| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-2884 | Cri | 0.64 | 9.8 | 0.01 | May 25, 2023 | Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG), Use of Insufficiently Random Values vulnerability in CBOT Chatbot allows Signature Spoofing by Key Recreation. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7. | ||
| CVE-2023-2882 | Cri | 0.64 | 9.8 | 0.01 | May 25, 2023 | Generation of Incorrect Security Tokens vulnerability in CBOT Chatbot allows Token Impersonation, Privilege Abuse. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7. | ||
| CVE-2023-2734 | Cri | 0.64 | 9.8 | 0.04 | May 25, 2023 | The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being supplied during the cart sync from mobile REST API request through the plugin. This makes it possible… | ||
| CVE-2023-2733 | Cri | 0.64 | 9.8 | 0.01 | May 25, 2023 | The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupon redemption REST API request through the plugin. This makes it possible for… | ||
| CVE-2023-2732 | Cri | 0.69 | 9.8 | 0.68 | May 25, 2023 | The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API request through the plugin. This makes it possible for… | ||
| CVE-2023-31458 | Cri | 0.64 | 9.8 | 0.01 | May 24, 2023 | A vulnerability in the Edge Gateway component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, because initial installation does not enforce… | ||
| CVE-2023-29721 | Cri | 0.64 | 9.8 | 0.01 | May 24, 2023 | SofaWiki <= 3.8.9 has a file upload vulnerability that leads to command execution. | ||
| CVE-2023-33796 | Cri | 0.59 | 9.1 | 0.01 | May 24, 2023 | A vulnerability in Netbox v3.5.1 allows unauthenticated attackers to execute queries against the GraphQL database, granting them access to sensitive data stored in the database. NOTE: the vendor disputes this because the reporter's only query was for the schema of the API, which… | ||
| CVE-2023-31457 | Cri | 0.64 | 9.8 | 0.01 | May 24, 2023 | A vulnerability in the Headquarters server component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated attacker with internal network access to execute arbitrary scripts due to improper access control. | ||
| CVE-2023-2868 | Cri | 0.83 | 9.4 | 0.88 | KEV | May 24, 2023 | A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape… | |
| CVE-2023-1174 | Cri | 0.64 | 9.8 | 0.01 | May 24, 2023 | This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected remote access to the minikube container. | ||
| CVE-2023-33246 | Cri | 0.79 | 9.8 | 0.97 | KEV | May 24, 2023 | For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit… | |
| CVE-2023-2064 | Cri | 0.64 | 9.8 | 0.01 | May 24, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Minova Technology eTrace allows SQL Injection. This issue affects eTrace: before 23.05.20. | ||
| CVE-2023-2045 | Cri | 0.64 | 9.8 | 0.01 | May 24, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ipekyolu Software Auto Damage Tracking Software allows SQL Injection. This issue affects Auto Damage Tracking Software: before 4. | ||
| CVE-2023-33010 | Cri | 0.78 | 9.8 | 0.29 | KEV | May 24, 2023 | A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions… | |
| CVE-2023-33009 | Cri | 0.78 | 9.8 | 0.28 | KEV | May 24, 2023 | A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions… | |
| CVE-2023-2750 | Cri | 0.64 | 9.8 | 0.01 | May 24, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cityboss E-municipality allows SQL Injection. This issue affects E-municipality: before 6.05. | ||
| CVE-2023-1424 | Cri | 0.65 | 10.0 | 0.03 | May 24, 2023 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules and MELSEC iQ-R Series CPU modules allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or… | ||
| CVE-2023-1508 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adam Retail Automation Systems Mobilmen Terminal Software allows SQL Injection. This issue affects Mobilmen Terminal Software: before 3. | ||
| CVE-2023-31752 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | SourceCodester Employee and Visitor Gate Pass Logging System v1.0 is vulnerable to SQL Injection via /employee_gatepass/classes/Login.php. | ||
| CVE-2023-23306 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnreability, which can result in an out-of-bounds write operation. A malicious application could create a specially crafted `Toybox.Ant.BurstPayload` object, call… | ||
| CVE-2023-23305 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | The GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 is vulnerable to various buffer overflows when loading binary resources. A malicious application embedding specially crafted resources could hijack the execution of the device's firmware. | ||
| CVE-2023-23304 | Cri | 0.59 | 9.1 | 0.01 | May 23, 2023 | The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head section to use the `Toybox.SensorHistory` module without permission. A malicious application could call any functions from the `Toybox.SensorHistory` module… | ||
| CVE-2023-23303 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copying various attributes. A malicious application could call the API method with specially crafted… | ||
| CVE-2023-23302 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | The `Toybox.GenericChannel.setDeviceConfig` API method in CIQ API version 1.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copying various attributes. A malicious application could call the API method with specially crafted object… | ||
| CVE-2023-23301 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | The `news` MonkeyC operation code in CIQ API version 1.0.0 through 4.1.7 fails to check that string resources are not extending past the end of the expected sections. A malicious CIQ application could craft a string that starts near the end of a section, and whose length extends… | ||
| CVE-2023-23300 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | The `Toybox.Cryptography.Cipher.initialize` API method in CIQ API version 3.0.0 through 4.1.7 does not validate its parameters, which can result in buffer overflows when copying data. A malicious application could call the API method with specially crafted parameters and hijack… | ||
| CVE-2023-23298 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | The `Toybox.Graphics.BufferedBitmap.initialize` API method in CIQ API version 2.3.0 through 4.1.7 does not validate its parameters, which can result in integer overflows when allocating the underlying bitmap buffer. A malicious application could call the API method with… | ||
| CVE-2023-33362 | Cri | 0.67 | 9.8 | 0.09 | May 23, 2023 | Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function. | ||
| CVE-2023-33361 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | Piwigo 13.6.0 is vulnerable to SQL Injection via /admin/permalinks.php. | ||
| CVE-2023-33338 | Cri | 0.64 | 9.8 | 0.04 | May 23, 2023 | Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter. | ||
| CVE-2023-28413 | Cri | 0.64 | 9.8 | 0.02 | May 23, 2023 | Directory traversal vulnerability in Snow Monkey Forms versions v5.0.6 and earlier allows a remote unauthenticated attacker to obtain sensitive information, alter the website, or cause a denial-of-service (DoS) condition. | ||
| CVE-2023-28409 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | Unrestricted upload of file with dangerous type exists in MW WP Form versions v4.4.2 and earlier, which may allow a remote unauthenticated attacker to upload an arbitrary file. | ||
| CVE-2023-28408 | Cri | 0.64 | 9.8 | 0.02 | May 23, 2023 | Directory traversal vulnerability in MW WP Form versions v4.4.2 and earlier allows a remote unauthenticated attacker to alter the website or cause a denial-of-service (DoS) condition, and obtain sensitive information depending on settings. | ||
| CVE-2023-27507 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | MicroEngine Mailform version 1.1.0 to 1.1.8 contains a path traversal vulnerability. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it. | ||
| CVE-2023-27397 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | Unrestricted upload of file with dangerous type exists in MicroEngine Mailform version 1.1.0 to 1.1.8. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it. | ||
| CVE-2023-27388 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | Improper authentication vulnerability in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login to the product as a registered user. Affected products and versions are as follows: T&D Corporation data logger products… | ||
| CVE-2023-25953 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | Code injection vulnerability in Drive Explorer for macOS versions 3.5.4 and earlier allows an attacker who can login to the client where the affected product is installed to inject arbitrary code while processing the product execution. Since a full disk access privilege is… | ||
| CVE-2023-31814 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php. | ||
| CVE-2023-29919 | Cri | 0.64 | 9.1 | 0.60 | May 23, 2023 | SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted. | ||
| CVE-2023-27068 | Cri | 0.64 | 9.8 | 0.02 | May 23, 2023 | Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.aspx. | ||
| CVE-2020-20012 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | WebPlus Pro v1.4.7.8.4-01 is vulnerable to Incorrect Access Control. | ||
| CVE-2023-31689 | Cri | 0.65 | 9.8 | 0.20 | May 22, 2023 | In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter and the textAreaCode parameter. It can write arbitrary strings into custom file names and upload any files, and write malicious code… | ||
| CVE-2023-2840 | Cri | 0.00 | 9.8 | 0.01 | May 22, 2023 | NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.2.2. | ||
| CVE-2023-2838 | Cri | 0.00 | 9.1 | 0.01 | May 22, 2023 | Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2. | ||
| CVE-2023-33294 | Cri | 0.64 | 9.8 | 0.01 | May 22, 2023 | An issue was discovered in KaiOS 3.0 before 3.1. The /system/bin/tctweb_server binary exposes a local web server that responds to GET and POST requests on port 2929. The server accepts arbitrary Bash commands and executes them as root. Because it is not permission or context… | ||
| CVE-2023-31098 | Cri | 0.57 | 9.8 | 0.01 | May 22, 2023 | Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.6.0. When users change their password to a simple password (with any character or symbol), attackers can easily guess the user's… | ||
| CVE-2023-31066 | Cri | 0.52 | 9.1 | 0.01 | May 22, 2023 | Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Different users in InLong could delete, edit, stop, and start others' sources! Users are advised to upgrade… | ||
| CVE-2023-31065 | Cri | 0.52 | 9.1 | 0.01 | May 22, 2023 | Insufficient Session Expiration vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. An old session can be used by an attacker even after the user has been deleted or the password has been changed. Users are… | ||
| CVE-2023-31062 | Cri | 0.57 | 9.8 | 0.01 | May 22, 2023 | Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. When the attacker has access to a valid (but unprivileged) account, the exploit can be executed using Burp Suite by sending a… |
- risk 0.64cvss 9.8epss 0.01
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG), Use of Insufficiently Random Values vulnerability in CBOT Chatbot allows Signature Spoofing by Key Recreation. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.
- risk 0.64cvss 9.8epss 0.01
Generation of Incorrect Security Tokens vulnerability in CBOT Chatbot allows Token Impersonation, Privilege Abuse. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.
- risk 0.64cvss 9.8epss 0.04
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being supplied during the cart sync from mobile REST API request through the plugin. This makes it possible…
- risk 0.64cvss 9.8epss 0.01
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupon redemption REST API request through the plugin. This makes it possible for…
- risk 0.69cvss 9.8epss 0.68
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API request through the plugin. This makes it possible for…
- risk 0.64cvss 9.8epss 0.01
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, because initial installation does not enforce…
- risk 0.64cvss 9.8epss 0.01
SofaWiki <= 3.8.9 has a file upload vulnerability that leads to command execution.
- risk 0.59cvss 9.1epss 0.01
A vulnerability in Netbox v3.5.1 allows unauthenticated attackers to execute queries against the GraphQL database, granting them access to sensitive data stored in the database. NOTE: the vendor disputes this because the reporter's only query was for the schema of the API, which…
- risk 0.64cvss 9.8epss 0.01
A vulnerability in the Headquarters server component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated attacker with internal network access to execute arbitrary scripts due to improper access control.
- risk 0.83cvss 9.4epss 0.88
A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape…
- risk 0.64cvss 9.8epss 0.01
This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected remote access to the minikube container.
- risk 0.79cvss 9.8epss 0.97
For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit…
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Minova Technology eTrace allows SQL Injection. This issue affects eTrace: before 23.05.20.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ipekyolu Software Auto Damage Tracking Software allows SQL Injection. This issue affects Auto Damage Tracking Software: before 4.
- risk 0.78cvss 9.8epss 0.29
A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions…
- risk 0.78cvss 9.8epss 0.28
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions…
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cityboss E-municipality allows SQL Injection. This issue affects E-municipality: before 6.05.
- risk 0.65cvss 10.0epss 0.03
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules and MELSEC iQ-R Series CPU modules allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or…
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adam Retail Automation Systems Mobilmen Terminal Software allows SQL Injection. This issue affects Mobilmen Terminal Software: before 3.
- risk 0.64cvss 9.8epss 0.01
SourceCodester Employee and Visitor Gate Pass Logging System v1.0 is vulnerable to SQL Injection via /employee_gatepass/classes/Login.php.
- risk 0.64cvss 9.8epss 0.01
The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnreability, which can result in an out-of-bounds write operation. A malicious application could create a specially crafted `Toybox.Ant.BurstPayload` object, call…
- risk 0.64cvss 9.8epss 0.01
The GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 is vulnerable to various buffer overflows when loading binary resources. A malicious application embedding specially crafted resources could hijack the execution of the device's firmware.
- risk 0.59cvss 9.1epss 0.01
The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head section to use the `Toybox.SensorHistory` module without permission. A malicious application could call any functions from the `Toybox.SensorHistory` module…
- risk 0.64cvss 9.8epss 0.01
The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copying various attributes. A malicious application could call the API method with specially crafted…
- risk 0.64cvss 9.8epss 0.01
The `Toybox.GenericChannel.setDeviceConfig` API method in CIQ API version 1.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copying various attributes. A malicious application could call the API method with specially crafted object…
- risk 0.64cvss 9.8epss 0.01
The `news` MonkeyC operation code in CIQ API version 1.0.0 through 4.1.7 fails to check that string resources are not extending past the end of the expected sections. A malicious CIQ application could craft a string that starts near the end of a section, and whose length extends…
- risk 0.64cvss 9.8epss 0.01
The `Toybox.Cryptography.Cipher.initialize` API method in CIQ API version 3.0.0 through 4.1.7 does not validate its parameters, which can result in buffer overflows when copying data. A malicious application could call the API method with specially crafted parameters and hijack…
- risk 0.64cvss 9.8epss 0.01
The `Toybox.Graphics.BufferedBitmap.initialize` API method in CIQ API version 2.3.0 through 4.1.7 does not validate its parameters, which can result in integer overflows when allocating the underlying bitmap buffer. A malicious application could call the API method with…
- risk 0.67cvss 9.8epss 0.09
Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.
- risk 0.64cvss 9.8epss 0.01
Piwigo 13.6.0 is vulnerable to SQL Injection via /admin/permalinks.php.
- risk 0.64cvss 9.8epss 0.04
Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter.
- risk 0.64cvss 9.8epss 0.02
Directory traversal vulnerability in Snow Monkey Forms versions v5.0.6 and earlier allows a remote unauthenticated attacker to obtain sensitive information, alter the website, or cause a denial-of-service (DoS) condition.
- risk 0.64cvss 9.8epss 0.01
Unrestricted upload of file with dangerous type exists in MW WP Form versions v4.4.2 and earlier, which may allow a remote unauthenticated attacker to upload an arbitrary file.
- risk 0.64cvss 9.8epss 0.02
Directory traversal vulnerability in MW WP Form versions v4.4.2 and earlier allows a remote unauthenticated attacker to alter the website or cause a denial-of-service (DoS) condition, and obtain sensitive information depending on settings.
- risk 0.64cvss 9.8epss 0.01
MicroEngine Mailform version 1.1.0 to 1.1.8 contains a path traversal vulnerability. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.
- risk 0.64cvss 9.8epss 0.01
Unrestricted upload of file with dangerous type exists in MicroEngine Mailform version 1.1.0 to 1.1.8. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.
- risk 0.64cvss 9.8epss 0.01
Improper authentication vulnerability in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login to the product as a registered user. Affected products and versions are as follows: T&D Corporation data logger products…
- risk 0.64cvss 9.8epss 0.01
Code injection vulnerability in Drive Explorer for macOS versions 3.5.4 and earlier allows an attacker who can login to the client where the affected product is installed to inject arbitrary code while processing the product execution. Since a full disk access privilege is…
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.
- risk 0.64cvss 9.1epss 0.60
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted.
- risk 0.64cvss 9.8epss 0.02
Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.aspx.
- risk 0.64cvss 9.8epss 0.01
WebPlus Pro v1.4.7.8.4-01 is vulnerable to Incorrect Access Control.
- risk 0.65cvss 9.8epss 0.20
In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter and the textAreaCode parameter. It can write arbitrary strings into custom file names and upload any files, and write malicious code…
- risk 0.00cvss 9.8epss 0.01
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.2.2.
- risk 0.00cvss 9.1epss 0.01
Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in KaiOS 3.0 before 3.1. The /system/bin/tctweb_server binary exposes a local web server that responds to GET and POST requests on port 2929. The server accepts arbitrary Bash commands and executes them as root. Because it is not permission or context…
- risk 0.57cvss 9.8epss 0.01
Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.6.0. When users change their password to a simple password (with any character or symbol), attackers can easily guess the user's…
- risk 0.52cvss 9.1epss 0.01
Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Different users in InLong could delete, edit, stop, and start others' sources! Users are advised to upgrade…
- risk 0.52cvss 9.1epss 0.01
Insufficient Session Expiration vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. An old session can be used by an attacker even after the user has been deleted or the password has been changed. Users are…
- risk 0.57cvss 9.8epss 0.01
Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. When the attacker has access to a valid (but unprivileged) account, the exploit can be executed using Burp Suite by sending a…