| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-20720 | Cri | 0.59 | 9.1 | 0.04 | Feb 15, 2024 | Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue… | ||
| CVE-2024-20719 | Cri | 0.59 | 9.1 | 0.01 | Feb 15, 2024 | Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into every admin page. Malicious JavaScript may be executed in a victim’s… | ||
| CVE-2024-20738 | Cri | 0.64 | 9.8 | 0.01 | Feb 15, 2024 | Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass authentication mechanisms and gain unauthorized access.… | ||
| CVE-2023-39245 | Cri | 0.64 | 9.8 | 0.01 | Feb 15, 2024 | DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level… | ||
| CVE-2023-32484 | Cri | 0.64 | 9.8 | 0.01 | Feb 15, 2024 | Dell Networking Switches running Enterprise SONiC versions 4.1.0, 4.0.5, 3.5.4 and below contains an improper input validation vulnerability. A remote unauthenticated malicious user may exploit this vulnerability and escalate privileges up to the highest administrative level.… | ||
| CVE-2023-32462 | Cri | 0.64 | 9.8 | 0.02 | Feb 15, 2024 | Dell OS10 Networking Switches running 10.5.2.x and above contain an OS command injection vulnerability when using remote user authentication. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands and… | ||
| CVE-2023-28078 | Cri | 0.59 | 9.1 | 0.01 | Feb 15, 2024 | Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A remote unauthenticated attacker could potentially exploit this vulnerability leading to information disclosure and a possible Denial of Service when a huge… | ||
| CVE-2024-0390 | Cri | 0.64 | 9.8 | 0.00 | Feb 15, 2024 | INPRAX "iZZi connect" application on Android contains hard-coded MQTT queue credentials. The same MQTT queue is used by corresponding physical recuperation devices. Exploiting this vulnerability could potentially allow unauthorized access to manage and read parameters of the… | ||
| CVE-2022-23088 | Cri | 0.64 | 9.8 | 0.04 | Feb 15, 2024 | The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-allocated buffer. While a FreeBSD Wi-Fi client is in scanning mode (i.e., not associated with a SSID) a malicious beacon frame may overwrite kernel memory,… | ||
| CVE-2024-26264 | Cri | 0.64 | 9.8 | 0.01 | Feb 15, 2024 | EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page is accessible without login. This allows remote attackers to inject SQL commands without authentication, enabling them to read, modify, and delete database… | ||
| CVE-2024-26261 | Cri | 0.64 | 9.8 | 0.01 | Feb 15, 2024 | The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put file path in specific request parameters, allowing them to download the file without login. Furthermore, the file will be deleted… | ||
| CVE-2024-26260 | Cri | 0.64 | 9.8 | 0.02 | Feb 15, 2024 | The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inject system commands within specific request parameters. This enables the execution of arbitrary code on the remote server without… | ||
| CVE-2024-24300 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2024 | 4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardless of how many times a user logs in, the content of the cookie remains unchanged. | ||
| CVE-2024-25223 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2024 | Simple Admin Panel App v1.0 was discovered to contain a SQL injection vulnerability via the orderID parameter at /adminView/viewEachOrder.php. | ||
| CVE-2024-25222 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2024 | Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the projectID parameter at /TaskManager/EditProject.php. | ||
| CVE-2024-25220 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2024 | Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the taskID parameter at /TaskManager/EditTask.php. | ||
| CVE-2024-25217 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2024 | Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /omos/?p=products/view_product. | ||
| CVE-2024-25216 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2024 | Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the mailud parameter at /aprocess.php. | ||
| CVE-2024-25215 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2024 | Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aprocess.php. | ||
| CVE-2024-25214 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2024 | An issue in Employee Managment System v1.0 allows attackers to bypass authentication via injecting a crafted payload into the E-mail and Password parameters at /alogin.html. | ||
| CVE-2024-25211 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2024 | Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the category parameter at /endpoint/delete_category.php. | ||
| CVE-2024-25210 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2024 | Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the expense parameter at /endpoint/delete_expense.php. | ||
| CVE-2024-25209 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2024 | Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident parameter at /endpoint/delete-resident.php. | ||
| CVE-2023-6441 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UNI-PA University Marketing & Computer Internet Trade Inc. University Information System allows SQL Injection. This issue affects University Information System: before… | ||
| CVE-2024-23786 | Cri | 0.61 | 9.3 | 0.01 | Feb 14, 2024 | Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the management page… | ||
| CVE-2024-24691 | Cri | 0.63 | 9.6 | 0.02 | Feb 14, 2024 | Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access. | ||
| CVE-2024-24142 | Cri | 0.64 | 9.8 | 0.01 | Feb 13, 2024 | Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter. | ||
| CVE-2024-1378 | Cri | 0.59 | 9.1 | 0.02 | Feb 13, 2024 | A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via nomad templates when configuring SMTP options. Exploitation of this vulnerability… | ||
| CVE-2024-1374 | Cri | 0.59 | 9.1 | 0.03 | Feb 13, 2024 | A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via nomad templates when configuring audit log forwarding. Exploitation of this… | ||
| CVE-2024-1372 | Cri | 0.59 | 9.1 | 0.02 | Feb 13, 2024 | A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when configuring SAML settings. Exploitation of this vulnerability required access to the… | ||
| CVE-2024-1369 | Cri | 0.59 | 9.1 | 0.02 | Feb 13, 2024 | A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when setting the username and password for collectd configurations. Exploitation of this… | ||
| CVE-2024-1359 | Cri | 0.59 | 9.1 | 0.02 | Feb 13, 2024 | A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when setting up an HTTP proxy. Exploitation of this vulnerability required access to the… | ||
| CVE-2024-1355 | Cri | 0.59 | 9.1 | 0.02 | Feb 13, 2024 | A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via the actions-console docker container while setting a service URL. Exploitation of… | ||
| CVE-2024-21413 | Cri | 0.83 | 9.8 | 0.95 | KEV | Feb 13, 2024 | Microsoft Outlook Remote Code Execution Vulnerability | |
| CVE-2024-21410 | Cri | 0.77 | 9.8 | 0.13 | KEV | Feb 13, 2024 | Microsoft Exchange Server Elevation of Privilege Vulnerability | |
| CVE-2024-21403 | Cri | 0.59 | 9.0 | 0.01 | Feb 13, 2024 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | ||
| CVE-2024-21401 | Cri | 0.64 | 9.8 | 0.01 | Feb 13, 2024 | Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability | ||
| CVE-2024-21376 | Cri | 0.59 | 9.0 | 0.01 | Feb 13, 2024 | Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability | ||
| CVE-2024-21364 | Cri | 0.60 | 9.3 | 0.01 | Feb 13, 2024 | Microsoft Azure Site Recovery Elevation of Privilege Vulnerability | ||
| CVE-2024-22923 | Cri | 0.64 | 9.8 | 0.01 | Feb 13, 2024 | SQL injection vulnerability in adv radius v.2.2.5 allows a local attacker to execute arbitrary code via a crafted script. | ||
| CVE-2024-23816 | Cri | 0.64 | 9.8 | 0.01 | Feb 13, 2024 | A vulnerability has been identified in Location Intelligence Perpetual Large (9DE5110-8CA13-1AX0) (All versions < V4.3), Location Intelligence Perpetual Medium (9DE5110-8CA12-1AX0) (All versions < V4.3), Location Intelligence Perpetual Non-Prod (9DE5110-8CA10-1AX0) (All versions… | ||
| CVE-2022-48623 | Cri | 0.00 | 9.1 | 0.01 | Feb 13, 2024 | The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensitive information or cause a denial of service. | ||
| CVE-2024-22131 | Cri | 0.59 | 9.1 | 0.01 | Feb 13, 2024 | In SAP ABA (Application Basis) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75I, an attacker authenticated as a user with a remote execution authorization can use a vulnerable interface. This allows the attacker to use the interface to invoke an application function… | ||
| CVE-2023-42374 | Cri | 0.00 | 9.8 | 0.01 | Feb 13, 2024 | An issue in mystenlabs Sui Blockchain before v.1.6.3 allow a remote attacker to execute arbitrary code and cause a denial of service via a crafted compressed script to the Sui node component. | ||
| CVE-2024-23763 | Cri | 0.64 | 9.8 | 0.01 | Feb 12, 2024 | SQL Injection vulnerability in Gambio through 4.9.2.0 allows attackers to run arbitrary SQL commands via crafted GET request using modifiers[attribute][] parameter. | ||
| CVE-2024-23761 | Cri | 0.64 | 9.8 | 0.01 | Feb 12, 2024 | Server Side Template Injection in Gambio 4.9.2.0 allows attackers to run arbitrary code via crafted smarty email template. | ||
| CVE-2024-23759 | Cri | 0.71 | 9.8 | 0.48 | Feb 12, 2024 | Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function. | ||
| CVE-2024-25110 | Cri | 0.01 | 9.8 | 0.07 | Feb 12, 2024 | The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-after-free issue and if a client called it during connection communication it may cause a remote code execution. Users are advised to… | ||
| CVE-2024-25108 | Cri | 0.57 | 9.9 | 0.01 | Feb 12, 2024 | Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to access far more functionality than users intended, including to the administrative and moderator functionality of the… | ||
| CVE-2023-6036 | Cri | 0.64 | 9.8 | 0.02 | Feb 12, 2024 | The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functions 'handle_auth_request' and 'hadle_login_request'. This makes it possible for non authenticated attackers to log in as any… |
- risk 0.59cvss 9.1epss 0.04
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue…
- risk 0.59cvss 9.1epss 0.01
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into every admin page. Malicious JavaScript may be executed in a victim’s…
- risk 0.64cvss 9.8epss 0.01
Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass authentication mechanisms and gain unauthorized access.…
- risk 0.64cvss 9.8epss 0.01
DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level…
- risk 0.64cvss 9.8epss 0.01
Dell Networking Switches running Enterprise SONiC versions 4.1.0, 4.0.5, 3.5.4 and below contains an improper input validation vulnerability. A remote unauthenticated malicious user may exploit this vulnerability and escalate privileges up to the highest administrative level.…
- risk 0.64cvss 9.8epss 0.02
Dell OS10 Networking Switches running 10.5.2.x and above contain an OS command injection vulnerability when using remote user authentication. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands and…
- risk 0.59cvss 9.1epss 0.01
Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A remote unauthenticated attacker could potentially exploit this vulnerability leading to information disclosure and a possible Denial of Service when a huge…
- risk 0.64cvss 9.8epss 0.00
INPRAX "iZZi connect" application on Android contains hard-coded MQTT queue credentials. The same MQTT queue is used by corresponding physical recuperation devices. Exploiting this vulnerability could potentially allow unauthorized access to manage and read parameters of the…
- risk 0.64cvss 9.8epss 0.04
The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-allocated buffer. While a FreeBSD Wi-Fi client is in scanning mode (i.e., not associated with a SSID) a malicious beacon frame may overwrite kernel memory,…
- risk 0.64cvss 9.8epss 0.01
EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page is accessible without login. This allows remote attackers to inject SQL commands without authentication, enabling them to read, modify, and delete database…
- risk 0.64cvss 9.8epss 0.01
The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put file path in specific request parameters, allowing them to download the file without login. Furthermore, the file will be deleted…
- risk 0.64cvss 9.8epss 0.02
The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inject system commands within specific request parameters. This enables the execution of arbitrary code on the remote server without…
- risk 0.64cvss 9.8epss 0.01
4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardless of how many times a user logs in, the content of the cookie remains unchanged.
- risk 0.64cvss 9.8epss 0.01
Simple Admin Panel App v1.0 was discovered to contain a SQL injection vulnerability via the orderID parameter at /adminView/viewEachOrder.php.
- risk 0.64cvss 9.8epss 0.01
Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the projectID parameter at /TaskManager/EditProject.php.
- risk 0.64cvss 9.8epss 0.01
Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the taskID parameter at /TaskManager/EditTask.php.
- risk 0.64cvss 9.8epss 0.01
Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /omos/?p=products/view_product.
- risk 0.64cvss 9.8epss 0.01
Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the mailud parameter at /aprocess.php.
- risk 0.64cvss 9.8epss 0.01
Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aprocess.php.
- risk 0.64cvss 9.8epss 0.01
An issue in Employee Managment System v1.0 allows attackers to bypass authentication via injecting a crafted payload into the E-mail and Password parameters at /alogin.html.
- risk 0.64cvss 9.8epss 0.01
Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the category parameter at /endpoint/delete_category.php.
- risk 0.64cvss 9.8epss 0.01
Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the expense parameter at /endpoint/delete_expense.php.
- risk 0.64cvss 9.8epss 0.01
Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident parameter at /endpoint/delete-resident.php.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UNI-PA University Marketing & Computer Internet Trade Inc. University Information System allows SQL Injection. This issue affects University Information System: before…
- risk 0.61cvss 9.3epss 0.01
Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the management page…
- risk 0.63cvss 9.6epss 0.02
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter.
- risk 0.59cvss 9.1epss 0.02
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via nomad templates when configuring SMTP options. Exploitation of this vulnerability…
- risk 0.59cvss 9.1epss 0.03
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via nomad templates when configuring audit log forwarding. Exploitation of this…
- risk 0.59cvss 9.1epss 0.02
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when configuring SAML settings. Exploitation of this vulnerability required access to the…
- risk 0.59cvss 9.1epss 0.02
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when setting the username and password for collectd configurations. Exploitation of this…
- risk 0.59cvss 9.1epss 0.02
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when setting up an HTTP proxy. Exploitation of this vulnerability required access to the…
- risk 0.59cvss 9.1epss 0.02
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via the actions-console docker container while setting a service URL. Exploitation of…
- risk 0.83cvss 9.8epss 0.95
Microsoft Outlook Remote Code Execution Vulnerability
- risk 0.77cvss 9.8epss 0.13
Microsoft Exchange Server Elevation of Privilege Vulnerability
- risk 0.59cvss 9.0epss 0.01
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
- risk 0.64cvss 9.8epss 0.01
Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability
- risk 0.59cvss 9.0epss 0.01
Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability
- risk 0.60cvss 9.3epss 0.01
Microsoft Azure Site Recovery Elevation of Privilege Vulnerability
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in adv radius v.2.2.5 allows a local attacker to execute arbitrary code via a crafted script.
- risk 0.64cvss 9.8epss 0.01
A vulnerability has been identified in Location Intelligence Perpetual Large (9DE5110-8CA13-1AX0) (All versions < V4.3), Location Intelligence Perpetual Medium (9DE5110-8CA12-1AX0) (All versions < V4.3), Location Intelligence Perpetual Non-Prod (9DE5110-8CA10-1AX0) (All versions…
- risk 0.00cvss 9.1epss 0.01
The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensitive information or cause a denial of service.
- risk 0.59cvss 9.1epss 0.01
In SAP ABA (Application Basis) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75I, an attacker authenticated as a user with a remote execution authorization can use a vulnerable interface. This allows the attacker to use the interface to invoke an application function…
- risk 0.00cvss 9.8epss 0.01
An issue in mystenlabs Sui Blockchain before v.1.6.3 allow a remote attacker to execute arbitrary code and cause a denial of service via a crafted compressed script to the Sui node component.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Gambio through 4.9.2.0 allows attackers to run arbitrary SQL commands via crafted GET request using modifiers[attribute][] parameter.
- risk 0.64cvss 9.8epss 0.01
Server Side Template Injection in Gambio 4.9.2.0 allows attackers to run arbitrary code via crafted smarty email template.
- risk 0.71cvss 9.8epss 0.48
Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function.
- risk 0.01cvss 9.8epss 0.07
The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-after-free issue and if a client called it during connection communication it may cause a remote code execution. Users are advised to…
- risk 0.57cvss 9.9epss 0.01
Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to access far more functionality than users intended, including to the administrative and moderator functionality of the…
- risk 0.64cvss 9.8epss 0.02
The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functions 'handle_auth_request' and 'hadle_login_request'. This makes it possible for non authenticated attackers to log in as any…