary code via the video link field to the Embed a video link feature. | |
| CVE-2023-27105 | Cri | 0.64 | 9.8 | 0.01 | Apr 25, 2023 | A vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and Shanling M2X Portable Music Player with Shanling MTouch OS v3.3 allows attackers to arbitrarily read, delete, or modify any critical system files via… | ||
| CVE-2023-28771 | Cri | 0.87 | 9.8 | 0.99 | KEV | Apr 25, 2023 | Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an… | |
| CVE-2023-30627 | Cri | 0.00 | 9.0 | 0.01 | Apr 24, 2023 | jellyfin-web is the web client for Jellyfin, a free-software media system. Starting in version 10.1.0 and prior to version 10.8.10, a stored cross-site scripting vulnerability in device.js can be used to make arbitrary calls to the `REST` endpoints with admin privileges. When… | ||
| CVE-2023-1020 | Cri | 0.64 | 9.8 | 0.05 | Apr 24, 2023 | The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | ||
| CVE-2023-29566 | — | Cri | 0.57 | 9.8 | 0.02 | Apr 24, 2023 | huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function. | |
| CVE-2023-27849 | Cri | 0.64 | 9.8 | 0.02 | Apr 24, 2023 | rails-routes-to-json v1.0.0 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function. | ||
| CVE-2023-27848 | — | Cri | 0.64 | 9.8 | 0.02 | Apr 24, 2023 | broccoli-compass v0.2.4 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function. | |
| CVE-2023-26865 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2023 | SQL injection vulnerability found in PrestaShop bdroppy v.2.2.12 and before allowing a remote attacker to gain privileges via the BdroppyCronModuleFrontController::importProducts component. | ||
| CVE-2023-24823 | Cri | 0.00 | 9.8 | 0.01 | Apr 24, 2023 | RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device resulting in a type confusion between IPv6 extension headers… | ||
| CVE-2023-30378 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2023 | In Tenda AC15 V15.03.05.19, the function "sub_8EE8" contains a stack-based buffer overflow vulnerability. | ||
| CVE-2023-30376 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2023 | In Tenda AC15 V15.03.05.19, the function "henan_pppoe_user" contains a stack-based buffer overflow vulnerability. | ||
| CVE-2023-30375 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2023 | In Tenda AC15 V15.03.05.19, the function "getIfIp" contains a stack-based buffer overflow vulnerability. | ||
| CVE-2023-30373 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2023 | In Tenda AC15 V15.03.05.19, the function "xian_pppoe_user" contains a stack-based buffer overflow vulnerability. | ||
| CVE-2023-30372 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2023 | In Tenda AC15 V15.03.05.19, The function "xkjs_ver32" contains a stack-based buffer overflow vulnerability. | ||
| CVE-2023-30371 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2023 | In Tenda AC15 V15.03.05.19, the function "sub_ED14" contains a stack-based buffer overflow vulnerability. | ||
| CVE-2023-30370 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2023 | In Tenda AC15 V15.03.05.19, the function GetValue contains a stack-based buffer overflow vulnerability. | ||
| CVE-2023-24819 | Cri | 0.00 | 9.8 | 0.01 | Apr 24, 2023 | RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device resulting in an out of bounds write in the packet buffer. The… | ||
| CVE-2023-30369 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2023 | Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow. | ||
| CVE-2023-30368 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2023 | Tenda AC5 V15.03.06.28 is vulnerable to Buffer Overflow via the initWebs function. | ||
| CVE-2023-25133 | Cri | 0.59 | 9.1 | 0.01 | Apr 24, 2023 | Improper privilege management vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and earlier, PowerPanel… | ||
| CVE-2023-25132 | Cri | 0.59 | 9.1 | 0.01 | Apr 24, 2023 | Unrestricted upload of file with dangerous type vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and… | ||
| CVE-2023-25131 | Cri | 0.61 | 9.4 | 0.01 | Apr 24, 2023 | Use of default password vulnerability in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and earlier, PowerPanel Business Local/Remote for… | ||
| CVE-2023-22581 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2023 | White Rabbit Switch contains a vulnerability which makes it possible for an attacker to perform system commands under the context of the web application (the default installation makes the webserver run as the root user). | ||
| CVE-2023-22577 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2023 | Within White Rabbit Switch it's possible as an unauthenticated user to retrieve sensitive information such as password hashes and the SNMP community strings. | ||
| CVE-2023-28131 | Cri | 0.64 | 9.6 | 0.23 | Apr 24, 2023 | A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achieved once a victim clicks a malicious link. The link itself… | ||
| CVE-2023-31060 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2023 | Repetier Server through 1.4.10 executes as SYSTEM. This can be leveraged in conjunction with CVE-2023-31059 for full compromise. | ||
| CVE-2023-31056 | Cri | 0.59 | 9.1 | 0.01 | Apr 24, 2023 | CloverDX before 5.17.3 writes passwords to the audit log in certain situations, if the audit log is enabled and single sign-on is not employed. The fixed versions are 5.15.4, 5.16.2, 5.17.3, and 6.0.x. | ||
| CVE-2023-23753 | Cri | 0.64 | 9.8 | 0.01 | Apr 23, 2023 | The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injection as concatenation is used to construct an SQL Query. An attacker can interact with the database and could be able to read, modify and delete data on it. | ||
| CVE-2023-30621 | Cri | 0.00 | 9.8 | 0.02 | Apr 21, 2023 | Gipsy is a multi-purpose discord bot which aim to be as modular and user-friendly as possible. In versions prior to 1.3 users can run command on the host machine with sudoer permission. The `!ping` command when provided with an IP or hostname used to run a bash `ping `… | ||
| CVE-2023-29924 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2023 | PowerJob V4.3.1 is vulnerable to Incorrect Access Control that allows for remote code execution. | ||
| CVE-2023-26556 | — | Cri | 0.59 | 9.1 | 0.01 | Apr 21, 2023 | io.finnet tss-lib before 2.0.0 can leak a secret key via a timing side-channel attack because it relies on the scalar-multiplication implementation in Go crypto/elliptic, which is not constant time (there is an if statement in a loop). One leak is in ecdsa/keygen/round_2.go.… | |
| CVE-2023-2231 | Cri | 0.64 | 9.8 | 0.02 | Apr 21, 2023 | A vulnerability, which was classified as critical, was found in MAXTECH MAX-G866ac 0.4.1_TBRO_20160314. This affects an unknown part of the component Remote Management. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The exploit… | ||
| CVE-2023-2227 | Cri | 0.56 | 9.1 | 0.44 | Apr 21, 2023 | Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0. | ||
| CVE-2023-1892 | Cri | 0.56 | 9.6 | 0.03 | Apr 21, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8. | ||
| CVE-2023-2131 | Cri | 0.65 | 10.0 | 0.02 | Apr 20, 2023 | Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command injection, which could allow an attacker to remotely execute arbitrary code. | ||
| CVE-2023-20873 | Cri | 0.57 | 9.8 | 0.01 | Apr 20, 2023 | In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to… | ||
| CVE-2023-20864 | Cri | 0.69 | 9.8 | 0.70 | Apr 20, 2023 | VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root. | ||
| CVE-2023-30076 | Cri | 0.64 | 9.8 | 0.01 | Apr 20, 2023 | Sourcecodester Judging Management System v1.0 is vulnerable to SQL Injection via /php-jms/print_judges.php?print_judges.php=&se_name=&sub_event_id=. | ||
| CVE-2023-29528 | Cri | 0.52 | 9.0 | 0.01 | Apr 20, 2023 | XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milestone-1 and massively improved in version 14.6-rc-1, allowed the injection of arbitrary HTML code and thus… | ||
| CVE-2023-27350 | Cri | 0.93 | 9.8 | 1.00 | KEV | Apr 20, 2023 | This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from… | |
| CVE-2023-29926 | Cri | 0.64 | 9.8 | 0.01 | Apr 20, 2023 | PowerJob V4.3.2 has unauthorized interface that causes remote code execution. | ||
| CVE-2022-29606 | Cri | 0.64 | 9.8 | 0.01 | Apr 20, 2023 | An issue was discovered in ONOS 2.5.1. An intent with a large port number shows the CORRUPT state, which is misleading to a network operator. Improper handling of such port numbers causes inconsistency between intent and flow rules in the network. | ||
| CVE-2022-29604 | Cri | 0.64 | 9.8 | 0.01 | Apr 20, 2023 | An issue was discovered in ONOS 2.5.1. An intent with an uppercase letter in a device ID shows the CORRUPT state, which is misleading to a network operator. Improper handling of case sensitivity causes inconsistency between intent and flow rules in the network. |
- risk 0.64cvss 9.8epss 0.02
Password vulnerability found in Vinga WR-AC1200 81.102.1.4370 and before allows a remote attacker to execute arbitrary code via the password parameter at the /goform/sysTools and /adm/systools.asp endpoints.
- risk 0.64cvss 9.8epss 0.02
Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability via the sysCmd parameter in the formSysCmd function. This vulnerability is exploited via a crafted HTTP request.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability found in PrestaShop askforaquote v.5.4.2 and before allow a remote attacker to gain privileges via the QuotesProduct::deleteProduct component.
- risk 0.57cvss 9.8epss 0.01
ARC (aka ARC2) through 2011-12-01 allows blind SQL Injection in getTriplePatternSQL in ARC2_StoreSelectQueryHandler.php via comments in a SPARQL WHERE clause.
- risk 0.57cvss 9.9epss 0.02
PrestaShop is an Open Source e-commerce web application. Versions prior to 8.0.4 and 1.7.8.9 contain a SQL filtering vulnerability. A BO user can write, update, and delete in the database, even without having specific rights. PrestaShop 8.0.4 and 1.7.8.9 contain a patch for this…
- risk 0.59cvss 9.1epss 0.01
A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading to privilege escalation.
- risk 0.57cvss 9.8epss 0.01
OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbitrary code via the video link field to the Embed a video link feature.
- risk 0.64cvss 9.8epss 0.01
A vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and Shanling M2X Portable Music Player with Shanling MTouch OS v3.3 allows attackers to arbitrarily read, delete, or modify any critical system files via…
- risk 0.87cvss 9.8epss 0.99
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an…
- risk 0.00cvss 9.0epss 0.01
jellyfin-web is the web client for Jellyfin, a free-software media system. Starting in version 10.1.0 and prior to version 10.8.10, a stored cross-site scripting vulnerability in device.js can be used to make arbitrary calls to the `REST` endpoints with admin privileges. When…
- risk 0.64cvss 9.8epss 0.05
The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
- risk 0.57cvss 9.8epss 0.02
huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.
- risk 0.64cvss 9.8epss 0.02
rails-routes-to-json v1.0.0 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.
- risk 0.64cvss 9.8epss 0.02
broccoli-compass v0.2.4 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability found in PrestaShop bdroppy v.2.2.12 and before allowing a remote attacker to gain privileges via the BdroppyCronModuleFrontController::importProducts component.
- risk 0.00cvss 9.8epss 0.01
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device resulting in a type confusion between IPv6 extension headers…
- risk 0.64cvss 9.8epss 0.01
In Tenda AC15 V15.03.05.19, the function "sub_8EE8" contains a stack-based buffer overflow vulnerability.
- risk 0.64cvss 9.8epss 0.01
In Tenda AC15 V15.03.05.19, the function "henan_pppoe_user" contains a stack-based buffer overflow vulnerability.
- risk 0.64cvss 9.8epss 0.01
In Tenda AC15 V15.03.05.19, the function "getIfIp" contains a stack-based buffer overflow vulnerability.
- risk 0.64cvss 9.8epss 0.01
In Tenda AC15 V15.03.05.19, the function "xian_pppoe_user" contains a stack-based buffer overflow vulnerability.
- risk 0.64cvss 9.8epss 0.01
In Tenda AC15 V15.03.05.19, The function "xkjs_ver32" contains a stack-based buffer overflow vulnerability.
- risk 0.64cvss 9.8epss 0.01
In Tenda AC15 V15.03.05.19, the function "sub_ED14" contains a stack-based buffer overflow vulnerability.
- risk 0.64cvss 9.8epss 0.01
In Tenda AC15 V15.03.05.19, the function GetValue contains a stack-based buffer overflow vulnerability.
- risk 0.00cvss 9.8epss 0.01
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device resulting in an out of bounds write in the packet buffer. The…
- risk 0.64cvss 9.8epss 0.01
Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow.
- risk 0.64cvss 9.8epss 0.01
Tenda AC5 V15.03.06.28 is vulnerable to Buffer Overflow via the initWebs function.
- risk 0.59cvss 9.1epss 0.01
Improper privilege management vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and earlier, PowerPanel…
- risk 0.59cvss 9.1epss 0.01
Unrestricted upload of file with dangerous type vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and…
- risk 0.61cvss 9.4epss 0.01
Use of default password vulnerability in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and earlier, PowerPanel Business Local/Remote for…
- risk 0.64cvss 9.8epss 0.01
White Rabbit Switch contains a vulnerability which makes it possible for an attacker to perform system commands under the context of the web application (the default installation makes the webserver run as the root user).
- risk 0.64cvss 9.8epss 0.01
Within White Rabbit Switch it's possible as an unauthenticated user to retrieve sensitive information such as password hashes and the SNMP community strings.
- risk 0.64cvss 9.6epss 0.23
A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achieved once a victim clicks a malicious link. The link itself…
- risk 0.64cvss 9.8epss 0.01
Repetier Server through 1.4.10 executes as SYSTEM. This can be leveraged in conjunction with CVE-2023-31059 for full compromise.
- risk 0.59cvss 9.1epss 0.01
CloverDX before 5.17.3 writes passwords to the audit log in certain situations, if the audit log is enabled and single sign-on is not employed. The fixed versions are 5.15.4, 5.16.2, 5.17.3, and 6.0.x.
- risk 0.64cvss 9.8epss 0.01
The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injection as concatenation is used to construct an SQL Query. An attacker can interact with the database and could be able to read, modify and delete data on it.
- risk 0.00cvss 9.8epss 0.02
Gipsy is a multi-purpose discord bot which aim to be as modular and user-friendly as possible. In versions prior to 1.3 users can run command on the host machine with sudoer permission. The `!ping` command when provided with an IP or hostname used to run a bash `ping `…
- risk 0.64cvss 9.8epss 0.01
PowerJob V4.3.1 is vulnerable to Incorrect Access Control that allows for remote code execution.
- risk 0.59cvss 9.1epss 0.01
io.finnet tss-lib before 2.0.0 can leak a secret key via a timing side-channel attack because it relies on the scalar-multiplication implementation in Go crypto/elliptic, which is not constant time (there is an if statement in a loop). One leak is in ecdsa/keygen/round_2.go.…
- risk 0.64cvss 9.8epss 0.02
A vulnerability, which was classified as critical, was found in MAXTECH MAX-G866ac 0.4.1_TBRO_20160314. This affects an unknown part of the component Remote Management. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The exploit…
- risk 0.56cvss 9.1epss 0.44
Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0.
- risk 0.56cvss 9.6epss 0.03
Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8.
- risk 0.65cvss 10.0epss 0.02
Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command injection, which could allow an attacker to remotely execute arbitrary code.
- risk 0.57cvss 9.8epss 0.01
In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to…
- risk 0.69cvss 9.8epss 0.70
VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Judging Management System v1.0 is vulnerable to SQL Injection via /php-jms/print_judges.php?print_judges.php=&se_name=&sub_event_id=.
- risk 0.52cvss 9.0epss 0.01
XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milestone-1 and massively improved in version 14.6-rc-1, allowed the injection of arbitrary HTML code and thus…
- risk 0.93cvss 9.8epss 1.00
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from…
- risk 0.64cvss 9.8epss 0.01
PowerJob V4.3.2 has unauthorized interface that causes remote code execution.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in ONOS 2.5.1. An intent with a large port number shows the CORRUPT state, which is misleading to a network operator. Improper handling of such port numbers causes inconsistency between intent and flow rules in the network.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in ONOS 2.5.1. An intent with an uppercase letter in a device ID shows the CORRUPT state, which is misleading to a network operator. Improper handling of case sensitivity causes inconsistency between intent and flow rules in the network.