| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-20386 | Cri | 0.64 | 9.8 | 0.00 | Sep 13, 2022 | Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227328 | ||
| CVE-2022-20385 | Cri | 0.64 | 9.8 | 0.00 | Sep 13, 2022 | a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (in this case, it is GSCAN_MAX), then it access polciy array 'policy[type]', which OOB access happens.Product: AndroidVersions: Android… | ||
| CVE-2021-0942 | Cri | 0.64 | 9.8 | 0.00 | Sep 13, 2022 | The path in this case is a little bit convoluted. The end result is that via an ioctl an untrusted app can control the ui32PageIndex offset in the expression:sPA.uiAddr = page_to_phys(psOSPageArrayData->pagearray[ui32PageIndex]);With the current PoC this crashes as an OOB read.… | ||
| CVE-2022-39206 | Cri | 0.00 | 9.9 | 0.02 | Sep 13, 2022 | Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. When using Docker-based job executors, the Docker socket (e.g. /var/run/docker.sock on Linux) is mounted into each Docker step. Users that can define and trigger CI/CD jobs on a project could use this to… | ||
| CVE-2022-39205 | Cri | 0.00 | 9.0 | 0.02 | Sep 13, 2022 | Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. In versions of Onedev prior to 7.3.0 unauthenticated users can take over a OneDev instance if there is no properly configured reverse proxy. The /git-prereceive-callback endpoint is used by the pre-receive… | ||
| CVE-2022-34722 | Cri | 0.64 | 9.8 | 0.02 | Sep 13, 2022 | Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | ||
| CVE-2022-34721 | Cri | 0.70 | 9.8 | 0.76 | Sep 13, 2022 | Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | ||
| CVE-2022-34718 | Cri | 0.68 | 9.8 | 0.46 | Sep 13, 2022 | Windows TCP/IP Remote Code Execution Vulnerability | ||
| CVE-2022-38542 | Cri | 0.64 | 9.8 | 0.01 | Sep 13, 2022 | Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the kill_session interface. The project has released an update, please upgrade to v1.9.0 and above. | ||
| CVE-2022-38541 | Cri | 0.64 | 9.8 | 0.01 | Sep 13, 2022 | Archery v1.8.3 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_time and stop_time parameters in the my2sql interface. | ||
| CVE-2022-38540 | Cri | 0.64 | 9.8 | 0.01 | Sep 13, 2022 | Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the create_kill_session interface. | ||
| CVE-2022-38539 | Cri | 0.64 | 9.8 | 0.01 | Sep 13, 2022 | Archery v1.7.5 to v1.8.5 was discovered to contain a SQL injection vulnerability via the where parameter at /archive/apply. | ||
| CVE-2022-38538 | Cri | 0.64 | 9.8 | 0.01 | Sep 13, 2022 | Archery v1.7.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the checksum parameter in the report module. | ||
| CVE-2022-38537 | Cri | 0.64 | 9.8 | 0.01 | Sep 13, 2022 | Archery v1.4.5 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_file, end_file, start_time, and stop_time parameters in the binlog2sql interface. | ||
| CVE-2022-37011 | Cri | 0.64 | 9.8 | 0.01 | Sep 13, 2022 | A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 8 compatible) (All versions < V2.3.0), Mendix SAML (Mendix 9 compatible, New Track) (All versions < V3.3.1), Mendix SAML (Mendix 9 compatible, Upgrade Track)… | ||
| CVE-2022-38297 | Cri | 0.64 | 9.8 | 0.01 | Sep 12, 2022 | UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning. | ||
| CVE-2022-38296 | Cri | 0.64 | 9.8 | 0.04 | Sep 12, 2022 | Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager. | ||
| CVE-2022-38292 | Cri | 0.64 | 9.8 | 0.01 | Sep 12, 2022 | SLiMS Senayan Library Management System v9.4.2 was discovered to contain multiple Server-Side Request Forgeries via the components /bibliography/marcsru.php and /bibliography/z3950sru.php. | ||
| CVE-2022-37860 | Cri | 0.70 | 9.8 | 0.80 | Sep 12, 2022 | The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication command injection vulnerability. | ||
| CVE-2022-37300 | Cri | 0.64 | 9.8 | 0.01 | Sep 12, 2022 | A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: EcoStruxure Control Expert Including all Unity Pro versions… | ||
| CVE-2022-37767 | — | Cri | 0.64 | 9.8 | 0.01 | Sep 12, 2022 | Pebble Templates 3.1.5 allows attackers to bypass a protection mechanism and implement arbitrary code execution with springbok. NOTE: the vendor disputes this because input to the Pebble templating engine is intended to include arbitrary Java code, and thus either the input… | |
| CVE-2022-37794 | Cri | 0.64 | 9.8 | 0.01 | Sep 12, 2022 | In Library Management System 1.0 the /card/in-card.php file id_no parameters are vulnerable to SQL injection. | ||
| CVE-2022-39135 | — | Cri | 0.64 | 9.8 | 0.02 | Sep 11, 2022 | Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity references in their configuration, making them vulnerable to a potential XML External Entity (XXE) attack. Therefore any client… | |
| CVE-2022-38638 | Cri | 0.52 | 9.1 | 0.01 | Sep 9, 2022 | Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource. | ||
| CVE-2021-44835 | Cri | 0.64 | 9.8 | 0.01 | Sep 9, 2022 | An issue was discovered in Active Intelligent Visualization 5. The Vdc header is used in a SQL query without being sanitized. This causes SQL injection. | ||
| CVE-2022-2526 | Cri | 0.00 | 9.8 | 0.01 | Sep 9, 2022 | A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks… | ||
| CVE-2022-40305 | Cri | 0.64 | 9.8 | 0.01 | Sep 9, 2022 | A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, overload network resources, and possibly have unspecified other impact via the server parameter to the /cwc/login login form. | ||
| CVE-2022-36084 | Cri | 0.57 | 9.9 | 0.01 | Sep 8, 2022 | cruddl is software for creating a GraphQL API for a database, using the GraphQL SDL to model a schema. If cruddl starting with version 1.1.0 and prior to versions 2.7.0 and 3.0.2 is used to generate a schema that uses `@flexSearchFulltext`, users of that schema may be able to… | ||
| CVE-2022-36100 | Cri | 0.63 | 9.9 | 0.74 | Sep 8, 2022 | XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform. Starting with version 1.7 in XWiki Platform Applications Tag and prior to 13.10.6 and 14.4 in XWiki Platform Tag UI, the tags document `Main.Tags` in XWiki didn't… | ||
| CVE-2022-36099 | Cri | 0.63 | 9.9 | 0.76 | Sep 8, 2022 | XWiki Platform Wiki UI Main Wiki is software for managing subwikis on XWiki Platform, a generic wiki platform. Starting with version 5.3-milestone-2 and prior to versions 13.10.6 and 14.4, it's possible to inject arbitrary wiki syntax including Groovy, Python and Velocity script… | ||
| CVE-2022-37164 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2022 | Inoda OnTrack v3.4 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper making it much easier for tools like hashcat to crack the… | ||
| CVE-2022-37163 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2022 | Bminusl IHateToBudget v1.5.7 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper making it much easier for tools like hashcat to… | ||
| CVE-2022-27593 | Cri | 0.90 | 10.0 | 0.88 | KEV | Sep 8, 2022 | An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo… | |
| CVE-2022-38394 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2022 | Use of hard-coded credentials for the telnet server of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote unauthenticated attacker to execute an arbitrary OS command. | ||
| CVE-2022-33941 | Cri | 0.64 | 9.8 | 0.02 | Sep 8, 2022 | PowerCMS XMLRPC API provided by Alfasado Inc. contains a command injection vulnerability. Sending a specially crafted message by POST method to PowerCMS XMLRPC API may allow arbitrary Perl script execution, and an arbitrary OS command may be executed through it. Affected… | ||
| CVE-2022-36588 | Cri | 0.64 | 9.8 | 0.02 | Sep 8, 2022 | In D-Link DAP1650 v1.04 firmware, the fileaccess.cgi program in the firmware has a buffer overflow vulnerability caused by strncpy. | ||
| CVE-2022-36586 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2022 | In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by strcpy in function 0x869f4 in the httpd binary. | ||
| CVE-2021-34236 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2022 | Buffer Overflow in Netgear R8000 Router with firmware v1.0.4.56 allows remote attackers to execute arbitrary code or cause a denial-of-service by sending a crafted POST to '/bd_genie_create_account.cgi' with a sufficiently long parameter 'register_country'. | ||
| CVE-2022-36585 | Cri | 0.64 | 9.8 | 0.01 | Sep 7, 2022 | In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, in httpd binary, the addDhcpRule function has a buffer overflow caused by sscanf. | ||
| CVE-2022-38250 | Cri | 0.64 | 9.8 | 0.03 | Sep 7, 2022 | Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page. | ||
| CVE-2022-38314 | Cri | 0.64 | 9.8 | 0.01 | Sep 7, 2022 | Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the urls parameter at /goform/saveParentControlInfo. | ||
| CVE-2022-38313 | Cri | 0.64 | 9.8 | 0.01 | Sep 7, 2022 | Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/saveParentControlInfo. | ||
| CVE-2022-38312 | Cri | 0.64 | 9.8 | 0.01 | Sep 7, 2022 | Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetIpMacBind. | ||
| CVE-2022-38311 | Cri | 0.64 | 9.8 | 0.01 | Sep 7, 2022 | Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/PowerSaveSet. | ||
| CVE-2022-38310 | Cri | 0.64 | 9.8 | 0.01 | Sep 7, 2022 | Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg. | ||
| CVE-2022-38309 | Cri | 0.64 | 9.8 | 0.01 | Sep 7, 2022 | Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg. | ||
| CVE-2022-36660 | Cri | 0.64 | 9.8 | 0.01 | Sep 7, 2022 | xhyve commit dfbe09b was discovered to contain a stack buffer overflow via the component pci_vtrnd_notify(). | ||
| CVE-2022-36587 | Cri | 0.64 | 9.8 | 0.01 | Sep 7, 2022 | In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by sprintf in function in the httpd binary. | ||
| CVE-2022-31247 | Cri | 0.59 | 9.1 | 0.01 | Sep 7, 2022 | An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project role template bindings (such as cluster-owner, manage cluster members, project-owner and manage project members) to gain owner… | ||
| CVE-2021-36783 | Cri | 0.64 | 9.9 | 0.01 | Sep 7, 2022 | A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners and Project Members to read credentials, passwords and API tokens that have been stored in cleartext and exposed via API endpoints. This… |
- risk 0.64cvss 9.8epss 0.00
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227328
- risk 0.64cvss 9.8epss 0.00
a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (in this case, it is GSCAN_MAX), then it access polciy array 'policy[type]', which OOB access happens.Product: AndroidVersions: Android…
- risk 0.64cvss 9.8epss 0.00
The path in this case is a little bit convoluted. The end result is that via an ioctl an untrusted app can control the ui32PageIndex offset in the expression:sPA.uiAddr = page_to_phys(psOSPageArrayData->pagearray[ui32PageIndex]);With the current PoC this crashes as an OOB read.…
- risk 0.00cvss 9.9epss 0.02
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. When using Docker-based job executors, the Docker socket (e.g. /var/run/docker.sock on Linux) is mounted into each Docker step. Users that can define and trigger CI/CD jobs on a project could use this to…
- risk 0.00cvss 9.0epss 0.02
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. In versions of Onedev prior to 7.3.0 unauthenticated users can take over a OneDev instance if there is no properly configured reverse proxy. The /git-prereceive-callback endpoint is used by the pre-receive…
- risk 0.64cvss 9.8epss 0.02
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
- risk 0.70cvss 9.8epss 0.76
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
- risk 0.68cvss 9.8epss 0.46
Windows TCP/IP Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.01
Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the kill_session interface. The project has released an update, please upgrade to v1.9.0 and above.
- risk 0.64cvss 9.8epss 0.01
Archery v1.8.3 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_time and stop_time parameters in the my2sql interface.
- risk 0.64cvss 9.8epss 0.01
Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the create_kill_session interface.
- risk 0.64cvss 9.8epss 0.01
Archery v1.7.5 to v1.8.5 was discovered to contain a SQL injection vulnerability via the where parameter at /archive/apply.
- risk 0.64cvss 9.8epss 0.01
Archery v1.7.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the checksum parameter in the report module.
- risk 0.64cvss 9.8epss 0.01
Archery v1.4.5 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_file, end_file, start_time, and stop_time parameters in the binlog2sql interface.
- risk 0.64cvss 9.8epss 0.01
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 8 compatible) (All versions < V2.3.0), Mendix SAML (Mendix 9 compatible, New Track) (All versions < V3.3.1), Mendix SAML (Mendix 9 compatible, Upgrade Track)…
- risk 0.64cvss 9.8epss 0.01
UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning.
- risk 0.64cvss 9.8epss 0.04
Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.
- risk 0.64cvss 9.8epss 0.01
SLiMS Senayan Library Management System v9.4.2 was discovered to contain multiple Server-Side Request Forgeries via the components /bibliography/marcsru.php and /bibliography/z3950sru.php.
- risk 0.70cvss 9.8epss 0.80
The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication command injection vulnerability.
- risk 0.64cvss 9.8epss 0.01
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: EcoStruxure Control Expert Including all Unity Pro versions…
- risk 0.64cvss 9.8epss 0.01
Pebble Templates 3.1.5 allows attackers to bypass a protection mechanism and implement arbitrary code execution with springbok. NOTE: the vendor disputes this because input to the Pebble templating engine is intended to include arbitrary Java code, and thus either the input…
- risk 0.64cvss 9.8epss 0.01
In Library Management System 1.0 the /card/in-card.php file id_no parameters are vulnerable to SQL injection.
- risk 0.64cvss 9.8epss 0.02
Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity references in their configuration, making them vulnerable to a potential XML External Entity (XXE) attack. Therefore any client…
- risk 0.52cvss 9.1epss 0.01
Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Active Intelligent Visualization 5. The Vdc header is used in a SQL query without being sanitized. This causes SQL injection.
- risk 0.00cvss 9.8epss 0.01
A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks…
- risk 0.64cvss 9.8epss 0.01
A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, overload network resources, and possibly have unspecified other impact via the server parameter to the /cwc/login login form.
- risk 0.57cvss 9.9epss 0.01
cruddl is software for creating a GraphQL API for a database, using the GraphQL SDL to model a schema. If cruddl starting with version 1.1.0 and prior to versions 2.7.0 and 3.0.2 is used to generate a schema that uses `@flexSearchFulltext`, users of that schema may be able to…
- risk 0.63cvss 9.9epss 0.74
XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform. Starting with version 1.7 in XWiki Platform Applications Tag and prior to 13.10.6 and 14.4 in XWiki Platform Tag UI, the tags document `Main.Tags` in XWiki didn't…
- risk 0.63cvss 9.9epss 0.76
XWiki Platform Wiki UI Main Wiki is software for managing subwikis on XWiki Platform, a generic wiki platform. Starting with version 5.3-milestone-2 and prior to versions 13.10.6 and 14.4, it's possible to inject arbitrary wiki syntax including Groovy, Python and Velocity script…
- risk 0.64cvss 9.8epss 0.01
Inoda OnTrack v3.4 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper making it much easier for tools like hashcat to crack the…
- risk 0.64cvss 9.8epss 0.00
Bminusl IHateToBudget v1.5.7 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper making it much easier for tools like hashcat to…
- risk 0.90cvss 10.0epss 0.88
An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo…
- risk 0.64cvss 9.8epss 0.01
Use of hard-coded credentials for the telnet server of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote unauthenticated attacker to execute an arbitrary OS command.
- risk 0.64cvss 9.8epss 0.02
PowerCMS XMLRPC API provided by Alfasado Inc. contains a command injection vulnerability. Sending a specially crafted message by POST method to PowerCMS XMLRPC API may allow arbitrary Perl script execution, and an arbitrary OS command may be executed through it. Affected…
- risk 0.64cvss 9.8epss 0.02
In D-Link DAP1650 v1.04 firmware, the fileaccess.cgi program in the firmware has a buffer overflow vulnerability caused by strncpy.
- risk 0.64cvss 9.8epss 0.01
In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by strcpy in function 0x869f4 in the httpd binary.
- risk 0.64cvss 9.8epss 0.01
Buffer Overflow in Netgear R8000 Router with firmware v1.0.4.56 allows remote attackers to execute arbitrary code or cause a denial-of-service by sending a crafted POST to '/bd_genie_create_account.cgi' with a sufficiently long parameter 'register_country'.
- risk 0.64cvss 9.8epss 0.01
In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, in httpd binary, the addDhcpRule function has a buffer overflow caused by sscanf.
- risk 0.64cvss 9.8epss 0.03
Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the urls parameter at /goform/saveParentControlInfo.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/saveParentControlInfo.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetIpMacBind.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/PowerSaveSet.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.
- risk 0.64cvss 9.8epss 0.01
xhyve commit dfbe09b was discovered to contain a stack buffer overflow via the component pci_vtrnd_notify().
- risk 0.64cvss 9.8epss 0.01
In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by sprintf in function in the httpd binary.
- risk 0.59cvss 9.1epss 0.01
An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project role template bindings (such as cluster-owner, manage cluster members, project-owner and manage project members) to gain owner…
- risk 0.64cvss 9.9epss 0.01
A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners and Project Members to read credentials, passwords and API tokens that have been stored in cleartext and exposed via API endpoints. This…