| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-32565 | Cri | 0.59 | 9.1 | 0.02 | Aug 10, 2023 | An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. Fixed in version 6.4.1. | ||
| CVE-2023-32564 | Cri | 0.67 | 9.8 | 0.44 | Aug 10, 2023 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution. | ||
| CVE-2023-32563 | Cri | 0.71 | 9.8 | 0.89 | Aug 10, 2023 | An unauthenticated attacker could achieve the code execution through a RemoteControl server. | ||
| CVE-2023-32562 | Cri | 0.67 | 9.8 | 0.46 | Aug 10, 2023 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution. Fixed in version 6.4.1. | ||
| CVE-2023-32560 | Cri | 0.75 | 9.8 | 0.99 | Aug 10, 2023 | An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution. Thanks to a Researcher at Tenable for finding and reporting. Fixed in version 6.4.1. | ||
| CVE-2023-38034 | Cri | 0.64 | 9.8 | 0.01 | Aug 10, 2023 | A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Points (Version 6.5.53 and earlier) All UniFi Switches… | ||
| CVE-2023-35085 | Cri | 0.64 | 9.8 | 0.01 | Aug 10, 2023 | An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and default settings enabled could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Points (Version 6.5.50 and earlier) All… | ||
| CVE-2023-32567 | Cri | 0.64 | 9.8 | 0.03 | Aug 10, 2023 | Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236 | ||
| CVE-2023-32566 | Cri | 0.59 | 9.1 | 0.02 | Aug 10, 2023 | An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. Fixed in version 6.4.1. | ||
| CVE-2023-36311 | Cri | 0.64 | 9.8 | 0.01 | Aug 10, 2023 | There is a SQL injection (SQLi) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0. | ||
| CVE-2023-39776 | Cri | 0.64 | 9.8 | 0.01 | Aug 10, 2023 | A File Upload vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to execute arbitrary code via uploading a crafted file. | ||
| CVE-2023-37734 | Cri | 0.64 | 9.8 | 0.01 | Aug 10, 2023 | EZ softmagic MP3 Audio Converter 2.7.3.700 was discovered to contain a buffer overflow. | ||
| CVE-2023-37069 | Cri | 0.64 | 9.8 | 0.01 | Aug 10, 2023 | Code-Projects Online Hospital Management System V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the login id and password… | ||
| CVE-2023-33242 | Cri | 0.62 | 9.6 | 0.02 | Aug 9, 2023 | Crypto wallets implementing the Lindell17 TSS protocol might allow an attacker to extract the full ECDSA private key by exfiltrating a single bit in every signature attempt (256 in total) because of not adhering to the paper's security proof's assumption regarding handling… | ||
| CVE-2023-33241 | Cri | 0.62 | 9.6 | 0.01 | Aug 9, 2023 | Crypto wallets implementing the GG18 or GG20 TSS protocol might allow an attacker to extract a full ECDSA private key by injecting a malicious pallier key and cheating in the range proof. Depending on the Beta parameters chosen in the protocol implementation, the attack might… | ||
| CVE-2023-37068 | Cri | 0.64 | 9.8 | 0.01 | Aug 9, 2023 | Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username… | ||
| CVE-2023-33468 | Cri | 0.59 | 9.1 | 0.01 | Aug 9, 2023 | KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device. This vulnerability involves extracting the connection confirmation code remotely, bypassing the need to obtain it directly… | ||
| CVE-2023-39008 | Cri | 0.00 | 9.8 | 0.03 | Aug 9, 2023 | A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands. | ||
| CVE-2023-39007 | Cri | 0.00 | 9.6 | 0.03 | Aug 9, 2023 | /ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows XSS via openAction in app/controllers/OPNsense/Cron/ItemController.php. | ||
| CVE-2023-39004 | Cri | 0.64 | 9.8 | 0.01 | Aug 9, 2023 | Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which could lead to privilege escalation. | ||
| CVE-2023-39001 | Cri | 0.00 | 9.8 | 0.04 | Aug 9, 2023 | A command injection vulnerability in the component diag_backup.php of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary commands via a crafted backup configuration file. | ||
| CVE-2023-39969 | Cri | 0.00 | 9.0 | 0.01 | Aug 9, 2023 | uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Version 1.0.9 of uthenticode hashed the entire file rather than hashing sections by virtual address, in violation of the Authenticode specification. As a result, an attacker… | ||
| CVE-2023-34545 | Cri | 0.64 | 9.8 | 0.01 | Aug 9, 2023 | A SQL injection vulnerability in CSZCMS 1.3.0 allows remote attackers to run arbitrary SQL commands via p parameter or the search URL. | ||
| CVE-2023-3632 | Cri | 0.64 | 9.8 | 0.01 | Aug 9, 2023 | Use of Hard-coded Cryptographic Key vulnerability in Sifir Bes Education and Informatics Kunduz - Homework Helper App allows Authentication Abuse, Authentication Bypass. This issue affects Kunduz - Homework Helper App: before 6.2.3. | ||
| CVE-2023-38208 | Cri | 0.59 | 9.1 | 0.03 | Aug 9, 2023 | Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead to arbitrary code execution by an… | ||
| CVE-2023-33934 | Cri | 0.59 | 9.1 | 0.02 | Aug 9, 2023 | Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1. | ||
| CVE-2023-39213 | Cri | 0.63 | 9.6 | 0.01 | Aug 8, 2023 | Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticated user to enable an escalation of privilege via network access. | ||
| CVE-2023-40042 | Cri | 0.64 | 9.8 | 0.02 | Aug 8, 2023 | TOTOLINK T10_v2 5.9c.5061_B20200511 has a stack-based buffer overflow in setStaticDhcpConfig in /lib/cste_modules/lan.so. Attackers can send crafted data in an MQTT packet, via the comment parameter, to control the return address and execute code. | ||
| CVE-2023-40041 | Cri | 0.64 | 9.8 | 0.01 | Aug 8, 2023 | TOTOLINK T10_v2 5.9c.5061_B20200511 has a stack-based buffer overflow in setWiFiWpsConfig in /lib/cste_modules/wps.so. Attackers can send crafted data in an MQTT packet, via the pin parameter, to control the return address and execute code. | ||
| CVE-2023-39216 | Cri | 0.62 | 9.6 | 0.01 | Aug 8, 2023 | Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network access. | ||
| CVE-2023-36911 | Cri | 0.64 | 9.8 | 0.02 | Aug 8, 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||
| CVE-2023-36910 | Cri | 0.64 | 9.8 | 0.03 | Aug 8, 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||
| CVE-2023-36534 | Cri | 0.61 | 9.3 | 0.02 | Aug 8, 2023 | Path traversal in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network access. | ||
| CVE-2023-35385 | Cri | 0.64 | 9.8 | 0.02 | Aug 8, 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||
| CVE-2023-21709 | Cri | 0.64 | 9.8 | 0.02 | Aug 8, 2023 | Microsoft Exchange Server Elevation of Privilege Vulnerability | ||
| CVE-2023-20586 | Cri | 0.64 | 9.8 | 0.01 | Aug 8, 2023 | A potential vulnerability was reported in Radeon™ Software Crimson ReLive Edition which may allow escalation of privilege. Radeon™ Software Crimson ReLive Edition falls outside of the security support lifecycle and AMD does not plan to release any mitigations | ||
| CVE-2023-39532 | Cri | 0.57 | 9.8 | 0.01 | Aug 8, 2023 | SES is a JavaScript environment that allows safe execution of arbitrary programs in Compartments. In version 0.18.0 prior to 0.18.7, 0.17.0 prior to 0.17.1, 0.16.0 prior to 0.16.1, 0.15.0 prior to 0.15.24, 0.14.0 prior to 0.14.5, an 0.13.0 prior to 0.13.5, there is a hole in the… | ||
| CVE-2023-3522 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 8, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in a2 License Portal System allows SQL Injection. This issue affects License Portal System: before 1.48. | |
| CVE-2023-3386 | Cri | 0.64 | 9.8 | 0.01 | Aug 8, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in a2 Camera Trap Tracking System allows SQL Injection. This issue affects Camera Trap Tracking System: before 3.1905. | ||
| CVE-2023-3651 | Cri | 0.64 | 9.8 | 0.01 | Aug 8, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digital Ant E-Commerce Software allows SQL Injection. This issue affects E-Commerce Software: before 11. | ||
| CVE-2023-3716 | Cri | 0.64 | 9.8 | 0.01 | Aug 8, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oduyo Online Collection Software allows SQL Injection. This issue affects Online Collection Software: before 1.0.1. | ||
| CVE-2023-37682 | Cri | 0.64 | 9.8 | 0.01 | Aug 8, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-jms/deductScores.php. | ||
| CVE-2023-4203 | Cri | 0.59 | 9.0 | 0.01 | Aug 8, 2023 | Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the ping tool of the web-interface. | ||
| CVE-2023-4202 | Cri | 0.59 | 9.0 | 0.01 | Aug 8, 2023 | Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the device name field of the web-interface. | ||
| CVE-2023-3717 | Cri | 0.64 | 9.8 | 0.01 | Aug 8, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farmakom Remote Administration Console allows SQL Injection. This issue affects Remote Administration Console: before 1.02. | ||
| CVE-2023-37372 | Cri | 0.64 | 9.8 | 0.01 | Aug 8, 2023 | A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications is vulnerable to SQL injection. This could allow an unauthenticated remote attackers to execute arbitrary SQL queries on the server database. | ||
| CVE-2023-28561 | Cri | 0.64 | 9.8 | 0.00 | Aug 8, 2023 | Memory corruption in QESL while processing payload from external ESL device to firmware. | ||
| CVE-2023-24845 | Cri | 0.59 | 9.1 | 0.01 | Aug 8, 2023 | A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCOM i803, RUGGEDCOM i803NC, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M2100NC, RUGGEDCOM M2200, RUGGEDCOM M2200F, RUGGEDCOM… | ||
| CVE-2023-21651 | Cri | 0.60 | 9.3 | 0.00 | Aug 8, 2023 | Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE. | ||
| CVE-2023-21643 | Cri | 0.59 | 9.1 | 0.00 | Aug 8, 2023 | Memory corruption due to untrusted pointer dereference in automotive during system call. |
- risk 0.59cvss 9.1epss 0.02
An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. Fixed in version 6.4.1.
- risk 0.67cvss 9.8epss 0.44
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.
- risk 0.71cvss 9.8epss 0.89
An unauthenticated attacker could achieve the code execution through a RemoteControl server.
- risk 0.67cvss 9.8epss 0.46
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution. Fixed in version 6.4.1.
- risk 0.75cvss 9.8epss 0.99
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution. Thanks to a Researcher at Tenable for finding and reporting. Fixed in version 6.4.1.
- risk 0.64cvss 9.8epss 0.01
A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Points (Version 6.5.53 and earlier) All UniFi Switches…
- risk 0.64cvss 9.8epss 0.01
An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and default settings enabled could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Points (Version 6.5.50 and earlier) All…
- risk 0.64cvss 9.8epss 0.03
Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236
- risk 0.59cvss 9.1epss 0.02
An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. Fixed in version 6.4.1.
- risk 0.64cvss 9.8epss 0.01
There is a SQL injection (SQLi) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0.
- risk 0.64cvss 9.8epss 0.01
A File Upload vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to execute arbitrary code via uploading a crafted file.
- risk 0.64cvss 9.8epss 0.01
EZ softmagic MP3 Audio Converter 2.7.3.700 was discovered to contain a buffer overflow.
- risk 0.64cvss 9.8epss 0.01
Code-Projects Online Hospital Management System V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the login id and password…
- risk 0.62cvss 9.6epss 0.02
Crypto wallets implementing the Lindell17 TSS protocol might allow an attacker to extract the full ECDSA private key by exfiltrating a single bit in every signature attempt (256 in total) because of not adhering to the paper's security proof's assumption regarding handling…
- risk 0.62cvss 9.6epss 0.01
Crypto wallets implementing the GG18 or GG20 TSS protocol might allow an attacker to extract a full ECDSA private key by injecting a malicious pallier key and cheating in the range proof. Depending on the Beta parameters chosen in the protocol implementation, the attack might…
- risk 0.64cvss 9.8epss 0.01
Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username…
- risk 0.59cvss 9.1epss 0.01
KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device. This vulnerability involves extracting the connection confirmation code remotely, bypassing the need to obtain it directly…
- risk 0.00cvss 9.8epss 0.03
A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands.
- risk 0.00cvss 9.6epss 0.03
/ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows XSS via openAction in app/controllers/OPNsense/Cron/ItemController.php.
- risk 0.64cvss 9.8epss 0.01
Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which could lead to privilege escalation.
- risk 0.00cvss 9.8epss 0.04
A command injection vulnerability in the component diag_backup.php of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary commands via a crafted backup configuration file.
- risk 0.00cvss 9.0epss 0.01
uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Version 1.0.9 of uthenticode hashed the entire file rather than hashing sections by virtual address, in violation of the Authenticode specification. As a result, an attacker…
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in CSZCMS 1.3.0 allows remote attackers to run arbitrary SQL commands via p parameter or the search URL.
- risk 0.64cvss 9.8epss 0.01
Use of Hard-coded Cryptographic Key vulnerability in Sifir Bes Education and Informatics Kunduz - Homework Helper App allows Authentication Abuse, Authentication Bypass. This issue affects Kunduz - Homework Helper App: before 6.2.3.
- risk 0.59cvss 9.1epss 0.03
Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead to arbitrary code execution by an…
- risk 0.59cvss 9.1epss 0.02
Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.
- risk 0.63cvss 9.6epss 0.01
Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticated user to enable an escalation of privilege via network access.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK T10_v2 5.9c.5061_B20200511 has a stack-based buffer overflow in setStaticDhcpConfig in /lib/cste_modules/lan.so. Attackers can send crafted data in an MQTT packet, via the comment parameter, to control the return address and execute code.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK T10_v2 5.9c.5061_B20200511 has a stack-based buffer overflow in setWiFiWpsConfig in /lib/cste_modules/wps.so. Attackers can send crafted data in an MQTT packet, via the pin parameter, to control the return address and execute code.
- risk 0.62cvss 9.6epss 0.01
Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network access.
- risk 0.64cvss 9.8epss 0.02
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.03
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- risk 0.61cvss 9.3epss 0.02
Path traversal in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network access.
- risk 0.64cvss 9.8epss 0.02
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Microsoft Exchange Server Elevation of Privilege Vulnerability
- risk 0.64cvss 9.8epss 0.01
A potential vulnerability was reported in Radeon™ Software Crimson ReLive Edition which may allow escalation of privilege. Radeon™ Software Crimson ReLive Edition falls outside of the security support lifecycle and AMD does not plan to release any mitigations
- risk 0.57cvss 9.8epss 0.01
SES is a JavaScript environment that allows safe execution of arbitrary programs in Compartments. In version 0.18.0 prior to 0.18.7, 0.17.0 prior to 0.17.1, 0.16.0 prior to 0.16.1, 0.15.0 prior to 0.15.24, 0.14.0 prior to 0.14.5, an 0.13.0 prior to 0.13.5, there is a hole in the…
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in a2 License Portal System allows SQL Injection. This issue affects License Portal System: before 1.48.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in a2 Camera Trap Tracking System allows SQL Injection. This issue affects Camera Trap Tracking System: before 3.1905.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digital Ant E-Commerce Software allows SQL Injection. This issue affects E-Commerce Software: before 11.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oduyo Online Collection Software allows SQL Injection. This issue affects Online Collection Software: before 1.0.1.
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-jms/deductScores.php.
- risk 0.59cvss 9.0epss 0.01
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the ping tool of the web-interface.
- risk 0.59cvss 9.0epss 0.01
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the device name field of the web-interface.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farmakom Remote Administration Console allows SQL Injection. This issue affects Remote Administration Console: before 1.02.
- risk 0.64cvss 9.8epss 0.01
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications is vulnerable to SQL injection. This could allow an unauthenticated remote attackers to execute arbitrary SQL queries on the server database.
- risk 0.64cvss 9.8epss 0.00
Memory corruption in QESL while processing payload from external ESL device to firmware.
- risk 0.59cvss 9.1epss 0.01
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCOM i803, RUGGEDCOM i803NC, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M2100NC, RUGGEDCOM M2200, RUGGEDCOM M2200F, RUGGEDCOM…
- risk 0.60cvss 9.3epss 0.00
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.
- risk 0.59cvss 9.1epss 0.00
Memory corruption due to untrusted pointer dereference in automotive during system call.