| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-33778 | Cri | 0.64 | 9.8 | 0.01 | Jun 1, 2023 | Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected… | ||
| CVE-2023-23952 | Cri | 0.64 | 9.8 | 0.01 | Jun 1, 2023 | Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability. | ||
| CVE-2023-34257 | Cri | 0.64 | 9.8 | 0.01 | May 31, 2023 | An issue was discovered in BMC Patrol through 23.1.00. The agent's configuration can be remotely modified (and, by default, authentication is not required). Some configuration fields related to SNMP (e.g., masterAgentName or masterAgentStartLine) result in code execution when… | ||
| CVE-2023-33735 | Cri | 0.66 | 9.8 | 0.32 | May 31, 2023 | D-Link DIR-846 v1.00A52 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in the /HNAP1 interface. | ||
| CVE-2023-33730 | Cri | 0.64 | 9.8 | 0.01 | May 31, 2023 | Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remote attacker to retrieve password of any admin or normal user in plain text format. | ||
| CVE-2021-45039 | Cri | 0.64 | 9.8 | 0.04 | May 31, 2023 | Multiple models of the Uniview IP Camera (e.g., IPC_G6103 B6103.16.10.B25.201218, IPC_G61, IPC21, IPC23, IPC32, IPC36, IPC62, and IPC_HCMN) offer an undocumented UDP service on port 7788 that allows a remote unauthenticated attacker to overflow an internal buffer and achieve… | ||
| CVE-2022-35744 | Cri | 0.64 | 9.8 | 0.02 | May 31, 2023 | Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability | ||
| CVE-2023-29747 | Cri | 0.64 | 9.8 | 0.01 | May 31, 2023 | Story Saver for Instragram - Video Downloader 1.0.6 for Android exists exposed component, the component provides the method to modify the SharedPreference file. The attacker can use the method to modify the data in any SharedPreference file, these data will be loaded into the… | ||
| CVE-2023-34218 | Cri | 0.59 | 9.1 | 0.01 | May 31, 2023 | In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible | ||
| CVE-2023-33509 | Cri | 0.64 | 9.8 | 0.01 | May 31, 2023 | KramerAV VIA GO² < 4.0.1.1326 is vulnerable to SQL Injection. | ||
| CVE-2023-33508 | Cri | 0.64 | 9.8 | 0.01 | May 31, 2023 | KramerAV VIA GO² < 4.0.1.1326 is vulnerable to unauthenticated file upload resulting in Remote Code Execution (RCE). | ||
| CVE-2023-33487 | Cri | 0.64 | 9.8 | 0.01 | May 31, 2023 | TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion vulnerability in setDiagnosisCfg.This vulnerability allows an attacker to execute arbitrary commands through the "ip" parameter. | ||
| CVE-2023-33486 | Cri | 0.64 | 9.8 | 0.01 | May 31, 2023 | TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setOpModeCfg. This vulnerability allows an attacker to execute arbitrary commands through the "hostName" parameter. | ||
| CVE-2023-2987 | Cri | 0.57 | 9.8 | 0.01 | May 31, 2023 | The Wordapp plugin for WordPress is vulnerable to authorization bypass due to an use of insufficiently unique cryptographic signature on the 'wa_pdx_op_config_set' function in versions up to, and including, 1.6.0. This makes it possible for unauthenticated attackers to the… | ||
| CVE-2023-28347 | Cri | 0.63 | 9.6 | 0.03 | May 31, 2023 | An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a proof-of-concept script that functions similarly to a Student Console, providing unauthenticated attackers with the ability to exploit XSS vulnerabilities within the… | ||
| CVE-2022-47526 | Cri | 0.64 | 9.8 | 0.01 | May 31, 2023 | Fox-IT DataDiode (aka Fox DataDiode) 3.4.3 suffers from a path traversal vulnerability with resultant arbitrary writing of files. A remote attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the downstream node user. Exploitation of… | ||
| CVE-2023-29741 | Cri | 0.64 | 9.8 | 0.01 | May 30, 2023 | An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause an escalation of privileges attack by manipulating the database. | ||
| CVE-2023-29739 | Cri | 0.64 | 9.8 | 0.01 | May 30, 2023 | An issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the component. | ||
| CVE-2023-29728 | Cri | 0.64 | 9.8 | 0.01 | May 30, 2023 | The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of privilege attack. | ||
| CVE-2023-29727 | Cri | 0.64 | 9.8 | 0.01 | May 30, 2023 | The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its database that is related to user privacy settings and affects the implementation of the normal functionality of the application. An attacker can… | ||
| CVE-2023-34152 | Cri | 0.64 | 9.8 | 0.08 | May 30, 2023 | A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured. | ||
| CVE-2023-33734 | Cri | 0.64 | 9.8 | 0.01 | May 30, 2023 | BlueCMS v1.6 was discovered to contain a SQL injection vulnerability via the keywords parameter at search.php. | ||
| CVE-2023-29734 | Cri | 0.64 | 9.8 | 0.01 | May 30, 2023 | An issue found in edjing Mix v.7.09.01 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the database. | ||
| CVE-2023-29732 | Cri | 0.64 | 9.8 | 0.01 | May 30, 2023 | SoLive 1.6.14 thru 1.6.20 for Android exists exposed component, the component provides the method to modify the SharedPreference file. The attacker can use the method to modify the data in any SharedPreference file, these data will be loaded into the memory when the application… | ||
| CVE-2022-36247 | Cri | 0.59 | 9.1 | 0.01 | May 30, 2023 | Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to IDOR via controlpanel.shopbeat.co.za. | ||
| CVE-2022-36246 | Cri | 0.64 | 9.8 | 0.01 | May 30, 2023 | Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Insecure Permissions. | ||
| CVE-2023-33975 | Cri | 0.00 | 9.8 | 0.01 | May 30, 2023 | RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. In version 2023.01 and prior, an attacker can send a crafted frame to the device resulting in an out of bounds write in the packet buffer. The… | ||
| CVE-2023-2972 | Cri | 0.57 | 9.8 | 0.01 | May 30, 2023 | Prototype Pollution in GitHub repository antfu/utils prior to 0.7.3. | ||
| CVE-2023-33193 | Cri | 0.59 | 9.1 | 0.02 | May 30, 2023 | Emby Server is a user-installable home media server which stores and organizes a user's media files of virtually any format and makes them available for viewing at home and abroad on a broad range of client devices. This vulnerability may allow administrative access to an Emby… | ||
| CVE-2023-33189 | Cri | 0.58 | 10.0 | 0.01 | May 30, 2023 | Pomerium is an identity and context-aware access proxy. With specially crafted requests, incorrect authorization decisions may be made by Pomerium. This issue has been patched in versions 0.17.4, 0.18.1, 0.19.2, 0.20.1, 0.21.4 and 0.22.2. | ||
| CVE-2023-33175 | Cri | 0.52 | 9.1 | 0.01 | May 30, 2023 | ToUI is a Python package for creating user interfaces (websites and desktop apps) from HTML. ToUI is using Flask-Caching (SimpleCache) to store user variables. Websites that use `Website.user_vars` property. It affects versions 2.0.1 to 2.4.0. This issue has been patched in… | ||
| CVE-2023-34205 | Cri | 0.52 | 9.1 | 0.00 | May 30, 2023 | In Moov signedxml through 1.0.0, parsing the raw XML (as received) can result in different output than parsing the canonicalized XML. Thus, signature validation can be bypassed via a Signature Wrapping attack (aka XSW). | ||
| CVE-2023-32692 | Cri | 0.57 | 9.8 | 0.01 | May 30, 2023 | CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. The vulnerability exists in the Validation library, and validation methods in the controller and in-model validation are also… | ||
| CVE-2022-24629 | Cri | 0.70 | 9.8 | 0.37 | May 29, 2023 | An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php. An attacker can upload a .php file to… | ||
| CVE-2022-24627 | Cri | 0.69 | 9.8 | 0.26 | May 29, 2023 | An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parameter of the process_login.php login form. | ||
| CVE-2019-19791 | Cri | 0.64 | 9.8 | 0.01 | May 29, 2023 | In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restrict access to SOAP/REST endpoints (when some LemonLDAP::NG setup options are used). For example, an attacker can insert index.fcgi/index.fcgi into a URL to… | ||
| CVE-2015-20108 | Cri | 0.57 | 9.8 | 0.01 | May 27, 2023 | xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used. | ||
| CVE-2023-32321 | Cri | 0.64 | 9.8 | 0.02 | May 26, 2023 | CKAN is an open-source data management system for powering data hubs and data portals. Multiple vulnerabilities have been discovered in Ckan which may lead to remote code execution. An arbitrary file write in `resource_create` and `package_update` actions, using the… | ||
| CVE-2023-2825 | Cri | 0.74 | 10.0 | 0.72 | May 26, 2023 | An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups. | ||
| CVE-2022-48479 | Cri | 0.64 | 9.8 | 0.00 | May 26, 2023 | The facial recognition TA of some products has the out-of-bounds memory read vulnerability. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service. | ||
| CVE-2022-48478 | Cri | 0.64 | 9.8 | 0.00 | May 26, 2023 | The facial recognition TA of some products lacks memory length verification. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service. | ||
| CVE-2021-46887 | Cri | 0.64 | 9.8 | 0.00 | May 26, 2023 | Lack of length check vulnerability in the HW_KEYMASTER module. Successful exploitation of this vulnerability may cause out-of-bounds read. | ||
| CVE-2023-30145 | Cri | 0.63 | 9.8 | 0.46 | May 26, 2023 | Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter. | ||
| CVE-2022-46945 | Cri | 0.55 | 9.1 | 0.04 | May 26, 2023 | Nagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagVisHoverUrl.php. | ||
| CVE-2023-33280 | Cri | 0.64 | 9.8 | 0.01 | May 25, 2023 | In the Store Commander scquickaccounting module for PrestaShop through 3.7.3, multiple sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection. | ||
| CVE-2023-33279 | Cri | 0.64 | 9.8 | 0.01 | May 25, 2023 | In the Store Commander scfixmyprestashop module through 2023-05-09 for PrestaShop, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection. | ||
| CVE-2023-33278 | Cri | 0.64 | 9.8 | 0.01 | May 25, 2023 | In the Store Commander scexportcustomers module for PrestaShop through 3.6.1, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection. | ||
| CVE-2023-26216 | Cri | 0.59 | 9.1 | 0.01 | May 25, 2023 | The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an exploitable vulnerability that allows an attacker to upload files to a directory accessible by the web server. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.5.16 and below. | ||
| CVE-2023-2851 | Cri | 0.64 | 9.8 | 0.01 | May 25, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AGT Tech Ceppatron allows Command Line Execution through SQL Injection, SQL Injection. This issue affects all versions of the sofware also EOS when CVE-ID assigned. | ||
| CVE-2023-2887 | Cri | 0.64 | 9.8 | 0.01 | May 25, 2023 | Authentication Bypass by Spoofing vulnerability in CBOT Chatbot allows Authentication Bypass. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7. |
- risk 0.64cvss 9.8epss 0.01
Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected…
- risk 0.64cvss 9.8epss 0.01
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in BMC Patrol through 23.1.00. The agent's configuration can be remotely modified (and, by default, authentication is not required). Some configuration fields related to SNMP (e.g., masterAgentName or masterAgentStartLine) result in code execution when…
- risk 0.66cvss 9.8epss 0.32
D-Link DIR-846 v1.00A52 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in the /HNAP1 interface.
- risk 0.64cvss 9.8epss 0.01
Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remote attacker to retrieve password of any admin or normal user in plain text format.
- risk 0.64cvss 9.8epss 0.04
Multiple models of the Uniview IP Camera (e.g., IPC_G6103 B6103.16.10.B25.201218, IPC_G61, IPC21, IPC23, IPC32, IPC36, IPC62, and IPC_HCMN) offer an undocumented UDP service on port 7788 that allows a remote unauthenticated attacker to overflow an internal buffer and achieve…
- risk 0.64cvss 9.8epss 0.02
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.01
Story Saver for Instragram - Video Downloader 1.0.6 for Android exists exposed component, the component provides the method to modify the SharedPreference file. The attacker can use the method to modify the data in any SharedPreference file, these data will be loaded into the…
- risk 0.59cvss 9.1epss 0.01
In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible
- risk 0.64cvss 9.8epss 0.01
KramerAV VIA GO² < 4.0.1.1326 is vulnerable to SQL Injection.
- risk 0.64cvss 9.8epss 0.01
KramerAV VIA GO² < 4.0.1.1326 is vulnerable to unauthenticated file upload resulting in Remote Code Execution (RCE).
- risk 0.64cvss 9.8epss 0.01
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion vulnerability in setDiagnosisCfg.This vulnerability allows an attacker to execute arbitrary commands through the "ip" parameter.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setOpModeCfg. This vulnerability allows an attacker to execute arbitrary commands through the "hostName" parameter.
- risk 0.57cvss 9.8epss 0.01
The Wordapp plugin for WordPress is vulnerable to authorization bypass due to an use of insufficiently unique cryptographic signature on the 'wa_pdx_op_config_set' function in versions up to, and including, 1.6.0. This makes it possible for unauthenticated attackers to the…
- risk 0.63cvss 9.6epss 0.03
An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a proof-of-concept script that functions similarly to a Student Console, providing unauthenticated attackers with the ability to exploit XSS vulnerabilities within the…
- risk 0.64cvss 9.8epss 0.01
Fox-IT DataDiode (aka Fox DataDiode) 3.4.3 suffers from a path traversal vulnerability with resultant arbitrary writing of files. A remote attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the downstream node user. Exploitation of…
- risk 0.64cvss 9.8epss 0.01
An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause an escalation of privileges attack by manipulating the database.
- risk 0.64cvss 9.8epss 0.01
An issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the component.
- risk 0.64cvss 9.8epss 0.01
The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of privilege attack.
- risk 0.64cvss 9.8epss 0.01
The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its database that is related to user privacy settings and affects the implementation of the normal functionality of the application. An attacker can…
- risk 0.64cvss 9.8epss 0.08
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
- risk 0.64cvss 9.8epss 0.01
BlueCMS v1.6 was discovered to contain a SQL injection vulnerability via the keywords parameter at search.php.
- risk 0.64cvss 9.8epss 0.01
An issue found in edjing Mix v.7.09.01 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the database.
- risk 0.64cvss 9.8epss 0.01
SoLive 1.6.14 thru 1.6.20 for Android exists exposed component, the component provides the method to modify the SharedPreference file. The attacker can use the method to modify the data in any SharedPreference file, these data will be loaded into the memory when the application…
- risk 0.59cvss 9.1epss 0.01
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to IDOR via controlpanel.shopbeat.co.za.
- risk 0.64cvss 9.8epss 0.01
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Insecure Permissions.
- risk 0.00cvss 9.8epss 0.01
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. In version 2023.01 and prior, an attacker can send a crafted frame to the device resulting in an out of bounds write in the packet buffer. The…
- risk 0.57cvss 9.8epss 0.01
Prototype Pollution in GitHub repository antfu/utils prior to 0.7.3.
- risk 0.59cvss 9.1epss 0.02
Emby Server is a user-installable home media server which stores and organizes a user's media files of virtually any format and makes them available for viewing at home and abroad on a broad range of client devices. This vulnerability may allow administrative access to an Emby…
- risk 0.58cvss 10.0epss 0.01
Pomerium is an identity and context-aware access proxy. With specially crafted requests, incorrect authorization decisions may be made by Pomerium. This issue has been patched in versions 0.17.4, 0.18.1, 0.19.2, 0.20.1, 0.21.4 and 0.22.2.
- risk 0.52cvss 9.1epss 0.01
ToUI is a Python package for creating user interfaces (websites and desktop apps) from HTML. ToUI is using Flask-Caching (SimpleCache) to store user variables. Websites that use `Website.user_vars` property. It affects versions 2.0.1 to 2.4.0. This issue has been patched in…
- risk 0.52cvss 9.1epss 0.00
In Moov signedxml through 1.0.0, parsing the raw XML (as received) can result in different output than parsing the canonicalized XML. Thus, signature validation can be bypassed via a Signature Wrapping attack (aka XSW).
- risk 0.57cvss 9.8epss 0.01
CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. The vulnerability exists in the Validation library, and validation methods in the controller and in-model validation are also…
- risk 0.70cvss 9.8epss 0.37
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php. An attacker can upload a .php file to…
- risk 0.69cvss 9.8epss 0.26
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parameter of the process_login.php login form.
- risk 0.64cvss 9.8epss 0.01
In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restrict access to SOAP/REST endpoints (when some LemonLDAP::NG setup options are used). For example, an attacker can insert index.fcgi/index.fcgi into a URL to…
- risk 0.57cvss 9.8epss 0.01
xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.
- risk 0.64cvss 9.8epss 0.02
CKAN is an open-source data management system for powering data hubs and data portals. Multiple vulnerabilities have been discovered in Ckan which may lead to remote code execution. An arbitrary file write in `resource_create` and `package_update` actions, using the…
- risk 0.74cvss 10.0epss 0.72
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.
- risk 0.64cvss 9.8epss 0.00
The facial recognition TA of some products has the out-of-bounds memory read vulnerability. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service.
- risk 0.64cvss 9.8epss 0.00
The facial recognition TA of some products lacks memory length verification. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service.
- risk 0.64cvss 9.8epss 0.00
Lack of length check vulnerability in the HW_KEYMASTER module. Successful exploitation of this vulnerability may cause out-of-bounds read.
- risk 0.63cvss 9.8epss 0.46
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter.
- risk 0.55cvss 9.1epss 0.04
Nagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagVisHoverUrl.php.
- risk 0.64cvss 9.8epss 0.01
In the Store Commander scquickaccounting module for PrestaShop through 3.7.3, multiple sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.
- risk 0.64cvss 9.8epss 0.01
In the Store Commander scfixmyprestashop module through 2023-05-09 for PrestaShop, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.
- risk 0.64cvss 9.8epss 0.01
In the Store Commander scexportcustomers module for PrestaShop through 3.6.1, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.
- risk 0.59cvss 9.1epss 0.01
The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an exploitable vulnerability that allows an attacker to upload files to a directory accessible by the web server. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.5.16 and below.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AGT Tech Ceppatron allows Command Line Execution through SQL Injection, SQL Injection. This issue affects all versions of the sofware also EOS when CVE-ID assigned.
- risk 0.64cvss 9.8epss 0.01
Authentication Bypass by Spoofing vulnerability in CBOT Chatbot allows Authentication Bypass. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.