| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-32101 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2022 | kkcms v1.3.7 was discovered to contain a SQL injection vulnerability via the cid parameter at /template/wapian/vlist.php. | ||
| CVE-2021-40940 | Cri | 0.64 | 9.8 | 0.02 | Jun 15, 2022 | Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability. | ||
| CVE-2019-4575 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2022 | IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end… | ||
| CVE-2022-20210 | Cri | 0.64 | 9.8 | 0.03 | Jun 15, 2022 | The UE and the EMM communicate with each other using NAS messages. When a new NAS message arrives from the EMM, the modem parses it and fills in internal objects based on the received data. A bug in the parsing code could be used by an attacker to remotely crash the modem, which… | ||
| CVE-2022-20191 | Cri | 0.64 | 9.8 | 0.00 | Jun 15, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-209324757References: N/A | ||
| CVE-2022-20173 | Cri | 0.64 | 9.8 | 0.00 | Jun 15, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-207116951References: N/A | ||
| CVE-2022-20171 | Cri | 0.64 | 9.8 | 0.00 | Jun 15, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-215565667References: N/A | ||
| CVE-2022-20170 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-209421931References: N/A | ||
| CVE-2022-20167 | Cri | 0.64 | 9.8 | 0.00 | Jun 15, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-204956204References: N/A | ||
| CVE-2022-20164 | Cri | 0.64 | 9.8 | 0.00 | Jun 15, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-204891956References: N/A | ||
| CVE-2022-20160 | Cri | 0.64 | 9.8 | 0.00 | Jun 15, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-210083655References: N/A | ||
| CVE-2022-20145 | Cri | 0.64 | 9.8 | 0.06 | Jun 15, 2022 | In startLegacyVpnPrivileged of Vpn.java, there is a possible way to retrieve VPN credentials due to a protocol downgrade attack. This could lead to remote escalation of privilege if a malicious Wi-Fi AP is used, with no additional execution privileges needed. User interaction is… | ||
| CVE-2022-20140 | Cri | 0.64 | 9.8 | 0.09 | Jun 15, 2022 | In read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2022-20130 | Cri | 0.64 | 9.8 | 0.08 | Jun 15, 2022 | In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2022-20127 | Cri | 0.64 | 9.8 | 0.07 | Jun 15, 2022 | In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10… | ||
| CVE-2021-40212 | Cri | 0.64 | 9.8 | 0.02 | Jun 15, 2022 | An exploitable out-of-bounds write vulnerability in PotPlayer 1.7.21523 build 210729 may lead to code execution, information disclosure, and denial of service. | ||
| CVE-2022-32559 | Cri | 0.59 | 9.1 | 0.01 | Jun 14, 2022 | An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked metrics. | ||
| CVE-2022-32337 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/patients/manage_patient.php?id=. | ||
| CVE-2022-27668 | Cri | 0.64 | 9.8 | 0.02 | Jun 14, 2022 | Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions KERNEL 7.49, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC… | ||
| CVE-2021-42675 | Cri | 0.64 | 9.8 | 0.02 | Jun 14, 2022 | Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP file and obtain remote code execution. | ||
| CVE-2022-32352 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_patient_admission. | ||
| CVE-2022-32328 | — | Cri | 0.59 | 9.1 | 0.01 | Jun 14, 2022 | Fast Food Ordering System v1.0 is vulnerable to Delete any file. via /ffos/classes/Master.php?f=delete_img. | |
| CVE-2022-32336 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2022 | Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/view_menu.php?id=. | ||
| CVE-2022-31311 | Cri | 0.64 | 9.8 | 0.03 | Jun 14, 2022 | An issue in adm.cgi of WAVLINK AERIAL X 1200M M79X3.V5030.180719 allows attackers to execute arbitrary commands via a crafted POST request. | ||
| CVE-2022-31273 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2022 | An issue in TopIDP3000 Topsec Operating System tos_3.3.005.665b.15_smpidp allows attackers to perform a brute-force attack via a crafted session_id cookie. | ||
| CVE-2022-30230 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2022 | A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated access for privileged functions. This could allow an unauthenticated attacker to create a new user with administrative permissions. | ||
| CVE-2022-25651 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2022 | Memory corruption in bluetooth host due to integer overflow while processing BT HFP-UNIT profile in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music | ||
| CVE-2021-35104 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2022 | Possible buffer overflow due to improper parsing of headers while playing the FLAC audio clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired… | ||
| CVE-2021-35090 | Cri | 0.60 | 9.3 | 0.00 | Jun 14, 2022 | Possible hypervisor memory corruption due to TOC TOU race condition when updating address mappings in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2021-35082 | Cri | 0.59 | 9.1 | 0.00 | Jun 14, 2022 | Improper integrity check can lead to race condition between tasks PDCP and RRC? right after a valid RRC security mode command packet has been received in Snapdragon Industrial IOT | ||
| CVE-2021-35081 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2022 | Possible buffer overflow due to improper validation of SSID length received from beacon or probe response during an IBSS session in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon… | ||
| CVE-2021-30347 | Cri | 0.59 | 9.1 | 0.00 | Jun 14, 2022 | Improper integrity check can lead to race condition between tasks PDCP and RRC? right after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2021-30343 | Cri | 0.59 | 9.1 | 0.00 | Jun 14, 2022 | Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2021-30342 | Cri | 0.59 | 9.1 | 0.00 | Jun 14, 2022 | Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables | ||
| CVE-2021-30341 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2022 | Improper buffer size validation of DSM packet received can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables | ||
| CVE-2021-30339 | Cri | 0.59 | 9.0 | 0.00 | Jun 14, 2022 | Reading PRNG output may lead to improper key generation due to lack of buffer validation in Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking | ||
| CVE-2022-25167 | — | Cri | 0.57 | 9.8 | 0.05 | Jun 14, 2022 | Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI to allow only the… | |
| CVE-2022-31446 | Cri | 0.66 | 9.8 | 0.33 | Jun 14, 2022 | Tenda AC18 router V15.03.05.19 and V15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/WriteFacMac. | ||
| CVE-2021-41662 | Cri | 0.64 | 9.8 | 0.02 | Jun 13, 2022 | The South Gate Inn Online Reservation System v1.0 contains an SQL injection vulnerability that can be chained with a malicious PHP file upload, which is caused by improper file handling in the editImg function. This vulnerability leads to remote code execution. | ||
| CVE-2021-41661 | Cri | 0.64 | 9.8 | 0.01 | Jun 13, 2022 | Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on the web server by uploading a PHP webshell. | ||
| CVE-2022-31053 | Cri | 0.64 | 9.8 | 0.01 | Jun 13, 2022 | Biscuit is an authentication and authorization token for microservices architectures. The Biscuit specification version 1 contains a vulnerable algorithm that allows malicious actors to forge valid Γ-signatures. Such an attack would allow an attacker to create a token with any… | ||
| CVE-2022-29797 | Cri | 0.64 | 9.8 | 0.01 | Jun 13, 2022 | There is a buffer overflow vulnerability in CV81-WDM FW 01.70.49.29.46. Successful exploitation of this vulnerability may lead to privilege escalation. | ||
| CVE-2022-33175 | — | Cri | 0.64 | 9.8 | 0.02 | Jun 13, 2022 | Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions setting on the user.token field that is accessible to everyone through the /cgi/get_param.cgi HTTP API. This leads to disclosing active session ids of currently… | |
| CVE-2022-33174 | Cri | 0.65 | 9.8 | 0.13 | Jun 13, 2022 | Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the… | ||
| CVE-2021-40604 | Cri | 0.59 | 9.1 | 0.01 | Jun 13, 2022 | A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbitrary URLs or trigger deserialization via phar protocol when generating class names dynamically. In some cases an exploitation is possible by… | ||
| CVE-2021-40036 | Cri | 0.64 | 9.8 | 0.01 | Jun 13, 2022 | The bone voice ID TA has a memory overwrite vulnerability. Successful exploitation of this vulnerability may result in malicious code execution. | ||
| CVE-2022-31760 | Cri | 0.59 | 9.1 | 0.01 | Jun 13, 2022 | Dialog boxes can still be displayed even if the screen is locked in carrier-customized USSD services. Successful exploitation of this vulnerability may affect data integrity and confidentiality. | ||
| CVE-2022-30311 | Cri | 0.64 | 9.8 | 0.03 | Jun 13, 2022 | In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command… | ||
| CVE-2022-30310 | Cri | 0.64 | 9.8 | 0.02 | Jun 13, 2022 | In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command… | ||
| CVE-2022-30309 | Cri | 0.64 | 9.8 | 0.03 | Jun 13, 2022 | In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control… |
- risk 0.64cvss 9.8epss 0.01
kkcms v1.3.7 was discovered to contain a SQL injection vulnerability via the cid parameter at /template/wapian/vlist.php.
- risk 0.64cvss 9.8epss 0.02
Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.
- risk 0.64cvss 9.8epss 0.01
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end…
- risk 0.64cvss 9.8epss 0.03
The UE and the EMM communicate with each other using NAS messages. When a new NAS message arrives from the EMM, the modem parses it and fills in internal objects based on the received data. A bug in the parsing code could be used by an attacker to remotely crash the modem, which…
- risk 0.64cvss 9.8epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-209324757References: N/A
- risk 0.64cvss 9.8epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-207116951References: N/A
- risk 0.64cvss 9.8epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-215565667References: N/A
- risk 0.64cvss 9.8epss 0.01
Product: AndroidVersions: Android kernelAndroid ID: A-209421931References: N/A
- risk 0.64cvss 9.8epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-204956204References: N/A
- risk 0.64cvss 9.8epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-204891956References: N/A
- risk 0.64cvss 9.8epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-210083655References: N/A
- risk 0.64cvss 9.8epss 0.06
In startLegacyVpnPrivileged of Vpn.java, there is a possible way to retrieve VPN credentials due to a protocol downgrade attack. This could lead to remote escalation of privilege if a malicious Wi-Fi AP is used, with no additional execution privileges needed. User interaction is…
- risk 0.64cvss 9.8epss 0.09
In read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.64cvss 9.8epss 0.08
In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.64cvss 9.8epss 0.07
In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10…
- risk 0.64cvss 9.8epss 0.02
An exploitable out-of-bounds write vulnerability in PotPlayer 1.7.21523 build 210729 may lead to code execution, information disclosure, and denial of service.
- risk 0.59cvss 9.1epss 0.01
An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked metrics.
- risk 0.64cvss 9.8epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/patients/manage_patient.php?id=.
- risk 0.64cvss 9.8epss 0.02
Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions KERNEL 7.49, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC…
- risk 0.64cvss 9.8epss 0.02
Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP file and obtain remote code execution.
- risk 0.64cvss 9.8epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_patient_admission.
- risk 0.59cvss 9.1epss 0.01
Fast Food Ordering System v1.0 is vulnerable to Delete any file. via /ffos/classes/Master.php?f=delete_img.
- risk 0.64cvss 9.8epss 0.01
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/view_menu.php?id=.
- risk 0.64cvss 9.8epss 0.03
An issue in adm.cgi of WAVLINK AERIAL X 1200M M79X3.V5030.180719 allows attackers to execute arbitrary commands via a crafted POST request.
- risk 0.64cvss 9.8epss 0.01
An issue in TopIDP3000 Topsec Operating System tos_3.3.005.665b.15_smpidp allows attackers to perform a brute-force attack via a crafted session_id cookie.
- risk 0.64cvss 9.8epss 0.01
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated access for privileged functions. This could allow an unauthenticated attacker to create a new user with administrative permissions.
- risk 0.64cvss 9.8epss 0.01
Memory corruption in bluetooth host due to integer overflow while processing BT HFP-UNIT profile in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
- risk 0.64cvss 9.8epss 0.01
Possible buffer overflow due to improper parsing of headers while playing the FLAC audio clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired…
- risk 0.60cvss 9.3epss 0.00
Possible hypervisor memory corruption due to TOC TOU race condition when updating address mappings in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.59cvss 9.1epss 0.00
Improper integrity check can lead to race condition between tasks PDCP and RRC? right after a valid RRC security mode command packet has been received in Snapdragon Industrial IOT
- risk 0.64cvss 9.8epss 0.01
Possible buffer overflow due to improper validation of SSID length received from beacon or probe response during an IBSS session in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon…
- risk 0.59cvss 9.1epss 0.00
Improper integrity check can lead to race condition between tasks PDCP and RRC? right after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.59cvss 9.1epss 0.00
Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.59cvss 9.1epss 0.00
Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables
- risk 0.64cvss 9.8epss 0.01
Improper buffer size validation of DSM packet received can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables
- risk 0.59cvss 9.0epss 0.00
Reading PRNG output may lead to improper key generation due to lack of buffer validation in Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
- risk 0.57cvss 9.8epss 0.05
Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI to allow only the…
- risk 0.66cvss 9.8epss 0.33
Tenda AC18 router V15.03.05.19 and V15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/WriteFacMac.
- risk 0.64cvss 9.8epss 0.02
The South Gate Inn Online Reservation System v1.0 contains an SQL injection vulnerability that can be chained with a malicious PHP file upload, which is caused by improper file handling in the editImg function. This vulnerability leads to remote code execution.
- risk 0.64cvss 9.8epss 0.01
Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on the web server by uploading a PHP webshell.
- risk 0.64cvss 9.8epss 0.01
Biscuit is an authentication and authorization token for microservices architectures. The Biscuit specification version 1 contains a vulnerable algorithm that allows malicious actors to forge valid Γ-signatures. Such an attack would allow an attacker to create a token with any…
- risk 0.64cvss 9.8epss 0.01
There is a buffer overflow vulnerability in CV81-WDM FW 01.70.49.29.46. Successful exploitation of this vulnerability may lead to privilege escalation.
- risk 0.64cvss 9.8epss 0.02
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions setting on the user.token field that is accessible to everyone through the /cgi/get_param.cgi HTTP API. This leads to disclosing active session ids of currently…
- risk 0.65cvss 9.8epss 0.13
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the…
- risk 0.59cvss 9.1epss 0.01
A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbitrary URLs or trigger deserialization via phar protocol when generating class names dynamically. In some cases an exploitation is possible by…
- risk 0.64cvss 9.8epss 0.01
The bone voice ID TA has a memory overwrite vulnerability. Successful exploitation of this vulnerability may result in malicious code execution.
- risk 0.59cvss 9.1epss 0.01
Dialog boxes can still be displayed even if the screen is locked in carrier-customized USSD services. Successful exploitation of this vulnerability may affect data integrity and confidentiality.
- risk 0.64cvss 9.8epss 0.03
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command…
- risk 0.64cvss 9.8epss 0.02
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command…
- risk 0.64cvss 9.8epss 0.03
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control…