| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-24107 | Cri | 0.64 | 9.8 | 0.01 | Feb 22, 2023 | hour_of_code_python_2015 commit 520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code. | ||
| CVE-2023-0947 | Cri | 0.00 | 9.8 | 0.04 | Feb 22, 2023 | Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3. | ||
| CVE-2023-24080 | Cri | 0.64 | 9.8 | 0.01 | Feb 21, 2023 | A lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222.0.32277 (on iOS) allows attackers to compromise user accounts via a bruteforce attack. | ||
| CVE-2023-25157 | Cri | 0.64 | 9.8 | 0.85 | Feb 21, 2023 | GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServer includes support for the OGC Filter expression language and the OGC Common Query Language (CQL) as part of the Web Feature Service (WFS) and Web Map Service… | ||
| CVE-2023-24320 | Cri | 0.64 | 9.8 | 0.01 | Feb 21, 2023 | An access control issue in Axcora POS #0~gitf77ec09 allows unauthenticated attackers to execute arbitrary commands via unspecified vectors. | ||
| CVE-2023-25158 | Cri | 0.57 | 9.8 | 0.01 | Feb 21, 2023 | GeoTools is an open source Java library that provides tools for geospatial data. GeoTools includes support for OGC Filter expression language parsing, encoding and execution against a range of datastore. SQL Injection Vulnerabilities have been found when executing OGC Filters… | ||
| CVE-2022-46637 | Cri | 0.64 | 9.8 | 0.02 | Feb 21, 2023 | Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP services. | ||
| CVE-2023-22920 | Cri | 0.64 | 9.8 | 0.01 | Feb 21, 2023 | A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a factory default misconfiguration intended for testing purposes. A remote attacker could leverage this vulnerability to access an affected device using Telnet. | ||
| CVE-2023-24184 | Cri | 0.64 | 9.8 | 0.01 | Feb 21, 2023 | TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability. | ||
| CVE-2022-45677 | Cri | 0.64 | 9.8 | 0.01 | Feb 21, 2023 | SQL Injection Vulnerability in tanujpatra228 Tution Management System (TMS) via the email parameter to processes/student_login.process.php. | ||
| CVE-2022-45564 | Cri | 0.64 | 9.8 | 0.01 | Feb 21, 2023 | SQL Injection vulnerability in znfit Home improvement ERP management system V50_20220207,v42 allows attackers to execute arbitrary sql commands via the userCode parameter to the wechat applet. | ||
| CVE-2023-0232 | Cri | 0.64 | 9.8 | 0.03 | Feb 21, 2023 | The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection. | ||
| CVE-2023-23453 | Cri | 0.64 | 9.8 | 0.01 | Feb 20, 2023 | Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000. | ||
| CVE-2023-23452 | Cri | 0.64 | 9.8 | 0.01 | Feb 20, 2023 | Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000. | ||
| CVE-2022-48337 | Cri | 0.64 | 9.8 | 0.02 | Feb 20, 2023 | GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the etags program. For example, a victim may use the "etags -u *" command… | ||
| CVE-2022-46836 | Cri | 0.59 | 9.1 | 0.01 | Feb 20, 2023 | PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker to inject and execute PHP code which will be executed upon request of the vulnerable component. | ||
| CVE-2023-25805 | — | Cri | 0.57 | 9.8 | 0.02 | Feb 20, 2023 | versionn, software for changing version information across multiple files, has a command injection vulnerability in all versions prior to version 1.1.0. This issue is patched in version 1.1.0. | |
| CVE-2023-25613 | — | Cri | 0.64 | 9.8 | 0.01 | Feb 20, 2023 | An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3. | |
| CVE-2023-26093 | Cri | 0.00 | 9.8 | 0.01 | Feb 20, 2023 | Liima before 1.17.28 allows Hibernate query language (HQL) injection, related to colToSort in the deployment filter. | ||
| CVE-2023-26092 | Cri | 0.00 | 9.8 | 0.01 | Feb 20, 2023 | Liima before 1.17.28 allows server-side template injection. | ||
| CVE-2022-48329 | Cri | 0.64 | 9.8 | 0.01 | Feb 20, 2023 | MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php. | ||
| CVE-2022-48328 | Cri | 0.64 | 9.8 | 0.01 | Feb 20, 2023 | app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters. | ||
| CVE-2023-23064 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | TOTOLINK A720R V4.1.5cu.532_ B20210610 is vulnerable to Incorrect Access Control. | ||
| CVE-2022-40021 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | QVidium Technologies Amino A140 (prior to firmware version 1.0.0-283) was discovered to contain a command injection vulnerability. | ||
| CVE-2023-23279 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | Canteen Management System 1.0 is vulnerable to SQL Injection via /php_action/getOrderReport.php. | ||
| CVE-2021-35261 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker to execute arbitrary remote code via the Upfile function of the extend/tools/Ueditor endpoint. | ||
| CVE-2021-34182 | — | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | An issue in ttyd v.1.6.3 allows attacker to execute arbitrary code via default configuration permissions. | |
| CVE-2021-33949 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | An issue in FeMiner WMS v1.1 allows attackers to execute arbitrary code via the filename parameter and the exec function. | ||
| CVE-2021-33948 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | SQL injection vulnerability in FantasticLBP Hotels Server v1.0 allows attacker to execute arbitrary code via the username parameter. | ||
| CVE-2021-33391 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c. | ||
| CVE-2021-33226 | Cri | 0.64 | 9.8 | 0.02 | Feb 17, 2023 | Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/modules/status.py file. NOTE: this is disputed by third parties because an attacker cannot influence the eval input | ||
| CVE-2021-32163 | — | Cri | 0.00 | 9.8 | 0.01 | Feb 17, 2023 | Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization. | |
| CVE-2022-47986 | Cri | 0.93 | 9.8 | 1.00 | KEV | Feb 17, 2023 | IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary… | |
| CVE-2020-29168 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | SQL Injection vulnerability in Projectworlds Online Doctor Appointment Booking System, allows attackers to gain sensitive information via the q parameter to the getuser.php endpoint. | ||
| CVE-2022-40032 | Cri | 0.68 | 9.8 | 0.21 | Feb 17, 2023 | SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' parameters, allows attackers to execute arbitrary code and gain sensitive information. | ||
| CVE-2022-40347 | Cri | 0.67 | 9.8 | 0.05 | Feb 17, 2023 | SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name' parameters, allows attackers to execute arbitrary code and gain sensitive information. | ||
| CVE-2023-24221 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/DeptMapper.xml. | ||
| CVE-2023-24220 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/RoleMapper.xml. | ||
| CVE-2023-24219 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/UserMapper.xml. | ||
| CVE-2021-43529 | Cri | 0.64 | 9.8 | 0.00 | Feb 16, 2023 | Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with… | ||
| CVE-2022-39952 | Cri | 0.75 | 9.8 | 1.00 | Feb 16, 2023 | A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or… | ||
| CVE-2022-38375 | Cri | 0.59 | 9.1 | 0.01 | Feb 16, 2023 | An improper authorization vulnerability [CWE-285] in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests. | ||
| CVE-2021-42761 | Cri | 0.59 | 9.0 | 0.01 | Feb 16, 2023 | A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 through 6.0.7, 5.9.0 through 5.9.1 may allow a remote, unauthenticated attacker to… | ||
| CVE-2021-42756 | Cri | 0.67 | 9.8 | 0.35 | Feb 16, 2023 | Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbitrary code… | ||
| CVE-2023-23947 | Cri | 0.52 | 9.1 | 0.01 | Feb 16, 2023 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All Argo CD versions starting with 2.3.0-rc1 and prior to 2.3.17, 2.4.23 2.5.11, and 2.6.2 are vulnerable to an improper authorization bug which allows users who have the ability to update at least one… | ||
| CVE-2023-24238 | Cri | 0.64 | 9.8 | 0.02 | Feb 16, 2023 | TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the city parameter at setting/delStaticDhcpRules. | ||
| CVE-2023-24236 | Cri | 0.64 | 9.8 | 0.02 | Feb 16, 2023 | TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the province parameter at setting/delStaticDhcpRules. | ||
| CVE-2023-22579 | Cri | 0.57 | 9.9 | 0.01 | Feb 16, 2023 | Due to improper parameter filtering in the sequalize js library, can a attacker peform injection. | ||
| CVE-2023-22578 | Cri | 0.58 | 10.0 | 0.01 | Feb 16, 2023 | Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections. | ||
| CVE-2022-3843 | Cri | 0.59 | 9.1 | 0.01 | Feb 16, 2023 | In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote attacker to read system information and configure a limited set of parameters. |
- risk 0.64cvss 9.8epss 0.01
hour_of_code_python_2015 commit 520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code.
- risk 0.00cvss 9.8epss 0.04
Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3.
- risk 0.64cvss 9.8epss 0.01
A lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222.0.32277 (on iOS) allows attackers to compromise user accounts via a bruteforce attack.
- risk 0.64cvss 9.8epss 0.85
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServer includes support for the OGC Filter expression language and the OGC Common Query Language (CQL) as part of the Web Feature Service (WFS) and Web Map Service…
- risk 0.64cvss 9.8epss 0.01
An access control issue in Axcora POS #0~gitf77ec09 allows unauthenticated attackers to execute arbitrary commands via unspecified vectors.
- risk 0.57cvss 9.8epss 0.01
GeoTools is an open source Java library that provides tools for geospatial data. GeoTools includes support for OGC Filter expression language parsing, encoding and execution against a range of datastore. SQL Injection Vulnerabilities have been found when executing OGC Filters…
- risk 0.64cvss 9.8epss 0.02
Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP services.
- risk 0.64cvss 9.8epss 0.01
A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a factory default misconfiguration intended for testing purposes. A remote attacker could leverage this vulnerability to access an affected device using Telnet.
- risk 0.64cvss 9.8epss 0.01
TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability.
- risk 0.64cvss 9.8epss 0.01
SQL Injection Vulnerability in tanujpatra228 Tution Management System (TMS) via the email parameter to processes/student_login.process.php.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in znfit Home improvement ERP management system V50_20220207,v42 allows attackers to execute arbitrary sql commands via the userCode parameter to the wechat applet.
- risk 0.64cvss 9.8epss 0.03
The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection.
- risk 0.64cvss 9.8epss 0.01
Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.
- risk 0.64cvss 9.8epss 0.01
Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.
- risk 0.64cvss 9.8epss 0.02
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the etags program. For example, a victim may use the "etags -u *" command…
- risk 0.59cvss 9.1epss 0.01
PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker to inject and execute PHP code which will be executed upon request of the vulnerable component.
- risk 0.57cvss 9.8epss 0.02
versionn, software for changing version information across multiple files, has a command injection vulnerability in all versions prior to version 1.1.0. This issue is patched in version 1.1.0.
- risk 0.64cvss 9.8epss 0.01
An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3.
- risk 0.00cvss 9.8epss 0.01
Liima before 1.17.28 allows Hibernate query language (HQL) injection, related to colToSort in the deployment filter.
- risk 0.00cvss 9.8epss 0.01
Liima before 1.17.28 allows server-side template injection.
- risk 0.64cvss 9.8epss 0.01
MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.
- risk 0.64cvss 9.8epss 0.01
app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK A720R V4.1.5cu.532_ B20210610 is vulnerable to Incorrect Access Control.
- risk 0.64cvss 9.8epss 0.01
QVidium Technologies Amino A140 (prior to firmware version 1.0.0-283) was discovered to contain a command injection vulnerability.
- risk 0.64cvss 9.8epss 0.01
Canteen Management System 1.0 is vulnerable to SQL Injection via /php_action/getOrderReport.php.
- risk 0.64cvss 9.8epss 0.01
File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker to execute arbitrary remote code via the Upfile function of the extend/tools/Ueditor endpoint.
- risk 0.64cvss 9.8epss 0.01
An issue in ttyd v.1.6.3 allows attacker to execute arbitrary code via default configuration permissions.
- risk 0.64cvss 9.8epss 0.01
An issue in FeMiner WMS v1.1 allows attackers to execute arbitrary code via the filename parameter and the exec function.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in FantasticLBP Hotels Server v1.0 allows attacker to execute arbitrary code via the username parameter.
- risk 0.64cvss 9.8epss 0.01
An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.
- risk 0.64cvss 9.8epss 0.02
Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/modules/status.py file. NOTE: this is disputed by third parties because an attacker cannot influence the eval input
- risk 0.00cvss 9.8epss 0.01
Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization.
- risk 0.93cvss 9.8epss 1.00
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary…
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Projectworlds Online Doctor Appointment Booking System, allows attackers to gain sensitive information via the q parameter to the getuser.php endpoint.
- risk 0.68cvss 9.8epss 0.21
SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' parameters, allows attackers to execute arbitrary code and gain sensitive information.
- risk 0.67cvss 9.8epss 0.05
SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name' parameters, allows attackers to execute arbitrary code and gain sensitive information.
- risk 0.64cvss 9.8epss 0.01
LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/DeptMapper.xml.
- risk 0.64cvss 9.8epss 0.01
LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/RoleMapper.xml.
- risk 0.64cvss 9.8epss 0.01
LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/UserMapper.xml.
- risk 0.64cvss 9.8epss 0.00
Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with…
- risk 0.75cvss 9.8epss 1.00
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or…
- risk 0.59cvss 9.1epss 0.01
An improper authorization vulnerability [CWE-285] in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests.
- risk 0.59cvss 9.0epss 0.01
A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 through 6.0.7, 5.9.0 through 5.9.1 may allow a remote, unauthenticated attacker to…
- risk 0.67cvss 9.8epss 0.35
Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbitrary code…
- risk 0.52cvss 9.1epss 0.01
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All Argo CD versions starting with 2.3.0-rc1 and prior to 2.3.17, 2.4.23 2.5.11, and 2.6.2 are vulnerable to an improper authorization bug which allows users who have the ability to update at least one…
- risk 0.64cvss 9.8epss 0.02
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the city parameter at setting/delStaticDhcpRules.
- risk 0.64cvss 9.8epss 0.02
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the province parameter at setting/delStaticDhcpRules.
- risk 0.57cvss 9.9epss 0.01
Due to improper parameter filtering in the sequalize js library, can a attacker peform injection.
- risk 0.58cvss 10.0epss 0.01
Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections.
- risk 0.59cvss 9.1epss 0.01
In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote attacker to read system information and configure a limited set of parameters.