| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-28154 | Cri | 0.57 | 9.8 | 0.01 | Mar 13, 2023 | Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object. | ||
| CVE-2022-48367 | — | Cri | 0.64 | 9.8 | 0.01 | Mar 12, 2023 | An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled. | |
| CVE-2023-27905 | Cri | 0.63 | 9.6 | 0.02 | Mar 10, 2023 | Jenkins update-center2 3.13 and 3.14 renders the required Jenkins core version on plugin download index pages without sanitization, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting. | ||
| CVE-2023-27898 | Cri | 0.56 | 9.6 | 0.02 | Mar 10, 2023 | Jenkins 2.270 through 2.393 (both inclusive), LTS 2.277.1 through 2.375.3 (both inclusive) does not escape the Jenkins version a plugin depends on when rendering the error message stating its incompatibility with the current version of Jenkins, resulting in a stored cross-site… | ||
| CVE-2023-25143 | Cri | 0.64 | 9.8 | 0.02 | Mar 10, 2023 | An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote code execution state on affected products. | ||
| CVE-2023-1198 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saysis Starcities allows SQL Injection. This issue affects Starcities: through 1.3. | ||
| CVE-2022-33257 | Cri | 0.60 | 9.3 | 0.00 | Mar 10, 2023 | Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone. | ||
| CVE-2022-33256 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2023 | Memory corruption due to improper validation of array index in Multi-mode call processor. | ||
| CVE-2023-27853 | Cri | 0.65 | 9.8 | 0.20 | Mar 10, 2023 | NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a format string vulnerability in a SOAP service that could allow an attacker to execute arbitrary code on the device. | ||
| CVE-2023-27852 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2023 | NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a buffer overflow vulnerability in various CGI mechanisms that could allow an attacker to execute arbitrary code on the device. | ||
| CVE-2021-33360 | — | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2023 | An issue found in Stoqey gnuplot v.0.0.3 and earlier allows attackers to execute arbitrary code via the src/index.ts, plotCallack, child_process, and/or filePath parameter(s). | |
| CVE-2023-24774 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php. | ||
| CVE-2023-1091 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alpata Licensed Warehousing Automation System allows Command Line Execution through SQL Injection. This issue affects Licensed Warehousing Automation System: through 2023.1.01. | ||
| CVE-2023-1307 | Cri | 0.57 | 9.8 | 0.01 | Mar 10, 2023 | Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13. | ||
| CVE-2023-27214 | Cri | 0.64 | 9.8 | 0.01 | Mar 9, 2023 | Online Student Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the fromdate and todate parameters at /eduauth/student/between-date-reprtsdetails.php. | ||
| CVE-2023-27213 | Cri | 0.64 | 9.8 | 0.01 | Mar 9, 2023 | Online Student Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /eduauth/student/search.php. | ||
| CVE-2023-27210 | Cri | 0.64 | 9.8 | 0.01 | Mar 9, 2023 | Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/view_order.php. | ||
| CVE-2023-27207 | Cri | 0.64 | 9.8 | 0.01 | Mar 9, 2023 | Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/manage_user.php. | ||
| CVE-2023-27205 | — | Cri | 0.64 | 9.8 | 0.01 | Mar 9, 2023 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php. | |
| CVE-2023-27204 | Cri | 0.64 | 9.8 | 0.01 | Mar 9, 2023 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php. | ||
| CVE-2023-27203 | Cri | 0.64 | 9.8 | 0.01 | Mar 9, 2023 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php. | ||
| CVE-2023-27202 | — | Cri | 0.64 | 9.8 | 0.01 | Mar 9, 2023 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/receipt.php. | |
| CVE-2023-26957 | Cri | 0.59 | 9.1 | 0.01 | Mar 9, 2023 | onekeyadmin v1.3.9 was discovered to contain an arbitrary file delete vulnerability via the component \admin\controller\plugins. | ||
| CVE-2023-1287 | Cri | 0.59 | 9.0 | 0.01 | Mar 9, 2023 | An XSL template vulnerability in ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution. | ||
| CVE-2023-1251 | Cri | 0.64 | 9.8 | 0.01 | Mar 9, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Akinsoft Wolvox. This issue affects Wolvox: before 8.02.03. | ||
| CVE-2023-24777 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list. | ||
| CVE-2023-1283 | Cri | 0.58 | 10.0 | 0.01 | Mar 8, 2023 | Code Injection in GitHub repository builderio/qwik prior to 0.21.0. | ||
| CVE-2021-33353 | Cri | 0.64 | 9.8 | 0.02 | Mar 8, 2023 | Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via the file attachment directory setting. | ||
| CVE-2021-33352 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2023 | An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via a phar file upload in the ticket message field. | ||
| CVE-2021-33351 | Cri | 0.59 | 9.0 | 0.01 | Mar 8, 2023 | Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before and fixed in v.1.3.7 allows attackers to escalte privileges via a crafted payload in the ticket message field. | ||
| CVE-2023-24782 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit. | ||
| CVE-2023-22889 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2023 | SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users. | ||
| CVE-2023-26489 | Cri | 0.57 | 9.9 | 0.01 | Mar 8, 2023 | wasmtime is a fast and secure runtime for WebAssembly. In affected versions wasmtime's code generator, Cranelift, has a bug on x86_64 targets where address-mode computation mistakenly would calculate a 35-bit effective address instead of WebAssembly's defined 33-bit effective… | ||
| CVE-2023-27482 | Cri | 0.71 | 10.0 | 0.70 | Mar 8, 2023 | homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been discovered. This impacts all Home Assistant installation types that use the Supervisor 2023.01.1… | ||
| CVE-2023-26922 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2023 | SQL injection vulnerability found in Varisicte matrix-gui v.2 allows a remote attacker to execute arbitrary code via the shell_exect parameter to the \www\pages\matrix-gui-2.0 endpoint. | ||
| CVE-2023-24773 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list. | ||
| CVE-2023-26261 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2023 | In UBIKA WAAP Gateway/Cloud through 6.10, a blind XPath injection leads to an authentication bypass by stealing the session of another connected user. The fixed versions are WAAP Gateway & Cloud 6.11.0 and 6.5.6-patch15. | ||
| CVE-2023-25395 | Cri | 0.64 | 9.8 | 0.02 | Mar 8, 2023 | TOTOlink A7100RU V7.4cu.2313_B20191024 router was discovered to contain a command injection vulnerability via the ou parameter at /setting/delStaticDhcpRules. | ||
| CVE-2023-1267 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ulkem Company PtteM Kart. This issue affects PtteM Kart: before 2.1. | ||
| CVE-2023-1269 | — | Cri | 0.57 | 9.8 | 0.01 | Mar 8, 2023 | Use of Hard-coded Credentials in GitHub repository alextselegidis/easyappointments prior to 1.5.0. | |
| CVE-2023-0090 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2023 | The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through 'eval injection'. Exploitation requires network access to the webservices API, but such access is a non-standard configuration.… | ||
| CVE-2023-24780 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns. | ||
| CVE-2023-27479 | Cri | 0.57 | 9.9 | 0.01 | Mar 7, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with view rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause… | ||
| CVE-2023-24775 | Cri | 0.65 | 9.8 | 0.20 | Mar 7, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php. | ||
| CVE-2023-25690 | Cri | 0.70 | 9.8 | 0.84 | Mar 7, 2023 | Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pattern matches some… | ||
| CVE-2023-24781 | Cri | 0.64 | 9.8 | 0.01 | Mar 7, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\MemberLevel.php. | ||
| CVE-2022-3760 | Cri | 0.64 | 9.8 | 0.01 | Mar 7, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mia Technology Mia-Med. This issue affects Mia-Med: before 1.0.0.58. | ||
| CVE-2022-45141 | Cri | 0.64 | 9.8 | 0.00 | Mar 6, 2023 | Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting… | ||
| CVE-2023-26949 | — | Cri | 0.64 | 9.8 | 0.01 | Mar 6, 2023 | An arbitrary file upload vulnerability in the component /admin1/config/update of onekeyadmin v1.3.9 allows attackers to execute arbitrary code via a crafted PHP file. | |
| CVE-2023-24736 | Cri | 0.64 | 9.8 | 0.02 | Mar 6, 2023 | PMB v7.4.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /sauvegarde/restaure_act.php. |
- risk 0.57cvss 9.8epss 0.01
Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled.
- risk 0.63cvss 9.6epss 0.02
Jenkins update-center2 3.13 and 3.14 renders the required Jenkins core version on plugin download index pages without sanitization, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting.
- risk 0.56cvss 9.6epss 0.02
Jenkins 2.270 through 2.393 (both inclusive), LTS 2.277.1 through 2.375.3 (both inclusive) does not escape the Jenkins version a plugin depends on when rendering the error message stating its incompatibility with the current version of Jenkins, resulting in a stored cross-site…
- risk 0.64cvss 9.8epss 0.02
An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote code execution state on affected products.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saysis Starcities allows SQL Injection. This issue affects Starcities: through 1.3.
- risk 0.60cvss 9.3epss 0.00
Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.
- risk 0.64cvss 9.8epss 0.01
Memory corruption due to improper validation of array index in Multi-mode call processor.
- risk 0.65cvss 9.8epss 0.20
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a format string vulnerability in a SOAP service that could allow an attacker to execute arbitrary code on the device.
- risk 0.64cvss 9.8epss 0.01
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a buffer overflow vulnerability in various CGI mechanisms that could allow an attacker to execute arbitrary code on the device.
- risk 0.64cvss 9.8epss 0.01
An issue found in Stoqey gnuplot v.0.0.3 and earlier allows attackers to execute arbitrary code via the src/index.ts, plotCallack, child_process, and/or filePath parameter(s).
- risk 0.64cvss 9.8epss 0.01
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alpata Licensed Warehousing Automation System allows Command Line Execution through SQL Injection. This issue affects Licensed Warehousing Automation System: through 2023.1.01.
- risk 0.57cvss 9.8epss 0.01
Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13.
- risk 0.64cvss 9.8epss 0.01
Online Student Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the fromdate and todate parameters at /eduauth/student/between-date-reprtsdetails.php.
- risk 0.64cvss 9.8epss 0.01
Online Student Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /eduauth/student/search.php.
- risk 0.64cvss 9.8epss 0.01
Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/view_order.php.
- risk 0.64cvss 9.8epss 0.01
Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/manage_user.php.
- risk 0.64cvss 9.8epss 0.01
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php.
- risk 0.64cvss 9.8epss 0.01
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php.
- risk 0.64cvss 9.8epss 0.01
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php.
- risk 0.64cvss 9.8epss 0.01
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/receipt.php.
- risk 0.59cvss 9.1epss 0.01
onekeyadmin v1.3.9 was discovered to contain an arbitrary file delete vulnerability via the component \admin\controller\plugins.
- risk 0.59cvss 9.0epss 0.01
An XSL template vulnerability in ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Akinsoft Wolvox. This issue affects Wolvox: before 8.02.03.
- risk 0.64cvss 9.8epss 0.01
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list.
- risk 0.58cvss 10.0epss 0.01
Code Injection in GitHub repository builderio/qwik prior to 0.21.0.
- risk 0.64cvss 9.8epss 0.02
Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via the file attachment directory setting.
- risk 0.64cvss 9.8epss 0.01
An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via a phar file upload in the ticket message field.
- risk 0.59cvss 9.0epss 0.01
Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before and fixed in v.1.3.7 allows attackers to escalte privileges via a crafted payload in the ticket message field.
- risk 0.64cvss 9.8epss 0.01
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit.
- risk 0.64cvss 9.8epss 0.01
SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users.
- risk 0.57cvss 9.9epss 0.01
wasmtime is a fast and secure runtime for WebAssembly. In affected versions wasmtime's code generator, Cranelift, has a bug on x86_64 targets where address-mode computation mistakenly would calculate a 35-bit effective address instead of WebAssembly's defined 33-bit effective…
- risk 0.71cvss 10.0epss 0.70
homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been discovered. This impacts all Home Assistant installation types that use the Supervisor 2023.01.1…
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability found in Varisicte matrix-gui v.2 allows a remote attacker to execute arbitrary code via the shell_exect parameter to the \www\pages\matrix-gui-2.0 endpoint.
- risk 0.64cvss 9.8epss 0.01
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list.
- risk 0.64cvss 9.8epss 0.01
In UBIKA WAAP Gateway/Cloud through 6.10, a blind XPath injection leads to an authentication bypass by stealing the session of another connected user. The fixed versions are WAAP Gateway & Cloud 6.11.0 and 6.5.6-patch15.
- risk 0.64cvss 9.8epss 0.02
TOTOlink A7100RU V7.4cu.2313_B20191024 router was discovered to contain a command injection vulnerability via the ou parameter at /setting/delStaticDhcpRules.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ulkem Company PtteM Kart. This issue affects PtteM Kart: before 2.1.
- risk 0.57cvss 9.8epss 0.01
Use of Hard-coded Credentials in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
- risk 0.64cvss 9.8epss 0.01
The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through 'eval injection'. Exploitation requires network access to the webservices API, but such access is a non-standard configuration.…
- risk 0.64cvss 9.8epss 0.01
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns.
- risk 0.57cvss 9.9epss 0.01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with view rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause…
- risk 0.65cvss 9.8epss 0.20
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php.
- risk 0.70cvss 9.8epss 0.84
Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pattern matches some…
- risk 0.64cvss 9.8epss 0.01
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\MemberLevel.php.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mia Technology Mia-Med. This issue affects Mia-Med: before 1.0.0.58.
- risk 0.64cvss 9.8epss 0.00
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting…
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the component /admin1/config/update of onekeyadmin v1.3.9 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.02
PMB v7.4.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /sauvegarde/restaure_act.php.