| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-29007 | Cri | 0.64 | 9.8 | 0.02 | Apr 15, 2023 | The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary… | ||
| CVE-2023-29210 | Cri | 0.57 | 9.9 | 0.01 | Apr 15, 2023 | XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents including the notification preferences macros can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access… | ||
| CVE-2023-29209 | Cri | 0.57 | 9.9 | 0.01 | Apr 15, 2023 | XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents including the legacy notification activity macro can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full… | ||
| CVE-2023-29206 | Cri | 0.52 | 9.0 | 0.01 | Apr 15, 2023 | XWiki Commons are technical libraries common to several other top level XWiki projects. There was no check in the author of a JavaScript xobject or StyleSheet xobject added in a XWiki document, so until now it was possible for a user having only Edit Right to create such object… | ||
| CVE-2023-29205 | Cri | 0.64 | 9.9 | 0.01 | Apr 15, 2023 | XWiki Commons are technical libraries common to several other top level XWiki projects. The HTML macro does not systematically perform a proper neutralization of script-related html tags. As a result, any user able to use the html macro in XWiki, is able to introduce an XSS… | ||
| CVE-2023-29202 | Cri | 0.52 | 9.0 | 0.01 | Apr 15, 2023 | XWiki Commons are technical libraries common to several other top level XWiki projects. The RSS macro that is bundled in XWiki included the content of the feed items without any cleaning in the HTML output when the parameter `content` was set to `true`. This allowed arbitrary… | ||
| CVE-2023-29201 | Cri | 0.52 | 9.0 | 0.01 | Apr 15, 2023 | XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milestone-1, only escaped `` and ``-tags but neither attributes that can be used to inject scripts… | ||
| CVE-2023-2106 | Cri | 0.57 | 9.8 | 0.01 | Apr 15, 2023 | Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20. | ||
| CVE-2022-2525 | Cri | 0.57 | 9.8 | 0.01 | Apr 15, 2023 | Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20. | ||
| CVE-2023-2027 | Cri | 0.64 | 9.8 | 0.01 | Apr 15, 2023 | The ZM Ajax Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.2. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for… | ||
| CVE-2023-26463 | Cri | 0.64 | 9.8 | 0.02 | Apr 15, 2023 | strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes within the same function. There is initially incorrect access control, later followed by an expired pointer dereference. One attack vector is… | ||
| CVE-2021-46880 | Cri | 0.00 | 9.8 | 0.01 | Apr 15, 2023 | x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certificate chain is sometimes discarded. | ||
| CVE-2023-27654 | Cri | 0.64 | 9.8 | 0.01 | Apr 14, 2023 | An issue found in WHOv.1.0.28, v.1.0.30, v.1.0.32 allows an attacker to cause a escalation of privileges via the TTMultiProvider component. | ||
| CVE-2023-29199 | Cri | 0.57 | 9.8 | 0.04 | Apr 14, 2023 | There exists a vulnerability in source code transformer (exception sanitization logic) of vm2 for versions up to 3.9.15, allowing attackers to bypass `handleException()` and leak unsanitized host exceptions which can be used to escape the sandbox and run arbitrary code in host… | ||
| CVE-2022-3748 | Cri | 0.64 | 9.8 | 0.01 | Apr 14, 2023 | Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5.0 through 7.2.0. | ||
| CVE-2023-29805 | Cri | 0.64 | 9.8 | 0.02 | Apr 14, 2023 | WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the pro_stor_canceltrans_handler_part_19 function. | ||
| CVE-2023-29803 | Cri | 0.64 | 9.8 | 0.02 | Apr 14, 2023 | TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the pid parameter in the disconnectVPN function. | ||
| CVE-2023-29802 | Cri | 0.64 | 9.8 | 0.02 | Apr 14, 2023 | TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function. | ||
| CVE-2023-29801 | Cri | 0.64 | 9.8 | 0.02 | Apr 14, 2023 | TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain multiple command injection vulnerabilities via the rtLogEnabled and rtLogServer parameters in the setSyslogCfg function. | ||
| CVE-2023-29800 | Cri | 0.64 | 9.8 | 0.02 | Apr 14, 2023 | TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function. | ||
| CVE-2023-29799 | Cri | 0.64 | 9.8 | 0.02 | Apr 14, 2023 | TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function. | ||
| CVE-2023-29798 | Cri | 0.64 | 9.8 | 0.02 | Apr 14, 2023 | TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg function. | ||
| CVE-2023-1833 | Cri | 0.64 | 9.8 | 0.01 | Apr 14, 2023 | Authentication Bypass by Primary Weakness vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass. This issue affects Redline Router: before 7.17. | ||
| CVE-2023-1803 | Cri | 0.64 | 9.8 | 0.01 | Apr 14, 2023 | Authentication Bypass by Alternate Name vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass. This issue affects Redline Router: before 7.17. | ||
| CVE-2022-45174 | Cri | 0.64 | 9.8 | 0.01 | Apr 14, 2023 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML Users can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/challenge endpoint. The correctness of the TOTP is not checked properly, and… | ||
| CVE-2022-45173 | Cri | 0.64 | 9.8 | 0.01 | Apr 14, 2023 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskintegration/challenge endpoint. Because only the client-side verifies whether a check was successful, an attacker can modify the response,… | ||
| CVE-2023-27648 | Cri | 0.64 | 9.8 | 0.03 | Apr 14, 2023 | Directory Traversal vulnerability found in T-ME Studios Change Color of Keypad v.1.275.1.277 allows a remote attacker to execute arbitrary code via the dex file in the internal storage. | ||
| CVE-2023-1617 | Cri | 0.64 | 9.8 | 0.01 | Apr 14, 2023 | Improper Authentication vulnerability in B&R Industrial Automation B&R VC4 (VNC-Server modules). This vulnerability may allow an unauthenticated network-based attacker to bypass the authentication mechanism of the VC4 visualization on affected devices. The impact of this… | ||
| CVE-2022-47027 | Cri | 0.64 | 9.8 | 0.01 | Apr 14, 2023 | Timmystudios Fast Typing Keyboard v1.275.1.162 allows unauthorized apps to overwrite arbitrary files in its internal storage via a dictionary traversal vulnerability and achieve arbitrary code execution. | ||
| CVE-2023-1863 | Cri | 0.64 | 9.8 | 0.01 | Apr 14, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eskom Water Metering Software allows Command Line Execution through SQL Injection. This issue affects Water Metering Software: before 23.04.06. | ||
| CVE-2023-29622 | Cri | 0.64 | 9.8 | 0.02 | Apr 14, 2023 | Purchase Order Management v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /purchase_order/admin/login.php. | ||
| CVE-2023-26918 | Cri | 0.67 | 9.8 | 0.06 | Apr 14, 2023 | Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed as LocalSystem. This occurs because %ProgramFiles%\FileReplicationPro allows Everyone:(F) access. | ||
| CVE-2023-27748 | Cri | 0.64 | 9.8 | 0.01 | Apr 13, 2023 | BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authenticity check for uploaded firmware. This can allow attackers to upload crafted firmware which contains backdoors and enables arbitrary code execution. | ||
| CVE-2023-27746 | Cri | 0.64 | 9.8 | 0.02 | Apr 13, 2023 | BlackVue DR750-2CH LTE v.1.012_2022.10.26 was discovered to contain a weak default passphrase which can be easily cracked via a brute force attack if the WPA2 handshake is intercepted. | ||
| CVE-2023-27667 | Cri | 0.64 | 9.8 | 0.01 | Apr 13, 2023 | Auto Dealer Management System v1.0 was discovered to contain a SQL injection vulnerability. | ||
| CVE-2023-24509 | Cri | 0.60 | 9.3 | 0.00 | Apr 13, 2023 | On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with RPR or SSO, an existing unprivileged user can login to the standby supervisor as a root user, leading to a privilege escalation.… | ||
| CVE-2023-27779 | Cri | 0.64 | 9.8 | 0.01 | Apr 13, 2023 | AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via the user parameter in the login form. | ||
| CVE-2023-29598 | Cri | 0.64 | 9.8 | 0.01 | Apr 13, 2023 | lmxcms v1.4.1 was discovered to contain a SQL injection vulnerability via the setbook parameter at index.php. | ||
| CVE-2023-27812 | Cri | 0.59 | 9.1 | 0.01 | Apr 13, 2023 | bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function. | ||
| CVE-2022-33288 | Cri | 0.60 | 9.3 | 0.00 | Apr 13, 2023 | Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information. | ||
| CVE-2022-33269 | Cri | 0.60 | 9.3 | 0.00 | Apr 13, 2023 | Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment. | ||
| CVE-2022-33259 | Cri | 0.64 | 9.8 | 0.00 | Apr 13, 2023 | Memory corruption due to buffer copy without checking the size of input in modem while decoding raw SMS received. | ||
| CVE-2022-33231 | Cri | 0.60 | 9.3 | 0.00 | Apr 13, 2023 | Memory corruption due to double free in core while initializing the encryption key. | ||
| CVE-2022-33211 | Cri | 0.64 | 9.8 | 0.00 | Apr 13, 2023 | memory corruption in modem due to improper check while calculating size of serialized CoAP message | ||
| CVE-2022-25745 | Cri | 0.64 | 9.8 | 0.00 | Apr 13, 2023 | Memory corruption in modem due to improper input validation while handling the incoming CoAP message | ||
| CVE-2022-25740 | Cri | 0.64 | 9.8 | 0.00 | Apr 13, 2023 | Memory corruption in modem due to buffer overwrite while building an IPv6 multicast address based on the MAC address of the iface | ||
| CVE-2022-25678 | Cri | 0.64 | 9.8 | 0.00 | Apr 13, 2023 | Memory correction in modem due to buffer overwrite during coap connection | ||
| CVE-2023-28121 | Cri | 0.74 | 9.8 | 0.87 | Apr 12, 2023 | An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the… | ||
| CVE-2023-27830 | Cri | 0.59 | 9.0 | 0.01 | Apr 12, 2023 | TightVNC before v2.8.75 allows attackers to escalate privileges on the host operating system via replacing legitimate files with crafted files when executing a file transfer. This is due to the fact that TightVNC runs in the backend as a high-privileges account. | ||
| CVE-2023-27032 | Cri | 0.64 | 9.8 | 0.03 | Apr 12, 2023 | Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the component AdvancedPopup::getPopups(). |
- risk 0.64cvss 9.8epss 0.02
The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary…
- risk 0.57cvss 9.9epss 0.01
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents including the notification preferences macros can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access…
- risk 0.57cvss 9.9epss 0.01
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents including the legacy notification activity macro can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full…
- risk 0.52cvss 9.0epss 0.01
XWiki Commons are technical libraries common to several other top level XWiki projects. There was no check in the author of a JavaScript xobject or StyleSheet xobject added in a XWiki document, so until now it was possible for a user having only Edit Right to create such object…
- risk 0.64cvss 9.9epss 0.01
XWiki Commons are technical libraries common to several other top level XWiki projects. The HTML macro does not systematically perform a proper neutralization of script-related html tags. As a result, any user able to use the html macro in XWiki, is able to introduce an XSS…
- risk 0.52cvss 9.0epss 0.01
XWiki Commons are technical libraries common to several other top level XWiki projects. The RSS macro that is bundled in XWiki included the content of the feed items without any cleaning in the HTML output when the parameter `content` was set to `true`. This allowed arbitrary…
- risk 0.52cvss 9.0epss 0.01
XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milestone-1, only escaped `` and ``-tags but neither attributes that can be used to inject scripts…
- risk 0.57cvss 9.8epss 0.01
Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20.
- risk 0.57cvss 9.8epss 0.01
Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20.
- risk 0.64cvss 9.8epss 0.01
The ZM Ajax Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.2. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for…
- risk 0.64cvss 9.8epss 0.02
strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes within the same function. There is initially incorrect access control, later followed by an expired pointer dereference. One attack vector is…
- risk 0.00cvss 9.8epss 0.01
x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certificate chain is sometimes discarded.
- risk 0.64cvss 9.8epss 0.01
An issue found in WHOv.1.0.28, v.1.0.30, v.1.0.32 allows an attacker to cause a escalation of privileges via the TTMultiProvider component.
- risk 0.57cvss 9.8epss 0.04
There exists a vulnerability in source code transformer (exception sanitization logic) of vm2 for versions up to 3.9.15, allowing attackers to bypass `handleException()` and leak unsanitized host exceptions which can be used to escape the sandbox and run arbitrary code in host…
- risk 0.64cvss 9.8epss 0.01
Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5.0 through 7.2.0.
- risk 0.64cvss 9.8epss 0.02
WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the pro_stor_canceltrans_handler_part_19 function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the pid parameter in the disconnectVPN function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain multiple command injection vulnerabilities via the rtLogEnabled and rtLogServer parameters in the setSyslogCfg function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg function.
- risk 0.64cvss 9.8epss 0.01
Authentication Bypass by Primary Weakness vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass. This issue affects Redline Router: before 7.17.
- risk 0.64cvss 9.8epss 0.01
Authentication Bypass by Alternate Name vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass. This issue affects Redline Router: before 7.17.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML Users can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/challenge endpoint. The correctness of the TOTP is not checked properly, and…
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskintegration/challenge endpoint. Because only the client-side verifies whether a check was successful, an attacker can modify the response,…
- risk 0.64cvss 9.8epss 0.03
Directory Traversal vulnerability found in T-ME Studios Change Color of Keypad v.1.275.1.277 allows a remote attacker to execute arbitrary code via the dex file in the internal storage.
- risk 0.64cvss 9.8epss 0.01
Improper Authentication vulnerability in B&R Industrial Automation B&R VC4 (VNC-Server modules). This vulnerability may allow an unauthenticated network-based attacker to bypass the authentication mechanism of the VC4 visualization on affected devices. The impact of this…
- risk 0.64cvss 9.8epss 0.01
Timmystudios Fast Typing Keyboard v1.275.1.162 allows unauthorized apps to overwrite arbitrary files in its internal storage via a dictionary traversal vulnerability and achieve arbitrary code execution.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eskom Water Metering Software allows Command Line Execution through SQL Injection. This issue affects Water Metering Software: before 23.04.06.
- risk 0.64cvss 9.8epss 0.02
Purchase Order Management v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /purchase_order/admin/login.php.
- risk 0.67cvss 9.8epss 0.06
Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed as LocalSystem. This occurs because %ProgramFiles%\FileReplicationPro allows Everyone:(F) access.
- risk 0.64cvss 9.8epss 0.01
BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authenticity check for uploaded firmware. This can allow attackers to upload crafted firmware which contains backdoors and enables arbitrary code execution.
- risk 0.64cvss 9.8epss 0.02
BlackVue DR750-2CH LTE v.1.012_2022.10.26 was discovered to contain a weak default passphrase which can be easily cracked via a brute force attack if the WPA2 handshake is intercepted.
- risk 0.64cvss 9.8epss 0.01
Auto Dealer Management System v1.0 was discovered to contain a SQL injection vulnerability.
- risk 0.60cvss 9.3epss 0.00
On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with RPR or SSO, an existing unprivileged user can login to the standby supervisor as a root user, leading to a privilege escalation.…
- risk 0.64cvss 9.8epss 0.01
AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via the user parameter in the login form.
- risk 0.64cvss 9.8epss 0.01
lmxcms v1.4.1 was discovered to contain a SQL injection vulnerability via the setbook parameter at index.php.
- risk 0.59cvss 9.1epss 0.01
bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function.
- risk 0.60cvss 9.3epss 0.00
Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information.
- risk 0.60cvss 9.3epss 0.00
Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment.
- risk 0.64cvss 9.8epss 0.00
Memory corruption due to buffer copy without checking the size of input in modem while decoding raw SMS received.
- risk 0.60cvss 9.3epss 0.00
Memory corruption due to double free in core while initializing the encryption key.
- risk 0.64cvss 9.8epss 0.00
memory corruption in modem due to improper check while calculating size of serialized CoAP message
- risk 0.64cvss 9.8epss 0.00
Memory corruption in modem due to improper input validation while handling the incoming CoAP message
- risk 0.64cvss 9.8epss 0.00
Memory corruption in modem due to buffer overwrite while building an IPv6 multicast address based on the MAC address of the iface
- risk 0.64cvss 9.8epss 0.00
Memory correction in modem due to buffer overwrite during coap connection
- risk 0.74cvss 9.8epss 0.87
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the…
- risk 0.59cvss 9.0epss 0.01
TightVNC before v2.8.75 allows attackers to escalate privileges on the host operating system via replacing legitimate files with crafted files when executing a file transfer. This is due to the fact that TightVNC runs in the backend as a high-privileges account.
- risk 0.64cvss 9.8epss 0.03
Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the component AdvancedPopup::getPopups().