| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-28201 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2023 | This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, tvOS 16.4. A remote user may be able to cause unexpected app termination or arbitrary code execution. | ||
| CVE-2023-27958 | Cri | 0.59 | 9.1 | 0.02 | May 8, 2023 | The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A remote user may be able to cause unexpected system termination or corrupt kernel memory. | ||
| CVE-2023-27953 | Cri | 0.64 | 9.8 | 0.02 | May 8, 2023 | The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A remote user may be able to cause unexpected system termination or corrupt kernel memory. | ||
| CVE-2023-23526 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2023 | This was addressed with additional checks by Gatekeeper on files downloaded from an iCloud shared-by-me folder. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4. A file from an iCloud shared-by-me folder may be able to bypass Gatekeeper. | ||
| CVE-2023-2583 | Cri | 0.58 | 10.0 | 0.01 | May 8, 2023 | Code Injection in GitHub repository jsreport/jsreport prior to 3.11.3. | ||
| CVE-2023-30092 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2023 | SourceCodester Online Pizza Ordering System v1.0 is vulnerable to SQL Injection via the QTY parameter. | ||
| CVE-2023-29696 | — | Cri | 0.64 | 9.8 | 0.01 | May 8, 2023 | H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function version_set. | |
| CVE-2023-29693 | — | Cri | 0.64 | 9.8 | 0.01 | May 8, 2023 | H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function set_tftp_upgrad. | |
| CVE-2023-22786 | Cri | 0.64 | 9.8 | 0.02 | May 8, 2023 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of… | ||
| CVE-2023-22785 | Cri | 0.64 | 9.8 | 0.02 | May 8, 2023 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of… | ||
| CVE-2023-22784 | Cri | 0.64 | 9.8 | 0.02 | May 8, 2023 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of… | ||
| CVE-2023-22783 | Cri | 0.64 | 9.8 | 0.02 | May 8, 2023 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of… | ||
| CVE-2023-22782 | Cri | 0.64 | 9.8 | 0.02 | May 8, 2023 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of… | ||
| CVE-2023-22781 | Cri | 0.64 | 9.8 | 0.02 | May 8, 2023 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of… | ||
| CVE-2023-22780 | Cri | 0.64 | 9.8 | 0.02 | May 8, 2023 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of… | ||
| CVE-2023-22779 | Cri | 0.64 | 9.8 | 0.02 | May 8, 2023 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of… | ||
| CVE-2023-1650 | Cri | 0.66 | 9.8 | 0.34 | May 8, 2023 | The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could allow them to perform PHP Object Injection when a suitable gadget is present on the blog | ||
| CVE-2022-4118 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2023 | The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by authenticated users | ||
| CVE-2020-23966 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2023 | SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /post.php in a crafted GET request. | ||
| CVE-2023-25754 | Cri | 0.57 | 9.8 | 0.02 | May 8, 2023 | Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.6.0. | ||
| CVE-2023-31039 | Cri | 0.64 | 9.8 | 0.02 | May 8, 2023 | Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptions::pid_file. An attacker that can influence the ServerOptions pid_file parameter with which the bRPC server is started can execute arbitrary code with the… | ||
| CVE-2023-30018 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2023 | Judging Management System v1.0 is vulnerable to SQL Injection. via /php-jms/review_se_result.php?mainevent_id=. | ||
| CVE-2023-30185 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2023 | CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php. | ||
| CVE-2023-29944 | Cri | 0.64 | 9.8 | 0.02 | May 8, 2023 | Metersphere v1.20.20-lts-79d354a6 is vulnerable to Remote Command Execution. The system command reverse-shell can be executed at the custom code snippet function of the metersphere system workbench | ||
| CVE-2023-2564 | Cri | 0.03 | 10.0 | 0.41 | May 7, 2023 | OS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0. | ||
| CVE-2023-31047 | Cri | 0.57 | 9.8 | 0.01 | May 7, 2023 | In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was… | ||
| CVE-2023-30054 | Cri | 0.64 | 9.8 | 0.02 | May 5, 2023 | TOTOLINK A7100RU V7.4cu.2313_B20191024 has a Command Injection vulnerability. An attacker can obtain a stable root shell through a specially constructed payload. | ||
| CVE-2023-30053 | Cri | 0.64 | 9.8 | 0.02 | May 5, 2023 | TOTOLINK A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection. | ||
| CVE-2023-30013 | Cri | 0.69 | 9.8 | 0.26 | May 5, 2023 | TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter. | ||
| CVE-2023-30242 | Cri | 0.64 | 9.8 | 0.01 | May 5, 2023 | NS-ASG v6.3 was discovered to contain a SQL injection vulnerability via the component /admin/add_ikev2.php. | ||
| CVE-2023-30090 | Cri | 0.64 | 9.8 | 0.01 | May 5, 2023 | Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php. This vulnerability allows attackers to execute arbitrary code via uploading a crafted PHP file. | ||
| CVE-2023-30135 | Cri | 0.64 | 9.8 | 0.02 | May 5, 2023 | Tenda AC18 v15.03.05.19(6318_)_cn was discovered to contain a command injection vulnerability via the deviceName parameter in the setUsbUnload function. | ||
| CVE-2023-30122 | Cri | 0.64 | 9.8 | 0.01 | May 5, 2023 | An arbitrary file upload vulnerability in the component /admin/ajax.php?action=save_menu of Online Food Ordering System v2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file. | ||
| CVE-2023-2531 | Cri | 0.57 | 9.8 | 0.01 | May 5, 2023 | Improper Restriction of Excessive Authentication Attempts in GitHub repository azuracast/azuracast prior to 0.18.3. | ||
| CVE-2023-30328 | Cri | 0.64 | 9.8 | 0.01 | May 4, 2023 | An issue in the helper tool of Mailbutler GmbH Shimo VPN Client for macOS v5.0.4 allows attackers to bypass authentication via PID re-use. | ||
| CVE-2023-30268 | Cri | 0.64 | 9.8 | 0.01 | May 4, 2023 | CLTPHP <=6.0 is vulnerable to Improper Input Validation. | ||
| CVE-2023-30264 | Cri | 0.64 | 9.8 | 0.01 | May 4, 2023 | CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via application/admin/controller/Template.php:update. | ||
| CVE-2023-23059 | Cri | 0.64 | 9.8 | 0.01 | May 4, 2023 | An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions within the default installation and allows attackers to execute arbitrary code and gain escalated privileges. | ||
| CVE-2023-20126 | Cri | 0.67 | 9.8 | 0.37 | May 4, 2023 | A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to a missing authentication process within the firmware upgrade… | ||
| CVE-2023-30203 | Cri | 0.64 | 9.8 | 0.01 | May 4, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the event_id parameter at /php-jms/result_sheet.php. | ||
| CVE-2023-29827 | Cri | 0.64 | 9.8 | 0.06 | May 4, 2023 | ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter. NOTE: this is disputed by the vendor because the render function is not intended… | ||
| CVE-2023-22651 | Cri | 0.64 | 9.9 | 0.01 | May 4, 2023 | Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook may lead to the misconfiguration of the Webhook. This component enforces validation rules and security checks before resources… | ||
| CVE-2023-30331 | Cri | 0.64 | 9.8 | 0.01 | May 4, 2023 | An issue in the render function of beetl v3.15.0 allows attackers to execute server-side template injection (SSTI) via a crafted payload. | ||
| CVE-2023-30077 | Cri | 0.64 | 9.8 | 0.01 | May 4, 2023 | Judging Management System v1.0 by oretnom23 was discovered to vulnerable to SQL injection via /php-jms/review_result.php?mainevent_id=, mainevent_id. | ||
| CVE-2022-47757 | Cri | 0.64 | 9.8 | 0.01 | May 4, 2023 | In imo.im 2022.11.1051, a path traversal vulnerability delivered via an unsanitized deeplink can force the application to write a file into the application's data directory. This may allow an attacker to save a shared library under a special directory which the app uses to… | ||
| CVE-2023-30204 | Cri | 0.64 | 9.8 | 0.01 | May 3, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the judge_id parameter at /php-jms/edit_judge.php. | ||
| CVE-2023-25826 | Cri | 0.63 | 9.8 | 0.43 | May 3, 2023 | Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameters and execute malicious code on the OpenTSDB host system. This exploit exists due to an incomplete fix that was made when this… | ||
| CVE-2023-29778 | Cri | 0.65 | 9.8 | 0.16 | May 2, 2023 | GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread. | ||
| CVE-2023-26089 | Cri | 0.64 | 9.8 | 0.01 | May 2, 2023 | European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5. | ||
| CVE-2023-2479 | Cri | 0.58 | 9.8 | 0.22 | May 2, 2023 | OS Command Injection in GitHub repository appium/appium-desktop prior to v1.22.3-4. |
- risk 0.64cvss 9.8epss 0.01
This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, tvOS 16.4. A remote user may be able to cause unexpected app termination or arbitrary code execution.
- risk 0.59cvss 9.1epss 0.02
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
- risk 0.64cvss 9.8epss 0.02
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
- risk 0.64cvss 9.8epss 0.01
This was addressed with additional checks by Gatekeeper on files downloaded from an iCloud shared-by-me folder. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4. A file from an iCloud shared-by-me folder may be able to bypass Gatekeeper.
- risk 0.58cvss 10.0epss 0.01
Code Injection in GitHub repository jsreport/jsreport prior to 3.11.3.
- risk 0.64cvss 9.8epss 0.01
SourceCodester Online Pizza Ordering System v1.0 is vulnerable to SQL Injection via the QTY parameter.
- risk 0.64cvss 9.8epss 0.01
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function version_set.
- risk 0.64cvss 9.8epss 0.01
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function set_tftp_upgrad.
- risk 0.64cvss 9.8epss 0.02
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…
- risk 0.64cvss 9.8epss 0.02
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…
- risk 0.64cvss 9.8epss 0.02
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…
- risk 0.64cvss 9.8epss 0.02
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…
- risk 0.64cvss 9.8epss 0.02
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…
- risk 0.64cvss 9.8epss 0.02
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…
- risk 0.64cvss 9.8epss 0.02
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…
- risk 0.64cvss 9.8epss 0.02
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…
- risk 0.66cvss 9.8epss 0.34
The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could allow them to perform PHP Object Injection when a suitable gadget is present on the blog
- risk 0.64cvss 9.8epss 0.01
The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by authenticated users
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /post.php in a crafted GET request.
- risk 0.57cvss 9.8epss 0.02
Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.6.0.
- risk 0.64cvss 9.8epss 0.02
Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptions::pid_file. An attacker that can influence the ServerOptions pid_file parameter with which the bRPC server is started can execute arbitrary code with the…
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 is vulnerable to SQL Injection. via /php-jms/review_se_result.php?mainevent_id=.
- risk 0.64cvss 9.8epss 0.01
CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.
- risk 0.64cvss 9.8epss 0.02
Metersphere v1.20.20-lts-79d354a6 is vulnerable to Remote Command Execution. The system command reverse-shell can be executed at the custom code snippet function of the metersphere system workbench
- risk 0.03cvss 10.0epss 0.41
OS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0.
- risk 0.57cvss 9.8epss 0.01
In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was…
- risk 0.64cvss 9.8epss 0.02
TOTOLINK A7100RU V7.4cu.2313_B20191024 has a Command Injection vulnerability. An attacker can obtain a stable root shell through a specially constructed payload.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection.
- risk 0.69cvss 9.8epss 0.26
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter.
- risk 0.64cvss 9.8epss 0.01
NS-ASG v6.3 was discovered to contain a SQL injection vulnerability via the component /admin/add_ikev2.php.
- risk 0.64cvss 9.8epss 0.01
Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php. This vulnerability allows attackers to execute arbitrary code via uploading a crafted PHP file.
- risk 0.64cvss 9.8epss 0.02
Tenda AC18 v15.03.05.19(6318_)_cn was discovered to contain a command injection vulnerability via the deviceName parameter in the setUsbUnload function.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the component /admin/ajax.php?action=save_menu of Online Food Ordering System v2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
- risk 0.57cvss 9.8epss 0.01
Improper Restriction of Excessive Authentication Attempts in GitHub repository azuracast/azuracast prior to 0.18.3.
- risk 0.64cvss 9.8epss 0.01
An issue in the helper tool of Mailbutler GmbH Shimo VPN Client for macOS v5.0.4 allows attackers to bypass authentication via PID re-use.
- risk 0.64cvss 9.8epss 0.01
CLTPHP <=6.0 is vulnerable to Improper Input Validation.
- risk 0.64cvss 9.8epss 0.01
CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via application/admin/controller/Template.php:update.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions within the default installation and allows attackers to execute arbitrary code and gain escalated privileges.
- risk 0.67cvss 9.8epss 0.37
A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to a missing authentication process within the firmware upgrade…
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the event_id parameter at /php-jms/result_sheet.php.
- risk 0.64cvss 9.8epss 0.06
ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter. NOTE: this is disputed by the vendor because the render function is not intended…
- risk 0.64cvss 9.9epss 0.01
Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook may lead to the misconfiguration of the Webhook. This component enforces validation rules and security checks before resources…
- risk 0.64cvss 9.8epss 0.01
An issue in the render function of beetl v3.15.0 allows attackers to execute server-side template injection (SSTI) via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 by oretnom23 was discovered to vulnerable to SQL injection via /php-jms/review_result.php?mainevent_id=, mainevent_id.
- risk 0.64cvss 9.8epss 0.01
In imo.im 2022.11.1051, a path traversal vulnerability delivered via an unsanitized deeplink can force the application to write a file into the application's data directory. This may allow an attacker to save a shared library under a special directory which the app uses to…
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the judge_id parameter at /php-jms/edit_judge.php.
- risk 0.63cvss 9.8epss 0.43
Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameters and execute malicious code on the OpenTSDB host system. This exploit exists due to an incomplete fix that was made when this…
- risk 0.65cvss 9.8epss 0.16
GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.
- risk 0.64cvss 9.8epss 0.01
European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5.
- risk 0.58cvss 9.8epss 0.22
OS Command Injection in GitHub repository appium/appium-desktop prior to v1.22.3-4.