| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-2586 | Cri | 0.59 | 9.0 | 0.01 | May 22, 2023 | Teltonika’s Remote Management System versions 4.14.0 is vulnerable to an unauthorized attacker registering previously unregistered devices through the RMS platform. If the user has not disabled the "RMS management feature" enabled by default, then an attacker could register… | ||
| CVE-2023-33236 | Cri | 0.64 | 9.8 | 0.01 | May 22, 2023 | MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequently bypass authentication for web-based APIs. | ||
| CVE-2023-2713 | Cri | 0.64 | 9.8 | 0.01 | May 20, 2023 | Authorization Bypass Through User-Controlled Key vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Authentication Abuse, Authentication Bypass. This issue affects Rental Module: before 23.05.15. | ||
| CVE-2023-2712 | Cri | 0.64 | 9.8 | 0.01 | May 20, 2023 | Unrestricted Upload of File with Dangerous Type vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Command Injection, Using Malicious Files, Upload a Web Shell to a Web Server. This issue affects Rental Module: before 23.05.15. | ||
| CVE-2023-2276 | Cri | 0.64 | 9.8 | 0.01 | May 20, 2023 | The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.10.7. This is due to the plugin providing user-controlled access to objects, letting a user… | ||
| CVE-2023-31707 | Cri | 0.64 | 9.8 | 0.01 | May 19, 2023 | SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php. | ||
| CVE-2023-2704 | Cri | 0.64 | 9.8 | 0.02 | May 19, 2023 | The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated… | ||
| CVE-2023-30470 | Cri | 0.00 | 9.8 | 0.01 | May 18, 2023 | A use-after-free related to unsound inference in the bytecode generation when optimizations are enabled for Hermes prior to commit da8990f737ebb9d9810633502f65ed462b819c09 could have been used by an attacker to achieve remote code execution. Note that this is only exploitable in… | ||
| CVE-2023-28753 | Cri | 0.00 | 9.8 | 0.02 | May 18, 2023 | netconsd prior to v0.2 was vulnerable to an integer overflow in its parse_packet function. A malicious individual could leverage this overflow to create heap memory corruption with attacker controlled data. | ||
| CVE-2023-28081 | Cri | 0.57 | 9.8 | 0.01 | May 18, 2023 | A bytecode optimization bug in Hermes prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could be used to cause an use-after-free and obtain arbitrary code execution via a carefully crafted payload. Note that this is only exploitable in cases where Hermes is used to… | ||
| CVE-2023-25933 | Cri | 0.00 | 9.8 | 0.01 | May 18, 2023 | A type confusion bug in TypedArray prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could have been used by a malicious attacker to execute arbitrary code via untrusted JavaScript. Note that this is only exploitable in cases where Hermes is used to execute untrusted… | ||
| CVE-2023-23557 | Cri | 0.00 | 9.8 | 0.01 | May 18, 2023 | An error in Hermes' algorithm for copying objects properties prior to commit a00d237346894c6067a594983be6634f4168c9ad could be used by a malicious attacker to execute arbitrary code via type confusion. Note that this is only exploitable in cases where Hermes is used to execute… | ||
| CVE-2023-23556 | Cri | 0.00 | 9.8 | 0.01 | May 18, 2023 | An error in BigInt conversion to Number in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have been used by a malicious attacker to execute arbitrary code due to an out-of-bound write. Note that this bug is only exploitable in cases where Hermes is used to… | ||
| CVE-2023-2024 | Cri | 0.65 | 10.0 | 0.01 | May 18, 2023 | Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances. | ||
| CVE-2023-30333 | Cri | 0.64 | 9.8 | 0.01 | May 18, 2023 | An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitrary code via a crafted file. | ||
| CVE-2023-27217 | Cri | 0.64 | 9.8 | 0.01 | May 18, 2023 | A stack-based buffer overflow in the ChangeFriendlyName() function of Belkin Smart Outlet V2 F7c063 firmware_2.00.11420.OWRT.PVT_SNSV2 allows attackers to cause a Denial of Service (DoS) via a crafted UPNP request. | ||
| CVE-2023-31729 | Cri | 0.64 | 9.8 | 0.01 | May 18, 2023 | TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi. | ||
| CVE-2023-29985 | Cri | 0.64 | 9.8 | 0.01 | May 18, 2023 | Sourcecodester Student Study Center Desk Management System v1.0 admin\reports\index.php#date_from has a SQL Injection vulnerability. | ||
| CVE-2023-2319 | Cri | 0.64 | 9.8 | 0.01 | May 17, 2023 | It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023-28154 (for PCS package), which was previously addressed in Red Hat Enterprise Linux 9.1 via… | ||
| CVE-2023-2780 | Cri | 0.57 | 9.8 | 0.06 | May 17, 2023 | Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1. | ||
| CVE-2023-30191 | Cri | 0.64 | 9.8 | 0.01 | May 17, 2023 | PrestaShop cdesigner < 3.1.9 is vulnerable to SQL Injection via CdesignerTraitementModuleFrontController::initContent(). | ||
| CVE-2023-31903 | Cri | 0.64 | 9.8 | 0.02 | May 17, 2023 | GuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload which allows remote attackers to execute arbitrary code by uploading a php file. | ||
| CVE-2023-31902 | Cri | 0.67 | 9.8 | 0.09 | May 17, 2023 | RPA Technology Mobile Mouse 3.6.0.4 is vulnerable to Remote Code Execution (RCE). | ||
| CVE-2023-31703 | Cri | 0.62 | 9.0 | 0.04 | May 17, 2023 | Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the from parameter. | ||
| CVE-2023-30438 | Cri | 0.60 | 9.3 | 0.00 | May 17, 2023 | An internally discovered vulnerability in PowerVM on IBM Power9 and Power10 systems could allow an attacker with privileged user access to a logical partition to perform an undetected violation of the isolation between logical partitions which could lead to data leakage or the… | ||
| CVE-2023-30189 | Cri | 0.64 | 9.8 | 0.01 | May 16, 2023 | Prestashop posstaticblocks <= 1.0.0 is vulnerable to SQL Injection via posstaticblocks::getPosCurrentHook(). | ||
| CVE-2023-27742 | Cri | 0.64 | 9.8 | 0.01 | May 16, 2023 | IDURAR ERP/CRM v1 was discovered to contain a SQL injection vulnerability via the component /api/login. | ||
| CVE-2023-31890 | Cri | 0.64 | 9.8 | 0.01 | May 16, 2023 | An XML Deserialization vulnerability in glazedlists v1.11.0 allows an attacker to execute arbitrary code via the BeanXMLByteCoder.decode() parameter. | ||
| CVE-2023-31857 | Cri | 0.64 | 9.8 | 0.02 | May 16, 2023 | Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code execution. The vulnerability path is /classes/Users.php?f=save. | ||
| CVE-2023-31856 | Cri | 0.64 | 9.8 | 0.03 | May 16, 2023 | A command injection vulnerability in the hostTime parameter in the function NTPSyncWithHostof TOTOLINK CP300+ V5.2cu.7594_B20200910 allows attackers to execute arbitrary commands via a crafted http packet. | ||
| CVE-2023-31587 | Cri | 0.64 | 9.8 | 0.02 | May 16, 2023 | Tenda AC5 router V15.03.06.28 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/WriteFacMac. | ||
| CVE-2023-31519 | Cri | 0.64 | 9.8 | 0.01 | May 16, 2023 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the email parameter at login_core.php. | ||
| CVE-2023-2499 | Cri | 0.64 | 9.8 | 0.01 | May 16, 2023 | The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.1.0. This is due to insufficient verification on the user being supplied during a Google social login through the plugin. This makes it possible for… | ||
| CVE-2023-32956 | Cri | 0.64 | 9.8 | 0.02 | May 16, 2023 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote attackers to execute arbitrary code via unspecified vectors. | ||
| CVE-2023-29961 | Cri | 0.64 | 9.8 | 0.01 | May 16, 2023 | D-Link DIR-605L firmware version 1.17B01 BETA is vulnerable to stack overflow via /goform/formTcpipSetup, | ||
| CVE-2021-0877 | Cri | 0.64 | 9.8 | 0.00 | May 15, 2023 | Product: AndroidVersions: Android SoCAndroid ID: A-273754094 | ||
| CVE-2023-32314 | Cri | 0.57 | 9.8 | 0.08 | May 15, 2023 | vm2 is a sandbox that can run untrusted code with Node's built-in modules. A sandbox escape vulnerability exists in vm2 for versions up to and including 3.9.17. It abuses an unexpected creation of a host object based on the specification of `Proxy`. As a result a threat actor… | ||
| CVE-2023-30245 | Cri | 0.64 | 9.8 | 0.01 | May 15, 2023 | SQL injection vulnerability found in Judging Management System v.1.0 allows a remote attacker to execute arbitrary code via the crit_id parameter of the edit_criteria.php file. | ||
| CVE-2023-29861 | Cri | 0.64 | 9.8 | 0.02 | May 15, 2023 | An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the management page of the device. | ||
| CVE-2023-29862 | Cri | 0.64 | 9.8 | 0.02 | May 15, 2023 | An issue found in Agasio-Camera device version not specified allows a remote attacker to execute arbitrary code via the check and authLevel parameters. | ||
| CVE-2023-0600 | Cri | 0.64 | 9.8 | 0.04 | May 15, 2023 | The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks. | ||
| CVE-2022-4774 | Cri | 0.64 | 9.8 | 0.02 | May 15, 2023 | The Bit Form WordPress plugin before 1.9 does not validate the file types uploaded via it's file upload form field, allowing unauthenticated users to upload arbitrary files types such as PHP or HTML files to the server, leading to Remote Code Execution. | ||
| CVE-2023-31986 | Cri | 0.64 | 9.8 | 0.08 | May 15, 2023 | A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the setWAN function in /bin/webs without any limitations. | ||
| CVE-2022-47937 | Cri | 0.64 | 9.8 | 0.02 | May 15, 2023 | Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted input. The org.apache.sling.commons.json bundle has been deprecated as of March 2017 and should not be used anymore. Consumers are… | ||
| CVE-2023-1698 | Cri | 0.70 | 9.8 | 0.82 | May 15, 2023 | In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise. | ||
| CVE-2023-1096 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2023 | SnapCenter versions 4.7 prior to 4.7P2 and 4.8 prior to 4.8P1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to gain access as an admin user. | ||
| CVE-2023-30247 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2023 | File Upload vulnerability found in Oretnom23 Storage Unit Rental Management System v.1.0 allows a remote attacker to execute arbitrary code via the update_settings parameter. | ||
| CVE-2023-31983 | Cri | 0.66 | 9.8 | 0.25 | May 12, 2023 | A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the mp function in /bin/webs without any limitations. | ||
| CVE-2023-27823 | Cri | 0.71 | 9.8 | 0.54 | May 12, 2023 | An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials. | ||
| CVE-2023-1934 | Cri | 0.67 | 9.8 | 0.08 | May 12, 2023 | The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL Injection vulnerability. Present within the hitlogcsv.jsp endpoint, this security flaw permits unauthenticated attackers to engage with the underlying… |
- risk 0.59cvss 9.0epss 0.01
Teltonika’s Remote Management System versions 4.14.0 is vulnerable to an unauthorized attacker registering previously unregistered devices through the RMS platform. If the user has not disabled the "RMS management feature" enabled by default, then an attacker could register…
- risk 0.64cvss 9.8epss 0.01
MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequently bypass authentication for web-based APIs.
- risk 0.64cvss 9.8epss 0.01
Authorization Bypass Through User-Controlled Key vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Authentication Abuse, Authentication Bypass. This issue affects Rental Module: before 23.05.15.
- risk 0.64cvss 9.8epss 0.01
Unrestricted Upload of File with Dangerous Type vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Command Injection, Using Malicious Files, Upload a Web Shell to a Web Server. This issue affects Rental Module: before 23.05.15.
- risk 0.64cvss 9.8epss 0.01
The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.10.7. This is due to the plugin providing user-controlled access to objects, letting a user…
- risk 0.64cvss 9.8epss 0.01
SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php.
- risk 0.64cvss 9.8epss 0.02
The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated…
- risk 0.00cvss 9.8epss 0.01
A use-after-free related to unsound inference in the bytecode generation when optimizations are enabled for Hermes prior to commit da8990f737ebb9d9810633502f65ed462b819c09 could have been used by an attacker to achieve remote code execution. Note that this is only exploitable in…
- risk 0.00cvss 9.8epss 0.02
netconsd prior to v0.2 was vulnerable to an integer overflow in its parse_packet function. A malicious individual could leverage this overflow to create heap memory corruption with attacker controlled data.
- risk 0.57cvss 9.8epss 0.01
A bytecode optimization bug in Hermes prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could be used to cause an use-after-free and obtain arbitrary code execution via a carefully crafted payload. Note that this is only exploitable in cases where Hermes is used to…
- risk 0.00cvss 9.8epss 0.01
A type confusion bug in TypedArray prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could have been used by a malicious attacker to execute arbitrary code via untrusted JavaScript. Note that this is only exploitable in cases where Hermes is used to execute untrusted…
- risk 0.00cvss 9.8epss 0.01
An error in Hermes' algorithm for copying objects properties prior to commit a00d237346894c6067a594983be6634f4168c9ad could be used by a malicious attacker to execute arbitrary code via type confusion. Note that this is only exploitable in cases where Hermes is used to execute…
- risk 0.00cvss 9.8epss 0.01
An error in BigInt conversion to Number in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have been used by a malicious attacker to execute arbitrary code due to an out-of-bound write. Note that this bug is only exploitable in cases where Hermes is used to…
- risk 0.65cvss 10.0epss 0.01
Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitrary code via a crafted file.
- risk 0.64cvss 9.8epss 0.01
A stack-based buffer overflow in the ChangeFriendlyName() function of Belkin Smart Outlet V2 F7c063 firmware_2.00.11420.OWRT.PVT_SNSV2 allows attackers to cause a Denial of Service (DoS) via a crafted UPNP request.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Student Study Center Desk Management System v1.0 admin\reports\index.php#date_from has a SQL Injection vulnerability.
- risk 0.64cvss 9.8epss 0.01
It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023-28154 (for PCS package), which was previously addressed in Red Hat Enterprise Linux 9.1 via…
- risk 0.57cvss 9.8epss 0.06
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1.
- risk 0.64cvss 9.8epss 0.01
PrestaShop cdesigner < 3.1.9 is vulnerable to SQL Injection via CdesignerTraitementModuleFrontController::initContent().
- risk 0.64cvss 9.8epss 0.02
GuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload which allows remote attackers to execute arbitrary code by uploading a php file.
- risk 0.67cvss 9.8epss 0.09
RPA Technology Mobile Mouse 3.6.0.4 is vulnerable to Remote Code Execution (RCE).
- risk 0.62cvss 9.0epss 0.04
Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the from parameter.
- risk 0.60cvss 9.3epss 0.00
An internally discovered vulnerability in PowerVM on IBM Power9 and Power10 systems could allow an attacker with privileged user access to a logical partition to perform an undetected violation of the isolation between logical partitions which could lead to data leakage or the…
- risk 0.64cvss 9.8epss 0.01
Prestashop posstaticblocks <= 1.0.0 is vulnerable to SQL Injection via posstaticblocks::getPosCurrentHook().
- risk 0.64cvss 9.8epss 0.01
IDURAR ERP/CRM v1 was discovered to contain a SQL injection vulnerability via the component /api/login.
- risk 0.64cvss 9.8epss 0.01
An XML Deserialization vulnerability in glazedlists v1.11.0 allows an attacker to execute arbitrary code via the BeanXMLByteCoder.decode() parameter.
- risk 0.64cvss 9.8epss 0.02
Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code execution. The vulnerability path is /classes/Users.php?f=save.
- risk 0.64cvss 9.8epss 0.03
A command injection vulnerability in the hostTime parameter in the function NTPSyncWithHostof TOTOLINK CP300+ V5.2cu.7594_B20200910 allows attackers to execute arbitrary commands via a crafted http packet.
- risk 0.64cvss 9.8epss 0.02
Tenda AC5 router V15.03.06.28 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/WriteFacMac.
- risk 0.64cvss 9.8epss 0.01
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the email parameter at login_core.php.
- risk 0.64cvss 9.8epss 0.01
The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.1.0. This is due to insufficient verification on the user being supplied during a Google social login through the plugin. This makes it possible for…
- risk 0.64cvss 9.8epss 0.02
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote attackers to execute arbitrary code via unspecified vectors.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-605L firmware version 1.17B01 BETA is vulnerable to stack overflow via /goform/formTcpipSetup,
- risk 0.64cvss 9.8epss 0.00
Product: AndroidVersions: Android SoCAndroid ID: A-273754094
- risk 0.57cvss 9.8epss 0.08
vm2 is a sandbox that can run untrusted code with Node's built-in modules. A sandbox escape vulnerability exists in vm2 for versions up to and including 3.9.17. It abuses an unexpected creation of a host object based on the specification of `Proxy`. As a result a threat actor…
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability found in Judging Management System v.1.0 allows a remote attacker to execute arbitrary code via the crit_id parameter of the edit_criteria.php file.
- risk 0.64cvss 9.8epss 0.02
An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the management page of the device.
- risk 0.64cvss 9.8epss 0.02
An issue found in Agasio-Camera device version not specified allows a remote attacker to execute arbitrary code via the check and authLevel parameters.
- risk 0.64cvss 9.8epss 0.04
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.
- risk 0.64cvss 9.8epss 0.02
The Bit Form WordPress plugin before 1.9 does not validate the file types uploaded via it's file upload form field, allowing unauthenticated users to upload arbitrary files types such as PHP or HTML files to the server, leading to Remote Code Execution.
- risk 0.64cvss 9.8epss 0.08
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the setWAN function in /bin/webs without any limitations.
- risk 0.64cvss 9.8epss 0.02
Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted input. The org.apache.sling.commons.json bundle has been deprecated as of March 2017 and should not be used anymore. Consumers are…
- risk 0.70cvss 9.8epss 0.82
In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.
- risk 0.64cvss 9.8epss 0.01
SnapCenter versions 4.7 prior to 4.7P2 and 4.8 prior to 4.8P1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to gain access as an admin user.
- risk 0.64cvss 9.8epss 0.01
File Upload vulnerability found in Oretnom23 Storage Unit Rental Management System v.1.0 allows a remote attacker to execute arbitrary code via the update_settings parameter.
- risk 0.66cvss 9.8epss 0.25
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the mp function in /bin/webs without any limitations.
- risk 0.71cvss 9.8epss 0.54
An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.
- risk 0.67cvss 9.8epss 0.08
The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL Injection vulnerability. Present within the hitlogcsv.jsp endpoint, this security flaw permits unauthenticated attackers to engage with the underlying…