| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-23513 | Cri | 0.64 | 9.8 | 0.02 | Feb 27, 2023 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7.3, macOS Ventura 13.2, macOS Monterey 12.6.3. Mounting a maliciously crafted Samba network share may lead to arbitrary code execution. | ||
| CVE-2022-46723 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2023 | This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.1, macOS Big Sur 11.7.1. A remote user may be able to write arbitrary files. | ||
| CVE-2022-26760 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2023 | A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 15.5 and iPadOS 15.5. A malicious application may be able to elevate privileges. | ||
| CVE-2023-24253 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2023 | Domotica Labs srl Ikon Server before v2.8.6 was discovered to contain a SQL injection vulnerability. | ||
| CVE-2022-48284 | Cri | 0.64 | 9.8 | 0.00 | Feb 27, 2023 | A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functions. | ||
| CVE-2022-48283 | Cri | 0.64 | 9.8 | 0.00 | Feb 27, 2023 | A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functions. | ||
| CVE-2022-48259 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2023 | There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation could allow attackers to gain higher privileges. | ||
| CVE-2022-48255 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2023 | There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325. A Huawei printer has a system command injection vulnerability. Successful exploitation could lead to remote code execution. | ||
| CVE-2023-25234 | Cri | 0.65 | 9.8 | 0.17 | Feb 27, 2023 | Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInterface. | ||
| CVE-2023-25233 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2023 | Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface. | ||
| CVE-2023-25231 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2023 | Tenda Router W30E V1.0.1.25(633) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface. | ||
| CVE-2023-23156 | Cri | 0.67 | 9.8 | 0.04 | Feb 27, 2023 | Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the single-product page. | ||
| CVE-2023-23155 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2023 | Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the username parameter in the Admin Login. | ||
| CVE-2022-45140 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2023 | The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise. | ||
| CVE-2022-45138 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2023 | The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full… | ||
| CVE-2023-23080 | Cri | 0.64 | 9.8 | 0.02 | Feb 27, 2023 | Certain Tenda products are vulnerable to command injection. This affects Tenda CP7 Tenda CP7<=V11.10.00.2211041403 and Tenda CP3 v.10 Tenda CP3 v.10<=V20220906024_2025 and Tenda IT7-PCS Tenda IT7-PCS<=V2209020914 and Tenda IT7-LCS Tenda IT7-LCS<=V2209020914 and Tenda IT7-PRS… | ||
| CVE-2023-24206 | — | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2023 | Davinci v0.3.0-rc was discovered to contain a SQL injection vulnerability via the copyDisplay function. | |
| CVE-2023-26602 | Cri | 0.68 | 9.8 | 0.17 | Feb 26, 2023 | ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions, as demonstrated by snmpset for NET-SNMP-EXTEND-MIB with /bin/sh for command execution. | ||
| CVE-2021-3329 | Cri | 0.62 | 9.6 | 0.01 | Feb 26, 2023 | Lack of proper validation in HCI Host stack initialization can cause a crash of the bluetooth stack | ||
| CVE-2023-26550 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2023 | A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON field. | ||
| CVE-2022-2024 | Cri | 0.01 | 9.8 | 0.98 | Feb 25, 2023 | OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11. | ||
| CVE-2023-26034 | Cri | 0.63 | 9.6 | 0.02 | Feb 25, 2023 | ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are affected by a SQL Injection vulnerability. The (blind) SQL Injection vulnerability is present within… | ||
| CVE-2023-24189 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2023 | An XML External Entity (XXE) vulnerability in urule v2.1.7 allows attackers to execute arbitrary code via uploading a crafted XML file to /urule/common/saveFile. | ||
| CVE-2021-35370 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2023 | An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function. | ||
| CVE-2021-33387 | Cri | 0.62 | 9.6 | 0.01 | Feb 24, 2023 | Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request. | ||
| CVE-2021-33224 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2023 | File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file. | ||
| CVE-2023-25696 | Cri | 0.57 | 9.8 | 0.02 | Feb 24, 2023 | Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3. | ||
| CVE-2023-25693 | Cri | 0.57 | 9.8 | 0.02 | Feb 24, 2023 | Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop Provider versions before 3.1.1. | ||
| CVE-2023-25691 | Cri | 0.57 | 9.8 | 0.02 | Feb 24, 2023 | Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0. | ||
| CVE-2021-4105 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2023 | Improper Handling of Parameters vulnerability in BG-TEK COSLAT Firewall allows Remote Code Inclusion. This issue affects COSLAT Firewall: from 5.24.0.R.20180630 before 5.24.0.R.20210727. | ||
| CVE-2023-26468 | Cri | 0.00 | 9.1 | 0.01 | Feb 24, 2023 | Cerebrate 1.12 does not properly consider organisation_id during creation of API keys. | ||
| CVE-2023-24212 | Cri | 0.64 | 9.8 | 0.01 | Feb 23, 2023 | Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the timeType function at /goform/SetSysTimeCfg. | ||
| CVE-2023-24205 | Cri | 0.64 | 9.8 | 0.01 | Feb 23, 2023 | Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via overwriting the configuration file (cfw-setting.yaml). | ||
| CVE-2023-0755 | Cri | 0.65 | 9.8 | 0.12 | Feb 23, 2023 | The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code. | ||
| CVE-2023-0754 | Cri | 0.64 | 9.8 | 0.03 | Feb 23, 2023 | The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely execute arbitrary code. | ||
| CVE-2022-36231 | — | Cri | 0.57 | 9.8 | 0.03 | Feb 23, 2023 | pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3. | |
| CVE-2023-26326 | Cri | 0.64 | 9.8 | 0.04 | Feb 23, 2023 | The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issue to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects… | ||
| CVE-2023-23914 | Cri | 0.59 | 9.1 | 0.01 | Feb 23, 2023 | A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP… | ||
| CVE-2023-24104 | Cri | 0.64 | 9.8 | 0.01 | Feb 23, 2023 | Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets. | ||
| CVE-2022-2504 | Cri | 0.64 | 9.8 | 0.01 | Feb 23, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SDD Computer Software SDD-Baro allows SQL Injection. This issue affects SDD-Baro: before 2.8.432. | ||
| CVE-2023-0939 | Cri | 0.64 | 9.8 | 0.01 | Feb 23, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NTN Information Technologies Online Services Software allows SQL Injection. This issue affects Online Services Software: before 1.17. | ||
| CVE-2022-48149 | Cri | 0.64 | 9.8 | 0.01 | Feb 22, 2023 | Online Student Admission System in PHP Free Source Code 1.0 was discovered to contain a SQL injection vulnerability via the username parameter. | ||
| CVE-2022-45599 | Cri | 0.64 | 9.8 | 0.01 | Feb 22, 2023 | Aztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, allows attackers to gain escalated privileges only when specific conditions regarding a given accounts hashed password. | ||
| CVE-2022-39983 | Cri | 0.64 | 9.8 | 0.01 | Feb 22, 2023 | File upload vulnerability in Pro Gamma Instant Developer RD3 22.5 r23, r30, and possibly earlier versions, allows attackers to execute arbitrary code. | ||
| CVE-2023-24114 | Cri | 0.64 | 9.8 | 0.01 | Feb 22, 2023 | typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php. | ||
| CVE-2023-0104 | Cri | 0.62 | 9.3 | 0.22 | Feb 22, 2023 | The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an attacker to gain control of the user’s computer or gain access to sensitive data. | ||
| CVE-2023-24093 | — | Cri | 0.64 | 9.8 | 0.01 | Feb 22, 2023 | An access control issue in H3C A210-G A210-GV100R005 allows attackers to authenticate without a password. | |
| CVE-2023-25813 | Cri | 0.58 | 10.0 | 0.01 | Feb 22, 2023 | Sequelize is a Node.js ORM tool. In versions prior to 6.19.1 a SQL injection exploit exists related to replacements. Parameters which are passed through replacements are not properly escaped which can lead to arbitrary SQL injection depending on the specific queries in use. The… | ||
| CVE-2022-41217 | Cri | 0.64 | 9.8 | 0.01 | Feb 22, 2023 | Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malicious files to the CLOUDFLOW PROOFSCOPE built-in storage. | ||
| CVE-2023-24108 | Cri | 0.64 | 9.8 | 0.01 | Feb 22, 2023 | MvcTools 6d48cd6830fc1df1d8c9d61caa1805fd6a1b7737 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code. |
- risk 0.64cvss 9.8epss 0.02
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7.3, macOS Ventura 13.2, macOS Monterey 12.6.3. Mounting a maliciously crafted Samba network share may lead to arbitrary code execution.
- risk 0.64cvss 9.8epss 0.01
This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.1, macOS Big Sur 11.7.1. A remote user may be able to write arbitrary files.
- risk 0.64cvss 9.8epss 0.01
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 15.5 and iPadOS 15.5. A malicious application may be able to elevate privileges.
- risk 0.64cvss 9.8epss 0.01
Domotica Labs srl Ikon Server before v2.8.6 was discovered to contain a SQL injection vulnerability.
- risk 0.64cvss 9.8epss 0.00
A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functions.
- risk 0.64cvss 9.8epss 0.00
A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functions.
- risk 0.64cvss 9.8epss 0.01
There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation could allow attackers to gain higher privileges.
- risk 0.64cvss 9.8epss 0.01
There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325. A Huawei printer has a system command injection vulnerability. Successful exploitation could lead to remote code execution.
- risk 0.65cvss 9.8epss 0.17
Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInterface.
- risk 0.64cvss 9.8epss 0.01
Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface.
- risk 0.64cvss 9.8epss 0.01
Tenda Router W30E V1.0.1.25(633) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface.
- risk 0.67cvss 9.8epss 0.04
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the single-product page.
- risk 0.64cvss 9.8epss 0.01
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the username parameter in the Admin Login.
- risk 0.64cvss 9.8epss 0.01
The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.
- risk 0.64cvss 9.8epss 0.01
The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full…
- risk 0.64cvss 9.8epss 0.02
Certain Tenda products are vulnerable to command injection. This affects Tenda CP7 Tenda CP7<=V11.10.00.2211041403 and Tenda CP3 v.10 Tenda CP3 v.10<=V20220906024_2025 and Tenda IT7-PCS Tenda IT7-PCS<=V2209020914 and Tenda IT7-LCS Tenda IT7-LCS<=V2209020914 and Tenda IT7-PRS…
- risk 0.64cvss 9.8epss 0.01
Davinci v0.3.0-rc was discovered to contain a SQL injection vulnerability via the copyDisplay function.
- risk 0.68cvss 9.8epss 0.17
ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions, as demonstrated by snmpset for NET-SNMP-EXTEND-MIB with /bin/sh for command execution.
- risk 0.62cvss 9.6epss 0.01
Lack of proper validation in HCI Host stack initialization can cause a crash of the bluetooth stack
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON field.
- risk 0.01cvss 9.8epss 0.98
OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11.
- risk 0.63cvss 9.6epss 0.02
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are affected by a SQL Injection vulnerability. The (blind) SQL Injection vulnerability is present within…
- risk 0.64cvss 9.8epss 0.01
An XML External Entity (XXE) vulnerability in urule v2.1.7 allows attackers to execute arbitrary code via uploading a crafted XML file to /urule/common/saveFile.
- risk 0.64cvss 9.8epss 0.01
An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function.
- risk 0.62cvss 9.6epss 0.01
Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request.
- risk 0.64cvss 9.8epss 0.01
File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file.
- risk 0.57cvss 9.8epss 0.02
Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3.
- risk 0.57cvss 9.8epss 0.02
Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop Provider versions before 3.1.1.
- risk 0.57cvss 9.8epss 0.02
Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0.
- risk 0.64cvss 9.8epss 0.01
Improper Handling of Parameters vulnerability in BG-TEK COSLAT Firewall allows Remote Code Inclusion. This issue affects COSLAT Firewall: from 5.24.0.R.20180630 before 5.24.0.R.20210727.
- risk 0.00cvss 9.1epss 0.01
Cerebrate 1.12 does not properly consider organisation_id during creation of API keys.
- risk 0.64cvss 9.8epss 0.01
Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the timeType function at /goform/SetSysTimeCfg.
- risk 0.64cvss 9.8epss 0.01
Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via overwriting the configuration file (cfw-setting.yaml).
- risk 0.65cvss 9.8epss 0.12
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.
- risk 0.64cvss 9.8epss 0.03
The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely execute arbitrary code.
- risk 0.57cvss 9.8epss 0.03
pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3.
- risk 0.64cvss 9.8epss 0.04
The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issue to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects…
- risk 0.59cvss 9.1epss 0.01
A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP…
- risk 0.64cvss 9.8epss 0.01
Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SDD Computer Software SDD-Baro allows SQL Injection. This issue affects SDD-Baro: before 2.8.432.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NTN Information Technologies Online Services Software allows SQL Injection. This issue affects Online Services Software: before 1.17.
- risk 0.64cvss 9.8epss 0.01
Online Student Admission System in PHP Free Source Code 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
- risk 0.64cvss 9.8epss 0.01
Aztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, allows attackers to gain escalated privileges only when specific conditions regarding a given accounts hashed password.
- risk 0.64cvss 9.8epss 0.01
File upload vulnerability in Pro Gamma Instant Developer RD3 22.5 r23, r30, and possibly earlier versions, allows attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php.
- risk 0.62cvss 9.3epss 0.22
The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an attacker to gain control of the user’s computer or gain access to sensitive data.
- risk 0.64cvss 9.8epss 0.01
An access control issue in H3C A210-G A210-GV100R005 allows attackers to authenticate without a password.
- risk 0.58cvss 10.0epss 0.01
Sequelize is a Node.js ORM tool. In versions prior to 6.19.1 a SQL injection exploit exists related to replacements. Parameters which are passed through replacements are not properly escaped which can lead to arbitrary SQL injection depending on the specific queries in use. The…
- risk 0.64cvss 9.8epss 0.01
Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malicious files to the CLOUDFLOW PROOFSCOPE built-in storage.
- risk 0.64cvss 9.8epss 0.01
MvcTools 6d48cd6830fc1df1d8c9d61caa1805fd6a1b7737 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code.