| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-40022 | Cri | 0.74 | 9.8 | 0.92 | Feb 13, 2023 | Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability. | ||
| CVE-2022-48323 | Cri | 0.68 | 9.8 | 0.57 | Feb 13, 2023 | Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A remote and unauthenticated attacker can execute arbitrary programs on the victim host by sending a crafted HTTP request, as demonstrated by /check?cmd=ping../… | ||
| CVE-2022-48322 | Cri | 0.64 | 9.8 | 0.01 | Feb 13, 2023 | NETGEAR Nighthawk WiFi Mesh systems and routers are affected by a stack-based buffer overflow vulnerability. This affects MR60 before 1.1.7.132, MS60 before 1.1.7.132, R6900P before 1.3.3.154, R7000P before 1.3.3.154, R7960P before 1.4.4.94, and R8000P before 1.4.4.94. | ||
| CVE-2022-4557 | Cri | 0.64 | 9.8 | 0.01 | Feb 12, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection. This issue affects Smartpower Web: before 23.01.01. | ||
| CVE-2022-45088 | Cri | 0.64 | 9.8 | 0.01 | Feb 12, 2023 | Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows PHP Local File Inclusion. This issue affects Smartpower Web: before 23.01.01. | ||
| CVE-2022-40514 | Cri | 0.64 | 9.8 | 0.00 | Feb 12, 2023 | Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in reassoc response frame. | ||
| CVE-2022-33279 | Cri | 0.64 | 9.8 | 0.01 | Feb 12, 2023 | Memory corruption due to stack based buffer overflow in WLAN having invalid WNM frame length. | ||
| CVE-2022-33232 | Cri | 0.60 | 9.3 | 0.00 | Feb 12, 2023 | Memory corruption due to buffer copy without checking size of input while running memory sharing tests with large scattered memory. | ||
| CVE-2022-25729 | Cri | 0.64 | 9.8 | 0.00 | Feb 12, 2023 | Memory corruption in modem due to improper length check while copying into memory | ||
| CVE-2023-23163 | Cri | 0.67 | 9.8 | 0.04 | Feb 10, 2023 | Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter. | ||
| CVE-2023-23162 | Cri | 0.67 | 9.8 | 0.04 | Feb 10, 2023 | Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php. | ||
| CVE-2023-0777 | Cri | 0.61 | 9.8 | 0.15 | Feb 10, 2023 | Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4. | ||
| CVE-2022-45766 | Cri | 0.59 | 9.1 | 0.01 | Feb 10, 2023 | Hardcoded credentials in Global Facilities Management Software (GFMS) Version 3 software distributed by Key Systems Management permits remote attackers to impact availability, confidentiality, accessibility and dependability of electronic key boxes. | ||
| CVE-2023-24352 | Cri | 0.64 | 9.8 | 0.01 | Feb 10, 2023 | D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWPS. | ||
| CVE-2023-24351 | Cri | 0.64 | 9.8 | 0.01 | Feb 10, 2023 | D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the FILECODE parameter at /goform/formLogin. | ||
| CVE-2023-24350 | Cri | 0.64 | 9.8 | 0.01 | Feb 10, 2023 | D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the config.smtp_email_subject parameter at /goform/formSetEmail. | ||
| CVE-2023-24349 | Cri | 0.64 | 9.8 | 0.01 | Feb 10, 2023 | D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetRoute. | ||
| CVE-2023-24348 | Cri | 0.64 | 9.8 | 0.01 | Feb 10, 2023 | D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetACLFilter. | ||
| CVE-2022-43501 | Cri | 0.59 | 9.1 | 0.01 | Feb 10, 2023 | KASAGO TCP/IP stack provided by Zuken Elmic generates ISNs(Initial Sequence Number) for TCP connections from an insufficiently random source. An attacker may be able to determine the ISN of the current or future TCP connections and either hijack existing ones or spoof future… | ||
| CVE-2022-45699 | Cri | 0.70 | 9.8 | 0.77 | Feb 10, 2023 | Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter. | ||
| CVE-2022-43550 | Cri | 0.00 | 9.8 | 0.02 | Feb 9, 2023 | A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching browsers on Windows which could allow an attacker to insert an arbitrary URL which opens up the opportunity to remote execution. | ||
| CVE-2022-48290 | Cri | 0.59 | 9.1 | 0.00 | Feb 9, 2023 | The phone-PC collaboration module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality and integrity. | ||
| CVE-2023-25168 | Cri | 0.55 | 9.6 | 0.01 | Feb 9, 2023 | Wings is Pterodactyl's server control plane. This vulnerability can be used to delete files and directories recursively on the host system. This vulnerability can be combined with `GHSA-p8r3-83r8-jwj5` to overwrite files on the host system. In order to use this exploit, an… | ||
| CVE-2022-45982 | Cri | 0.64 | 9.8 | 0.01 | Feb 8, 2023 | thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload. | ||
| CVE-2022-45527 | Cri | 0.64 | 9.8 | 0.01 | Feb 8, 2023 | File upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to directly upload malicious files to the courseimg directory. | ||
| CVE-2022-45526 | Cri | 0.64 | 9.8 | 0.01 | Feb 8, 2023 | SQL Injection vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows attackers to execute arbitrary commands via the ad parameter to /admin_area/login_transfer.php. | ||
| CVE-2022-43764 | Cri | 0.64 | 9.8 | 0.01 | Feb 8, 2023 | Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07 could result in buffer overflow. This may lead to Denial-of-Service conditions or execution of arbitrary code. | ||
| CVE-2022-43761 | Cri | 0.61 | 9.4 | 0.01 | Feb 8, 2023 | Missing authentication when creating and managing the B&R APROL database in versions < R 4.2-07 allows reading and changing the system configuration. | ||
| CVE-2023-0744 | Cri | 0.60 | 9.8 | 0.06 | Feb 8, 2023 | Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4. | ||
| CVE-2023-0743 | Cri | 0.52 | 9.0 | 0.01 | Feb 8, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository answerdev/answer prior to 1.0.4. | ||
| CVE-2023-0742 | Cri | 0.52 | 9.0 | 0.01 | Feb 8, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4. | ||
| CVE-2023-0741 | Cri | 0.52 | 9.0 | 0.01 | Feb 8, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository answerdev/answer prior to 1.0.4. | ||
| CVE-2023-0740 | Cri | 0.52 | 9.0 | 0.01 | Feb 8, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4. | ||
| CVE-2021-36471 | Cri | 0.64 | 9.8 | 0.02 | Feb 7, 2023 | Directory Traversal vulnerability in AdminLTE 3.1.0 allows remote attackers to gain escalated privilege and view sensitive information via /admin/index2.html, /admin/index3.html URIs. Note: AdminLTE developers dispute that this a weakness with AdminLTE and is instead a… | ||
| CVE-2023-24813 | Cri | 0.58 | 10.0 | 0.02 | Feb 7, 2023 | Dompdf is an HTML to PDF converter written in php. Due to the difference in the attribute parser of Dompdf and php-svg-lib, an attacker can still call arbitrary URLs with arbitrary protocols. Dompdf parses the href attribute of `image` tags and respects `xlink:href` even if… | ||
| CVE-2022-43757 | Cri | 0.57 | 9.9 | 0.01 | Feb 7, 2023 | A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows users on managed clusters to gain access to credentials. The impact depends on the credentials exposed This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to… | ||
| CVE-2022-3229 | Cri | 0.08 | 9.8 | 0.66 | Feb 6, 2023 | Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this now-unauthenticated… | ||
| CVE-2023-23333 | Cri | 0.75 | 9.8 | 0.99 | Feb 6, 2023 | There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php. | ||
| CVE-2021-31578 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | In Boa, there is a possible escalation of privilege due to a stack buffer overflow. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20210008;… | ||
| CVE-2021-31577 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | In Boa, there is a possible escalation of privilege due to a missing permission check. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20210008;… | ||
| CVE-2021-31575 | Cri | 0.64 | 9.8 | 0.02 | Feb 6, 2023 | In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:… | ||
| CVE-2021-31574 | Cri | 0.64 | 9.8 | 0.02 | Feb 6, 2023 | In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:… | ||
| CVE-2021-31573 | Cri | 0.64 | 9.8 | 0.02 | Feb 6, 2023 | In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:… | ||
| CVE-2022-48311 | Cri | 0.59 | 9.0 | 0.01 | Feb 6, 2023 | **UNSUPPORTED WHEN ASSIGNED** Cross Site Scripting (XSS) in HP Deskjet 2540 series printer Firmware Version CEP1FN1418BR and Product Model Number A9U23B allows authenticated attacker to inject their own script into the page via HTTP configuration page. NOTE: This vulnerability… | ||
| CVE-2022-4681 | Cri | 0.67 | 9.8 | 0.04 | Feb 6, 2023 | The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | ||
| CVE-2022-47071 | Cri | 0.66 | 9.8 | 0.26 | Feb 6, 2023 | In NVS365 V01, the background network test function can trigger command execution. | ||
| CVE-2022-48078 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | pycdc commit 44a730f3a889503014fec94ae6e62d8401cb75e5 was discovered to contain a stack overflow via the component ASTree.cpp:BuildFromCode. | ||
| CVE-2023-24276 | Cri | 0.64 | 9.8 | 0.02 | Feb 6, 2023 | TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the country parameter at setting/delStaticDhcpRules. | ||
| CVE-2023-24202 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php. | ||
| CVE-2023-24201 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at get_ticket.php. |
- risk 0.74cvss 9.8epss 0.92
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
- risk 0.68cvss 9.8epss 0.57
Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A remote and unauthenticated attacker can execute arbitrary programs on the victim host by sending a crafted HTTP request, as demonstrated by /check?cmd=ping../…
- risk 0.64cvss 9.8epss 0.01
NETGEAR Nighthawk WiFi Mesh systems and routers are affected by a stack-based buffer overflow vulnerability. This affects MR60 before 1.1.7.132, MS60 before 1.1.7.132, R6900P before 1.3.3.154, R7000P before 1.3.3.154, R7960P before 1.4.4.94, and R8000P before 1.4.4.94.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection. This issue affects Smartpower Web: before 23.01.01.
- risk 0.64cvss 9.8epss 0.01
Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows PHP Local File Inclusion. This issue affects Smartpower Web: before 23.01.01.
- risk 0.64cvss 9.8epss 0.00
Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in reassoc response frame.
- risk 0.64cvss 9.8epss 0.01
Memory corruption due to stack based buffer overflow in WLAN having invalid WNM frame length.
- risk 0.60cvss 9.3epss 0.00
Memory corruption due to buffer copy without checking size of input while running memory sharing tests with large scattered memory.
- risk 0.64cvss 9.8epss 0.00
Memory corruption in modem due to improper length check while copying into memory
- risk 0.67cvss 9.8epss 0.04
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter.
- risk 0.67cvss 9.8epss 0.04
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php.
- risk 0.61cvss 9.8epss 0.15
Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4.
- risk 0.59cvss 9.1epss 0.01
Hardcoded credentials in Global Facilities Management Software (GFMS) Version 3 software distributed by Key Systems Management permits remote attackers to impact availability, confidentiality, accessibility and dependability of electronic key boxes.
- risk 0.64cvss 9.8epss 0.01
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWPS.
- risk 0.64cvss 9.8epss 0.01
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the FILECODE parameter at /goform/formLogin.
- risk 0.64cvss 9.8epss 0.01
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the config.smtp_email_subject parameter at /goform/formSetEmail.
- risk 0.64cvss 9.8epss 0.01
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetRoute.
- risk 0.64cvss 9.8epss 0.01
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetACLFilter.
- risk 0.59cvss 9.1epss 0.01
KASAGO TCP/IP stack provided by Zuken Elmic generates ISNs(Initial Sequence Number) for TCP connections from an insufficiently random source. An attacker may be able to determine the ISN of the current or future TCP connections and either hijack existing ones or spoof future…
- risk 0.70cvss 9.8epss 0.77
Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter.
- risk 0.00cvss 9.8epss 0.02
A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching browsers on Windows which could allow an attacker to insert an arbitrary URL which opens up the opportunity to remote execution.
- risk 0.59cvss 9.1epss 0.00
The phone-PC collaboration module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality and integrity.
- risk 0.55cvss 9.6epss 0.01
Wings is Pterodactyl's server control plane. This vulnerability can be used to delete files and directories recursively on the host system. This vulnerability can be combined with `GHSA-p8r3-83r8-jwj5` to overwrite files on the host system. In order to use this exploit, an…
- risk 0.64cvss 9.8epss 0.01
thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
File upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to directly upload malicious files to the courseimg directory.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows attackers to execute arbitrary commands via the ad parameter to /admin_area/login_transfer.php.
- risk 0.64cvss 9.8epss 0.01
Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07 could result in buffer overflow. This may lead to Denial-of-Service conditions or execution of arbitrary code.
- risk 0.61cvss 9.4epss 0.01
Missing authentication when creating and managing the B&R APROL database in versions < R 4.2-07 allows reading and changing the system configuration.
- risk 0.60cvss 9.8epss 0.06
Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4.
- risk 0.52cvss 9.0epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository answerdev/answer prior to 1.0.4.
- risk 0.52cvss 9.0epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.
- risk 0.52cvss 9.0epss 0.01
Cross-site Scripting (XSS) - DOM in GitHub repository answerdev/answer prior to 1.0.4.
- risk 0.52cvss 9.0epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.
- risk 0.64cvss 9.8epss 0.02
Directory Traversal vulnerability in AdminLTE 3.1.0 allows remote attackers to gain escalated privilege and view sensitive information via /admin/index2.html, /admin/index3.html URIs. Note: AdminLTE developers dispute that this a weakness with AdminLTE and is instead a…
- risk 0.58cvss 10.0epss 0.02
Dompdf is an HTML to PDF converter written in php. Due to the difference in the attribute parser of Dompdf and php-svg-lib, an attacker can still call arbitrary URLs with arbitrary protocols. Dompdf parses the href attribute of `image` tags and respects `xlink:href` even if…
- risk 0.57cvss 9.9epss 0.01
A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows users on managed clusters to gain access to credentials. The impact depends on the credentials exposed This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to…
- risk 0.08cvss 9.8epss 0.66
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this now-unauthenticated…
- risk 0.75cvss 9.8epss 0.99
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php.
- risk 0.64cvss 9.8epss 0.01
In Boa, there is a possible escalation of privilege due to a stack buffer overflow. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20210008;…
- risk 0.64cvss 9.8epss 0.01
In Boa, there is a possible escalation of privilege due to a missing permission check. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20210008;…
- risk 0.64cvss 9.8epss 0.02
In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…
- risk 0.64cvss 9.8epss 0.02
In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…
- risk 0.64cvss 9.8epss 0.02
In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…
- risk 0.59cvss 9.0epss 0.01
**UNSUPPORTED WHEN ASSIGNED** Cross Site Scripting (XSS) in HP Deskjet 2540 series printer Firmware Version CEP1FN1418BR and Product Model Number A9U23B allows authenticated attacker to inject their own script into the page via HTTP configuration page. NOTE: This vulnerability…
- risk 0.67cvss 9.8epss 0.04
The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
- risk 0.66cvss 9.8epss 0.26
In NVS365 V01, the background network test function can trigger command execution.
- risk 0.64cvss 9.8epss 0.01
pycdc commit 44a730f3a889503014fec94ae6e62d8401cb75e5 was discovered to contain a stack overflow via the component ASTree.cpp:BuildFromCode.
- risk 0.64cvss 9.8epss 0.02
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the country parameter at setting/delStaticDhcpRules.
- risk 0.64cvss 9.8epss 0.01
Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php.
- risk 0.64cvss 9.8epss 0.01
Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at get_ticket.php.