| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-4897 | Cri | 0.00 | 9.8 | 0.01 | Sep 11, 2023 | Relative Path Traversal in GitHub repository mintplex-labs/anything-llm prior to 0.0.1. | ||
| CVE-2023-35681 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | In eatt_l2cap_reconfig_completed of eatt_impl.h, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-40946 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | Schoolmate 1.3 is vulnerable to SQL Injection in the variable $username from SESSION in ValidateLogin.php. | ||
| CVE-2023-40945 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails.php. | ||
| CVE-2023-40944 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | Schoolmate 1.3 is vulnerable to SQL Injection in the variable $schoolname from Database at ~\header.php. | ||
| CVE-2023-40150 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | Softneta MedDream PACS does not perform an authentication check and performs some dangerous functionality, which could result in unauthenticated remote code execution.0 | ||
| CVE-2023-41256 | Cri | 0.59 | 9.1 | 0.01 | Sep 11, 2023 | Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 are vulnerable to authentication bypass that could allow an unauthorized attacker to obtain user access. | ||
| CVE-2023-31069 | Cri | 0.67 | 9.8 | 0.04 | Sep 11, 2023 | An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML source code of the login page. | ||
| CVE-2023-31068 | Cri | 0.67 | 9.8 | 0.05 | Sep 11, 2023 | An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\UserDesktop\themes. | ||
| CVE-2023-31067 | Cri | 0.67 | 9.8 | 0.05 | Sep 11, 2023 | An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\Clients\www. | ||
| CVE-2020-19559 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | An issue in Diebold Aglis XFS for Opteva v.4.1.61.1 allows a remote attacker to execute arbitrary code via a crafted payload to the ResolveMethod() parameter. | ||
| CVE-2020-19320 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the curTime parameter on login. | ||
| CVE-2020-19319 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the FILECODE parameter on login. | ||
| CVE-2023-30058 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | novel-plus 3.6.2 is vulnerable to SQL Injection. | ||
| CVE-2023-36140 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts. | ||
| CVE-2023-42471 | Cri | 0.64 | 9.8 | 0.03 | Sep 11, 2023 | The wave.ai.browser application through 1.0.35 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. It contains a manifest entry that exports the wave.ai.browser.ui.splash.SplashScreen activity. This activity uses a WebView component to… | ||
| CVE-2023-42470 | Cri | 0.64 | 9.8 | 0.02 | Sep 11, 2023 | The Imou Life com.mm.android.smartlifeiot application through 6.8.0 for Android allows Remote Code Execution via a crafted intent to an exported component. This relates to the com.mm.android.easy4ip.MainActivity activity. JavaScript execution is enabled in the WebView, and… | ||
| CVE-2023-40039 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | An issue was discovered on ARRIS TG852G, TG862G, and TG1672G devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame. | ||
| CVE-2023-42277 | Cri | 0.57 | 9.8 | 0.01 | Sep 8, 2023 | hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonObject.putByPath. | ||
| CVE-2023-42276 | Cri | 0.57 | 9.8 | 0.01 | Sep 8, 2023 | hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonArray. | ||
| CVE-2023-42268 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2023 | Jeecg boot up to v3.5.3 was discovered to contain a SQL injection vulnerability via the component /jeecg-boot/jmreport/show. | ||
| CVE-2023-39320 | Cri | 0.64 | 9.8 | 0.02 | Sep 8, 2023 | The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "go" command from the module proxy, as… | ||
| CVE-2023-41615 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2023 | Zoo Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the Admin sign-in page via the username and password fields. | ||
| CVE-2023-37759 | Cri | 0.67 | 9.8 | 0.07 | Sep 8, 2023 | Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticated attackers to register as an Admin account via a crafted POST request. | ||
| CVE-2021-27715 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2023 | An issue was discovered in MoFi Network MOFI4500-4GXeLTE-V2 3.5.6-xnet-5052 allows attackers to bypass the authentication and execute arbitrary code via crafted HTTP request. | ||
| CVE-2023-40029 | Cri | 0.57 | 9.9 | 0.01 | Sep 7, 2023 | Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively using Argo CD / kubectl apply. As a result, the full secret body is stored in`kubectl.kubernetes.io/last-applied-configuration` annotation. pull request #7139… | ||
| CVE-2023-30908 | Cri | 0.64 | 9.8 | 0.01 | Sep 7, 2023 | A remote authentication bypass issue exists in a OneView API. | ||
| CVE-2023-40942 | Cri | 0.64 | 9.8 | 0.01 | Sep 7, 2023 | Tenda AC9 V3.0BR_V15.03.06.42_multi_TD01 was discovered stack overflow via parameter 'firewall_value' at url /goform/SetFirewallCfg. | ||
| CVE-2023-39424 | Cri | 0.64 | 9.9 | 0.01 | Sep 7, 2023 | A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication… | ||
| CVE-2023-39420 | Cri | 0.64 | 9.9 | 0.01 | Sep 7, 2023 | The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL file. Once reverse-engineered, this routine can help an… | ||
| CVE-2023-40397 | Cri | 0.64 | 9.8 | 0.02 | Sep 6, 2023 | The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5. A remote attacker may be able to cause arbitrary javascript code execution. | ||
| CVE-2023-39967 | Cri | 0.65 | 10.0 | 0.01 | Sep 6, 2023 | WireMock is a tool for mocking HTTP services. When certain request URLs like “@127.0.0.1:1234" are used in WireMock Studio configuration fields, the request might be forwarded to an arbitrary service reachable from WireMock’s instance. There are 3 identified potential attack… | ||
| CVE-2020-10131 | Cri | 0.64 | 9.8 | 0.02 | Sep 6, 2023 | SearchBlox before Version 9.2.1 is vulnerable to CSV macro injection in "Featured Results" parameter. | ||
| CVE-2023-41330 | Cri | 0.57 | 9.8 | 0.02 | Sep 6, 2023 | knplabs/knp-snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. ## Issue On March 17th the vulnerability CVE-2023-28115 was disclosed, allowing an attacker to gain remote code execution through PHAR deserialization. Version 1.4.2… | ||
| CVE-2023-20238 | Cri | 0.66 | 10.0 | 0.15 | Sep 6, 2023 | A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to forge the credentials required to access an affected system. This… | ||
| CVE-2023-0925 | Cri | 0.64 | 9.8 | 0.01 | Sep 6, 2023 | Version 10.11 of webMethods OneData runs an embedded instance of Azul Zulu Java 11.0.15 which hosts a Java RMI registry (listening on TCP port 2099 by default) and two RMI interfaces (listening on a single, dynamically assigned TCP high port). Port 2099 serves as a Java… | ||
| CVE-2021-36023 | Cri | 0.59 | 9.1 | 0.02 | Sep 6, 2023 | Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution. | ||
| CVE-2023-41149 | Cri | 0.64 | 9.8 | 0.01 | Sep 6, 2023 | F-RevoCRM version7.3.7 and version7.3.8 contains an OS command injection vulnerability. If this vulnerability is exploited, an attacker who can access the product may execute an arbitrary OS command on the server where the product is running. | ||
| CVE-2023-4589 | Cri | 0.59 | 9.1 | 0.00 | Sep 6, 2023 | Insufficient verification of data authenticity vulnerability in Delinea Secret Server, in its v10.9.000002 version. An attacker with an administrator account could perform software updates without proper integrity verification mechanisms. In this scenario, the update process… | ||
| CVE-2023-4634 | Cri | 0.73 | 9.8 | 0.86 | Sep 6, 2023 | The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the… | ||
| CVE-2023-4485 | Cri | 0.64 | 9.8 | 0.01 | Sep 6, 2023 | ARDEREG Sistema SCADA Central versions 2.203 and prior login page are vulnerable to an unauthenticated blind SQL injection attack. An attacker could manipulate the application's SQL query logic to extract sensitive information or perform unauthorized actions within the… | ||
| CVE-2023-41507 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | Super Store Finder v3.6 was discovered to contain multiple SQL injection vulnerabilities in the store locator component via the products, distance, lat, and lng parameters. | ||
| CVE-2023-4310 | Cri | 0.64 | 9.8 | 0.02 | Sep 5, 2023 | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious HTTP request. Successful exploitation of this vulnerability can allow an unauthenticated remote… | ||
| CVE-2023-41508 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | A hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel. | ||
| CVE-2023-39361 | Cri | 0.71 | 9.8 | 0.89 | Sep 5, 2023 | Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an… | ||
| CVE-2023-41009 | Cri | 0.64 | 9.8 | 0.02 | Sep 5, 2023 | File Upload vulnerability in adlered bolo-solo v.2.6 allows a remote attacker to execute arbitrary code via a crafted script to the authorization field in the header. | ||
| CVE-2023-39654 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | abupy up to v0.4.0 was discovered to contain a SQL injection vulnerability via the component abupy.MarketBu.ABuSymbol.search_to_symbol_dict. | ||
| CVE-2023-4531 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestav Software E-commerce Software allows SQL Injection. This issue affects E-commerce Software: before 20230901 . | ||
| CVE-2023-4178 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | Authentication Bypass by Spoofing vulnerability in Neutron Neutron Smart VMS allows Authentication Bypass. This issue affects Neutron Smart VMS: before b1130.1.0.1. | ||
| CVE-2023-4034 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digita Information Technology Smartrise Document Management System allows SQL Injection. This issue affects Smartrise Document Management System: before Hvl-2.0. |
- risk 0.00cvss 9.8epss 0.01
Relative Path Traversal in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.
- risk 0.64cvss 9.8epss 0.01
In eatt_l2cap_reconfig_completed of eatt_impl.h, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.64cvss 9.8epss 0.01
Schoolmate 1.3 is vulnerable to SQL Injection in the variable $username from SESSION in ValidateLogin.php.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails.php.
- risk 0.64cvss 9.8epss 0.01
Schoolmate 1.3 is vulnerable to SQL Injection in the variable $schoolname from Database at ~\header.php.
- risk 0.64cvss 9.8epss 0.01
Softneta MedDream PACS does not perform an authentication check and performs some dangerous functionality, which could result in unauthenticated remote code execution.0
- risk 0.59cvss 9.1epss 0.01
Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 are vulnerable to authentication bypass that could allow an unauthorized attacker to obtain user access.
- risk 0.67cvss 9.8epss 0.04
An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML source code of the login page.
- risk 0.67cvss 9.8epss 0.05
An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\UserDesktop\themes.
- risk 0.67cvss 9.8epss 0.05
An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\Clients\www.
- risk 0.64cvss 9.8epss 0.01
An issue in Diebold Aglis XFS for Opteva v.4.1.61.1 allows a remote attacker to execute arbitrary code via a crafted payload to the ResolveMethod() parameter.
- risk 0.64cvss 9.8epss 0.01
Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the curTime parameter on login.
- risk 0.64cvss 9.8epss 0.01
Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the FILECODE parameter on login.
- risk 0.64cvss 9.8epss 0.01
novel-plus 3.6.2 is vulnerable to SQL Injection.
- risk 0.64cvss 9.8epss 0.01
In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts.
- risk 0.64cvss 9.8epss 0.03
The wave.ai.browser application through 1.0.35 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. It contains a manifest entry that exports the wave.ai.browser.ui.splash.SplashScreen activity. This activity uses a WebView component to…
- risk 0.64cvss 9.8epss 0.02
The Imou Life com.mm.android.smartlifeiot application through 6.8.0 for Android allows Remote Code Execution via a crafted intent to an exported component. This relates to the com.mm.android.easy4ip.MainActivity activity. JavaScript execution is enabled in the WebView, and…
- risk 0.64cvss 9.8epss 0.01
An issue was discovered on ARRIS TG852G, TG862G, and TG1672G devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame.
- risk 0.57cvss 9.8epss 0.01
hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonObject.putByPath.
- risk 0.57cvss 9.8epss 0.01
hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonArray.
- risk 0.64cvss 9.8epss 0.01
Jeecg boot up to v3.5.3 was discovered to contain a SQL injection vulnerability via the component /jeecg-boot/jmreport/show.
- risk 0.64cvss 9.8epss 0.02
The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "go" command from the module proxy, as…
- risk 0.64cvss 9.8epss 0.01
Zoo Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the Admin sign-in page via the username and password fields.
- risk 0.67cvss 9.8epss 0.07
Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticated attackers to register as an Admin account via a crafted POST request.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in MoFi Network MOFI4500-4GXeLTE-V2 3.5.6-xnet-5052 allows attackers to bypass the authentication and execute arbitrary code via crafted HTTP request.
- risk 0.57cvss 9.9epss 0.01
Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively using Argo CD / kubectl apply. As a result, the full secret body is stored in`kubectl.kubernetes.io/last-applied-configuration` annotation. pull request #7139…
- risk 0.64cvss 9.8epss 0.01
A remote authentication bypass issue exists in a OneView API.
- risk 0.64cvss 9.8epss 0.01
Tenda AC9 V3.0BR_V15.03.06.42_multi_TD01 was discovered stack overflow via parameter 'firewall_value' at url /goform/SetFirewallCfg.
- risk 0.64cvss 9.9epss 0.01
A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication…
- risk 0.64cvss 9.9epss 0.01
The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL file. Once reverse-engineered, this routine can help an…
- risk 0.64cvss 9.8epss 0.02
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5. A remote attacker may be able to cause arbitrary javascript code execution.
- risk 0.65cvss 10.0epss 0.01
WireMock is a tool for mocking HTTP services. When certain request URLs like “@127.0.0.1:1234" are used in WireMock Studio configuration fields, the request might be forwarded to an arbitrary service reachable from WireMock’s instance. There are 3 identified potential attack…
- risk 0.64cvss 9.8epss 0.02
SearchBlox before Version 9.2.1 is vulnerable to CSV macro injection in "Featured Results" parameter.
- risk 0.57cvss 9.8epss 0.02
knplabs/knp-snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. ## Issue On March 17th the vulnerability CVE-2023-28115 was disclosed, allowing an attacker to gain remote code execution through PHAR deserialization. Version 1.4.2…
- risk 0.66cvss 10.0epss 0.15
A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to forge the credentials required to access an affected system. This…
- risk 0.64cvss 9.8epss 0.01
Version 10.11 of webMethods OneData runs an embedded instance of Azul Zulu Java 11.0.15 which hosts a Java RMI registry (listening on TCP port 2099 by default) and two RMI interfaces (listening on a single, dynamically assigned TCP high port). Port 2099 serves as a Java…
- risk 0.59cvss 9.1epss 0.02
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.
- risk 0.64cvss 9.8epss 0.01
F-RevoCRM version7.3.7 and version7.3.8 contains an OS command injection vulnerability. If this vulnerability is exploited, an attacker who can access the product may execute an arbitrary OS command on the server where the product is running.
- risk 0.59cvss 9.1epss 0.00
Insufficient verification of data authenticity vulnerability in Delinea Secret Server, in its v10.9.000002 version. An attacker with an administrator account could perform software updates without proper integrity verification mechanisms. In this scenario, the update process…
- risk 0.73cvss 9.8epss 0.86
The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the…
- risk 0.64cvss 9.8epss 0.01
ARDEREG Sistema SCADA Central versions 2.203 and prior login page are vulnerable to an unauthenticated blind SQL injection attack. An attacker could manipulate the application's SQL query logic to extract sensitive information or perform unauthorized actions within the…
- risk 0.64cvss 9.8epss 0.01
Super Store Finder v3.6 was discovered to contain multiple SQL injection vulnerabilities in the store locator component via the products, distance, lat, and lng parameters.
- risk 0.64cvss 9.8epss 0.02
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious HTTP request. Successful exploitation of this vulnerability can allow an unauthenticated remote…
- risk 0.64cvss 9.8epss 0.01
A hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel.
- risk 0.71cvss 9.8epss 0.89
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an…
- risk 0.64cvss 9.8epss 0.02
File Upload vulnerability in adlered bolo-solo v.2.6 allows a remote attacker to execute arbitrary code via a crafted script to the authorization field in the header.
- risk 0.64cvss 9.8epss 0.01
abupy up to v0.4.0 was discovered to contain a SQL injection vulnerability via the component abupy.MarketBu.ABuSymbol.search_to_symbol_dict.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestav Software E-commerce Software allows SQL Injection. This issue affects E-commerce Software: before 20230901 .
- risk 0.64cvss 9.8epss 0.01
Authentication Bypass by Spoofing vulnerability in Neutron Neutron Smart VMS allows Authentication Bypass. This issue affects Neutron Smart VMS: before b1130.1.0.1.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digita Information Technology Smartrise Document Management System allows SQL Injection. This issue affects Smartrise Document Management System: before Hvl-2.0.