| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-27034 | Cri | 0.68 | 9.8 | 0.59 | Mar 23, 2023 | PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability. | ||
| CVE-2023-28611 | Cri | 0.64 | 9.8 | 0.01 | Mar 23, 2023 | Incorrect authorization in OMICRON StationGuard 1.10 through 2.20 and StationScout 1.30 through 2.20 allows an attacker to bypass intended access restrictions. | ||
| CVE-2023-28333 | Cri | 0.57 | 9.8 | 0.01 | Mar 23, 2023 | The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS). | ||
| CVE-2023-26359 | Cri | 0.77 | 9.8 | 0.18 | KEV | Mar 23, 2023 | Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require… | |
| CVE-2023-25655 | Cri | 0.57 | 9.8 | 0.01 | Mar 23, 2023 | baserCMS is a Content Management system. Prior to version 4.7.5, any file may be uploaded on the management system of baserCMS. Version 4.7.5 contains a patch. | ||
| CVE-2023-25654 | Cri | 0.57 | 9.8 | 0.02 | Mar 23, 2023 | baserCMS is a Content Management system. Prior to version 4.7.5, there is a Remote Code Execution (RCE) Vulnerability in the management system of baserCMS. Version 4.7.5 contains a patch. | ||
| CVE-2022-36413 | Cri | 0.59 | 9.1 | 0.03 | Mar 23, 2023 | Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications. | ||
| CVE-2022-28496 | Cri | 0.64 | 9.8 | 0.01 | Mar 23, 2023 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 discovered to contain a command injection vulnerability in the setPasswordCfg function via the adminuser and adminpassparameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | ||
| CVE-2023-28610 | Cri | 0.64 | 9.8 | 0.01 | Mar 23, 2023 | The update process in OMICRON StationGuard and OMICRON StationScout before 2.21 can be exploited by providing a modified firmware update image. This allows a remote attacker to gain root access to the system. | ||
| CVE-2022-28497 | Cri | 0.64 | 9.8 | 0.01 | Mar 23, 2023 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the mtd_write_bootloader function via the filename parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | ||
| CVE-2023-27135 | Cri | 0.64 | 9.8 | 0.02 | Mar 23, 2023 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the enabled parameter at /setting/setWanIeCfg. | ||
| CVE-2023-27078 | Cri | 0.64 | 9.8 | 0.02 | Mar 23, 2023 | A command injection issue was found in TP-Link MR3020 v.1_150921 that allows a remote attacker to execute arbitrary commands via a crafted request to the tftp endpoint. | ||
| CVE-2022-28493 | Cri | 0.64 | 9.8 | 0.01 | Mar 23, 2023 | A vulnerability in TOTOLINK CP900 V6.3c.566 allows attackers to start the Telnet service, | ||
| CVE-2022-28491 | Cri | 0.64 | 9.8 | 0.05 | Mar 23, 2023 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 contains a command injection vulnerability in the NTPSyncWithHost function via the host_name parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | ||
| CVE-2022-28492 | Cri | 0.64 | 9.8 | 0.01 | Mar 23, 2023 | TOTOLINK Technology CPE with firmware V6.3c.566 ,allows remote attackers to bypass Login. | ||
| CVE-2023-1050 | Cri | 0.64 | 9.8 | 0.01 | Mar 23, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in As Koc Energy Web Report System allows SQL Injection. This issue affects Web Report System: before 23.03.10. | ||
| CVE-2022-22512 | Cri | 0.64 | 9.8 | 0.01 | Mar 23, 2023 | Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network. | ||
| CVE-2023-24655 | Cri | 0.64 | 9.8 | 0.01 | Mar 23, 2023 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Profile Update function. | ||
| CVE-2022-28494 | Cri | 0.64 | 9.8 | 0.03 | Mar 23, 2023 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setUpgradeFW function via the filename parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | ||
| CVE-2023-27100 | Cri | 0.67 | 9.8 | 0.10 | Mar 22, 2023 | Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests. | ||
| CVE-2023-27060 | Cri | 0.64 | 9.8 | 0.01 | Mar 22, 2023 | LightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function. | ||
| CVE-2023-28667 | Cri | 0.64 | 9.8 | 0.01 | Mar 22, 2023 | The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue. The tve_labels parameter of the tve_api_form_submit action is passed to the PHP unserialize() function without being sanitized or verified, and as a result… | ||
| CVE-2023-28662 | Cri | 0.67 | 9.8 | 0.42 | Mar 22, 2023 | The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgv_doajax_voucher_pdf_save_func action. | ||
| CVE-2023-27224 | Cri | 0.64 | 9.8 | 0.01 | Mar 22, 2023 | An issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the configuration file. | ||
| CVE-2023-27638 | Cri | 0.64 | 9.8 | 0.03 | Mar 22, 2023 | An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised tshirtecommerce_design_cart_id GET parameter in order to exploit an insecure parameter in the functions… | ||
| CVE-2023-27637 | — | Cri | 0.64 | 9.8 | 0.03 | Mar 22, 2023 | An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to exploit an insecure parameter in the front controller file designer.php, which could… | |
| CVE-2023-25589 | Cri | 0.64 | 9.8 | 0.01 | Mar 22, 2023 | A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to create arbitrary users on the platform. A successful exploit allows an attacker to achieve total cluster compromise. | ||
| CVE-2023-28725 | Cri | 0.61 | 9.1 | 0.21 | Mar 22, 2023 | General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary Java code by uploading a Java application to the /batm/app/admin/standalone/deployments directory, aka BATM-4780, as exploited in… | ||
| CVE-2023-27855 | Cri | 0.68 | 9.8 | 0.13 | Mar 22, 2023 | In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrary files to any directory on the disk drive where… | ||
| CVE-2023-1529 | Cri | 0.64 | 9.8 | 0.01 | Mar 21, 2023 | Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a malicious HID device. (Chromium security severity: High) | ||
| CVE-2022-37337 | Cri | 0.59 | 9.1 | 0.03 | Mar 21, 2023 | A command execution vulnerability exists in the access control functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. | ||
| CVE-2023-27570 | Cri | 0.64 | 9.8 | 0.01 | Mar 21, 2023 | The eo_tags package before 1.4.19 for PrestaShop allows SQL injection via a crafted _ga cookie. | ||
| CVE-2023-27569 | Cri | 0.64 | 9.8 | 0.01 | Mar 21, 2023 | The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header. | ||
| CVE-2022-45637 | Cri | 0.64 | 9.8 | 0.01 | Mar 21, 2023 | An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via insecure expiry mechanism. | ||
| CVE-2023-27874 | Cri | 0.64 | 9.9 | 0.01 | Mar 21, 2023 | IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. IBM X-Force ID: 249845. | ||
| CVE-2023-1153 | Cri | 0.64 | 9.8 | 0.01 | Mar 21, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pacsrapor allows SQL Injection, Command Line Execution through SQL Injection. This issue affects Pacsrapor: before 1.22. | ||
| CVE-2023-1537 | — | Cri | 0.57 | 9.8 | 0.01 | Mar 21, 2023 | Authentication Bypass by Capture-replay in GitHub repository answerdev/answer prior to 1.0.6. | |
| CVE-2023-27578 | Cri | 0.59 | 9.1 | 0.01 | Mar 20, 2023 | Galaxy is an open-source platform for data analysis. All supported versions of Galaxy are affected prior to 22.01, 22.05, and 23.0 are affected by an insufficient permission check. Unsupported versions are likely affected as far back as the functionality of Visualizations/Pages… | ||
| CVE-2023-27586 | Cri | 0.57 | 9.9 | 0.01 | Mar 20, 2023 | CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to external hosts when processing SVG files. A malicious actor could send a specially crafted SVG file that allows them to perform a server-side request forgery or… | ||
| CVE-2023-28424 | Cri | 0.00 | 9.1 | 0.01 | Mar 20, 2023 | Soko if the code that powers packages.gentoo.org. Prior to version 1.0.2, the two package search handlers, `Search` and `SearchFeed`, implemented in `pkg/app/handler/packages/search.go`, are affected by a SQL injection via the `q` parameter. As a result, unauthenticated… | ||
| CVE-2023-26905 | Cri | 0.64 | 9.8 | 0.01 | Mar 19, 2023 | An issue was discovered in Alphaware - Simple E-Commerce System v1.0. There is a SQL injection that can directly issue instructions to the background database system via /alphaware/details.php?id. | ||
| CVE-2023-26806 | Cri | 0.64 | 9.8 | 0.01 | Mar 19, 2023 | Tenda W20E v15.11.0.6(US_W20EV4.0br_v15.11.0.6(1068_1546_841 is vulnerable to Buffer Overflow via function formSetSysTime, | ||
| CVE-2023-26805 | Cri | 0.64 | 9.8 | 0.01 | Mar 19, 2023 | Tenda W20E v15.11.0.6 (US_W20EV4.0br_v15.11.0.6(1068_1546_841)_CN_TDC) is vulnerable to Buffer Overflow via function formIPMacBindModify. | ||
| CVE-2023-28609 | — | Cri | 0.57 | 9.8 | 0.01 | Mar 18, 2023 | api/auth.go in Ansible Semaphore before 2.8.89 mishandles authentication. | |
| CVE-2023-28115 | Cri | 0.57 | 9.8 | 0.03 | Mar 17, 2023 | Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.4.2, Snappy is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the `file_exists()` function. If an attacker… | ||
| CVE-2023-1152 | Cri | 0.64 | 9.8 | 0.01 | Mar 17, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information Technologies Persolus allows SQL Injection. This issue affects Persolus: before 2.03.93. | ||
| CVE-2023-28531 | Cri | 0.64 | 9.8 | 0.02 | Mar 17, 2023 | ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9. | ||
| CVE-2023-21456 | Cri | 0.59 | 9.0 | 0.00 | Mar 16, 2023 | Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid. | ||
| CVE-2022-43605 | Cri | 0.66 | 10.0 | 0.14 | Mar 16, 2023 | An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out of bounds write, potentially causing the server to crash or… | ||
| CVE-2022-43604 | Cri | 0.66 | 10.0 | 0.14 | Mar 16, 2023 | An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out-of-bounds write, potentially causing the server to crash or… |
- risk 0.68cvss 9.8epss 0.59
PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability.
- risk 0.64cvss 9.8epss 0.01
Incorrect authorization in OMICRON StationGuard 1.10 through 2.20 and StationScout 1.30 through 2.20 allows an attacker to bypass intended access restrictions.
- risk 0.57cvss 9.8epss 0.01
The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS).
- risk 0.77cvss 9.8epss 0.18
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require…
- risk 0.57cvss 9.8epss 0.01
baserCMS is a Content Management system. Prior to version 4.7.5, any file may be uploaded on the management system of baserCMS. Version 4.7.5 contains a patch.
- risk 0.57cvss 9.8epss 0.02
baserCMS is a Content Management system. Prior to version 4.7.5, there is a Remote Code Execution (RCE) Vulnerability in the management system of baserCMS. Version 4.7.5 contains a patch.
- risk 0.59cvss 9.1epss 0.03
Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications.
- risk 0.64cvss 9.8epss 0.01
TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 discovered to contain a command injection vulnerability in the setPasswordCfg function via the adminuser and adminpassparameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
- risk 0.64cvss 9.8epss 0.01
The update process in OMICRON StationGuard and OMICRON StationScout before 2.21 can be exploited by providing a modified firmware update image. This allows a remote attacker to gain root access to the system.
- risk 0.64cvss 9.8epss 0.01
TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the mtd_write_bootloader function via the filename parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
- risk 0.64cvss 9.8epss 0.02
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the enabled parameter at /setting/setWanIeCfg.
- risk 0.64cvss 9.8epss 0.02
A command injection issue was found in TP-Link MR3020 v.1_150921 that allows a remote attacker to execute arbitrary commands via a crafted request to the tftp endpoint.
- risk 0.64cvss 9.8epss 0.01
A vulnerability in TOTOLINK CP900 V6.3c.566 allows attackers to start the Telnet service,
- risk 0.64cvss 9.8epss 0.05
TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 contains a command injection vulnerability in the NTPSyncWithHost function via the host_name parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK Technology CPE with firmware V6.3c.566 ,allows remote attackers to bypass Login.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in As Koc Energy Web Report System allows SQL Injection. This issue affects Web Report System: before 23.03.10.
- risk 0.64cvss 9.8epss 0.01
Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network.
- risk 0.64cvss 9.8epss 0.01
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Profile Update function.
- risk 0.64cvss 9.8epss 0.03
TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setUpgradeFW function via the filename parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
- risk 0.67cvss 9.8epss 0.10
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.
- risk 0.64cvss 9.8epss 0.01
LightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function.
- risk 0.64cvss 9.8epss 0.01
The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue. The tve_labels parameter of the tve_api_form_submit action is passed to the PHP unserialize() function without being sanitized or verified, and as a result…
- risk 0.67cvss 9.8epss 0.42
The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgv_doajax_voucher_pdf_save_func action.
- risk 0.64cvss 9.8epss 0.01
An issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the configuration file.
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised tshirtecommerce_design_cart_id GET parameter in order to exploit an insecure parameter in the functions…
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to exploit an insecure parameter in the front controller file designer.php, which could…
- risk 0.64cvss 9.8epss 0.01
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to create arbitrary users on the platform. A successful exploit allows an attacker to achieve total cluster compromise.
- risk 0.61cvss 9.1epss 0.21
General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary Java code by uploading a Java application to the /batm/app/admin/standalone/deployments directory, aka BATM-4780, as exploited in…
- risk 0.68cvss 9.8epss 0.13
In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrary files to any directory on the disk drive where…
- risk 0.64cvss 9.8epss 0.01
Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a malicious HID device. (Chromium security severity: High)
- risk 0.59cvss 9.1epss 0.03
A command execution vulnerability exists in the access control functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
- risk 0.64cvss 9.8epss 0.01
The eo_tags package before 1.4.19 for PrestaShop allows SQL injection via a crafted _ga cookie.
- risk 0.64cvss 9.8epss 0.01
The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header.
- risk 0.64cvss 9.8epss 0.01
An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via insecure expiry mechanism.
- risk 0.64cvss 9.9epss 0.01
IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. IBM X-Force ID: 249845.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pacsrapor allows SQL Injection, Command Line Execution through SQL Injection. This issue affects Pacsrapor: before 1.22.
- risk 0.57cvss 9.8epss 0.01
Authentication Bypass by Capture-replay in GitHub repository answerdev/answer prior to 1.0.6.
- risk 0.59cvss 9.1epss 0.01
Galaxy is an open-source platform for data analysis. All supported versions of Galaxy are affected prior to 22.01, 22.05, and 23.0 are affected by an insufficient permission check. Unsupported versions are likely affected as far back as the functionality of Visualizations/Pages…
- risk 0.57cvss 9.9epss 0.01
CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to external hosts when processing SVG files. A malicious actor could send a specially crafted SVG file that allows them to perform a server-side request forgery or…
- risk 0.00cvss 9.1epss 0.01
Soko if the code that powers packages.gentoo.org. Prior to version 1.0.2, the two package search handlers, `Search` and `SearchFeed`, implemented in `pkg/app/handler/packages/search.go`, are affected by a SQL injection via the `q` parameter. As a result, unauthenticated…
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Alphaware - Simple E-Commerce System v1.0. There is a SQL injection that can directly issue instructions to the background database system via /alphaware/details.php?id.
- risk 0.64cvss 9.8epss 0.01
Tenda W20E v15.11.0.6(US_W20EV4.0br_v15.11.0.6(1068_1546_841 is vulnerable to Buffer Overflow via function formSetSysTime,
- risk 0.64cvss 9.8epss 0.01
Tenda W20E v15.11.0.6 (US_W20EV4.0br_v15.11.0.6(1068_1546_841)_CN_TDC) is vulnerable to Buffer Overflow via function formIPMacBindModify.
- risk 0.57cvss 9.8epss 0.01
api/auth.go in Ansible Semaphore before 2.8.89 mishandles authentication.
- risk 0.57cvss 9.8epss 0.03
Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.4.2, Snappy is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the `file_exists()` function. If an attacker…
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information Technologies Persolus allows SQL Injection. This issue affects Persolus: before 2.03.93.
- risk 0.64cvss 9.8epss 0.02
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
- risk 0.59cvss 9.0epss 0.00
Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid.
- risk 0.66cvss 10.0epss 0.14
An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out of bounds write, potentially causing the server to crash or…
- risk 0.66cvss 10.0epss 0.14
An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out-of-bounds write, potentially causing the server to crash or…