| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-41138 | Cri | 0.64 | 9.8 | 0.02 | Sep 20, 2022 | In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution. | ||
| CVE-2022-38340 | Cri | 0.59 | 9.1 | 0.01 | Sep 20, 2022 | Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a Path Traversal vulnerability via the component fmedataupload. | ||
| CVE-2022-37265 | — | Cri | 0.64 | 9.8 | 0.01 | Sep 20, 2022 | Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js. | |
| CVE-2017-20148 | Cri | 0.64 | 9.8 | 0.01 | Sep 20, 2022 | In the ebuild package through logcheck-1.3.23.ebuild for Logcheck on Gentoo, it is possible to achieve root privilege escalation from the logcheck user because of insecure recursive chown calls. | ||
| CVE-2022-38916 | Cri | 0.65 | 9.8 | 0.18 | Sep 20, 2022 | A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious files | ||
| CVE-2022-37204 | Cri | 0.64 | 9.8 | 0.01 | Sep 20, 2022 | Final CMS 5.1.0 is vulnerable to SQL Injection. | ||
| CVE-2022-2177 | Cri | 0.61 | 9.4 | 0.01 | Sep 20, 2022 | Kayrasoft product before version 2 has an unauthenticated SQL Injection vulnerability. This is fixed in version 2. | ||
| CVE-2022-38545 | — | Cri | 0.58 | 9.6 | 0.33 | Sep 19, 2022 | Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request. | |
| CVE-2022-38509 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking_id parameter at /admin/budget.php. | ||
| CVE-2022-38339 | Cri | 0.62 | 9.6 | 0.01 | Sep 19, 2022 | Safe Software FME Server v2021.2.5, v2022.0.0.2 and below contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the login page. | ||
| CVE-2022-37032 | Cri | 0.00 | 9.1 | 0.02 | Sep 19, 2022 | An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c. | ||
| CVE-2022-28321 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctly restrict login if a user tries to connect from an IP address that is not resolvable via DNS. In such conditions, a user with… | ||
| CVE-2022-0143 | Cri | 0.60 | 9.3 | 0.01 | Sep 19, 2022 | When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remote Connector Server (RCS) | ||
| CVE-2022-40980 | Cri | 0.59 | 9.1 | 0.01 | Sep 19, 2022 | A potential unathenticated file deletion vulnerabilty on Trend Micro Mobile Security for Enterprise 9.8 SP5 could allow an attacker with access to the Management Server to delete files. This issue was resolved in 9.8 SP5 Critical Patch 2. | ||
| CVE-2022-40144 | Cri | 0.64 | 9.8 | 0.02 | Sep 19, 2022 | A vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service could allow an attacker to bypass the product's login authentication by falsifying request parameters on affected installations. | ||
| CVE-2022-3218 | Cri | 0.09 | 9.8 | 0.73 | Sep 19, 2022 | Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism is trivially bypassed, which can result in remote code execution. | ||
| CVE-2022-40812 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0. | ||
| CVE-2022-40810 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-ip-addresses for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0 | ||
| CVE-2022-40809 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-dicts for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0 | ||
| CVE-2022-40432 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0. | ||
| CVE-2022-40431 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0. | ||
| CVE-2022-40430 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-utility for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0. | ||
| CVE-2022-40429 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-ip-addresses for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0. | ||
| CVE-2022-40428 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-mpeg for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0. | ||
| CVE-2022-40426 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-asns for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0. | ||
| CVE-2022-40425 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-html for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0. | ||
| CVE-2022-38887 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The democritus-strings package. The affected version is 0.1.0. | ||
| CVE-2022-38886 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0. | ||
| CVE-2022-38885 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-netstrings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0. | ||
| CVE-2022-38884 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-grammars for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0. | ||
| CVE-2022-38883 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-math for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0. | ||
| CVE-2022-38882 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-json for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0. | ||
| CVE-2022-38881 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-archives for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0. | ||
| CVE-2022-37203 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection. | ||
| CVE-2022-35914 | Cri | 0.87 | 9.8 | 1.00 | KEV | Sep 19, 2022 | /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection. | |
| CVE-2022-40811 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0. | ||
| CVE-2022-40808 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-dates for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0 | ||
| CVE-2022-40807 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-domains for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0 | ||
| CVE-2022-40806 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-uuids for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0 | ||
| CVE-2022-40805 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-urls for python 0.1.0, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-hypothesis package. | ||
| CVE-2022-40427 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-domains for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0 | ||
| CVE-2022-40424 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-networking package. The affected version of d8s-urls is 0.1.0 | ||
| CVE-2022-38880 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The affected version is 0.1.0. | ||
| CVE-2022-2840 | Cri | 0.67 | 9.8 | 0.10 | Sep 19, 2022 | The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections | ||
| CVE-2022-2754 | Cri | 0.67 | 9.8 | 0.38 | Sep 19, 2022 | The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacks | ||
| CVE-2022-40766 | Cri | 0.64 | 9.8 | 0.01 | Sep 18, 2022 | Modern Campus Omni CMS (formerly OU Campus) 10.2.4 allows login-page SQL injection via a '" OR 1 = 1 -- - , <?php' substring. | ||
| CVE-2022-40300 | Cri | 0.72 | 9.8 | 0.99 | Sep 16, 2022 | Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities. | ||
| CVE-2022-37258 | — | Cri | 0.64 | 9.8 | 0.01 | Sep 16, 2022 | Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName variable in npm-convert.js. | |
| CVE-2022-3214 | Cri | 0.64 | 9.8 | 0.02 | Sep 16, 2022 | Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions prior to 1.9.03.009 have this vulnerability. Executable files could be uploaded to certain directories using hard-coded bearer… | ||
| CVE-2022-38621 | Cri | 0.66 | 9.8 | 0.24 | Sep 16, 2022 | Doufox v0.0.4 was discovered to contain a remote code execution (RCE) vulnerability via the edit file page. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. |
- risk 0.64cvss 9.8epss 0.02
In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution.
- risk 0.59cvss 9.1epss 0.01
Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a Path Traversal vulnerability via the component fmedataupload.
- risk 0.64cvss 9.8epss 0.01
Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js.
- risk 0.64cvss 9.8epss 0.01
In the ebuild package through logcheck-1.3.23.ebuild for Logcheck on Gentoo, it is possible to achieve root privilege escalation from the logcheck user because of insecure recursive chown calls.
- risk 0.65cvss 9.8epss 0.18
A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious files
- risk 0.64cvss 9.8epss 0.01
Final CMS 5.1.0 is vulnerable to SQL Injection.
- risk 0.61cvss 9.4epss 0.01
Kayrasoft product before version 2 has an unauthenticated SQL Injection vulnerability. This is fixed in version 2.
- risk 0.58cvss 9.6epss 0.33
Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request.
- risk 0.64cvss 9.8epss 0.01
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking_id parameter at /admin/budget.php.
- risk 0.62cvss 9.6epss 0.01
Safe Software FME Server v2021.2.5, v2022.0.0.2 and below contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the login page.
- risk 0.00cvss 9.1epss 0.02
An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c.
- risk 0.64cvss 9.8epss 0.01
The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctly restrict login if a user tries to connect from an IP address that is not resolvable via DNS. In such conditions, a user with…
- risk 0.60cvss 9.3epss 0.01
When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remote Connector Server (RCS)
- risk 0.59cvss 9.1epss 0.01
A potential unathenticated file deletion vulnerabilty on Trend Micro Mobile Security for Enterprise 9.8 SP5 could allow an attacker with access to the Management Server to delete files. This issue was resolved in 9.8 SP5 Critical Patch 2.
- risk 0.64cvss 9.8epss 0.02
A vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service could allow an attacker to bypass the product's login authentication by falsifying request parameters on affected installations.
- risk 0.09cvss 9.8epss 0.73
Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism is trivially bypassed, which can result in remote code execution.
- risk 0.64cvss 9.8epss 0.01
The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-ip-addresses for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0
- risk 0.64cvss 9.8epss 0.01
The d8s-dicts for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0
- risk 0.64cvss 9.8epss 0.01
The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-utility for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-ip-addresses for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-mpeg for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-asns for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-html for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The democritus-strings package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-netstrings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-grammars for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-math for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-json for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-archives for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
- risk 0.87cvss 9.8epss 1.00
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
- risk 0.64cvss 9.8epss 0.01
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-dates for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0
- risk 0.64cvss 9.8epss 0.01
The d8s-domains for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0
- risk 0.64cvss 9.8epss 0.01
The d8s-uuids for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0
- risk 0.64cvss 9.8epss 0.01
The d8s-urls for python 0.1.0, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-hypothesis package.
- risk 0.64cvss 9.8epss 0.01
The d8s-domains for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0
- risk 0.64cvss 9.8epss 0.01
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-networking package. The affected version of d8s-urls is 0.1.0
- risk 0.64cvss 9.8epss 0.01
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The affected version is 0.1.0.
- risk 0.67cvss 9.8epss 0.10
The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections
- risk 0.67cvss 9.8epss 0.38
The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacks
- risk 0.64cvss 9.8epss 0.01
Modern Campus Omni CMS (formerly OU Campus) 10.2.4 allows login-page SQL injection via a '" OR 1 = 1 -- - , <?php' substring.
- risk 0.72cvss 9.8epss 0.99
Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities.
- risk 0.64cvss 9.8epss 0.01
Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName variable in npm-convert.js.
- risk 0.64cvss 9.8epss 0.02
Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions prior to 1.9.03.009 have this vulnerability. Executable files could be uploaded to certain directories using hard-coded bearer…
- risk 0.66cvss 9.8epss 0.24
Doufox v0.0.4 was discovered to contain a remote code execution (RCE) vulnerability via the edit file page. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.