| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-23108 | Cri | 0.71 | 10.0 | 0.78 | Feb 5, 2024 | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests. | ||
| CVE-2021-4436 | Cri | 0.64 | 9.8 | 0.07 | Feb 5, 2024 | The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJAX action , allowing unauthenticated users to upload arbitrary file to the web server. However, there is a .htaccess, preventing… | ||
| CVE-2023-7077 | Cri | 0.64 | 9.8 | 0.01 | Feb 5, 2024 | Sharp NEC Displays (P403, P463, P553, P703, P801, X554UN, X464UN, X554UNS, X464UNV, X474HB, X464UNS, X554UNV, X555UNS, X555UNV, X754HB, X554HB, E705, E805, E905, UN551S, UN551VS, X551UHD, X651UHD, X841UHD, X981UHD, MD551C8) allows an attacker execute remote code by sending… | ||
| CVE-2024-20011 | Cri | 0.64 | 9.8 | 0.00 | Feb 5, 2024 | In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08441146; Issue ID: ALPS08441146. | ||
| CVE-2024-25089 | Cri | 0.64 | 9.8 | 0.02 | Feb 4, 2024 | Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes. | ||
| CVE-2020-36773 | Cri | 0.57 | 9.8 | 0.01 | Feb 4, 2024 | Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature). | ||
| CVE-2024-24029 | Cri | 0.64 | 9.8 | 0.01 | Feb 2, 2024 | JFinalCMS 5.0.0 is vulnerable to SQL injection via /admin/content/data. | ||
| CVE-2024-22108 | Cri | 0.64 | 9.8 | 0.01 | Feb 2, 2024 | An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method setTermsHashAction at /opt/webapp/lib/PureApi/CCApi.class.php is vulnerable to an unauthenticated SQL injection via /ccapi.php that an attacker can abuse in order to change the Administrator password to… | ||
| CVE-2023-45025 | Cri | 0.59 | 9.0 | 0.01 | Feb 2, 2024 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build… | ||
| CVE-2022-34381 | Cri | 0.59 | 9.1 | 0.01 | Feb 2, 2024 | Dell BSAFE SSL-J version 7.0 and all versions prior to 6.5, and Dell BSAFE Crypto-J versions prior to 6.2.6.1 contain an unmaintained third-party component vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to the compromise… | ||
| CVE-2023-6675 | Cri | 0.64 | 9.8 | 0.01 | Feb 2, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in National Keep Cyber Security Services CyberMath allows Upload a Web Shell to a Web Server. This issue affects CyberMath: from v.1.4 before v.1.5. | ||
| CVE-2023-47143 | Cri | 0.65 | 10.0 | 0.01 | Feb 2, 2024 | IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including… | ||
| CVE-2023-50488 | Cri | 0.64 | 9.8 | 0.01 | Feb 2, 2024 | An issue in Blurams Lumi Security Camera (A31C) v23.0406.435.4120 allows attackers to execute arbitrary code. | ||
| CVE-2024-23978 | Cri | 0.64 | 9.8 | 0.01 | Feb 2, 2024 | Heap-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. By processing invalid values, arbitrary code may be executed. Note that the affected products are no longer supported. | ||
| CVE-2024-1143 | Cri | 0.53 | 9.3 | 0.00 | Feb 2, 2024 | Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of user sessions and subsequent authentication bypass. | ||
| CVE-2024-24482 | Cri | 0.64 | 9.8 | 0.01 | Feb 2, 2024 | Aprktool before 2.9.3 on Windows allows ../ and /.. directory traversal. | ||
| CVE-2024-22533 | Cri | 0.64 | 9.8 | 0.01 | Feb 2, 2024 | Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the DefaultNativeSecurityManager blacklist. Because blacklist filtering is not strict, the blacklist can be… | ||
| CVE-2024-22320 | Cri | 0.70 | 9.8 | 0.73 | Feb 2, 2024 | IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code in the… | ||
| CVE-2024-23746 | Cri | 0.64 | 9.8 | 0.01 | Feb 2, 2024 | Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in some environments (bypass a kTCCServiceSystemPolicyAppBundles requirement via a file copy, an app.app/Contents rename, an asar modification, and a rename back… | ||
| CVE-2024-22902 | Cri | 0.64 | 9.8 | 0.01 | Feb 2, 2024 | Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials. | ||
| CVE-2024-22901 | Cri | 0.64 | 9.8 | 0.01 | Feb 2, 2024 | Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials. | ||
| CVE-2023-48793 | Cri | 0.64 | 9.8 | 0.07 | Feb 2, 2024 | Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature. | ||
| CVE-2023-48792 | Cri | 0.64 | 9.8 | 0.07 | Feb 2, 2024 | Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option. | ||
| CVE-2024-21764 | Cri | 0.64 | 9.8 | 0.01 | Feb 2, 2024 | In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may allow an attacker to connect to a specific port. | ||
| CVE-2023-49617 | Cri | 0.65 | 10.0 | 0.01 | Feb 1, 2024 | The MachineSense application programmable interface (API) is improperly protected and can be accessed without authentication. A remote attacker could retrieve and modify sensitive information without any authentication. | ||
| CVE-2023-46706 | Cri | 0.59 | 9.1 | 0.01 | Feb 1, 2024 | Multiple MachineSense devices have credentials unable to be changed by the user or administrator. | ||
| CVE-2024-1039 | Cri | 0.64 | 9.8 | 0.01 | Feb 1, 2024 | Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management of the device. | ||
| CVE-2023-4472 | Cri | 0.64 | 9.8 | 0.01 | Feb 1, 2024 | Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which could lead to an unauthenticated account takeover of any user on the application. | ||
| CVE-2023-5841 | Cri | 0.59 | 9.1 | 0.01 | Feb 1, 2024 | Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved… | ||
| CVE-2024-24561 | Cri | 0.64 | 9.8 | 0.01 | Feb 1, 2024 | Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In versions 0.3.10 and earlier, the bounds check for slices does not account for the ability for start + length to overflow when the values aren't literals. If a slice() function uses a non-literal… | ||
| CVE-2024-23832 | Cri | 0.00 | 9.4 | 0.02 | Feb 1, 2024 | Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account. Every Mastodon version prior to… | ||
| CVE-2024-23653 | Cri | 0.57 | 9.8 | 0.03 | Jan 31, 2024 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running containers as build steps, BuildKit also provides APIs for running interactive containers based on built images. It was possible to use… | ||
| CVE-2024-23652 | Cri | 0.58 | 10.0 | 0.02 | Jan 31, 2024 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file… | ||
| CVE-2022-47072 | Cri | 0.64 | 9.8 | 0.01 | Jan 31, 2024 | SQL injection vulnerability in Enterprise Architect 16.0.1605 32-bit allows attackers to run arbitrary SQL commands via the Find parameter in the Select Classifier dialog box.. | ||
| CVE-2024-21917 | Cri | 0.64 | 9.8 | 0.01 | Jan 31, 2024 | A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authentication on another FTSP directory. This is due to the lack of digital signing between the FTSP service token and directory.… | ||
| CVE-2024-23745 | Cri | 0.64 | 9.8 | 0.02 | Jan 31, 2024 | In Notion Web Clipper 1.0.3(7), a .nib file is susceptible to the Dirty NIB attack. NIB files can be manipulated to execute arbitrary commands. Additionally, even if a NIB file is modified within an application, Gatekeeper may still permit the execution of the application,… | ||
| CVE-2023-5389 | Cri | 0.59 | 9.1 | 0.01 | Jan 30, 2024 | An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC . This exploit could be used to write a file that may result in unexpected behavior based on configuration changes… | ||
| CVE-2024-24333 | Cri | 0.64 | 9.8 | 0.02 | Jan 30, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc parameter in the setWiFiAclRules function. | ||
| CVE-2024-24332 | Cri | 0.64 | 9.8 | 0.02 | Jan 30, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the url parameter in the setUrlFilterRules function. | ||
| CVE-2024-24331 | Cri | 0.64 | 9.8 | 0.02 | Jan 30, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setWiFiScheduleCfg function. | ||
| CVE-2024-24330 | Cri | 0.64 | 9.8 | 0.02 | Jan 30, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the port or enable parameter in the setRemoteCfg function. | ||
| CVE-2024-24329 | Cri | 0.64 | 9.8 | 0.06 | Jan 30, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRules function. | ||
| CVE-2024-24328 | Cri | 0.64 | 9.8 | 0.06 | Jan 30, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setMacFilterRules function. | ||
| CVE-2024-24327 | Cri | 0.64 | 9.8 | 0.02 | Jan 30, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the setIpv6Cfg function. | ||
| CVE-2024-24326 | Cri | 0.64 | 9.8 | 0.02 | Jan 30, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable parameter in the setStaticDhcpRules function. | ||
| CVE-2024-24325 | Cri | 0.64 | 9.8 | 0.02 | Jan 30, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setParentalRules function. | ||
| CVE-2024-24324 | Cri | 0.64 | 9.8 | 0.01 | Jan 30, 2024 | TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow. | ||
| CVE-2023-6943 | Cri | 0.64 | 9.8 | 0.02 | Jan 30, 2024 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GOT1000) versions 1.325P and prior, GT Designer3 Version1(GOT2000) versions 1.320J and prior,… | ||
| CVE-2023-51982 | Cri | 0.57 | 9.8 | 0.01 | Jan 30, 2024 | CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After configuring password authentication and_ Local_ In the case of an address, identity authentication can be bypassed by setting the X-Real IP request header to a specific value and… | ||
| CVE-2023-51837 | Cri | 0.64 | 9.8 | 0.00 | Jan 30, 2024 | Ylianst MeshCentral 1.1.16 is vulnerable to Missing SSL Certificate Validation. |
- risk 0.71cvss 10.0epss 0.78
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.
- risk 0.64cvss 9.8epss 0.07
The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJAX action , allowing unauthenticated users to upload arbitrary file to the web server. However, there is a .htaccess, preventing…
- risk 0.64cvss 9.8epss 0.01
Sharp NEC Displays (P403, P463, P553, P703, P801, X554UN, X464UN, X554UNS, X464UNV, X474HB, X464UNS, X554UNV, X555UNS, X555UNV, X754HB, X554HB, E705, E805, E905, UN551S, UN551VS, X551UHD, X651UHD, X841UHD, X981UHD, MD551C8) allows an attacker execute remote code by sending…
- risk 0.64cvss 9.8epss 0.00
In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08441146; Issue ID: ALPS08441146.
- risk 0.64cvss 9.8epss 0.02
Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes.
- risk 0.57cvss 9.8epss 0.01
Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).
- risk 0.64cvss 9.8epss 0.01
JFinalCMS 5.0.0 is vulnerable to SQL injection via /admin/content/data.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method setTermsHashAction at /opt/webapp/lib/PureApi/CCApi.class.php is vulnerable to an unauthenticated SQL injection via /ccapi.php that an attacker can abuse in order to change the Administrator password to…
- risk 0.59cvss 9.0epss 0.01
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build…
- risk 0.59cvss 9.1epss 0.01
Dell BSAFE SSL-J version 7.0 and all versions prior to 6.5, and Dell BSAFE Crypto-J versions prior to 6.2.6.1 contain an unmaintained third-party component vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to the compromise…
- risk 0.64cvss 9.8epss 0.01
Unrestricted Upload of File with Dangerous Type vulnerability in National Keep Cyber Security Services CyberMath allows Upload a Web Shell to a Web Server. This issue affects CyberMath: from v.1.4 before v.1.5.
- risk 0.65cvss 10.0epss 0.01
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including…
- risk 0.64cvss 9.8epss 0.01
An issue in Blurams Lumi Security Camera (A31C) v23.0406.435.4120 allows attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. By processing invalid values, arbitrary code may be executed. Note that the affected products are no longer supported.
- risk 0.53cvss 9.3epss 0.00
Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of user sessions and subsequent authentication bypass.
- risk 0.64cvss 9.8epss 0.01
Aprktool before 2.9.3 on Windows allows ../ and /.. directory traversal.
- risk 0.64cvss 9.8epss 0.01
Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the DefaultNativeSecurityManager blacklist. Because blacklist filtering is not strict, the blacklist can be…
- risk 0.70cvss 9.8epss 0.73
IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code in the…
- risk 0.64cvss 9.8epss 0.01
Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in some environments (bypass a kTCCServiceSystemPolicyAppBundles requirement via a file copy, an app.app/Contents rename, an asar modification, and a rename back…
- risk 0.64cvss 9.8epss 0.01
Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.
- risk 0.64cvss 9.8epss 0.01
Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.
- risk 0.64cvss 9.8epss 0.07
Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature.
- risk 0.64cvss 9.8epss 0.07
Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option.
- risk 0.64cvss 9.8epss 0.01
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may allow an attacker to connect to a specific port.
- risk 0.65cvss 10.0epss 0.01
The MachineSense application programmable interface (API) is improperly protected and can be accessed without authentication. A remote attacker could retrieve and modify sensitive information without any authentication.
- risk 0.59cvss 9.1epss 0.01
Multiple MachineSense devices have credentials unable to be changed by the user or administrator.
- risk 0.64cvss 9.8epss 0.01
Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management of the device.
- risk 0.64cvss 9.8epss 0.01
Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which could lead to an unauthenticated account takeover of any user on the application.
- risk 0.59cvss 9.1epss 0.01
Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved…
- risk 0.64cvss 9.8epss 0.01
Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In versions 0.3.10 and earlier, the bounds check for slices does not account for the ability for start + length to overflow when the values aren't literals. If a slice() function uses a non-literal…
- risk 0.00cvss 9.4epss 0.02
Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account. Every Mastodon version prior to…
- risk 0.57cvss 9.8epss 0.03
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running containers as build steps, BuildKit also provides APIs for running interactive containers based on built images. It was possible to use…
- risk 0.58cvss 10.0epss 0.02
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file…
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in Enterprise Architect 16.0.1605 32-bit allows attackers to run arbitrary SQL commands via the Find parameter in the Select Classifier dialog box..
- risk 0.64cvss 9.8epss 0.01
A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authentication on another FTSP directory. This is due to the lack of digital signing between the FTSP service token and directory.…
- risk 0.64cvss 9.8epss 0.02
In Notion Web Clipper 1.0.3(7), a .nib file is susceptible to the Dirty NIB attack. NIB files can be manipulated to execute arbitrary commands. Additionally, even if a NIB file is modified within an application, Gatekeeper may still permit the execution of the application,…
- risk 0.59cvss 9.1epss 0.01
An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC . This exploit could be used to write a file that may result in unexpected behavior based on configuration changes…
- risk 0.64cvss 9.8epss 0.02
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc parameter in the setWiFiAclRules function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the url parameter in the setUrlFilterRules function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setWiFiScheduleCfg function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the port or enable parameter in the setRemoteCfg function.
- risk 0.64cvss 9.8epss 0.06
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRules function.
- risk 0.64cvss 9.8epss 0.06
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setMacFilterRules function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the setIpv6Cfg function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable parameter in the setStaticDhcpRules function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setParentalRules function.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.
- risk 0.64cvss 9.8epss 0.02
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GOT1000) versions 1.325P and prior, GT Designer3 Version1(GOT2000) versions 1.320J and prior,…
- risk 0.57cvss 9.8epss 0.01
CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After configuring password authentication and_ Local_ In the case of an address, identity authentication can be bypassed by setting the X-Real IP request header to a specific value and…
- risk 0.64cvss 9.8epss 0.00
Ylianst MeshCentral 1.1.16 is vulnerable to Missing SSL Certificate Validation.