| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-40920 | Cri | 0.64 | 9.8 | 0.01 | Oct 5, 2023 | Prixan prixanconnect up to v1.62 was discovered to contain a SQL injection vulnerability via the component CartsGuruCatalogModuleFrontController::importProducts(). | ||
| CVE-2023-32485 | Cri | 0.64 | 9.8 | 0.01 | Oct 5, 2023 | Dell SmartFabric Storage Software version 1.3 and lower contain an improper input validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability and escalate privileges up to the highest administration level. This is a critical severity vulnerability… | ||
| CVE-2023-2306 | Cri | 0.65 | 10.0 | 0.01 | Oct 5, 2023 | Qognify NiceVision versions 3.1 and prior are vulnerable to exposing sensitive information using hard-coded credentials. With these credentials an attacker can retrieve information about the cameras, user information, and modify database records. | ||
| CVE-2023-35803 | Cri | 0.64 | 9.8 | 0.02 | Oct 4, 2023 | IQ Engine before 10.6r2 on Extreme Network AP devices has a Buffer Overflow. | ||
| CVE-2023-41094 | Cri | 0.65 | 10.0 | 0.01 | Oct 4, 2023 | TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid TouchLink range or pairing duration This issue affects Ember ZNet… | ||
| CVE-2023-36619 | Cri | 0.64 | 9.8 | 0.04 | Oct 4, 2023 | Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthenticated users. | ||
| CVE-2023-42809 | Cri | 0.55 | 9.6 | 0.01 | Oct 4, 2023 | Redisson is a Java Redis client that uses the Netty framework. Prior to version 3.22.0, some of the messages received from the Redis server contain Java objects that the client deserializes without further validation. Attackers that manage to trick clients into communicating… | ||
| CVE-2023-5399 | Cri | 0.67 | 9.8 | 0.35 | Oct 4, 2023 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause tampering of files on the personal computer running C-Bus when using the File Command. | ||
| CVE-2023-5391 | Cri | 0.64 | 9.8 | 0.01 | Oct 4, 2023 | A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application. | ||
| CVE-2023-38701 | Cri | 0.59 | 9.1 | 0.01 | Oct 4, 2023 | Hydra is the layer-two scalability solution for Cardano. Users of the Hydra head protocol send the UTxOs they wish to commit into the Hydra head first to the `commit` validator, where they remain until they are either collected into the `head` validator or the protocol… | ||
| CVE-2023-5402 | Cri | 0.64 | 9.8 | 0.01 | Oct 4, 2023 | A CWE-269: Improper Privilege Management vulnerability exists that could cause a remote code execution when the transfer command is used over the network. | ||
| CVE-2023-20101 | Cri | 0.64 | 9.8 | 0.03 | Oct 4, 2023 | A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted. This vulnerability is due to the presence of static… | ||
| CVE-2022-36276 | Cri | 0.64 | 9.9 | 0.01 | Oct 4, 2023 | TCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'. The exploitation of this vulnerability might allow a remote attacker to directly interact with the database. | ||
| CVE-2023-22515 | Cri | 0.93 | 9.8 | 0.99 | KEV | Oct 4, 2023 | Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts… | |
| CVE-2023-4494 | Cri | 0.64 | 9.8 | 0.01 | Oct 4, 2023 | Stack-based buffer overflow vulnerability in Easy Chat Server 3.1 version. An attacker could send an excessively long username string to the register.ghp file asking for the name via a GET request resulting in arbitrary code execution on the remote machine. | ||
| CVE-2023-4491 | Cri | 0.64 | 9.8 | 0.01 | Oct 4, 2023 | Buffer overflow vulnerability in Easy Address Book Web Server 1.6 version. The exploitation of this vulnerability could allow an attacker to send a very long username string to /searchbook.ghp, asking for the name via a POST request, resulting in arbitrary code execution on the… | ||
| CVE-2023-4037 | Cri | 0.64 | 9.9 | 0.00 | Oct 4, 2023 | Blind SQL injection vulnerability in the Conacwin 3.7.1.2 web interface, the exploitation of which could allow a local attacker to obtain sensitive data stored in the database by sending a specially crafted SQL query to the xml parameter. | ||
| CVE-2023-44208 | Cri | 0.59 | 9.1 | 0.00 | Oct 4, 2023 | Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40713, Acronis True Image OEM (Windows) before build 42575. | ||
| CVE-2023-3038 | Cri | 0.64 | 9.8 | 0.01 | Oct 4, 2023 | SQL injection vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the rows parameter of the jsonGrid route and extract all the information stored in the application. | ||
| CVE-2023-3701 | Cri | 0.64 | 9.9 | 0.01 | Oct 4, 2023 | Aqua Drive, in its 2.4 version, is vulnerable to a relative path traversal vulnerability. By exploiting this vulnerability, an authenticated non privileged user could access/modify stored resources of other users. It could also be possible to access and modify the source and… | ||
| CVE-2023-39647 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2023 | Improper neutralization of SQL parameter in Theme Volty CMS Category Product module for PrestaShop. In the module “Theme Volty CMS Category Product” (tvcmscategoryproduct) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected… | ||
| CVE-2023-39651 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2023 | Improper neutralization of SQL parameter in Theme Volty CMS BrandList module for PrestaShop In the module “Theme Volty CMS BrandList” (tvcmsbrandlist) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions. | ||
| CVE-2023-39649 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2023 | Improper neutralization of SQL parameter in Theme Volty CMS Category Slider module for PrestaShop. In the module “Theme Volty CMS Category Slider” (tvcmscategoryslider) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected… | ||
| CVE-2023-39648 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2023 | Improper neutralization of SQL parameter in Theme Volty CMS Testimonial module for PrestaShop. In the module “Theme Volty CMS Testimonial” (tvcmstestimonial) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions. | ||
| CVE-2023-39646 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2023 | Improper neutralization of SQL parameter in Theme Volty CMS Category Chain Slider module for PrestaShop. In the module “Theme Volty CMS Category Chain Slide"(tvcmscategorychainslider) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in… | ||
| CVE-2023-44974 | Cri | 0.65 | 9.8 | 0.20 | Oct 3, 2023 | An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file. | ||
| CVE-2023-44973 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2023 | An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file. | ||
| CVE-2023-39645 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2023 | Improper neutralization of SQL parameter in Theme Volty CMS Payment Icon module for PrestaShop. In the module “Theme Volty CMS Payment Icon” (tvcmspaymenticon) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions. | ||
| CVE-2023-33273 | Cri | 0.64 | 9.8 | 0.03 | Oct 3, 2023 | An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the WGET check function is vulnerable to OS command injection (blind). | ||
| CVE-2023-33272 | Cri | 0.64 | 9.8 | 0.03 | Oct 3, 2023 | An issue was discovered in DTS Monitoring 3.57.0. The parameter ip within the Ping check function is vulnerable to OS command injection (blind). | ||
| CVE-2023-33271 | Cri | 0.64 | 9.8 | 0.02 | Oct 3, 2023 | An issue was discovered in DTS Monitoring 3.57.0. The parameter common_name within the SSL Certificate check function is vulnerable to OS command injection (blind). | ||
| CVE-2023-33270 | Cri | 0.64 | 9.8 | 0.03 | Oct 3, 2023 | An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the Curl check function is vulnerable to OS command injection (blind). | ||
| CVE-2023-33269 | Cri | 0.64 | 9.8 | 0.02 | Oct 3, 2023 | An issue was discovered in DTS Monitoring 3.57.0. The parameter options within the WGET check function is vulnerable to OS command injection (blind). | ||
| CVE-2023-33268 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2023 | An issue was discovered in DTS Monitoring 3.57.0. The parameter port within the SSL Certificate check function is vulnerable to OS command injection (blind). | ||
| CVE-2023-40830 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2023 | Tenda AC6 v15.03.05.19 is vulnerable to Buffer Overflow as the Index parameter does not verify the length. | ||
| CVE-2023-32670 | Cri | 0.59 | 9.0 | 0.00 | Oct 3, 2023 | Cross-Site Scripting vulnerability in BuddyBoss 2.2.9 version , which could allow a local attacker with basic privileges to execute a malicious payload through the "[name]=image.jpg" parameter, allowing to assign a persistent javascript payload that would be triggered when… | ||
| CVE-2023-5350 | Cri | 0.03 | 9.1 | 0.02 | Oct 3, 2023 | SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1. | ||
| CVE-2022-47893 | Cri | 0.65 | 10.0 | 0.01 | Oct 3, 2023 | There is a remote code execution vulnerability that affects all versions of NetMan 204. A remote attacker could upload a firmware file containing a webshell, that could allow him to execute arbitrary code as root. | ||
| CVE-2023-3654 | Cri | 0.61 | 9.4 | 0.00 | Oct 3, 2023 | cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by a origin bypass via the host header in an HTTP request. This vulnerability can be triggered by an HTTP endpoint exposed to the network. | ||
| CVE-2023-3656 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2023 | cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by an unauthenticated remote code execution vulnerability. This vulnerability can be triggered by an HTTP endpoint exposed to the network. | ||
| CVE-2023-33028 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2023 | Memory corruption in WLAN Firmware while doing a memory copy of pmk cache. | ||
| CVE-2023-28540 | Cri | 0.59 | 9.1 | 0.00 | Oct 3, 2023 | Cryptographic issue in Data Modem due to improper authentication during TLS handshake. | ||
| CVE-2023-24855 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2023 | Memory corruption in Modem while processing security related configuration before AS Security Exchange. | ||
| CVE-2023-43980 | Cri | 0.64 | 9.8 | 0.01 | Oct 2, 2023 | Presto Changeo testsitecreator up to v1.1.1 was discovered to contain a SQL injection vulnerability via the component disable_json.php. | ||
| CVE-2023-44011 | Cri | 0.64 | 9.8 | 0.02 | Oct 2, 2023 | An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.master skin file at the Skin management component. | ||
| CVE-2023-43893 | Cri | 0.64 | 9.8 | 0.02 | Oct 2, 2023 | Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeup_mac parameter in the Wake-On-LAN (WoL) function. This vulnerability is exploited via a crafted payload. | ||
| CVE-2023-43892 | Cri | 0.64 | 9.8 | 0.02 | Oct 2, 2023 | Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the Hostname parameter within the WAN settings. This vulnerability is exploited via a crafted payload. | ||
| CVE-2023-43891 | Cri | 0.64 | 9.8 | 0.02 | Oct 2, 2023 | Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password function. This vulnerability is exploited via a crafted payload. | ||
| CVE-2023-44009 | Cri | 0.64 | 9.8 | 0.02 | Oct 2, 2023 | File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function. | ||
| CVE-2023-44008 | Cri | 0.64 | 9.8 | 0.02 | Oct 2, 2023 | File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function. |
- risk 0.64cvss 9.8epss 0.01
Prixan prixanconnect up to v1.62 was discovered to contain a SQL injection vulnerability via the component CartsGuruCatalogModuleFrontController::importProducts().
- risk 0.64cvss 9.8epss 0.01
Dell SmartFabric Storage Software version 1.3 and lower contain an improper input validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability and escalate privileges up to the highest administration level. This is a critical severity vulnerability…
- risk 0.65cvss 10.0epss 0.01
Qognify NiceVision versions 3.1 and prior are vulnerable to exposing sensitive information using hard-coded credentials. With these credentials an attacker can retrieve information about the cameras, user information, and modify database records.
- risk 0.64cvss 9.8epss 0.02
IQ Engine before 10.6r2 on Extreme Network AP devices has a Buffer Overflow.
- risk 0.65cvss 10.0epss 0.01
TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid TouchLink range or pairing duration This issue affects Ember ZNet…
- risk 0.64cvss 9.8epss 0.04
Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthenticated users.
- risk 0.55cvss 9.6epss 0.01
Redisson is a Java Redis client that uses the Netty framework. Prior to version 3.22.0, some of the messages received from the Redis server contain Java objects that the client deserializes without further validation. Attackers that manage to trick clients into communicating…
- risk 0.67cvss 9.8epss 0.35
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause tampering of files on the personal computer running C-Bus when using the File Command.
- risk 0.64cvss 9.8epss 0.01
A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application.
- risk 0.59cvss 9.1epss 0.01
Hydra is the layer-two scalability solution for Cardano. Users of the Hydra head protocol send the UTxOs they wish to commit into the Hydra head first to the `commit` validator, where they remain until they are either collected into the `head` validator or the protocol…
- risk 0.64cvss 9.8epss 0.01
A CWE-269: Improper Privilege Management vulnerability exists that could cause a remote code execution when the transfer command is used over the network.
- risk 0.64cvss 9.8epss 0.03
A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted. This vulnerability is due to the presence of static…
- risk 0.64cvss 9.9epss 0.01
TCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'. The exploitation of this vulnerability might allow a remote attacker to directly interact with the database.
- risk 0.93cvss 9.8epss 0.99
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts…
- risk 0.64cvss 9.8epss 0.01
Stack-based buffer overflow vulnerability in Easy Chat Server 3.1 version. An attacker could send an excessively long username string to the register.ghp file asking for the name via a GET request resulting in arbitrary code execution on the remote machine.
- risk 0.64cvss 9.8epss 0.01
Buffer overflow vulnerability in Easy Address Book Web Server 1.6 version. The exploitation of this vulnerability could allow an attacker to send a very long username string to /searchbook.ghp, asking for the name via a POST request, resulting in arbitrary code execution on the…
- risk 0.64cvss 9.9epss 0.00
Blind SQL injection vulnerability in the Conacwin 3.7.1.2 web interface, the exploitation of which could allow a local attacker to obtain sensitive data stored in the database by sending a specially crafted SQL query to the xml parameter.
- risk 0.59cvss 9.1epss 0.00
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40713, Acronis True Image OEM (Windows) before build 42575.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the rows parameter of the jsonGrid route and extract all the information stored in the application.
- risk 0.64cvss 9.9epss 0.01
Aqua Drive, in its 2.4 version, is vulnerable to a relative path traversal vulnerability. By exploiting this vulnerability, an authenticated non privileged user could access/modify stored resources of other users. It could also be possible to access and modify the source and…
- risk 0.64cvss 9.8epss 0.01
Improper neutralization of SQL parameter in Theme Volty CMS Category Product module for PrestaShop. In the module “Theme Volty CMS Category Product” (tvcmscategoryproduct) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected…
- risk 0.64cvss 9.8epss 0.01
Improper neutralization of SQL parameter in Theme Volty CMS BrandList module for PrestaShop In the module “Theme Volty CMS BrandList” (tvcmsbrandlist) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.
- risk 0.64cvss 9.8epss 0.01
Improper neutralization of SQL parameter in Theme Volty CMS Category Slider module for PrestaShop. In the module “Theme Volty CMS Category Slider” (tvcmscategoryslider) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected…
- risk 0.64cvss 9.8epss 0.01
Improper neutralization of SQL parameter in Theme Volty CMS Testimonial module for PrestaShop. In the module “Theme Volty CMS Testimonial” (tvcmstestimonial) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.
- risk 0.64cvss 9.8epss 0.01
Improper neutralization of SQL parameter in Theme Volty CMS Category Chain Slider module for PrestaShop. In the module “Theme Volty CMS Category Chain Slide"(tvcmscategorychainslider) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in…
- risk 0.65cvss 9.8epss 0.20
An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
- risk 0.64cvss 9.8epss 0.01
Improper neutralization of SQL parameter in Theme Volty CMS Payment Icon module for PrestaShop. In the module “Theme Volty CMS Payment Icon” (tvcmspaymenticon) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the WGET check function is vulnerable to OS command injection (blind).
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in DTS Monitoring 3.57.0. The parameter ip within the Ping check function is vulnerable to OS command injection (blind).
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in DTS Monitoring 3.57.0. The parameter common_name within the SSL Certificate check function is vulnerable to OS command injection (blind).
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the Curl check function is vulnerable to OS command injection (blind).
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in DTS Monitoring 3.57.0. The parameter options within the WGET check function is vulnerable to OS command injection (blind).
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in DTS Monitoring 3.57.0. The parameter port within the SSL Certificate check function is vulnerable to OS command injection (blind).
- risk 0.64cvss 9.8epss 0.01
Tenda AC6 v15.03.05.19 is vulnerable to Buffer Overflow as the Index parameter does not verify the length.
- risk 0.59cvss 9.0epss 0.00
Cross-Site Scripting vulnerability in BuddyBoss 2.2.9 version , which could allow a local attacker with basic privileges to execute a malicious payload through the "[name]=image.jpg" parameter, allowing to assign a persistent javascript payload that would be triggered when…
- risk 0.03cvss 9.1epss 0.02
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1.
- risk 0.65cvss 10.0epss 0.01
There is a remote code execution vulnerability that affects all versions of NetMan 204. A remote attacker could upload a firmware file containing a webshell, that could allow him to execute arbitrary code as root.
- risk 0.61cvss 9.4epss 0.00
cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by a origin bypass via the host header in an HTTP request. This vulnerability can be triggered by an HTTP endpoint exposed to the network.
- risk 0.64cvss 9.8epss 0.01
cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by an unauthenticated remote code execution vulnerability. This vulnerability can be triggered by an HTTP endpoint exposed to the network.
- risk 0.64cvss 9.8epss 0.01
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
- risk 0.59cvss 9.1epss 0.00
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
- risk 0.64cvss 9.8epss 0.01
Memory corruption in Modem while processing security related configuration before AS Security Exchange.
- risk 0.64cvss 9.8epss 0.01
Presto Changeo testsitecreator up to v1.1.1 was discovered to contain a SQL injection vulnerability via the component disable_json.php.
- risk 0.64cvss 9.8epss 0.02
An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.master skin file at the Skin management component.
- risk 0.64cvss 9.8epss 0.02
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeup_mac parameter in the Wake-On-LAN (WoL) function. This vulnerability is exploited via a crafted payload.
- risk 0.64cvss 9.8epss 0.02
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the Hostname parameter within the WAN settings. This vulnerability is exploited via a crafted payload.
- risk 0.64cvss 9.8epss 0.02
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password function. This vulnerability is exploited via a crafted payload.
- risk 0.64cvss 9.8epss 0.02
File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function.
- risk 0.64cvss 9.8epss 0.02
File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function.