| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-1153 | Cri | 0.64 | 9.8 | 0.01 | Mar 21, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pacsrapor allows SQL Injection, Command Line Execution through SQL Injection. This issue affects Pacsrapor: before 1.22. | ||
| CVE-2023-1537 | Cri | 0.57 | 9.8 | 0.01 | Mar 21, 2023 | Authentication Bypass by Capture-replay in GitHub repository answerdev/answer prior to 1.0.6. | ||
| CVE-2023-27578 | Cri | 0.59 | 9.1 | 0.01 | Mar 20, 2023 | Galaxy is an open-source platform for data analysis. All supported versions of Galaxy are affected prior to 22.01, 22.05, and 23.0 are affected by an insufficient permission check. Unsupported versions are likely affected as far back as the functionality of Visualizations/Pages… | ||
| CVE-2023-27586 | Cri | 0.57 | 9.9 | 0.01 | Mar 20, 2023 | CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to external hosts when processing SVG files. A malicious actor could send a specially crafted SVG file that allows them to perform a server-side request forgery or… | ||
| CVE-2023-28424 | Cri | 0.00 | 9.1 | 0.01 | Mar 20, 2023 | Soko if the code that powers packages.gentoo.org. Prior to version 1.0.2, the two package search handlers, `Search` and `SearchFeed`, implemented in `pkg/app/handler/packages/search.go`, are affected by a SQL injection via the `q` parameter. As a result, unauthenticated… | ||
| CVE-2023-26905 | Cri | 0.64 | 9.8 | 0.01 | Mar 19, 2023 | An issue was discovered in Alphaware - Simple E-Commerce System v1.0. There is a SQL injection that can directly issue instructions to the background database system via /alphaware/details.php?id. | ||
| CVE-2023-26806 | Cri | 0.64 | 9.8 | 0.01 | Mar 19, 2023 | Tenda W20E v15.11.0.6(US_W20EV4.0br_v15.11.0.6(1068_1546_841 is vulnerable to Buffer Overflow via function formSetSysTime, | ||
| CVE-2023-26805 | Cri | 0.64 | 9.8 | 0.01 | Mar 19, 2023 | Tenda W20E v15.11.0.6 (US_W20EV4.0br_v15.11.0.6(1068_1546_841)_CN_TDC) is vulnerable to Buffer Overflow via function formIPMacBindModify. | ||
| CVE-2023-28609 | Cri | 0.57 | 9.8 | 0.01 | Mar 18, 2023 | api/auth.go in Ansible Semaphore before 2.8.89 mishandles authentication. | ||
| CVE-2023-28115 | Cri | 0.57 | 9.8 | 0.03 | Mar 17, 2023 | Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.4.2, Snappy is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the `file_exists()` function. If an attacker… | ||
| CVE-2023-1152 | Cri | 0.64 | 9.8 | 0.01 | Mar 17, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information Technologies Persolus allows SQL Injection. This issue affects Persolus: before 2.03.93. | ||
| CVE-2023-28531 | Cri | 0.64 | 9.8 | 0.02 | Mar 17, 2023 | ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9. | ||
| CVE-2023-21456 | Cri | 0.59 | 9.0 | 0.00 | Mar 16, 2023 | Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid. | ||
| CVE-2022-43605 | Cri | 0.66 | 10.0 | 0.14 | Mar 16, 2023 | An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out of bounds write, potentially causing the server to crash or… | ||
| CVE-2022-43604 | Cri | 0.66 | 10.0 | 0.14 | Mar 16, 2023 | An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out-of-bounds write, potentially causing the server to crash or… | ||
| CVE-2023-1256 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2023 | The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states. | ||
| CVE-2023-0811 | Cri | 0.59 | 9.1 | 0.01 | Mar 16, 2023 | Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an adversary issues a PROGRAM AREA WRITE command to a specific memory region, they could overwrite the password. This may lead to disabling UM protections or… | ||
| CVE-2023-27041 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2023 | School Registration and Fee System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at/bilal final/edit_user.php. | ||
| CVE-2023-28100 | Cri | 0.00 | 10.0 | 0.01 | Mar 16, 2023 | Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. Versions prior to 1.10.8, 1.12.8, 1.14.4, and 1.15.4 contain a vulnerability similar to CVE-2017-5226, but using the `TIOCLINUX` ioctl command instead of `TIOCSTI`. If a Flatpak… | ||
| CVE-2023-27040 | Cri | 0.64 | 9.8 | 0.02 | Mar 16, 2023 | Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username parameter. | ||
| CVE-2020-22647 | Cri | 0.59 | 9.1 | 0.01 | Mar 16, 2023 | An issue found in DepositGame v.1.0 allows an attacker to gain sensitive information via the GetBonusWithdraw and withdraw functions. | ||
| CVE-2020-19947 | Cri | 0.62 | 9.6 | 0.01 | Mar 16, 2023 | Cross Site Scripting vulnerability found in Markdown Edit allows a remote attacker to execute arbitrary code via the edit parameter of the webpage. | ||
| CVE-2023-27250 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2023 | Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php. | ||
| CVE-2023-26784 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2023 | SQL Injection vulnerability found in Kirin Fortress Machine v.1.7-2020-0610 allows attackers to execute arbitrary code via the /admin.php?controller=admin_commonuser parameter. | ||
| CVE-2023-24795 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2023 | Command execution vulnerability was discovered in JHR-N916R router firmware version<=21.11.1.1483. | ||
| CVE-2023-23150 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2023 | SA-WR915ND router firmware v17.35.1 was discovered to be vulnerable to code execution. | ||
| CVE-2023-25280 | Cri | 0.84 | 9.8 | 0.98 | KEV | Mar 16, 2023 | OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp. | |
| CVE-2023-28461 | Cri | 0.87 | 9.8 | 0.68 | KEV | Mar 15, 2023 | Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable… | |
| CVE-2023-24468 | Cri | 0.64 | 9.8 | 0.01 | Mar 15, 2023 | Broken access control in Advanced Authentication versions prior to 6.4.1.1 and 6.3.7.2 | ||
| CVE-2023-25344 | Cri | 0.64 | 9.8 | 0.01 | Mar 15, 2023 | An issue was discovered in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to execute arbitrary code via crafted Object.prototype anonymous function. | ||
| CVE-2020-27507 | Cri | 0.64 | 9.8 | 0.01 | Mar 15, 2023 | The Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a buffer overflow that crashes the server or possibly have unspecified other impact. | ||
| CVE-2022-44580 | Cri | 0.59 | 9.1 | 0.01 | Mar 15, 2023 | SQL Injection (SQLi) vulnerability in RichPlugins Plugin for Google Reviews plugin <= 2.2.3 versions. | ||
| CVE-2023-24726 | Cri | 0.64 | 9.8 | 0.01 | Mar 15, 2023 | Art Gallery Management System v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter on the enquiry page. | ||
| CVE-2023-27240 | Cri | 0.64 | 9.8 | 0.03 | Mar 15, 2023 | Tenda AX3 V16.03.12.11 was discovered to contain a command injection vulnerability via the lanip parameter at /goform/AdvSetLanip. | ||
| CVE-2023-27239 | Cri | 0.64 | 9.8 | 0.01 | Mar 15, 2023 | Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the shareSpeed parameter at /goform/WifiGuestSet. | ||
| CVE-2023-28371 | Cri | 0.00 | 9.8 | 0.02 | Mar 15, 2023 | In Stellarium through 1.2, attackers can write to files that are typically unintended, such as ones with absolute pathnames or .. directory traversal. | ||
| CVE-2023-27757 | Cri | 0.64 | 9.8 | 0.01 | Mar 15, 2023 | An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to execute arbitrary code via a crafted JPG file. | ||
| CVE-2023-1327 | Cri | 0.64 | 9.8 | 0.01 | Mar 14, 2023 | Netgear RAX30 (AX2400), prior to version 1.0.6.74, was affected by an authentication bypass vulnerability, allowing an unauthenticated attacker to gain administrative access to the device's web management interface by resetting the admin password. | ||
| CVE-2023-26511 | Cri | 0.64 | 9.8 | 0.01 | Mar 14, 2023 | A Hard Coded Admin Credentials issue in the Web-UI Admin Panel in Propius MachineSelector 6.6.0 and 6.6.1 allows remote attackers to gain access to the admin panel Propiusadmin.php, which allows taking control of the affected system. | ||
| CVE-2023-28343 | Cri | 0.74 | 9.8 | 0.85 | Mar 14, 2023 | OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php. | ||
| CVE-2023-23415 | Cri | 0.64 | 9.8 | 0.03 | Mar 14, 2023 | Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability | ||
| CVE-2023-23397 | Cri | 0.83 | 9.8 | 0.97 | KEV | Mar 14, 2023 | Microsoft Outlook Elevation of Privilege Vulnerability | |
| CVE-2023-23392 | Cri | 0.64 | 9.8 | 0.02 | Mar 14, 2023 | HTTP Protocol Stack Remote Code Execution Vulnerability | ||
| CVE-2023-21708 | Cri | 0.64 | 9.8 | 0.01 | Mar 14, 2023 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | ||
| CVE-2022-39214 | Cri | 0.02 | 9.6 | 0.26 | Mar 14, 2023 | Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just by knowing the account's username. This issue is fixed in versions 2.7.8 and 3.0.2-1. | ||
| CVE-2023-27074 | Cri | 0.64 | 9.8 | 0.01 | Mar 14, 2023 | BP Monitoring Management System v1.0 was discovered to contain a SQL injection vulnerability via the emailid parameter in the login page. | ||
| CVE-2023-25957 | Cri | 0.59 | 9.1 | 0.01 | Mar 14, 2023 | A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAML (Mendix 8 compatible) (All versions >= V2.2.0 < V2.3.0), Mendix SAML (Mendix 9 latest compatible, New Track) (All versions >= V3.1.9 < V3.3.1), Mendix SAML… | ||
| CVE-2023-27500 | Cri | 0.62 | 9.6 | 0.01 | Mar 14, 2023 | An attacker with non-administrative authorizations can exploit a directory traversal flaw in program SAPRSBRO to over-write system files. In this attack, no data can be read but potentially critical OS files can be over-written making the system unavailable. | ||
| CVE-2023-27269 | Cri | 0.62 | 9.6 | 0.01 | Mar 14, 2023 | SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker with non-administrative authorizations to exploit a directory traversal flaw in an available service to overwrite the… | ||
| CVE-2023-25617 | Cri | 0.59 | 9.0 | 0.01 | Mar 14, 2023 | SAP Business Object (Adaptive Job Server) - versions 420, 430, allows remote execution of arbitrary commands on Unix, when program objects execution is enabled, to authenticated users with scheduling rights, using the BI Launchpad, Central Management Console or a custom… |
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pacsrapor allows SQL Injection, Command Line Execution through SQL Injection. This issue affects Pacsrapor: before 1.22.
- risk 0.57cvss 9.8epss 0.01
Authentication Bypass by Capture-replay in GitHub repository answerdev/answer prior to 1.0.6.
- risk 0.59cvss 9.1epss 0.01
Galaxy is an open-source platform for data analysis. All supported versions of Galaxy are affected prior to 22.01, 22.05, and 23.0 are affected by an insufficient permission check. Unsupported versions are likely affected as far back as the functionality of Visualizations/Pages…
- risk 0.57cvss 9.9epss 0.01
CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to external hosts when processing SVG files. A malicious actor could send a specially crafted SVG file that allows them to perform a server-side request forgery or…
- risk 0.00cvss 9.1epss 0.01
Soko if the code that powers packages.gentoo.org. Prior to version 1.0.2, the two package search handlers, `Search` and `SearchFeed`, implemented in `pkg/app/handler/packages/search.go`, are affected by a SQL injection via the `q` parameter. As a result, unauthenticated…
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Alphaware - Simple E-Commerce System v1.0. There is a SQL injection that can directly issue instructions to the background database system via /alphaware/details.php?id.
- risk 0.64cvss 9.8epss 0.01
Tenda W20E v15.11.0.6(US_W20EV4.0br_v15.11.0.6(1068_1546_841 is vulnerable to Buffer Overflow via function formSetSysTime,
- risk 0.64cvss 9.8epss 0.01
Tenda W20E v15.11.0.6 (US_W20EV4.0br_v15.11.0.6(1068_1546_841)_CN_TDC) is vulnerable to Buffer Overflow via function formIPMacBindModify.
- risk 0.57cvss 9.8epss 0.01
api/auth.go in Ansible Semaphore before 2.8.89 mishandles authentication.
- risk 0.57cvss 9.8epss 0.03
Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.4.2, Snappy is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the `file_exists()` function. If an attacker…
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information Technologies Persolus allows SQL Injection. This issue affects Persolus: before 2.03.93.
- risk 0.64cvss 9.8epss 0.02
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
- risk 0.59cvss 9.0epss 0.00
Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid.
- risk 0.66cvss 10.0epss 0.14
An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out of bounds write, potentially causing the server to crash or…
- risk 0.66cvss 10.0epss 0.14
An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out-of-bounds write, potentially causing the server to crash or…
- risk 0.64cvss 9.8epss 0.01
The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states.
- risk 0.59cvss 9.1epss 0.01
Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an adversary issues a PROGRAM AREA WRITE command to a specific memory region, they could overwrite the password. This may lead to disabling UM protections or…
- risk 0.64cvss 9.8epss 0.01
School Registration and Fee System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at/bilal final/edit_user.php.
- risk 0.00cvss 10.0epss 0.01
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. Versions prior to 1.10.8, 1.12.8, 1.14.4, and 1.15.4 contain a vulnerability similar to CVE-2017-5226, but using the `TIOCLINUX` ioctl command instead of `TIOCSTI`. If a Flatpak…
- risk 0.64cvss 9.8epss 0.02
Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username parameter.
- risk 0.59cvss 9.1epss 0.01
An issue found in DepositGame v.1.0 allows an attacker to gain sensitive information via the GetBonusWithdraw and withdraw functions.
- risk 0.62cvss 9.6epss 0.01
Cross Site Scripting vulnerability found in Markdown Edit allows a remote attacker to execute arbitrary code via the edit parameter of the webpage.
- risk 0.64cvss 9.8epss 0.01
Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability found in Kirin Fortress Machine v.1.7-2020-0610 allows attackers to execute arbitrary code via the /admin.php?controller=admin_commonuser parameter.
- risk 0.64cvss 9.8epss 0.01
Command execution vulnerability was discovered in JHR-N916R router firmware version<=21.11.1.1483.
- risk 0.64cvss 9.8epss 0.01
SA-WR915ND router firmware v17.35.1 was discovered to be vulnerable to code execution.
- risk 0.84cvss 9.8epss 0.98
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.
- risk 0.87cvss 9.8epss 0.68
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable…
- risk 0.64cvss 9.8epss 0.01
Broken access control in Advanced Authentication versions prior to 6.4.1.1 and 6.3.7.2
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to execute arbitrary code via crafted Object.prototype anonymous function.
- risk 0.64cvss 9.8epss 0.01
The Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a buffer overflow that crashes the server or possibly have unspecified other impact.
- risk 0.59cvss 9.1epss 0.01
SQL Injection (SQLi) vulnerability in RichPlugins Plugin for Google Reviews plugin <= 2.2.3 versions.
- risk 0.64cvss 9.8epss 0.01
Art Gallery Management System v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter on the enquiry page.
- risk 0.64cvss 9.8epss 0.03
Tenda AX3 V16.03.12.11 was discovered to contain a command injection vulnerability via the lanip parameter at /goform/AdvSetLanip.
- risk 0.64cvss 9.8epss 0.01
Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the shareSpeed parameter at /goform/WifiGuestSet.
- risk 0.00cvss 9.8epss 0.02
In Stellarium through 1.2, attackers can write to files that are typically unintended, such as ones with absolute pathnames or .. directory traversal.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to execute arbitrary code via a crafted JPG file.
- risk 0.64cvss 9.8epss 0.01
Netgear RAX30 (AX2400), prior to version 1.0.6.74, was affected by an authentication bypass vulnerability, allowing an unauthenticated attacker to gain administrative access to the device's web management interface by resetting the admin password.
- risk 0.64cvss 9.8epss 0.01
A Hard Coded Admin Credentials issue in the Web-UI Admin Panel in Propius MachineSelector 6.6.0 and 6.6.1 allows remote attackers to gain access to the admin panel Propiusadmin.php, which allows taking control of the affected system.
- risk 0.74cvss 9.8epss 0.85
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php.
- risk 0.64cvss 9.8epss 0.03
Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability
- risk 0.83cvss 9.8epss 0.97
Microsoft Outlook Elevation of Privilege Vulnerability
- risk 0.64cvss 9.8epss 0.02
HTTP Protocol Stack Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.01
Remote Procedure Call Runtime Remote Code Execution Vulnerability
- risk 0.02cvss 9.6epss 0.26
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just by knowing the account's username. This issue is fixed in versions 2.7.8 and 3.0.2-1.
- risk 0.64cvss 9.8epss 0.01
BP Monitoring Management System v1.0 was discovered to contain a SQL injection vulnerability via the emailid parameter in the login page.
- risk 0.59cvss 9.1epss 0.01
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAML (Mendix 8 compatible) (All versions >= V2.2.0 < V2.3.0), Mendix SAML (Mendix 9 latest compatible, New Track) (All versions >= V3.1.9 < V3.3.1), Mendix SAML…
- risk 0.62cvss 9.6epss 0.01
An attacker with non-administrative authorizations can exploit a directory traversal flaw in program SAPRSBRO to over-write system files. In this attack, no data can be read but potentially critical OS files can be over-written making the system unavailable.
- risk 0.62cvss 9.6epss 0.01
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker with non-administrative authorizations to exploit a directory traversal flaw in an available service to overwrite the…
- risk 0.59cvss 9.0epss 0.01
SAP Business Object (Adaptive Job Server) - versions 420, 430, allows remote execution of arbitrary commands on Unix, when program objects execution is enabled, to authenticated users with scheduling rights, using the BI Launchpad, Central Management Console or a custom…