| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-4474 | Cri | 0.66 | 9.8 | 0.30 | Nov 30, 2023 | The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL… | ||
| CVE-2023-4473 | Cri | 0.67 | 9.8 | 0.41 | Nov 30, 2023 | A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable… | ||
| CVE-2023-35138 | Cri | 0.67 | 9.8 | 0.40 | Nov 30, 2023 | A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by… | ||
| CVE-2023-3741 | Cri | 0.64 | 9.8 | 0.01 | Nov 30, 2023 | An OS Command injection vulnerability in NEC Platforms DT900 and DT900S Series all versions allows an attacker to execute any command on the device. | ||
| CVE-2023-49693 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2023 | NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticated users, allowing attackers to execute arbitrary code. | ||
| CVE-2022-42541 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2023 | Remote code execution | ||
| CVE-2022-42540 | Cri | 0.64 | 9.8 | 0.00 | Nov 29, 2023 | Elevation of privilege | ||
| CVE-2022-42538 | Cri | 0.64 | 9.8 | 0.00 | Nov 29, 2023 | Elevation of privilege | ||
| CVE-2022-42537 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2023 | Remote code execution | ||
| CVE-2022-42536 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2023 | Remote code execution | ||
| CVE-2023-49079 | Cri | 0.60 | 9.3 | 0.00 | Nov 29, 2023 | Misskey is an open source, decentralized social media platform. Misskey's missing signature validation allows arbitrary users to impersonate any remote user. This issue has been patched in version 2023.11.1-beta.1. | ||
| CVE-2023-49656 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2023 | Jenkins MATLAB Plugin 2.11.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | ||
| CVE-2023-49654 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2023 | Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file from the Jenkins controller file system. | ||
| CVE-2023-6345 | Cri | 0.76 | 9.6 | 0.16 | KEV | Nov 29, 2023 | Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High) | |
| CVE-2023-45484 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2023 | Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWifiGuestBasic. | ||
| CVE-2023-45483 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2023 | Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the time parameter in the function compare_parentcontrol_time. | ||
| CVE-2023-45482 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2023 | Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info. | ||
| CVE-2023-45481 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2023 | Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the firewallEn parameter in the function SetFirewallCfg. | ||
| CVE-2023-45480 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2023 | Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the src parameter in the function sub_47D878. | ||
| CVE-2023-45479 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2023 | Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the list parameter in the function sub_49E098. | ||
| CVE-2023-47462 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2023 | Insecure Permissions vulnerability in GL.iNet AX1800 v.3.215 and before allows a remote attacker to execute arbitrary code via the file sharing function. | ||
| CVE-2023-46886 | Cri | 0.59 | 9.1 | 0.01 | Nov 29, 2023 | Dreamer CMS before version 4.0.1 is vulnerable to Directory Traversal. Background template management allows arbitrary modification of the template file, allowing system sensitive files to be read. | ||
| CVE-2023-23325 | Cri | 0.64 | 9.8 | 0.02 | Nov 29, 2023 | Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain a command injection vulnerability via the NetHostname parameter. | ||
| CVE-2023-23324 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2023 | Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain hardcoded credentials for the Administrator account. | ||
| CVE-2023-48193 | Cri | 0.64 | 9.8 | 0.02 | Nov 28, 2023 | Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassing the command filtering function. NOTE: this is disputed because command filtering is not intended to restrict what code can be run by authorized users… | ||
| CVE-2023-41264 | Cri | 0.64 | 9.8 | 0.01 | Nov 28, 2023 | Netwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on deployment endpoints, leading to privilege escalation. This only occurs if the configuration omits the required restSettings.AuthorizedClientId and… | ||
| CVE-2023-49313 | Cri | 0.64 | 9.8 | 0.01 | Nov 28, 2023 | A dylib injection vulnerability in XMachOViewer 0.04 allows attackers to compromise integrity. By exploiting this, unauthorized code can be injected into the product's processes, potentially leading to remote control and unauthorized access to sensitive user data. | ||
| CVE-2023-48023 | Cri | 0.62 | 9.1 | 0.35 | Nov 28, 2023 | Anyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment | ||
| CVE-2023-48022 | Cri | 0.66 | 9.8 | 0.84 | Nov 28, 2023 | Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network… | ||
| CVE-2023-3545 | Cri | 0.00 | 9.8 | 0.02 | Nov 28, 2023 | Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of `.htaccess` file. This… | ||
| CVE-2023-3533 | Cri | 0.00 | 9.8 | 0.04 | Nov 28, 2023 | Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via arbitrary file write. | ||
| CVE-2023-3368 | Cri | 0.06 | 9.8 | 0.70 | Nov 28, 2023 | Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a bypass of CVE-2023-34960. | ||
| CVE-2023-47503 | Cri | 0.64 | 9.8 | 0.01 | Nov 28, 2023 | An issue in jflyfox jfinalCMS v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the login.jsp component in the template management module. | ||
| CVE-2023-48188 | Cri | 0.64 | 9.8 | 0.01 | Nov 27, 2023 | SQL injection vulnerability in PrestaShop opartdevis v.4.5.18 thru v.4.6.12 allows a remote attacker to execute arbitrary code via a crafted script to the getModuleTranslation function. | ||
| CVE-2023-46480 | Cri | 0.64 | 9.8 | 0.02 | Nov 27, 2023 | An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the authHost parameter of the indieauth function. | ||
| CVE-2023-46349 | Cri | 0.64 | 9.8 | 0.01 | Nov 27, 2023 | In the module "Product Catalog (CSV, Excel) Export/Update" (updateproducts) < 3.8.5 from MyPrestaModules for PrestaShop, a guest can perform SQL injection. The method `productsUpdateModel::getExportIds()` has sensitive SQL calls that can be executed with a trivial http call and… | ||
| CVE-2023-49044 | Cri | 0.64 | 9.8 | 0.01 | Nov 27, 2023 | Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the ssid parameter in the function form_fast_setting_wifi_set. | ||
| CVE-2023-6329 | Cri | 0.72 | 9.8 | 0.65 | Nov 27, 2023 | An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. The login routine used by iDS-Core.dll contains a "passwordCustom" option that allows an unauthenticated attacker to compute valid credentials that can be used to bypass authentication and act as an… | ||
| CVE-2023-5974 | Cri | 0.64 | 9.8 | 0.03 | Nov 27, 2023 | The WPB Show Core WordPress plugin through 2.2 is vulnerable to server-side request forgery (SSRF) via the `path` parameter. | ||
| CVE-2023-5604 | Cri | 0.64 | 9.8 | 0.02 | Nov 27, 2023 | The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially leading to remote code… | ||
| CVE-2023-5559 | Cri | 0.59 | 9.1 | 0.03 | Nov 27, 2023 | The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service. | ||
| CVE-2023-4922 | Cri | 0.65 | 9.8 | 0.16 | Nov 27, 2023 | The WPB Show Core WordPress plugin through 2.2 is vulnerable to a local file inclusion via the `path` parameter. | ||
| CVE-2023-49042 | Cri | 0.64 | 9.8 | 0.01 | Nov 27, 2023 | Heap Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the schedStartTime parameter or the schedEndTime parameter in the function setSchedWifi. | ||
| CVE-2023-49040 | Cri | 0.64 | 9.8 | 0.02 | Nov 27, 2023 | An issue in Tneda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the adslPwd parameter in the form_fast_setting_internet_set function. | ||
| CVE-2023-42000 | Cri | 0.64 | 9.8 | 0.01 | Nov 27, 2023 | Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthenticated remote attacker can exploit it to upload arbitrary files to any location on the file system where the UDP agent is installed. | ||
| CVE-2023-41999 | Cri | 0.64 | 9.8 | 0.01 | Nov 27, 2023 | An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifier that allows them to authenticate to the management console and perform tasks that require authentication. | ||
| CVE-2023-41998 | Cri | 0.65 | 9.8 | 0.15 | Nov 27, 2023 | Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows an attacker to upload and execute arbitrary files. | ||
| CVE-2023-49046 | Cri | 0.64 | 9.8 | 0.01 | Nov 27, 2023 | Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the devName parameter in the function formAddMacfilterRule. | ||
| CVE-2023-49043 | Cri | 0.65 | 9.8 | 0.13 | Nov 27, 2023 | Buffer Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the wpapsk_crypto parameter in the function fromSetWirelessRepeat. | ||
| CVE-2023-49312 | Cri | 0.59 | 9.1 | 0.01 | Nov 26, 2023 | Precision Bridge PrecisionBridge.exe (aka the thick client) before 7.3.21 allows an integrity violation in which the same license key is used on multiple systems, via vectors involving a Process Hacker memory dump, error message inspection, and modification of a MAC address. |
- risk 0.66cvss 9.8epss 0.30
The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL…
- risk 0.67cvss 9.8epss 0.41
A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable…
- risk 0.67cvss 9.8epss 0.40
A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by…
- risk 0.64cvss 9.8epss 0.01
An OS Command injection vulnerability in NEC Platforms DT900 and DT900S Series all versions allows an attacker to execute any command on the device.
- risk 0.64cvss 9.8epss 0.01
NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticated users, allowing attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
Remote code execution
- risk 0.64cvss 9.8epss 0.00
Elevation of privilege
- risk 0.64cvss 9.8epss 0.00
Elevation of privilege
- risk 0.64cvss 9.8epss 0.01
Remote code execution
- risk 0.64cvss 9.8epss 0.01
Remote code execution
- risk 0.60cvss 9.3epss 0.00
Misskey is an open source, decentralized social media platform. Misskey's missing signature validation allows arbitrary users to impersonate any remote user. This issue has been patched in version 2023.11.1-beta.1.
- risk 0.64cvss 9.8epss 0.01
Jenkins MATLAB Plugin 2.11.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- risk 0.64cvss 9.8epss 0.01
Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file from the Jenkins controller file system.
- risk 0.76cvss 9.6epss 0.16
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWifiGuestBasic.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the time parameter in the function compare_parentcontrol_time.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the firewallEn parameter in the function SetFirewallCfg.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the src parameter in the function sub_47D878.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the list parameter in the function sub_49E098.
- risk 0.64cvss 9.8epss 0.01
Insecure Permissions vulnerability in GL.iNet AX1800 v.3.215 and before allows a remote attacker to execute arbitrary code via the file sharing function.
- risk 0.59cvss 9.1epss 0.01
Dreamer CMS before version 4.0.1 is vulnerable to Directory Traversal. Background template management allows arbitrary modification of the template file, allowing system sensitive files to be read.
- risk 0.64cvss 9.8epss 0.02
Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain a command injection vulnerability via the NetHostname parameter.
- risk 0.64cvss 9.8epss 0.01
Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain hardcoded credentials for the Administrator account.
- risk 0.64cvss 9.8epss 0.02
Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassing the command filtering function. NOTE: this is disputed because command filtering is not intended to restrict what code can be run by authorized users…
- risk 0.64cvss 9.8epss 0.01
Netwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on deployment endpoints, leading to privilege escalation. This only occurs if the configuration omits the required restSettings.AuthorizedClientId and…
- risk 0.64cvss 9.8epss 0.01
A dylib injection vulnerability in XMachOViewer 0.04 allows attackers to compromise integrity. By exploiting this, unauthorized code can be injected into the product's processes, potentially leading to remote control and unauthorized access to sensitive user data.
- risk 0.62cvss 9.1epss 0.35
Anyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment
- risk 0.66cvss 9.8epss 0.84
Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network…
- risk 0.00cvss 9.8epss 0.02
Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of `.htaccess` file. This…
- risk 0.00cvss 9.8epss 0.04
Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via arbitrary file write.
- risk 0.06cvss 9.8epss 0.70
Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a bypass of CVE-2023-34960.
- risk 0.64cvss 9.8epss 0.01
An issue in jflyfox jfinalCMS v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the login.jsp component in the template management module.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in PrestaShop opartdevis v.4.5.18 thru v.4.6.12 allows a remote attacker to execute arbitrary code via a crafted script to the getModuleTranslation function.
- risk 0.64cvss 9.8epss 0.02
An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the authHost parameter of the indieauth function.
- risk 0.64cvss 9.8epss 0.01
In the module "Product Catalog (CSV, Excel) Export/Update" (updateproducts) < 3.8.5 from MyPrestaModules for PrestaShop, a guest can perform SQL injection. The method `productsUpdateModel::getExportIds()` has sensitive SQL calls that can be executed with a trivial http call and…
- risk 0.64cvss 9.8epss 0.01
Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the ssid parameter in the function form_fast_setting_wifi_set.
- risk 0.72cvss 9.8epss 0.65
An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. The login routine used by iDS-Core.dll contains a "passwordCustom" option that allows an unauthenticated attacker to compute valid credentials that can be used to bypass authentication and act as an…
- risk 0.64cvss 9.8epss 0.03
The WPB Show Core WordPress plugin through 2.2 is vulnerable to server-side request forgery (SSRF) via the `path` parameter.
- risk 0.64cvss 9.8epss 0.02
The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially leading to remote code…
- risk 0.59cvss 9.1epss 0.03
The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.
- risk 0.65cvss 9.8epss 0.16
The WPB Show Core WordPress plugin through 2.2 is vulnerable to a local file inclusion via the `path` parameter.
- risk 0.64cvss 9.8epss 0.01
Heap Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the schedStartTime parameter or the schedEndTime parameter in the function setSchedWifi.
- risk 0.64cvss 9.8epss 0.02
An issue in Tneda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the adslPwd parameter in the form_fast_setting_internet_set function.
- risk 0.64cvss 9.8epss 0.01
Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthenticated remote attacker can exploit it to upload arbitrary files to any location on the file system where the UDP agent is installed.
- risk 0.64cvss 9.8epss 0.01
An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifier that allows them to authenticate to the management console and perform tasks that require authentication.
- risk 0.65cvss 9.8epss 0.15
Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows an attacker to upload and execute arbitrary files.
- risk 0.64cvss 9.8epss 0.01
Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the devName parameter in the function formAddMacfilterRule.
- risk 0.65cvss 9.8epss 0.13
Buffer Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the wpapsk_crypto parameter in the function fromSetWirelessRepeat.
- risk 0.59cvss 9.1epss 0.01
Precision Bridge PrecisionBridge.exe (aka the thick client) before 7.3.21 allows an integrity violation in which the same license key is used on multiple systems, via vectors involving a Process Hacker memory dump, error message inspection, and modification of a MAC address.