| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-39618 | Cri | 0.64 | 9.8 | 0.02 | Aug 21, 2023 | TOTOLINK X5000R B20210419 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg interface. | ||
| CVE-2023-39617 | Cri | 0.64 | 9.8 | 0.02 | Aug 21, 2023 | TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contain a remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function. | ||
| CVE-2023-39809 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2023 | N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain an OS command injection vulnerability via shell metacharacters in the system_hostname parameter at /manage/network-basic.php. | ||
| CVE-2023-39808 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2023 | N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password that allows attackers to login with root privileges via the SSH service. The cleartext password corresponding to the $1$4Tmm01jl$7HRvcW.bz7uGmX9hiQWvR hash was not determined by the… | ||
| CVE-2023-39807 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2023 | N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a SQL injection vulnerability via the a_passwd parameter at /portal/user-register.php. | ||
| CVE-2022-24989 | Cri | 0.69 | 9.8 | 0.32 | Aug 20, 2023 | TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?mobile/createRaid URI. (Shell metacharacters can be placed in raidtype because popen is used… | ||
| CVE-2023-40069 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | OS command injection vulnerability in ELECOM wireless LAN routers allows an attacker who can access the product to execute an arbitrary OS command by sending a specially crafted request. Affected products and versions are as follows: WRC-F1167ACF all versions, WRC-1750GHBK all… | ||
| CVE-2023-39454 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | Buffer overflow vulnerability exists in ELECOM wireless LAN routers, which may allow an unauthenticated attacker to execute arbitrary code. | ||
| CVE-2023-35991 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | Hidden functionality vulnerability in LOGITEC wireless LAN routers allows an unauthenticated attacker to log in to the product's certain management console and execute arbitrary OS commands. Affected products and versions are as follows: LAN-W300N/DR all versions, LAN-WH300N/DR… | ||
| CVE-2023-32626 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | Hidden functionality vulnerability in LAN-W300N/RS all versions, and LAN-W300N/PR5 all versions allows an unauthenticated attacker to log in to the product's certain management console and execute arbitrary OS commands. | ||
| CVE-2023-39674 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | D-Link DIR-880 A1_FW107WWb08 was discovered to contain a buffer overflow via the function fgets. | ||
| CVE-2023-39673 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | Tenda AC15 V1.0BR_V15.03.05.18_multi_TD01 was discovered to contain a buffer overflow via the function FUN_00010e34(). | ||
| CVE-2023-39672 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | Tenda WH450 v1.0.0.18 was discovered to contain a buffer overflow via the function fgets. | ||
| CVE-2023-39671 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | D-Link DIR-880 A1_FW107WWb08 was discovered to contain a buffer overflow via the function FUN_0001be68. | ||
| CVE-2023-39670 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | Tenda AC6 _US_AC6V1.0BR_V15.03.05.16 was discovered to contain a buffer overflow via the function fgets. | ||
| CVE-2023-39668 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the inet_ntoa() function. | ||
| CVE-2023-39667 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the FUN_0000acb4 function. | ||
| CVE-2023-39666 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | D-Link DIR-842 fw_revA_1-02_eu_multi_20151008 was discovered to contain multiple buffer overflows in the fgets function via the acStack_120 and acStack_220 parameters. | ||
| CVE-2023-39665 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the acStack_50 parameter. | ||
| CVE-2023-40171 | Cri | 0.00 | 9.1 | 0.01 | Aug 17, 2023 | Dispatch is an open source security incident management tool. The server response includes the JWT Secret Key used for signing JWT tokens in error message when the `Dispatch Plugin - Basic Authentication Provider` plugin encounters an error when attempting to decode a JWT token.… | ||
| CVE-2023-39970 | Cri | 0.64 | 9.8 | 0.01 | Aug 17, 2023 | Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. It allows remote code execution. | ||
| CVE-2023-36845 | Cri | 0.86 | 9.8 | 0.95 | KEV | Aug 17, 2023 | A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code. Using a crafted request which sets the variable PHPRC an attacker is able to… | |
| CVE-2023-26469 | Cri | 0.73 | 9.8 | 0.83 | Aug 17, 2023 | In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server. | ||
| CVE-2023-37914 | Cri | 0.57 | 9.9 | 0.02 | Aug 17, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can view `Invitation.WebHome` can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read… | ||
| CVE-2023-2917 | Cri | 0.72 | 9.8 | 0.72 | Aug 17, 2023 | The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability. Due to an improper input validation, a path traversal vulnerability exists, via the filename field, when the ThinManager processes a certain function. If exploited, an… | ||
| CVE-2023-39846 | Cri | 0.64 | 9.8 | 0.01 | Aug 16, 2023 | An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token. | ||
| CVE-2023-38894 | Cri | 0.57 | 9.8 | 0.02 | Aug 16, 2023 | A Prototype Pollution issue in Cronvel Tree-kit v.0.7.4 and before allows a remote attacker to execute arbitrary code via the extend function. | ||
| CVE-2023-35893 | Cri | 0.64 | 9.9 | 0.01 | Aug 16, 2023 | IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 258824. | ||
| CVE-2023-39115 | Cri | 0.67 | 9.8 | 0.08 | Aug 16, 2023 | install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document. | ||
| CVE-2023-33663 | Cri | 0.64 | 9.8 | 0.01 | Aug 16, 2023 | In the module “Customization fields fee for your store” (aicustomfee) from ai-dev module for PrestaShop, an attacker can perform SQL injection up to 0.2.0. Release 0.2.1 fixed this security issue. | ||
| CVE-2020-26037 | Cri | 0.64 | 9.8 | 0.02 | Aug 16, 2023 | Directory Traversal vulnerability in Server functionalty in Even Balance Punkbuster version 1.902 before 1.905 allows remote attackers to execute arbitrary code. | ||
| CVE-2023-39851 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | webchess v1.0 was discovered to contain a SQL injection vulnerability via the $playerID parameter at mainmenu.php. NOTE: this is disputed by a third party who indicates that the playerID is a session variable controlled by the server, and thus cannot be used for exploitation. | ||
| CVE-2023-39850 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | Schoolmate v1.3 was discovered to contain multiple SQL injection vulnerabilities via the $courseid and $teacherid parameters at DeleteFunctions.php. | ||
| CVE-2023-39852 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | Doctormms v1.0 was discovered to contain a SQL injection vulnerability via the $userid parameter at myAppoinment.php. NOTE: this is disputed by a third party who claims that the userid is a session variable controlled by the server, and thus cannot be used for exploitation. The… | ||
| CVE-2023-38866 | Cri | 0.64 | 9.8 | 0.02 | Aug 15, 2023 | COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter interface and display_name. | ||
| CVE-2023-38864 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protal_delete_picname parameter in the sub_41171C function at bin/webmgnt. | ||
| CVE-2023-4344 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection | ||
| CVE-2023-4342 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security policy | ||
| CVE-2023-4341 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI | ||
| CVE-2023-4340 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file | ||
| CVE-2023-4338 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers | ||
| CVE-2023-4337 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installation | ||
| CVE-2023-4336 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard cookies with Secure attribute | ||
| CVE-2023-4329 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard SESSIONID cookie with SameSite attribute | ||
| CVE-2023-4325 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities | ||
| CVE-2023-4324 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers | ||
| CVE-2023-4323 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup | ||
| CVE-2023-38865 | Cri | 0.64 | 9.8 | 0.02 | Aug 15, 2023 | COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter timestr. | ||
| CVE-2023-38863 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the ifname and mac parameters in the sub_410074 function at bin/webmgnt. | ||
| CVE-2023-38862 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the destination parameter of sub_431F64 function in bin/webmgnt. |
- risk 0.64cvss 9.8epss 0.02
TOTOLINK X5000R B20210419 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg interface.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contain a remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.
- risk 0.64cvss 9.8epss 0.01
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain an OS command injection vulnerability via shell metacharacters in the system_hostname parameter at /manage/network-basic.php.
- risk 0.64cvss 9.8epss 0.01
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password that allows attackers to login with root privileges via the SSH service. The cleartext password corresponding to the $1$4Tmm01jl$7HRvcW.bz7uGmX9hiQWvR hash was not determined by the…
- risk 0.64cvss 9.8epss 0.01
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a SQL injection vulnerability via the a_passwd parameter at /portal/user-register.php.
- risk 0.69cvss 9.8epss 0.32
TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?mobile/createRaid URI. (Shell metacharacters can be placed in raidtype because popen is used…
- risk 0.64cvss 9.8epss 0.01
OS command injection vulnerability in ELECOM wireless LAN routers allows an attacker who can access the product to execute an arbitrary OS command by sending a specially crafted request. Affected products and versions are as follows: WRC-F1167ACF all versions, WRC-1750GHBK all…
- risk 0.64cvss 9.8epss 0.01
Buffer overflow vulnerability exists in ELECOM wireless LAN routers, which may allow an unauthenticated attacker to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
Hidden functionality vulnerability in LOGITEC wireless LAN routers allows an unauthenticated attacker to log in to the product's certain management console and execute arbitrary OS commands. Affected products and versions are as follows: LAN-W300N/DR all versions, LAN-WH300N/DR…
- risk 0.64cvss 9.8epss 0.01
Hidden functionality vulnerability in LAN-W300N/RS all versions, and LAN-W300N/PR5 all versions allows an unauthenticated attacker to log in to the product's certain management console and execute arbitrary OS commands.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-880 A1_FW107WWb08 was discovered to contain a buffer overflow via the function fgets.
- risk 0.64cvss 9.8epss 0.01
Tenda AC15 V1.0BR_V15.03.05.18_multi_TD01 was discovered to contain a buffer overflow via the function FUN_00010e34().
- risk 0.64cvss 9.8epss 0.01
Tenda WH450 v1.0.0.18 was discovered to contain a buffer overflow via the function fgets.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-880 A1_FW107WWb08 was discovered to contain a buffer overflow via the function FUN_0001be68.
- risk 0.64cvss 9.8epss 0.01
Tenda AC6 _US_AC6V1.0BR_V15.03.05.16 was discovered to contain a buffer overflow via the function fgets.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the inet_ntoa() function.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the FUN_0000acb4 function.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-842 fw_revA_1-02_eu_multi_20151008 was discovered to contain multiple buffer overflows in the fgets function via the acStack_120 and acStack_220 parameters.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the acStack_50 parameter.
- risk 0.00cvss 9.1epss 0.01
Dispatch is an open source security incident management tool. The server response includes the JWT Secret Key used for signing JWT tokens in error message when the `Dispatch Plugin - Basic Authentication Provider` plugin encounters an error when attempting to decode a JWT token.…
- risk 0.64cvss 9.8epss 0.01
Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. It allows remote code execution.
- risk 0.86cvss 9.8epss 0.95
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code. Using a crafted request which sets the variable PHPRC an attacker is able to…
- risk 0.73cvss 9.8epss 0.83
In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.
- risk 0.57cvss 9.9epss 0.02
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can view `Invitation.WebHome` can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read…
- risk 0.72cvss 9.8epss 0.72
The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability. Due to an improper input validation, a path traversal vulnerability exists, via the filename field, when the ThinManager processes a certain function. If exploited, an…
- risk 0.64cvss 9.8epss 0.01
An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token.
- risk 0.57cvss 9.8epss 0.02
A Prototype Pollution issue in Cronvel Tree-kit v.0.7.4 and before allows a remote attacker to execute arbitrary code via the extend function.
- risk 0.64cvss 9.9epss 0.01
IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 258824.
- risk 0.67cvss 9.8epss 0.08
install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document.
- risk 0.64cvss 9.8epss 0.01
In the module “Customization fields fee for your store” (aicustomfee) from ai-dev module for PrestaShop, an attacker can perform SQL injection up to 0.2.0. Release 0.2.1 fixed this security issue.
- risk 0.64cvss 9.8epss 0.02
Directory Traversal vulnerability in Server functionalty in Even Balance Punkbuster version 1.902 before 1.905 allows remote attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
webchess v1.0 was discovered to contain a SQL injection vulnerability via the $playerID parameter at mainmenu.php. NOTE: this is disputed by a third party who indicates that the playerID is a session variable controlled by the server, and thus cannot be used for exploitation.
- risk 0.64cvss 9.8epss 0.01
Schoolmate v1.3 was discovered to contain multiple SQL injection vulnerabilities via the $courseid and $teacherid parameters at DeleteFunctions.php.
- risk 0.64cvss 9.8epss 0.01
Doctormms v1.0 was discovered to contain a SQL injection vulnerability via the $userid parameter at myAppoinment.php. NOTE: this is disputed by a third party who claims that the userid is a session variable controlled by the server, and thus cannot be used for exploitation. The…
- risk 0.64cvss 9.8epss 0.02
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter interface and display_name.
- risk 0.64cvss 9.8epss 0.01
An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protal_delete_picname parameter in the sub_41171C function at bin/webmgnt.
- risk 0.64cvss 9.8epss 0.01
Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection
- risk 0.64cvss 9.8epss 0.01
Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security policy
- risk 0.64cvss 9.8epss 0.01
Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI
- risk 0.64cvss 9.8epss 0.01
Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file
- risk 0.64cvss 9.8epss 0.01
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers
- risk 0.64cvss 9.8epss 0.01
Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installation
- risk 0.64cvss 9.8epss 0.01
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard cookies with Secure attribute
- risk 0.64cvss 9.8epss 0.01
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard SESSIONID cookie with SameSite attribute
- risk 0.64cvss 9.8epss 0.01
Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities
- risk 0.64cvss 9.8epss 0.01
Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers
- risk 0.64cvss 9.8epss 0.01
Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup
- risk 0.64cvss 9.8epss 0.02
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter timestr.
- risk 0.64cvss 9.8epss 0.01
An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the ifname and mac parameters in the sub_410074 function at bin/webmgnt.
- risk 0.64cvss 9.8epss 0.01
An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the destination parameter of sub_431F64 function in bin/webmgnt.