| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-27962 | Cri | 0.64 | 9.8 | 0.01 | May 3, 2022 | Bluecms 1.6 has a SQL injection vulnerability at cooike. | ||
| CVE-2022-28561 | Cri | 0.64 | 9.8 | 0.10 | May 3, 2022 | There is a stack overflow vulnerability in the /goform/setMacFilterCfg function in the httpd service of Tenda ax12 22.03.01.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload | ||
| CVE-2022-28560 | Cri | 0.64 | 9.8 | 0.02 | May 3, 2022 | There is a stack overflow vulnerability in the goform/fast_setting_wifi_set function in the httpd service of Tenda ac9 15.03.2.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload | ||
| CVE-2022-28118 | — | Cri | 0.64 | 9.8 | 0.03 | May 3, 2022 | SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in. | |
| CVE-2020-23621 | Cri | 0.64 | 9.8 | 0.02 | May 2, 2022 | The Java Remote Management Interface of all versions of SVI MS Management System was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object. | ||
| CVE-2020-23620 | Cri | 0.64 | 9.8 | 0.02 | May 2, 2022 | The Java Remote Management Interface of all versions of Orlansoft ERP was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object. | ||
| CVE-2022-1378 | Cri | 0.65 | 9.8 | 0.19 | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_pgHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands. | ||
| CVE-2022-1377 | Cri | 0.64 | 9.8 | 0.01 | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_rltHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands. | ||
| CVE-2022-1376 | Cri | 0.64 | 9.8 | 0.01 | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_privgrpHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands. | ||
| CVE-2022-1375 | Cri | 0.64 | 9.8 | 0.01 | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_slogHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands. | ||
| CVE-2022-1374 | Cri | 0.64 | 9.8 | 0.01 | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_unHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands. | ||
| CVE-2022-1372 | Cri | 0.64 | 9.8 | 0.01 | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in dlSlog.aspx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands. | ||
| CVE-2022-1371 | Cri | 0.64 | 9.8 | 0.01 | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegf. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands. | ||
| CVE-2022-1370 | Cri | 0.64 | 9.8 | 0.01 | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadREGbyID. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands. | ||
| CVE-2022-1369 | Cri | 0.64 | 9.8 | 0.01 | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegIND. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands. | ||
| CVE-2022-1367 | Cri | 0.65 | 9.8 | 0.19 | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handler_TCV.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands. | ||
| CVE-2021-3643 | Cri | 0.59 | 9.1 | 0.02 | May 2, 2022 | A flaw was found in sox 14.4.1. The lsx_adpcm_init function within libsox leads to a global-buffer-overflow. This flaw allows an attacker to input a malicious file, leading to the disclosure of sensitive information. | ||
| CVE-2022-1366 | Cri | 0.65 | 9.8 | 0.19 | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerChart.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands. | ||
| CVE-2022-1281 | Cri | 0.66 | 9.8 | 0.23 | May 2, 2022 | The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible. | ||
| CVE-2022-0783 | Cri | 0.64 | 9.8 | 0.08 | May 2, 2022 | The Multiple Shipping Address Woocommerce WordPress plugin before 2.0 does not properly sanitise and escape numerous parameters before using them in SQL statements via some AJAX actions available to unauthenticated users, leading to unauthenticated SQL injections | ||
| CVE-2022-0773 | Cri | 0.67 | 9.8 | 0.43 | May 2, 2022 | The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then executed, leading to an SQL Injection exploitable by unauthenticated users. | ||
| CVE-2022-0771 | Cri | 0.64 | 9.8 | 0.02 | May 2, 2022 | The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before using them in SQL statements via AJAX actions (available to both unauthenticated and authenticated users), leading to Unauthenticated SQL Injections | ||
| CVE-2022-28573 | Cri | 0.66 | 9.8 | 0.28 | May 2, 2022 | D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNTPserverSeting. This vulnerability allows attackers to execute arbitrary commands via the system_time_timezone parameter. | ||
| CVE-2022-28056 | — | Cri | 0.64 | 9.8 | 0.01 | May 2, 2022 | ShopXO v2.2.5 and below was discovered to contain a system re-install vulnerability via the Add function in app/install/controller/Index.php. | |
| CVE-2022-28054 | Cri | 0.66 | 9.8 | 0.31 | May 2, 2022 | Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execute arbitrary code via a crafted value. | ||
| CVE-2022-27982 | Cri | 0.64 | 9.8 | 0.02 | May 2, 2022 | RG-NBR-E Enterprise Gateway RG-NBR2100G-E was discovered to contain a remote code execution (RCE) vulnerability via the fileName parameter at /guest_auth/cfg/upLoadCfg.php. | ||
| CVE-2022-27466 | Cri | 0.64 | 9.8 | 0.02 | May 2, 2022 | MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do. | ||
| CVE-2022-28571 | Cri | 0.64 | 9.8 | 0.06 | May 2, 2022 | D-link 882 DIR882A1_FW130B06 was discovered to contain a command injection vulnerability in`/usr/bin/cli. | ||
| CVE-2022-1300 | Cri | 0.64 | 9.8 | 0.01 | May 2, 2022 | Multiple Version of TRUMPF TruTops products expose a service function without necessary authentication. Execution of this function may result in unauthorized access to change of data or disruption of the whole service. | ||
| CVE-2022-25767 | — | Cri | 0.64 | 9.8 | 0.03 | May 1, 2022 | All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets. | |
| CVE-2022-24437 | — | Cri | 0.57 | 9.8 | 0.04 | May 1, 2022 | The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack feature of git which is also supported for git clone. The source includes the use of the secure child process API spawn(). However, the outpath parameter passed to… | |
| CVE-2022-28481 | — | Cri | 0.57 | 9.8 | 0.02 | May 1, 2022 | CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection. | |
| CVE-2022-28994 | Cri | 0.64 | 9.8 | 0.02 | Apr 29, 2022 | Small HTTP Server version 3.06 suffers from a remote buffer overflow vulnerability via long GET request. | ||
| CVE-2022-28480 | Cri | 0.64 | 9.8 | 0.02 | Apr 29, 2022 | ALLMediaServer 1.6 is vulnerable to Buffer Overflow via MediaServer.exe. | ||
| CVE-2022-28452 | Cri | 0.65 | 9.8 | 0.17 | Apr 29, 2022 | Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection. | ||
| CVE-2022-24900 | Cri | 0.01 | 9.9 | 0.08 | Apr 29, 2022 | Piano LED Visualizer is software that allows LED lights to light up as a person plays a piano connected to a computer. Version 1.3 and prior are vulnerable to a path traversal attack. The `os.path.join` call is unsafe for use with untrusted input. When the `os.path.join` call… | ||
| CVE-2021-44596 | Cri | 0.68 | 9.8 | 0.23 | Apr 29, 2022 | Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can communicate over UDP with the "InstallAssistService.exe" service(the service is running under SYSTEM privileges) and manipulate it to… | ||
| CVE-2022-1531 | Cri | 0.00 | 9.8 | 0.04 | Apr 29, 2022 | SQL injection vulnerability in ARAX-UI Synonym Lookup functionality in GitHub repository rtxteam/rtx prior to checkpoint_2022-04-20 . This vulnerability is critical as it can lead to remote code execution and thus complete server takeover. | ||
| CVE-2022-29906 | Cri | 0.64 | 9.8 | 0.01 | Apr 29, 2022 | The admin API module in the QuizGame extension for MediaWiki through 1.37.2 (before 665e33a68f6fa1167df99c0aa18ed0157cdf9f66) omits a check for the quizadmin user. | ||
| CVE-2022-29904 | Cri | 0.65 | 9.8 | 0.17 | Apr 29, 2022 | The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain '-' and '_' constraints. | ||
| CVE-2022-24449 | Cri | 0.64 | 9.8 | 0.02 | Apr 28, 2022 | Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML document. | ||
| CVE-2022-29556 | Cri | 0.64 | 9.8 | 0.01 | Apr 28, 2022 | The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several SSRF primitives that can execute cross-tenant actions via internal API endpoints. | ||
| CVE-2022-29081 | Cri | 0.70 | 9.8 | 0.84 | Apr 28, 2022 | Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via… | ||
| CVE-2022-28114 | Cri | 0.59 | 9.1 | 0.01 | Apr 28, 2022 | DSCMS v3.0 was discovered to contain an arbitrary file deletion vulnerability via /controller/Adv.php. | ||
| CVE-2021-43934 | Cri | 0.64 | 9.8 | 0.01 | Apr 28, 2022 | Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate upload requests, enabling a malicious user to potentially upload arbitrary files. | ||
| CVE-2021-43932 | Cri | 0.59 | 9.0 | 0.01 | Apr 28, 2022 | Elcomplus SmartPTT is vulnerable when an attacker injects JavaScript code into a specific parameter that can executed upon accessing the dashboard or the main page. | ||
| CVE-2022-28101 | Cri | 0.59 | 9.0 | 0.01 | Apr 28, 2022 | Turtlapp Turtle Note v0.7.2.6 does not filter the tag during markdown parsing, allowing attackers to execute HTML injection. | ||
| CVE-2021-41945 | — | Cri | 0.52 | 9.1 | 0.02 | Apr 28, 2022 | Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`. | |
| CVE-2021-41921 | Cri | 0.64 | 9.8 | 0.02 | Apr 28, 2022 | novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution. | ||
| CVE-2022-1509 | Cri | 0.00 | 9.9 | 0.05 | Apr 28, 2022 | Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context. |
- risk 0.64cvss 9.8epss 0.01
Bluecms 1.6 has a SQL injection vulnerability at cooike.
- risk 0.64cvss 9.8epss 0.10
There is a stack overflow vulnerability in the /goform/setMacFilterCfg function in the httpd service of Tenda ax12 22.03.01.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload
- risk 0.64cvss 9.8epss 0.02
There is a stack overflow vulnerability in the goform/fast_setting_wifi_set function in the httpd service of Tenda ac9 15.03.2.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload
- risk 0.64cvss 9.8epss 0.03
SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.
- risk 0.64cvss 9.8epss 0.02
The Java Remote Management Interface of all versions of SVI MS Management System was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object.
- risk 0.64cvss 9.8epss 0.02
The Java Remote Management Interface of all versions of Orlansoft ERP was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object.
- risk 0.65cvss 9.8epss 0.19
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_pgHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
- risk 0.64cvss 9.8epss 0.01
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_rltHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
- risk 0.64cvss 9.8epss 0.01
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_privgrpHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
- risk 0.64cvss 9.8epss 0.01
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_slogHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
- risk 0.64cvss 9.8epss 0.01
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_unHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
- risk 0.64cvss 9.8epss 0.01
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in dlSlog.aspx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
- risk 0.64cvss 9.8epss 0.01
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegf. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
- risk 0.64cvss 9.8epss 0.01
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadREGbyID. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
- risk 0.64cvss 9.8epss 0.01
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegIND. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
- risk 0.65cvss 9.8epss 0.19
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handler_TCV.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
- risk 0.59cvss 9.1epss 0.02
A flaw was found in sox 14.4.1. The lsx_adpcm_init function within libsox leads to a global-buffer-overflow. This flaw allows an attacker to input a malicious file, leading to the disclosure of sensitive information.
- risk 0.65cvss 9.8epss 0.19
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerChart.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
- risk 0.66cvss 9.8epss 0.23
The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible.
- risk 0.64cvss 9.8epss 0.08
The Multiple Shipping Address Woocommerce WordPress plugin before 2.0 does not properly sanitise and escape numerous parameters before using them in SQL statements via some AJAX actions available to unauthenticated users, leading to unauthenticated SQL injections
- risk 0.67cvss 9.8epss 0.43
The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then executed, leading to an SQL Injection exploitable by unauthenticated users.
- risk 0.64cvss 9.8epss 0.02
The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before using them in SQL statements via AJAX actions (available to both unauthenticated and authenticated users), leading to Unauthenticated SQL Injections
- risk 0.66cvss 9.8epss 0.28
D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNTPserverSeting. This vulnerability allows attackers to execute arbitrary commands via the system_time_timezone parameter.
- risk 0.64cvss 9.8epss 0.01
ShopXO v2.2.5 and below was discovered to contain a system re-install vulnerability via the Add function in app/install/controller/Index.php.
- risk 0.66cvss 9.8epss 0.31
Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execute arbitrary code via a crafted value.
- risk 0.64cvss 9.8epss 0.02
RG-NBR-E Enterprise Gateway RG-NBR2100G-E was discovered to contain a remote code execution (RCE) vulnerability via the fileName parameter at /guest_auth/cfg/upLoadCfg.php.
- risk 0.64cvss 9.8epss 0.02
MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do.
- risk 0.64cvss 9.8epss 0.06
D-link 882 DIR882A1_FW130B06 was discovered to contain a command injection vulnerability in`/usr/bin/cli.
- risk 0.64cvss 9.8epss 0.01
Multiple Version of TRUMPF TruTops products expose a service function without necessary authentication. Execution of this function may result in unauthorized access to change of data or disruption of the whole service.
- risk 0.64cvss 9.8epss 0.03
All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets.
- risk 0.57cvss 9.8epss 0.04
The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack feature of git which is also supported for git clone. The source includes the use of the secure child process API spawn(). However, the outpath parameter passed to…
- risk 0.57cvss 9.8epss 0.02
CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection.
- risk 0.64cvss 9.8epss 0.02
Small HTTP Server version 3.06 suffers from a remote buffer overflow vulnerability via long GET request.
- risk 0.64cvss 9.8epss 0.02
ALLMediaServer 1.6 is vulnerable to Buffer Overflow via MediaServer.exe.
- risk 0.65cvss 9.8epss 0.17
Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.
- risk 0.01cvss 9.9epss 0.08
Piano LED Visualizer is software that allows LED lights to light up as a person plays a piano connected to a computer. Version 1.3 and prior are vulnerable to a path traversal attack. The `os.path.join` call is unsafe for use with untrusted input. When the `os.path.join` call…
- risk 0.68cvss 9.8epss 0.23
Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can communicate over UDP with the "InstallAssistService.exe" service(the service is running under SYSTEM privileges) and manipulate it to…
- risk 0.00cvss 9.8epss 0.04
SQL injection vulnerability in ARAX-UI Synonym Lookup functionality in GitHub repository rtxteam/rtx prior to checkpoint_2022-04-20 . This vulnerability is critical as it can lead to remote code execution and thus complete server takeover.
- risk 0.64cvss 9.8epss 0.01
The admin API module in the QuizGame extension for MediaWiki through 1.37.2 (before 665e33a68f6fa1167df99c0aa18ed0157cdf9f66) omits a check for the quizadmin user.
- risk 0.65cvss 9.8epss 0.17
The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain '-' and '_' constraints.
- risk 0.64cvss 9.8epss 0.02
Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML document.
- risk 0.64cvss 9.8epss 0.01
The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several SSRF primitives that can execute cross-tenant actions via internal API endpoints.
- risk 0.70cvss 9.8epss 0.84
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via…
- risk 0.59cvss 9.1epss 0.01
DSCMS v3.0 was discovered to contain an arbitrary file deletion vulnerability via /controller/Adv.php.
- risk 0.64cvss 9.8epss 0.01
Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate upload requests, enabling a malicious user to potentially upload arbitrary files.
- risk 0.59cvss 9.0epss 0.01
Elcomplus SmartPTT is vulnerable when an attacker injects JavaScript code into a specific parameter that can executed upon accessing the dashboard or the main page.
- risk 0.59cvss 9.0epss 0.01
Turtlapp Turtle Note v0.7.2.6 does not filter the tag during markdown parsing, allowing attackers to execute HTML injection.
- risk 0.52cvss 9.1epss 0.02
Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`.
- risk 0.64cvss 9.8epss 0.02
novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution.
- risk 0.00cvss 9.9epss 0.05
Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.