| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-3110 | Cri | 0.62 | 9.6 | 0.00 | Jun 21, 2023 | Description: A vulnerability in SiLabs Unify Gateway 1.3.1 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution. | ||
| CVE-2023-0972 | Cri | 0.62 | 9.6 | 0.00 | Jun 21, 2023 | Description: A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution. | ||
| CVE-2023-0971 | Cri | 0.62 | 9.6 | 0.00 | Jun 21, 2023 | A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered. | ||
| CVE-2023-33584 | Cri | 0.68 | 9.8 | 0.14 | Jun 21, 2023 | Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the username and password fields… | ||
| CVE-2023-34340 | Cri | 0.57 | 9.8 | 0.01 | Jun 21, 2023 | Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo. This issue affects Apache Accumulo: 2.1.0. Accumulo 2.1.0 contains a defect in the user authentication process that may succeed when invalid credentials are provided. Users are advised to… | ||
| CVE-2023-34563 | Cri | 0.65 | 9.8 | 0.14 | Jun 20, 2023 | netgear R6250 Firmware Version 1.0.4.48 is vulnerable to Buffer Overflow after authentication. | ||
| CVE-2023-35885 | Cri | 0.70 | 9.8 | 0.75 | Jun 20, 2023 | CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication. | ||
| CVE-2023-35166 | Cri | 0.62 | 9.9 | 0.62 | Jun 20, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute any wiki content with the right of the TipsPanel author by creating a tip UI extension. This has been patched in XWiki 15.1-rc-1 and 14.10.5. | ||
| CVE-2023-34600 | Cri | 0.66 | 9.8 | 0.24 | Jun 20, 2023 | Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection. | ||
| CVE-2023-34541 | Cri | 0.57 | 9.8 | 0.01 | Jun 20, 2023 | Langchain 0.0.171 is vulnerable to Arbitrary code execution in load_prompt. | ||
| CVE-2020-21489 | Cri | 0.57 | 9.8 | 0.01 | Jun 20, 2023 | File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.php?r=admin-user%2Fupdate-self component. | ||
| CVE-2020-21474 | Cri | 0.64 | 9.8 | 0.01 | Jun 20, 2023 | File Upload vulnerability in NucleusCMS v.3.71 allows a remote attacker to execute arbitrary code via the /nucleus/plugins/skinfiles/?dir=rsd parameter. | ||
| CVE-2020-21174 | Cri | 0.57 | 9.8 | 0.01 | Jun 20, 2023 | File Upload vulenrability in liufee CMS v.2.0.7.1 allows a remote attacker to execute arbitrary code via the image suffix function. | ||
| CVE-2020-20735 | Cri | 0.64 | 9.8 | 0.01 | Jun 20, 2023 | File Upload vulnerability in LJCMS v.4.3.R60321 allows a remote attacker to execute arbitrary code via the ljcms/index.php parameter. | ||
| CVE-2020-20718 | Cri | 0.64 | 9.8 | 0.01 | Jun 20, 2023 | File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to the the save_file() parameter. | ||
| CVE-2020-20703 | Cri | 0.64 | 9.8 | 0.02 | Jun 20, 2023 | Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter. | ||
| CVE-2020-20413 | Cri | 0.64 | 9.8 | 0.01 | Jun 20, 2023 | SQL injection vulnerability found in WUZHICMS v.4.1.0 allows a remote attacker to execute arbitrary code via the checktitle() function in admin/content.php. | ||
| CVE-2023-35854 | Cri | 0.64 | 9.8 | 0.06 | Jun 20, 2023 | Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is… | ||
| CVE-2023-34159 | Cri | 0.64 | 9.8 | 0.00 | Jun 19, 2023 | Improper permission control vulnerability in the Notepad app.Successful exploitation of the vulnerability may lead to privilege escalation, which affects availability and confidentiality. | ||
| CVE-2023-31411 | Cri | 0.64 | 9.8 | 0.01 | Jun 19, 2023 | A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of API authentication. The lack of authentication in the API allows the attacker to potentially compromise the functionality of the EventCam App. | ||
| CVE-2023-31410 | Cri | 0.64 | 9.8 | 0.00 | Jun 19, 2023 | A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK EventCam App. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive… | ||
| CVE-2023-2907 | Cri | 0.64 | 9.8 | 0.01 | Jun 19, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Marksoft allows SQL Injection. This issue affects Marksoft: through Mobile:v.7.1.7 ; Login:1.4 ; API:20230605. | ||
| CVE-2023-27992 | Cri | 0.82 | 9.8 | 0.83 | KEV | Jun 19, 2023 | The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to… | |
| CVE-2023-34417 | Cri | 0.64 | 9.8 | 0.01 | Jun 19, 2023 | Memory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 114. | ||
| CVE-2023-34416 | Cri | 0.64 | 9.8 | 0.01 | Jun 19, 2023 | Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox… | ||
| CVE-2023-29542 | Cri | 0.64 | 9.8 | 0.01 | Jun 19, 2023 | A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code. *This bug only affects Firefox and Thunderbird on… | ||
| CVE-2023-29534 | Cri | 0.52 | 9.1 | 0.01 | Jun 19, 2023 | Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected.* This… | ||
| CVE-2023-25736 | Cri | 0.64 | 9.8 | 0.01 | Jun 19, 2023 | An invalid downcast from `nsHTMLDocument` to `nsIContent` could have lead to undefined behavior. This vulnerability affects Firefox < 110. | ||
| CVE-2019-25136 | Cri | 0.65 | 10.0 | 0.01 | Jun 19, 2023 | A compromised child process could have injected XBL Bindings into privileged CSS rules, resulting in arbitrary code execution and a sandbox escape. This vulnerability affects Firefox < 70. | ||
| CVE-2023-32216 | Cri | 0.64 | 9.8 | 0.01 | Jun 19, 2023 | Mozilla developers and community members Ronald Crane, Andrew McCreight, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 112. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these… | ||
| CVE-2023-29531 | Cri | 0.64 | 9.8 | 0.01 | Jun 19, 2023 | An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash. *This bug only affects Firefox and Thunderbird for macOS. Other operating systems are unaffected.* This vulnerability affects… | ||
| CVE-2023-27396 | Cri | 0.64 | 9.8 | 0.01 | Jun 19, 2023 | FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation) networks, and is used in FA networks composed of OMRON products. Multiple OMRON products that implement FINS protocol contain following… | ||
| CVE-2023-35857 | Cri | 0.64 | 9.8 | 0.01 | Jun 19, 2023 | In Siren Investigate before 13.2.2, session keys remain active even after logging out. | ||
| CVE-2023-35856 | Cri | 0.64 | 9.8 | 0.01 | Jun 19, 2023 | A buffer overflow in Nintendo Mario Kart Wii RMCP01, RMCE01, RMCJ01, and RMCK01 can be exploited by a game client to execute arbitrary code on a client's machine via a crafted packet. | ||
| CVE-2023-35855 | Cri | 0.64 | 9.8 | 0.01 | Jun 19, 2023 | A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client's machine by modifying the lservercfgfile console variable. | ||
| CVE-2023-35853 | Cri | 0.00 | 9.8 | 0.01 | Jun 19, 2023 | In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code. This is addressed in 6.0.13 by disabling Lua unless allow-rules is true in the security lua configuration section. | ||
| CVE-2023-35839 | Cri | 0.64 | 9.8 | 0.01 | Jun 19, 2023 | A bypass in the component sofa-hessian of Solon before v2.3.3 allows attackers to execute arbitrary code via providing crafted payload. | ||
| CVE-2023-35813 | Cri | 0.71 | 9.8 | 0.87 | Jun 17, 2023 | Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3. | ||
| CVE-2014-125106 | Cri | 0.57 | 9.8 | 0.01 | Jun 17, 2023 | Nanopb before 0.3.1 allows size_t overflows in pb_dec_bytes and pb_dec_string. | ||
| CVE-2023-35784 | Cri | 0.00 | 9.8 | 0.01 | Jun 16, 2023 | A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected. | ||
| CVE-2023-34832 | Cri | 0.64 | 9.8 | 0.01 | Jun 16, 2023 | TP-Link Archer AX10(EU)_V1.2_230220 was discovered to contain a buffer overflow via the function FUN_131e8 - 0x132B4. | ||
| CVE-2023-34659 | Cri | 0.65 | 9.8 | 0.12 | Jun 16, 2023 | jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface. | ||
| CVE-2023-25366 | Cri | 0.64 | 9.8 | 0.00 | Jun 16, 2023 | In Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS, insecure SCPI interface discloses web password. | ||
| CVE-2023-34548 | Cri | 0.64 | 9.8 | 0.01 | Jun 16, 2023 | Simple Customer Relationship Management 1.0 is vulnerable to SQL Injection via the email parameter. | ||
| CVE-2022-48472 | Cri | 0.64 | 9.8 | 0.01 | Jun 16, 2023 | A Huawei printer has a system command injection vulnerability. Successful exploitation could lead to remote code execution. Affected product versions include:BiSheng-WNM versions OTA-BiSheng-FW-2.0.0.211-beta,BiSheng-WNM FW 3.0.0.325,BiSheng-WNM FW 2.0.0.211. | ||
| CVE-2023-34157 | Cri | 0.65 | 10.0 | 0.00 | Jun 16, 2023 | Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app. | ||
| CVE-2023-35708 | Cri | 0.71 | 9.8 | 0.97 | Jun 16, 2023 | In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain… | ||
| CVE-2023-32754 | Cri | 0.64 | 9.8 | 0.01 | Jun 16, 2023 | Thinking Software Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify or delete database. | ||
| CVE-2023-32753 | Cri | 0.64 | 9.8 | 0.01 | Jun 16, 2023 | OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service. | ||
| CVE-2023-32752 | Cri | 0.64 | 9.8 | 0.01 | Jun 16, 2023 | L7 Networks InstantScan IS-8000 & InstantQoS IQ-8000’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system… |
- risk 0.62cvss 9.6epss 0.00
Description: A vulnerability in SiLabs Unify Gateway 1.3.1 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.
- risk 0.62cvss 9.6epss 0.00
Description: A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.
- risk 0.62cvss 9.6epss 0.00
A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered.
- risk 0.68cvss 9.8epss 0.14
Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the username and password fields…
- risk 0.57cvss 9.8epss 0.01
Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo. This issue affects Apache Accumulo: 2.1.0. Accumulo 2.1.0 contains a defect in the user authentication process that may succeed when invalid credentials are provided. Users are advised to…
- risk 0.65cvss 9.8epss 0.14
netgear R6250 Firmware Version 1.0.4.48 is vulnerable to Buffer Overflow after authentication.
- risk 0.70cvss 9.8epss 0.75
CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
- risk 0.62cvss 9.9epss 0.62
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute any wiki content with the right of the TipsPanel author by creating a tip UI extension. This has been patched in XWiki 15.1-rc-1 and 14.10.5.
- risk 0.66cvss 9.8epss 0.24
Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection.
- risk 0.57cvss 9.8epss 0.01
Langchain 0.0.171 is vulnerable to Arbitrary code execution in load_prompt.
- risk 0.57cvss 9.8epss 0.01
File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.php?r=admin-user%2Fupdate-self component.
- risk 0.64cvss 9.8epss 0.01
File Upload vulnerability in NucleusCMS v.3.71 allows a remote attacker to execute arbitrary code via the /nucleus/plugins/skinfiles/?dir=rsd parameter.
- risk 0.57cvss 9.8epss 0.01
File Upload vulenrability in liufee CMS v.2.0.7.1 allows a remote attacker to execute arbitrary code via the image suffix function.
- risk 0.64cvss 9.8epss 0.01
File Upload vulnerability in LJCMS v.4.3.R60321 allows a remote attacker to execute arbitrary code via the ljcms/index.php parameter.
- risk 0.64cvss 9.8epss 0.01
File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to the the save_file() parameter.
- risk 0.64cvss 9.8epss 0.02
Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability found in WUZHICMS v.4.1.0 allows a remote attacker to execute arbitrary code via the checktitle() function in admin/content.php.
- risk 0.64cvss 9.8epss 0.06
Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is…
- risk 0.64cvss 9.8epss 0.00
Improper permission control vulnerability in the Notepad app.Successful exploitation of the vulnerability may lead to privilege escalation, which affects availability and confidentiality.
- risk 0.64cvss 9.8epss 0.01
A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of API authentication. The lack of authentication in the API allows the attacker to potentially compromise the functionality of the EventCam App.
- risk 0.64cvss 9.8epss 0.00
A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK EventCam App. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive…
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Marksoft allows SQL Injection. This issue affects Marksoft: through Mobile:v.7.1.7 ; Login:1.4 ; API:20230605.
- risk 0.82cvss 9.8epss 0.83
The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to…
- risk 0.64cvss 9.8epss 0.01
Memory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 114.
- risk 0.64cvss 9.8epss 0.01
Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox…
- risk 0.64cvss 9.8epss 0.01
A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code. *This bug only affects Firefox and Thunderbird on…
- risk 0.52cvss 9.1epss 0.01
Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected.* This…
- risk 0.64cvss 9.8epss 0.01
An invalid downcast from `nsHTMLDocument` to `nsIContent` could have lead to undefined behavior. This vulnerability affects Firefox < 110.
- risk 0.65cvss 10.0epss 0.01
A compromised child process could have injected XBL Bindings into privileged CSS rules, resulting in arbitrary code execution and a sandbox escape. This vulnerability affects Firefox < 70.
- risk 0.64cvss 9.8epss 0.01
Mozilla developers and community members Ronald Crane, Andrew McCreight, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 112. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these…
- risk 0.64cvss 9.8epss 0.01
An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash. *This bug only affects Firefox and Thunderbird for macOS. Other operating systems are unaffected.* This vulnerability affects…
- risk 0.64cvss 9.8epss 0.01
FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation) networks, and is used in FA networks composed of OMRON products. Multiple OMRON products that implement FINS protocol contain following…
- risk 0.64cvss 9.8epss 0.01
In Siren Investigate before 13.2.2, session keys remain active even after logging out.
- risk 0.64cvss 9.8epss 0.01
A buffer overflow in Nintendo Mario Kart Wii RMCP01, RMCE01, RMCJ01, and RMCK01 can be exploited by a game client to execute arbitrary code on a client's machine via a crafted packet.
- risk 0.64cvss 9.8epss 0.01
A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client's machine by modifying the lservercfgfile console variable.
- risk 0.00cvss 9.8epss 0.01
In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code. This is addressed in 6.0.13 by disabling Lua unless allow-rules is true in the security lua configuration section.
- risk 0.64cvss 9.8epss 0.01
A bypass in the component sofa-hessian of Solon before v2.3.3 allows attackers to execute arbitrary code via providing crafted payload.
- risk 0.71cvss 9.8epss 0.87
Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.
- risk 0.57cvss 9.8epss 0.01
Nanopb before 0.3.1 allows size_t overflows in pb_dec_bytes and pb_dec_string.
- risk 0.00cvss 9.8epss 0.01
A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected.
- risk 0.64cvss 9.8epss 0.01
TP-Link Archer AX10(EU)_V1.2_230220 was discovered to contain a buffer overflow via the function FUN_131e8 - 0x132B4.
- risk 0.65cvss 9.8epss 0.12
jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.
- risk 0.64cvss 9.8epss 0.00
In Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS, insecure SCPI interface discloses web password.
- risk 0.64cvss 9.8epss 0.01
Simple Customer Relationship Management 1.0 is vulnerable to SQL Injection via the email parameter.
- risk 0.64cvss 9.8epss 0.01
A Huawei printer has a system command injection vulnerability. Successful exploitation could lead to remote code execution. Affected product versions include:BiSheng-WNM versions OTA-BiSheng-FW-2.0.0.211-beta,BiSheng-WNM FW 3.0.0.325,BiSheng-WNM FW 2.0.0.211.
- risk 0.65cvss 10.0epss 0.00
Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app.
- risk 0.71cvss 9.8epss 0.97
In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain…
- risk 0.64cvss 9.8epss 0.01
Thinking Software Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify or delete database.
- risk 0.64cvss 9.8epss 0.01
OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service.
- risk 0.64cvss 9.8epss 0.01
L7 Networks InstantScan IS-8000 & InstantQoS IQ-8000’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system…