| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-43222 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file. | ||
| CVE-2023-43216 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php. | ||
| CVE-2023-43187 | Cri | 0.67 | 9.8 | 0.47 | Sep 27, 2023 | A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted XML-RPC requests. | ||
| CVE-2023-43154 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | In Macrob7 Macs Framework Content Management System (CMS) 1.1.4f, loose comparison in "isValidLogin()" function during login attempt results in PHP type confusion vulnerability that leads to authentication bypass and takeover of the administrator account. | ||
| CVE-2023-42657 | Cri | 0.66 | 9.9 | 0.16 | Sep 27, 2023 | In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered. An attacker could leverage this vulnerability to perform file operations (delete, rename, rmdir, mkdir) on files and folders outside of their authorized WS_FTP folder… | ||
| CVE-2023-40455 | Cri | 0.65 | 10.0 | 0.01 | Sep 27, 2023 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed process may be able to circumvent sandbox restrictions. | ||
| CVE-2023-40436 | Cri | 0.59 | 9.1 | 0.01 | Sep 27, 2023 | The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14. An attacker may be able to cause unexpected system termination or read kernel memory. | ||
| CVE-2023-40400 | Cri | 0.64 | 9.8 | 0.02 | Sep 27, 2023 | This issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. A remote user may cause an unexpected app termination or arbitrary code execution. | ||
| CVE-2023-40044 | Cri | 0.93 | 10.0 | 0.90 | KEV | Sep 27, 2023 | In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system. | |
| CVE-2023-3767 | Cri | 0.64 | 9.8 | 0.02 | Sep 27, 2023 | An OS command injection vulnerability has been found on EasyPHP Webserver affecting version 14.1. This vulnerability could allow an attacker to get full access to the system by sending a specially crafted exploit to the /index.php?zone=settings parameter. | ||
| CVE-2023-38586 | Cri | 0.65 | 10.0 | 0.01 | Sep 27, 2023 | An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed process may be able to circumvent sandbox restrictions. | ||
| CVE-2023-35071 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MRV Tech Logging Administration Panel allows SQL Injection. This issue affects Logging Administration Panel: before 20230915 . | ||
| CVE-2021-38243 | Cri | 0.64 | 9.8 | 0.02 | Sep 27, 2023 | xunruicms up to v4.5.1 was discovered to contain a remote code execution (RCE) vulnerability in /index.php. This vulnerability allows attackers to execute arbitrary code via a crafted GET request. | ||
| CVE-2023-43457 | Cri | 0.64 | 9.8 | 0.01 | Sep 25, 2023 | An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/admin/?page=user/ endpoint. | ||
| CVE-2023-43644 | Cri | 0.52 | 9.1 | 0.01 | Sep 25, 2023 | Sing-box is an open source proxy system. Affected versions are subject to an authentication bypass when specially crafted requests are sent to sing-box. This affects all SOCKS5 inbounds with user authentication and an attacker may be able to bypass authentication. Users are… | ||
| CVE-2023-39640 | Cri | 0.64 | 9.8 | 0.01 | Sep 25, 2023 | UpLight cookiebanner before 1.5.1 was discovered to contain a SQL injection vulnerability via the component Hook::getHookModuleExecList(). | ||
| CVE-2023-4521 | Cri | 0.67 | 9.8 | 0.41 | Sep 25, 2023 | The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue… | ||
| CVE-2023-4490 | Cri | 0.64 | 9.8 | 0.04 | Sep 25, 2023 | The WP Job Portal WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users | ||
| CVE-2023-43141 | Cri | 0.64 | 9.8 | 0.01 | Sep 25, 2023 | TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control. | ||
| CVE-2023-40163 | Cri | 0.64 | 9.8 | 0.01 | Sep 25, 2023 | An out-of-bounds write vulnerability exists in the allocate_buffer_for_jpeg_decoding functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability. | ||
| CVE-2023-39453 | Cri | 0.64 | 9.8 | 0.01 | Sep 25, 2023 | A use-after-free vulnerability exists in the tif_parse_sub_IFD functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can deliver this file to trigger this vulnerability. | ||
| CVE-2023-35002 | Cri | 0.64 | 9.8 | 0.01 | Sep 25, 2023 | A heap-based buffer overflow vulnerability exists in the pictwread functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | ||
| CVE-2023-32653 | Cri | 0.64 | 9.8 | 0.01 | Sep 25, 2023 | An out-of-bounds write vulnerability exists in the dcm_pixel_data_decode functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability. | ||
| CVE-2023-43131 | Cri | 0.64 | 9.8 | 0.01 | Sep 25, 2023 | General Device Manager 2.5.2.2 is vulnerable to Buffer Overflow. | ||
| CVE-2022-48605 | Cri | 0.64 | 9.8 | 0.00 | Sep 25, 2023 | Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability. | ||
| CVE-2023-41419 | Cri | 0.57 | 9.8 | 0.02 | Sep 25, 2023 | An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component. | ||
| CVE-2023-41297 | Cri | 0.64 | 9.8 | 0.00 | Sep 25, 2023 | Vulnerability of defects introduced in the design process in the HiviewTunner module. Successful exploitation of this vulnerability may cause service hijacking. | ||
| CVE-2023-41296 | Cri | 0.59 | 9.1 | 0.00 | Sep 25, 2023 | Vulnerability of missing authorization in the kernel module. Successful exploitation of this vulnerability may affect integrity and confidentiality. | ||
| CVE-2023-41294 | Cri | 0.64 | 9.8 | 0.00 | Sep 25, 2023 | The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services. | ||
| CVE-2023-39407 | Cri | 0.59 | 9.1 | 0.00 | Sep 25, 2023 | The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability may affect confidentiality and integrity. | ||
| CVE-2023-43470 | Cri | 0.64 | 9.8 | 0.01 | Sep 23, 2023 | SQL injection vulnerability in janobe Online Voting System v.1.0 allows a remote attacker to execute arbitrary code via the checklogin.php component. | ||
| CVE-2023-43469 | Cri | 0.64 | 9.8 | 0.01 | Sep 23, 2023 | SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the ForPass.php component. | ||
| CVE-2023-43468 | Cri | 0.64 | 9.8 | 0.01 | Sep 23, 2023 | SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the login.php component. | ||
| CVE-2023-43338 | Cri | 0.64 | 9.8 | 0.01 | Sep 23, 2023 | Cesanta mjs v2.20.0 was discovered to contain a function pointer hijacking vulnerability via the function mjs_get_ptr(). This vulnerability allows attackers to execute arbitrary code via a crafted input. | ||
| CVE-2023-43130 | Cri | 0.64 | 9.8 | 0.03 | Sep 22, 2023 | D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection. | ||
| CVE-2023-43129 | Cri | 0.64 | 9.8 | 0.03 | Sep 22, 2023 | D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection due to lax filtering of REMOTE_PORT parameters. | ||
| CVE-2023-40989 | Cri | 0.57 | 9.8 | 0.02 | Sep 22, 2023 | SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted request to the report/jeecgboot/jmreport/queryFieldBySql component. | ||
| CVE-2023-43270 | Cri | 0.64 | 9.8 | 0.02 | Sep 22, 2023 | dst-admin v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the userId parameter at /home/playerOperate. | ||
| CVE-2023-43144 | Cri | 0.64 | 9.8 | 0.01 | Sep 22, 2023 | Projectworldsl Assets-management-system-in-php 1.0 is vulnerable to SQL Injection via the "id" parameter in delete.php. | ||
| CVE-2023-43762 | Cri | 0.64 | 9.8 | 0.01 | Sep 22, 2023 | Certain WithSecure products allow Unauthenticated Remote Code Execution via the web server (backend). This affects WithSecure Policy Manager 15 and Policy Manager Proxy 15. | ||
| CVE-2023-31719 | Cri | 0.66 | 9.8 | 0.26 | Sep 22, 2023 | FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin. | ||
| CVE-2023-43128 | Cri | 0.64 | 9.8 | 0.03 | Sep 21, 2023 | D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection due to lax filtering of HTTP_ST parameters. | ||
| CVE-2023-34576 | Cri | 0.64 | 9.8 | 0.01 | Sep 21, 2023 | SQL injection vulnerability in updatepos.php in PrestaShop opartfaq through 1.0.3 allows remote attackers to run arbitrary SQL commands via unspedified vector. | ||
| CVE-2023-42810 | Cri | 0.57 | 9.8 | 0.02 | Sep 21, 2023 | systeminformation is a System Information Library for Node.JS. Versions 5.0.0 through 5.21.6 have a SSID Command Injection Vulnerability. The problem was fixed with a parameter check in version 5.21.7. As a workaround, check or sanitize parameter strings that are passed to… | ||
| CVE-2023-42279 | Cri | 0.64 | 9.8 | 0.01 | Sep 21, 2023 | Dreamer CMS v4.1.3 was discovered to contain a SQL injection vulnerability via the model-form-management-field form. | ||
| CVE-2023-34577 | Cri | 0.64 | 9.8 | 0.01 | Sep 21, 2023 | SQL injection vulnerability in Prestashop opartplannedpopup 1.4.11 and earlier allows remote attackers to run arbitrary SQL commands via OpartPlannedPopupModuleFrontController::prepareHook() method. | ||
| CVE-2023-43632 | Cri | 0.59 | 9.0 | 0.01 | Sep 21, 2023 | As noted in the “VTPM.md” file in the eve documentation, “VTPM is a server listening on port 8877 in EVE, exposing limited functionality of the TPM to the clients. VTPM allows clients to execute tpm2-tools binaries from a list of hardcoded options” The communication… | ||
| CVE-2023-43242 | Cri | 0.64 | 9.8 | 0.01 | Sep 21, 2023 | D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter removeRuleList in form2IPQoSTcDel. | ||
| CVE-2023-43241 | Cri | 0.64 | 9.8 | 0.01 | Sep 21, 2023 | D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter TXPower and GuardInt in SetWLanRadioSecurity. | ||
| CVE-2023-43240 | Cri | 0.65 | 9.8 | 0.13 | Sep 21, 2023 | D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter sip_address in ipportFilter. |
- risk 0.64cvss 9.8epss 0.01
SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.
- risk 0.64cvss 9.8epss 0.01
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.
- risk 0.67cvss 9.8epss 0.47
A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted XML-RPC requests.
- risk 0.64cvss 9.8epss 0.01
In Macrob7 Macs Framework Content Management System (CMS) 1.1.4f, loose comparison in "isValidLogin()" function during login attempt results in PHP type confusion vulnerability that leads to authentication bypass and takeover of the administrator account.
- risk 0.66cvss 9.9epss 0.16
In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered. An attacker could leverage this vulnerability to perform file operations (delete, rename, rmdir, mkdir) on files and folders outside of their authorized WS_FTP folder…
- risk 0.65cvss 10.0epss 0.01
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed process may be able to circumvent sandbox restrictions.
- risk 0.59cvss 9.1epss 0.01
The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14. An attacker may be able to cause unexpected system termination or read kernel memory.
- risk 0.64cvss 9.8epss 0.02
This issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. A remote user may cause an unexpected app termination or arbitrary code execution.
- risk 0.93cvss 10.0epss 0.90
In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.
- risk 0.64cvss 9.8epss 0.02
An OS command injection vulnerability has been found on EasyPHP Webserver affecting version 14.1. This vulnerability could allow an attacker to get full access to the system by sending a specially crafted exploit to the /index.php?zone=settings parameter.
- risk 0.65cvss 10.0epss 0.01
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed process may be able to circumvent sandbox restrictions.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MRV Tech Logging Administration Panel allows SQL Injection. This issue affects Logging Administration Panel: before 20230915 .
- risk 0.64cvss 9.8epss 0.02
xunruicms up to v4.5.1 was discovered to contain a remote code execution (RCE) vulnerability in /index.php. This vulnerability allows attackers to execute arbitrary code via a crafted GET request.
- risk 0.64cvss 9.8epss 0.01
An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/admin/?page=user/ endpoint.
- risk 0.52cvss 9.1epss 0.01
Sing-box is an open source proxy system. Affected versions are subject to an authentication bypass when specially crafted requests are sent to sing-box. This affects all SOCKS5 inbounds with user authentication and an attacker may be able to bypass authentication. Users are…
- risk 0.64cvss 9.8epss 0.01
UpLight cookiebanner before 1.5.1 was discovered to contain a SQL injection vulnerability via the component Hook::getHookModuleExecList().
- risk 0.67cvss 9.8epss 0.41
The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue…
- risk 0.64cvss 9.8epss 0.04
The WP Job Portal WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users
- risk 0.64cvss 9.8epss 0.01
TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control.
- risk 0.64cvss 9.8epss 0.01
An out-of-bounds write vulnerability exists in the allocate_buffer_for_jpeg_decoding functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
- risk 0.64cvss 9.8epss 0.01
A use-after-free vulnerability exists in the tif_parse_sub_IFD functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can deliver this file to trigger this vulnerability.
- risk 0.64cvss 9.8epss 0.01
A heap-based buffer overflow vulnerability exists in the pictwread functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
- risk 0.64cvss 9.8epss 0.01
An out-of-bounds write vulnerability exists in the dcm_pixel_data_decode functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.
- risk 0.64cvss 9.8epss 0.01
General Device Manager 2.5.2.2 is vulnerable to Buffer Overflow.
- risk 0.64cvss 9.8epss 0.00
Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability.
- risk 0.57cvss 9.8epss 0.02
An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component.
- risk 0.64cvss 9.8epss 0.00
Vulnerability of defects introduced in the design process in the HiviewTunner module. Successful exploitation of this vulnerability may cause service hijacking.
- risk 0.59cvss 9.1epss 0.00
Vulnerability of missing authorization in the kernel module. Successful exploitation of this vulnerability may affect integrity and confidentiality.
- risk 0.64cvss 9.8epss 0.00
The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services.
- risk 0.59cvss 9.1epss 0.00
The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability may affect confidentiality and integrity.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in janobe Online Voting System v.1.0 allows a remote attacker to execute arbitrary code via the checklogin.php component.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the ForPass.php component.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the login.php component.
- risk 0.64cvss 9.8epss 0.01
Cesanta mjs v2.20.0 was discovered to contain a function pointer hijacking vulnerability via the function mjs_get_ptr(). This vulnerability allows attackers to execute arbitrary code via a crafted input.
- risk 0.64cvss 9.8epss 0.03
D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection.
- risk 0.64cvss 9.8epss 0.03
D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection due to lax filtering of REMOTE_PORT parameters.
- risk 0.57cvss 9.8epss 0.02
SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted request to the report/jeecgboot/jmreport/queryFieldBySql component.
- risk 0.64cvss 9.8epss 0.02
dst-admin v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the userId parameter at /home/playerOperate.
- risk 0.64cvss 9.8epss 0.01
Projectworldsl Assets-management-system-in-php 1.0 is vulnerable to SQL Injection via the "id" parameter in delete.php.
- risk 0.64cvss 9.8epss 0.01
Certain WithSecure products allow Unauthenticated Remote Code Execution via the web server (backend). This affects WithSecure Policy Manager 15 and Policy Manager Proxy 15.
- risk 0.66cvss 9.8epss 0.26
FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.
- risk 0.64cvss 9.8epss 0.03
D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection due to lax filtering of HTTP_ST parameters.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in updatepos.php in PrestaShop opartfaq through 1.0.3 allows remote attackers to run arbitrary SQL commands via unspedified vector.
- risk 0.57cvss 9.8epss 0.02
systeminformation is a System Information Library for Node.JS. Versions 5.0.0 through 5.21.6 have a SSID Command Injection Vulnerability. The problem was fixed with a parameter check in version 5.21.7. As a workaround, check or sanitize parameter strings that are passed to…
- risk 0.64cvss 9.8epss 0.01
Dreamer CMS v4.1.3 was discovered to contain a SQL injection vulnerability via the model-form-management-field form.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in Prestashop opartplannedpopup 1.4.11 and earlier allows remote attackers to run arbitrary SQL commands via OpartPlannedPopupModuleFrontController::prepareHook() method.
- risk 0.59cvss 9.0epss 0.01
As noted in the “VTPM.md” file in the eve documentation, “VTPM is a server listening on port 8877 in EVE, exposing limited functionality of the TPM to the clients. VTPM allows clients to execute tpm2-tools binaries from a list of hardcoded options” The communication…
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter removeRuleList in form2IPQoSTcDel.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter TXPower and GuardInt in SetWLanRadioSecurity.
- risk 0.65cvss 9.8epss 0.13
D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter sip_address in ipportFilter.