| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-27172 | Cri | 0.66 | 9.8 | 0.27 | Jun 14, 2024 | Remote Command program allows an attacker to get Remote Code Execution. As for the affected products/models/versions, see the reference URL. | ||
| CVE-2024-3080 | Cri | 0.67 | 9.8 | 0.43 | Jun 14, 2024 | Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device. | ||
| CVE-2024-27145 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2024 | The Toshiba printers provide several ways to upload files using the admin web interface. An attacker can remotely compromise any Toshiba printer. An attacker can overwrite any insecure files. This vulnerability can be executed in combination with other vulnerabilities and … | ||
| CVE-2024-27144 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2024 | The Toshiba printers provide several ways to upload files using the web interface without authentication. An attacker can overwrite any insecure files. And the Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any… | ||
| CVE-2024-27143 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2024 | Toshiba printers use SNMP for configuration. Using the private community, it is possible to remotely execute commands as root on the remote printer. Using this vulnerability will allow any attacker to get a root access on a remote Toshiba printer. This vulnerability can be… | ||
| CVE-2024-31777 | Cri | 0.67 | 9.8 | 0.04 | Jun 13, 2024 | File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.php endpoint. | ||
| CVE-2024-0095 | Cri | 0.59 | 9.0 | 0.01 | Jun 13, 2024 | NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where a user can inject forged logs and executable commands by injecting arbitrary data as a new log entry. A successful exploit of this vulnerability might lead to code execution, denial of service,… | ||
| CVE-2024-32913 | Cri | 0.64 | 9.8 | 0.00 | Jun 13, 2024 | In wl_notify_rx_mgmt_frame of wl_cfg80211.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2024-32911 | Cri | 0.64 | 9.8 | 0.00 | Jun 13, 2024 | There is a possible escalation of privilege due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2024-32905 | Cri | 0.64 | 9.8 | 0.00 | Jun 13, 2024 | In circ_read of link_device_memory_legacy.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2024-29786 | Cri | 0.64 | 9.8 | 0.00 | Jun 13, 2024 | In pktproc_fill_data_addr_without_bm of link_rx_pktproc.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2024-37635 | Cri | 0.64 | 9.8 | 0.01 | Jun 13, 2024 | TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfg | ||
| CVE-2024-37634 | Cri | 0.64 | 9.8 | 0.01 | Jun 13, 2024 | TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiEasyCfg. | ||
| CVE-2024-37632 | Cri | 0.64 | 9.8 | 0.01 | Jun 13, 2024 | TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the password parameter in function loginAuth . | ||
| CVE-2024-38281 | Cri | 0.64 | 9.8 | 0.00 | Jun 13, 2024 | An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device. | ||
| CVE-2024-22441 | Cri | 0.64 | 9.8 | 0.00 | Jun 13, 2024 | HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass. | ||
| CVE-2024-37849 | Cri | 0.64 | 9.8 | 0.01 | Jun 13, 2024 | A SQL Injection vulnerability in itsourcecode Billing System 1.0 allows a local attacker to execute arbitrary code in process.php via the username parameter. | ||
| CVE-2024-30300 | Cri | 0.64 | 9.8 | 0.01 | Jun 13, 2024 | Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Information Exposure vulnerability (CWE-200) that could lead to privilege escalation. An attacker could exploit this vulnerability to gain access to sensitive information which may include… | ||
| CVE-2024-30299 | Cri | 0.65 | 10.0 | 0.01 | Jun 13, 2024 | Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized access or elevated privileges within the… | ||
| CVE-2024-4371 | Cri | 0.59 | 9.0 | 0.01 | Jun 13, 2024 | The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.1 via deserialization of untrusted input from the recently_viewed_products… | ||
| CVE-2024-34108 | Cri | 0.59 | 9.1 | 0.01 | Jun 13, 2024 | Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, but… | ||
| CVE-2024-34102 | Cri | 0.80 | 9.8 | 1.00 | KEV | Jun 13, 2024 | Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted… | |
| CVE-2024-3552 | Cri | 0.69 | 9.8 | 0.67 | Jun 13, 2024 | The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection with different techniques like UNION, Time-Based and Error-Based. | ||
| CVE-2024-38295 | Cri | 0.64 | 9.8 | 0.01 | Jun 13, 2024 | ALCASAR before 3.6.1 allows still_connected.php remote code execution. | ||
| CVE-2024-38294 | Cri | 0.64 | 9.8 | 0.01 | Jun 13, 2024 | ALCASAR before 3.6.1 allows email_registration_back.php remote code execution. | ||
| CVE-2024-38293 | Cri | 0.62 | 9.6 | 0.00 | Jun 13, 2024 | ALCASAR before 3.6.1 allows CSRF and remote code execution in activity.php. | ||
| CVE-2024-3922 | Cri | 0.62 | 10.0 | 0.53 | Jun 13, 2024 | The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and including, 3.10.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | ||
| CVE-2024-37036 | Cri | 0.64 | 9.8 | 0.01 | Jun 12, 2024 | CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed POST request and particular configuration parameters are set. | ||
| CVE-2024-36761 | Cri | 0.64 | 9.8 | 0.01 | Jun 12, 2024 | naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs. | ||
| CVE-2024-36840 | Cri | 0.59 | 9.1 | 0.02 | Jun 12, 2024 | SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code and obtain sensitive information via the id parameter to news_details.php and location_details.php; and the section parameter to services.php. | ||
| CVE-2024-36265 | Cri | 0.64 | 9.8 | 0.01 | Jun 12, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: from 0.8.0. An attacker can bypass authentication by sending specially crafted REST requests. As this project is retired, we… | ||
| CVE-2024-36264 | Cri | 0.57 | 9.8 | 0.01 | Jun 12, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submarine.auth.default.secret`, a default value will be used. This issue affects Apache Submarine Commons Utils: from 0.8.0. As this… | ||
| CVE-2024-1659 | Cri | 0.64 | 9.8 | 0.01 | Jun 12, 2024 | Arbitrary File Upload vulnerability in MegaBIP software allows attacker to upload any file to the server (including a PHP code file) without an authentication. This issue affects MegaBIP software versions through 5.10. | ||
| CVE-2024-1577 | Cri | 0.64 | 9.8 | 0.01 | Jun 12, 2024 | Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring authentication by saving crafted by the attacker PHP code to one of the website files. This issue affects MegaBIP software versions through 5.11.2. | ||
| CVE-2024-1576 | Cri | 0.64 | 9.8 | 0.01 | Jun 12, 2024 | SQL Injection vulnerability in MegaBIP software allows attacker to obtain site administrator privileges, including access to the administration panel and the ability to change the administrator password. This issue affects MegaBIP software versions through 5.09. | ||
| CVE-2024-4898 | Cri | 0.64 | 9.8 | 0.04 | Jun 12, 2024 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization checks on the REST API calls in all versions up to, and including, 0.1.0.38. This makes it possible for unauthenticated attackers… | ||
| CVE-2024-4315 | Cri | 0.52 | 9.1 | 0.01 | Jun 12, 2024 | parisneo/lollms version 9.5 is vulnerable to Local File Inclusion (LFI) attacks due to insufficient path sanitization. The `sanitize_path_from_endpoint` function fails to properly sanitize Windows-style paths (backward slash `\`), allowing attackers to perform directory… | ||
| CVE-2024-35225 | Cri | 0.55 | 9.6 | 0.00 | Jun 11, 2024 | Jupyter Server Proxy allows users to run arbitrary external processes alongside their notebook server and provide authenticated web access to them. Versions of 3.x prior to 3.2.4 and 4.x prior to 4.2.0 have a reflected cross-site scripting (XSS) issue. The `/proxy` endpoint… | ||
| CVE-2024-35213 | Cri | 0.59 | 9.0 | 0.01 | Jun 11, 2024 | An improper input validation vulnerability in the SGI Image Codec of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially cause a denial-of-service condition or execute code in the context of the image processing process. | ||
| CVE-2024-34405 | Cri | 0.59 | 9.1 | 0.00 | Jun 11, 2024 | Improper deep link validation in McAfee Security: Antivirus VPN for Android before 8.3.0 could allow an attacker to launch an arbitrary URL within the app. | ||
| CVE-2024-30080 | Cri | 0.67 | 9.8 | 0.43 | Jun 11, 2024 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||
| CVE-2024-2013 | Cri | 0.65 | 10.0 | 0.01 | Jun 11, 2024 | An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited allows attackers without any access to interact with the services and the post-authentication attack surface. | ||
| CVE-2024-2012 | Cri | 0.59 | 9.1 | 0.01 | Jun 11, 2024 | vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or code to be executed on the UNEM server allowing sensitive data to be read or modified or could cause other unintended behavior | ||
| CVE-2024-5701 | Cri | 0.64 | 9.8 | 0.01 | Jun 11, 2024 | Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127. | ||
| CVE-2024-5699 | Cri | 0.64 | 9.8 | 0.01 | Jun 11, 2024 | In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be checked with a case-insensitive comparison. This could have resulted in the browser not correctly honoring the behaviors specified by the… | ||
| CVE-2024-5695 | Cri | 0.64 | 9.8 | 0.01 | Jun 11, 2024 | If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer situations, memory corruption could have occurred. This vulnerability affects Firefox < 127. | ||
| CVE-2024-36266 | Cri | 0.60 | 9.3 | 0.00 | Jun 11, 2024 | A vulnerability has been identified in PowerSys (All versions < V3.11). The affected application insufficiently protects responses to authentication requests. This could allow a local attacker to bypass authentication, thereby gaining administrative privileges for the managed… | ||
| CVE-2024-3549 | Cri | 0.57 | 9.9 | 0.01 | Jun 11, 2024 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSortPostType' parameter in all versions up to, and including, 7.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation… | ||
| CVE-2024-36360 | Cri | 0.64 | 9.8 | 0.02 | Jun 11, 2024 | OS command injection vulnerability exists in awkblog v0.0.1 (commit hash:7b761b192d0e0dc3eef0f30630e00ece01c8d552) and earlier. If a remote unauthenticated attacker sends a specially crafted HTTP request, an arbitrary OS command may be executed with the privileges of the… | ||
| CVE-2024-31401 | Cri | 0.59 | 9.0 | 0.01 | Jun 11, 2024 | Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script on the web browser of the user who is logging in to the product. |
- risk 0.66cvss 9.8epss 0.27
Remote Command program allows an attacker to get Remote Code Execution. As for the affected products/models/versions, see the reference URL.
- risk 0.67cvss 9.8epss 0.43
Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.
- risk 0.64cvss 9.8epss 0.01
The Toshiba printers provide several ways to upload files using the admin web interface. An attacker can remotely compromise any Toshiba printer. An attacker can overwrite any insecure files. This vulnerability can be executed in combination with other vulnerabilities and …
- risk 0.64cvss 9.8epss 0.01
The Toshiba printers provide several ways to upload files using the web interface without authentication. An attacker can overwrite any insecure files. And the Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any…
- risk 0.64cvss 9.8epss 0.01
Toshiba printers use SNMP for configuration. Using the private community, it is possible to remotely execute commands as root on the remote printer. Using this vulnerability will allow any attacker to get a root access on a remote Toshiba printer. This vulnerability can be…
- risk 0.67cvss 9.8epss 0.04
File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.php endpoint.
- risk 0.59cvss 9.0epss 0.01
NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where a user can inject forged logs and executable commands by injecting arbitrary data as a new log entry. A successful exploit of this vulnerability might lead to code execution, denial of service,…
- risk 0.64cvss 9.8epss 0.00
In wl_notify_rx_mgmt_frame of wl_cfg80211.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.64cvss 9.8epss 0.00
There is a possible escalation of privilege due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.64cvss 9.8epss 0.00
In circ_read of link_device_memory_legacy.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.64cvss 9.8epss 0.00
In pktproc_fill_data_addr_without_bm of link_rx_pktproc.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfg
- risk 0.64cvss 9.8epss 0.01
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiEasyCfg.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the password parameter in function loginAuth .
- risk 0.64cvss 9.8epss 0.00
An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.
- risk 0.64cvss 9.8epss 0.00
HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.
- risk 0.64cvss 9.8epss 0.01
A SQL Injection vulnerability in itsourcecode Billing System 1.0 allows a local attacker to execute arbitrary code in process.php via the username parameter.
- risk 0.64cvss 9.8epss 0.01
Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Information Exposure vulnerability (CWE-200) that could lead to privilege escalation. An attacker could exploit this vulnerability to gain access to sensitive information which may include…
- risk 0.65cvss 10.0epss 0.01
Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized access or elevated privileges within the…
- risk 0.59cvss 9.0epss 0.01
The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.1 via deserialization of untrusted input from the recently_viewed_products…
- risk 0.59cvss 9.1epss 0.01
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, but…
- risk 0.80cvss 9.8epss 1.00
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted…
- risk 0.69cvss 9.8epss 0.67
The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection with different techniques like UNION, Time-Based and Error-Based.
- risk 0.64cvss 9.8epss 0.01
ALCASAR before 3.6.1 allows still_connected.php remote code execution.
- risk 0.64cvss 9.8epss 0.01
ALCASAR before 3.6.1 allows email_registration_back.php remote code execution.
- risk 0.62cvss 9.6epss 0.00
ALCASAR before 3.6.1 allows CSRF and remote code execution in activity.php.
- risk 0.62cvss 10.0epss 0.53
The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and including, 3.10.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…
- risk 0.64cvss 9.8epss 0.01
CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed POST request and particular configuration parameters are set.
- risk 0.64cvss 9.8epss 0.01
naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs.
- risk 0.59cvss 9.1epss 0.02
SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code and obtain sensitive information via the id parameter to news_details.php and location_details.php; and the section parameter to services.php.
- risk 0.64cvss 9.8epss 0.01
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: from 0.8.0. An attacker can bypass authentication by sending specially crafted REST requests. As this project is retired, we…
- risk 0.57cvss 9.8epss 0.01
** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submarine.auth.default.secret`, a default value will be used. This issue affects Apache Submarine Commons Utils: from 0.8.0. As this…
- risk 0.64cvss 9.8epss 0.01
Arbitrary File Upload vulnerability in MegaBIP software allows attacker to upload any file to the server (including a PHP code file) without an authentication. This issue affects MegaBIP software versions through 5.10.
- risk 0.64cvss 9.8epss 0.01
Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring authentication by saving crafted by the attacker PHP code to one of the website files. This issue affects MegaBIP software versions through 5.11.2.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in MegaBIP software allows attacker to obtain site administrator privileges, including access to the administration panel and the ability to change the administrator password. This issue affects MegaBIP software versions through 5.09.
- risk 0.64cvss 9.8epss 0.04
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization checks on the REST API calls in all versions up to, and including, 0.1.0.38. This makes it possible for unauthenticated attackers…
- risk 0.52cvss 9.1epss 0.01
parisneo/lollms version 9.5 is vulnerable to Local File Inclusion (LFI) attacks due to insufficient path sanitization. The `sanitize_path_from_endpoint` function fails to properly sanitize Windows-style paths (backward slash `\`), allowing attackers to perform directory…
- risk 0.55cvss 9.6epss 0.00
Jupyter Server Proxy allows users to run arbitrary external processes alongside their notebook server and provide authenticated web access to them. Versions of 3.x prior to 3.2.4 and 4.x prior to 4.2.0 have a reflected cross-site scripting (XSS) issue. The `/proxy` endpoint…
- risk 0.59cvss 9.0epss 0.01
An improper input validation vulnerability in the SGI Image Codec of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially cause a denial-of-service condition or execute code in the context of the image processing process.
- risk 0.59cvss 9.1epss 0.00
Improper deep link validation in McAfee Security: Antivirus VPN for Android before 8.3.0 could allow an attacker to launch an arbitrary URL within the app.
- risk 0.67cvss 9.8epss 0.43
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- risk 0.65cvss 10.0epss 0.01
An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited allows attackers without any access to interact with the services and the post-authentication attack surface.
- risk 0.59cvss 9.1epss 0.01
vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or code to be executed on the UNEM server allowing sensitive data to be read or modified or could cause other unintended behavior
- risk 0.64cvss 9.8epss 0.01
Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127.
- risk 0.64cvss 9.8epss 0.01
In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be checked with a case-insensitive comparison. This could have resulted in the browser not correctly honoring the behaviors specified by the…
- risk 0.64cvss 9.8epss 0.01
If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer situations, memory corruption could have occurred. This vulnerability affects Firefox < 127.
- risk 0.60cvss 9.3epss 0.00
A vulnerability has been identified in PowerSys (All versions < V3.11). The affected application insufficiently protects responses to authentication requests. This could allow a local attacker to bypass authentication, thereby gaining administrative privileges for the managed…
- risk 0.57cvss 9.9epss 0.01
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSortPostType' parameter in all versions up to, and including, 7.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
- risk 0.64cvss 9.8epss 0.02
OS command injection vulnerability exists in awkblog v0.0.1 (commit hash:7b761b192d0e0dc3eef0f30630e00ece01c8d552) and earlier. If a remote unauthenticated attacker sends a specially crafted HTTP request, an arbitrary OS command may be executed with the privileges of the…
- risk 0.59cvss 9.0epss 0.01
Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script on the web browser of the user who is logging in to the product.