| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-28035 | Cri | 0.64 | 9.8 | 0.01 | Apr 12, 2022 | Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_blur-save.php | ||
| CVE-2022-28034 | Cri | 0.64 | 9.8 | 0.01 | Apr 12, 2022 | AtomCMS 2.0 is vulnerabie to SQL Injection via Atom.CMS_admin_ajax_list-sort.php | ||
| CVE-2022-28033 | Cri | 0.64 | 9.8 | 0.05 | Apr 12, 2022 | Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php | ||
| CVE-2022-28032 | Cri | 0.64 | 9.8 | 0.06 | Apr 12, 2022 | AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.php | ||
| CVE-2022-27473 | Cri | 0.64 | 9.8 | 0.01 | Apr 12, 2022 | SQL injection vulnerability in Topics Searching feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitrary SQL commands via the "s" parameter remotely. | ||
| CVE-2022-27472 | Cri | 0.64 | 9.8 | 0.01 | Apr 12, 2022 | SQL injection vulnerability in Topics Counting feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitrary SQL commands via the "s" parameter remotely. | ||
| CVE-2022-27165 | Cri | 0.64 | 9.8 | 0.01 | Apr 12, 2022 | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatus | ||
| CVE-2022-27164 | Cri | 0.64 | 9.8 | 0.01 | Apr 12, 2022 | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_viewUsers | ||
| CVE-2022-27163 | Cri | 0.64 | 9.8 | 0.01 | Apr 12, 2022 | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_editUser | ||
| CVE-2022-27162 | Cri | 0.64 | 9.8 | 0.01 | Apr 12, 2022 | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_editUser | ||
| CVE-2022-27161 | Cri | 0.64 | 9.8 | 0.01 | Apr 12, 2022 | Csz Cms 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_viewUsers | ||
| CVE-2021-31805 | Cri | 0.71 | 9.8 | 0.85 | Apr 12, 2022 | The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted… | ||
| CVE-2022-0142 | Cri | 0.64 | 9.8 | 0.03 | Apr 12, 2022 | The Visual Form Builder WordPress plugin before 3.0.8 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible code execution. | ||
| CVE-2022-25752 | Cri | 0.64 | 9.8 | 0.01 | Apr 12, 2022 | A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X302-7 EEC (24V, coated), SCALANCE X302-7 EEC (2x 230V), SCALANCE X302-7 EEC (2x 230V, coated), SCALANCE X302-7 EEC (2x 24V), SCALANCE… | ||
| CVE-2022-23450 | Cri | 0.67 | 9.8 | 0.36 | Apr 12, 2022 | A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). The affected system allows remote users to send maliciously crafted objects. Due to insecure deserialization of… | ||
| CVE-2022-29080 | — | Cri | 0.64 | 9.8 | 0.02 | Apr 12, 2022 | The npm-dependency-versions package through 0.3.0 for Node.js allows command injection if an attacker is able to call dependencyVersions with a JSON object in which pkgs is a key, and there are shell metacharacters in a value. | |
| CVE-2022-28347 | Cri | 0.57 | 9.8 | 0.03 | Apr 12, 2022 | A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion) as the **options argument, and placing the injection payload in an option name. | ||
| CVE-2022-28346 | Cri | 0.58 | 9.8 | 0.19 | Apr 12, 2022 | An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs. | ||
| CVE-2022-27577 | Cri | 0.59 | 9.1 | 0.01 | Apr 11, 2022 | The vulnerability in the MSC800 in all versions before 4.15 allows for an attacker to predict the TCP initial sequence number. When the TCP sequence is predictable, an attacker can send packets that are forged to appear to come from a trusted computer. These forged packets could… | ||
| CVE-2022-22954 | Cri | 0.93 | 9.8 | 1.00 | KEV | Apr 11, 2022 | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution. | |
| CVE-2022-22258 | Cri | 0.64 | 9.8 | 0.01 | Apr 11, 2022 | The Wi-Fi module has an event notification vulnerability.Successful exploitation of this vulnerability may allow third-party applications to intercept event notifications and add information and result in elevation-of-privilege. | ||
| CVE-2022-1161 | Cri | 0.65 | 10.0 | 0.05 | Apr 11, 2022 | An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an… | ||
| CVE-2021-46742 | Cri | 0.59 | 9.1 | 0.01 | Apr 11, 2022 | The multi-window module has a vulnerability of unauthorized insertion and tampering of Settings.Secure data.Successful exploitation of this vulnerability may affect the availability. | ||
| CVE-2021-38125 | Cri | 0.64 | 9.8 | 0.02 | Apr 11, 2022 | Unauthenticated remote code execution in Micro Focus Operations Bridge containerized, affecting versions 2021.05, 2021.08, and newer versions of Micro Focus Operations Bridge containerized if the deployment was upgraded from 2021.05 or 2021.08. The vulnerability could be… | ||
| CVE-2021-37291 | Cri | 0.64 | 9.8 | 0.08 | Apr 11, 2022 | An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php. | ||
| CVE-2022-27115 | Cri | 0.59 | 9.8 | 0.29 | Apr 11, 2022 | In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload. | ||
| CVE-2022-0949 | Cri | 0.64 | 9.8 | 0.08 | Apr 11, 2022 | The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does not properly sanitise and escape the fingerprint parameter before using it in a SQL statement via the stopbadbots_grava_fingerprint AJAX action, available to… | ||
| CVE-2022-1297 | Cri | 0.00 | 9.1 | 0.01 | Apr 11, 2022 | Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash. | ||
| CVE-2022-1296 | Cri | 0.00 | 9.1 | 0.01 | Apr 11, 2022 | Out-of-bounds read in `r_bin_ne_get_relocs` function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash. | ||
| CVE-2022-1295 | — | Cri | 0.57 | 9.8 | 0.01 | Apr 11, 2022 | Prototype Pollution in GitHub repository alvarotrigo/fullpage.js prior to 4.0.2. | |
| CVE-2021-32157 | Cri | 0.63 | 9.6 | 0.04 | Apr 11, 2022 | A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature. | ||
| CVE-2022-27477 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2022 | Newbee-Mall v1.0.0 was discovered to contain an arbitrary file upload via the Upload function at /admin/goods/edit. | ||
| CVE-2022-27277 | Cri | 0.59 | 9.1 | 0.01 | Apr 10, 2022 | InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain an arbitrary file deletion vulnerability via the function sub_17C08. | ||
| CVE-2022-27276 | Cri | 0.64 | 9.8 | 0.03 | Apr 10, 2022 | InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_10F2C. This vulnerability is triggered via a crafted packet. | ||
| CVE-2022-27275 | Cri | 0.64 | 9.8 | 0.03 | Apr 10, 2022 | InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_122D0. This vulnerability is triggered via a crafted packet. | ||
| CVE-2022-27274 | Cri | 0.64 | 9.8 | 0.03 | Apr 10, 2022 | InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_12028. This vulnerability is triggered via a crafted packet. | ||
| CVE-2022-27273 | Cri | 0.64 | 9.8 | 0.03 | Apr 10, 2022 | InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_12168. This vulnerability is triggered via a crafted packet. | ||
| CVE-2022-27272 | Cri | 0.64 | 9.8 | 0.03 | Apr 10, 2022 | InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_1791C. This vulnerability is triggered via a crafted packet. | ||
| CVE-2022-27271 | Cri | 0.64 | 9.8 | 0.03 | Apr 10, 2022 | InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component python-lib. This vulnerability is triggered via a crafted packet. | ||
| CVE-2022-27270 | Cri | 0.64 | 9.8 | 0.03 | Apr 10, 2022 | InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component ipsec_secrets. This vulnerability is triggered via a crafted packet. | ||
| CVE-2022-27269 | Cri | 0.64 | 9.8 | 0.04 | Apr 10, 2022 | InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component config_ovpn. This vulnerability is triggered via a crafted packet. | ||
| CVE-2022-27268 | Cri | 0.64 | 9.8 | 0.04 | Apr 10, 2022 | InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component get_cgi_from_memory. This vulnerability is triggered via a crafted packet. | ||
| CVE-2022-27133 | Cri | 0.59 | 9.1 | 0.01 | Apr 10, 2022 | zbzcms v1.0 was discovered to contain an arbitrary file deletion vulnerability via /include/up.php. | ||
| CVE-2022-27131 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2022 | An arbitrary file upload vulnerability at /zbzedit/php/zbz.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-27129 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2022 | An arbitrary file upload vulnerability at /admin/ajax.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-27128 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2022 | An incorrect access control issue at /admin/run_ajax.php in zbzcms v1.0 allows attackers to arbitrarily add administrator accounts. | ||
| CVE-2022-27126 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2022 | zbzcms v1.0 was discovered to contain a SQL injection vulnerability via the art parameter at /include/make.php. | ||
| CVE-2022-1286 | Cri | 0.00 | 9.8 | 0.01 | Apr 10, 2022 | heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited. | ||
| CVE-2022-1276 | Cri | 0.00 | 9.8 | 0.01 | Apr 10, 2022 | Out-of-bounds Read in mrb_get_args in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited. | ||
| CVE-2022-26851 | Cri | 0.59 | 9.1 | 0.01 | Apr 8, 2022 | Dell PowerScale OneFS, 8.2.2-9.3.x, contains a predictable file name from observable state vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to data loss. |
- risk 0.64cvss 9.8epss 0.01
Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_blur-save.php
- risk 0.64cvss 9.8epss 0.01
AtomCMS 2.0 is vulnerabie to SQL Injection via Atom.CMS_admin_ajax_list-sort.php
- risk 0.64cvss 9.8epss 0.05
Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php
- risk 0.64cvss 9.8epss 0.06
AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.php
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in Topics Searching feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitrary SQL commands via the "s" parameter remotely.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in Topics Counting feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitrary SQL commands via the "s" parameter remotely.
- risk 0.64cvss 9.8epss 0.01
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatus
- risk 0.64cvss 9.8epss 0.01
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_viewUsers
- risk 0.64cvss 9.8epss 0.01
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_editUser
- risk 0.64cvss 9.8epss 0.01
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_editUser
- risk 0.64cvss 9.8epss 0.01
Csz Cms 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_viewUsers
- risk 0.71cvss 9.8epss 0.85
The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted…
- risk 0.64cvss 9.8epss 0.03
The Visual Form Builder WordPress plugin before 3.0.8 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.
- risk 0.64cvss 9.8epss 0.01
A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X302-7 EEC (24V, coated), SCALANCE X302-7 EEC (2x 230V), SCALANCE X302-7 EEC (2x 230V, coated), SCALANCE X302-7 EEC (2x 24V), SCALANCE…
- risk 0.67cvss 9.8epss 0.36
A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). The affected system allows remote users to send maliciously crafted objects. Due to insecure deserialization of…
- risk 0.64cvss 9.8epss 0.02
The npm-dependency-versions package through 0.3.0 for Node.js allows command injection if an attacker is able to call dependencyVersions with a JSON object in which pkgs is a key, and there are shell metacharacters in a value.
- risk 0.57cvss 9.8epss 0.03
A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion) as the **options argument, and placing the injection payload in an option name.
- risk 0.58cvss 9.8epss 0.19
An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.
- risk 0.59cvss 9.1epss 0.01
The vulnerability in the MSC800 in all versions before 4.15 allows for an attacker to predict the TCP initial sequence number. When the TCP sequence is predictable, an attacker can send packets that are forged to appear to come from a trusted computer. These forged packets could…
- risk 0.93cvss 9.8epss 1.00
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.
- risk 0.64cvss 9.8epss 0.01
The Wi-Fi module has an event notification vulnerability.Successful exploitation of this vulnerability may allow third-party applications to intercept event notifications and add information and result in elevation-of-privilege.
- risk 0.65cvss 10.0epss 0.05
An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an…
- risk 0.59cvss 9.1epss 0.01
The multi-window module has a vulnerability of unauthorized insertion and tampering of Settings.Secure data.Successful exploitation of this vulnerability may affect the availability.
- risk 0.64cvss 9.8epss 0.02
Unauthenticated remote code execution in Micro Focus Operations Bridge containerized, affecting versions 2021.05, 2021.08, and newer versions of Micro Focus Operations Bridge containerized if the deployment was upgraded from 2021.05 or 2021.08. The vulnerability could be…
- risk 0.64cvss 9.8epss 0.08
An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.
- risk 0.59cvss 9.8epss 0.29
In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.
- risk 0.64cvss 9.8epss 0.08
The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does not properly sanitise and escape the fingerprint parameter before using it in a SQL statement via the stopbadbots_grava_fingerprint AJAX action, available to…
- risk 0.00cvss 9.1epss 0.01
Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash.
- risk 0.00cvss 9.1epss 0.01
Out-of-bounds read in `r_bin_ne_get_relocs` function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash.
- risk 0.57cvss 9.8epss 0.01
Prototype Pollution in GitHub repository alvarotrigo/fullpage.js prior to 4.0.2.
- risk 0.63cvss 9.6epss 0.04
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.
- risk 0.64cvss 9.8epss 0.01
Newbee-Mall v1.0.0 was discovered to contain an arbitrary file upload via the Upload function at /admin/goods/edit.
- risk 0.59cvss 9.1epss 0.01
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain an arbitrary file deletion vulnerability via the function sub_17C08.
- risk 0.64cvss 9.8epss 0.03
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_10F2C. This vulnerability is triggered via a crafted packet.
- risk 0.64cvss 9.8epss 0.03
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_122D0. This vulnerability is triggered via a crafted packet.
- risk 0.64cvss 9.8epss 0.03
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_12028. This vulnerability is triggered via a crafted packet.
- risk 0.64cvss 9.8epss 0.03
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_12168. This vulnerability is triggered via a crafted packet.
- risk 0.64cvss 9.8epss 0.03
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_1791C. This vulnerability is triggered via a crafted packet.
- risk 0.64cvss 9.8epss 0.03
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component python-lib. This vulnerability is triggered via a crafted packet.
- risk 0.64cvss 9.8epss 0.03
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component ipsec_secrets. This vulnerability is triggered via a crafted packet.
- risk 0.64cvss 9.8epss 0.04
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component config_ovpn. This vulnerability is triggered via a crafted packet.
- risk 0.64cvss 9.8epss 0.04
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component get_cgi_from_memory. This vulnerability is triggered via a crafted packet.
- risk 0.59cvss 9.1epss 0.01
zbzcms v1.0 was discovered to contain an arbitrary file deletion vulnerability via /include/up.php.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability at /zbzedit/php/zbz.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability at /admin/ajax.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.01
An incorrect access control issue at /admin/run_ajax.php in zbzcms v1.0 allows attackers to arbitrarily add administrator accounts.
- risk 0.64cvss 9.8epss 0.01
zbzcms v1.0 was discovered to contain a SQL injection vulnerability via the art parameter at /include/make.php.
- risk 0.00cvss 9.8epss 0.01
heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.
- risk 0.00cvss 9.8epss 0.01
Out-of-bounds Read in mrb_get_args in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.
- risk 0.59cvss 9.1epss 0.01
Dell PowerScale OneFS, 8.2.2-9.3.x, contains a predictable file name from observable state vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to data loss.