| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-24200 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at save_ticket.php. | ||
| CVE-2023-24199 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at delete_ticket.php. | ||
| CVE-2023-24198 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | Raffle Draw System v1.0 was discovered to contain multiple SQL injection vulnerabilities at save_winner.php via the ticket_id and draw parameters. | ||
| CVE-2021-36226 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files. | ||
| CVE-2021-36224 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | Western Digital My Cloud devices before OS5 have a nobody account with a blank password. | ||
| CVE-2022-31733 | Cri | 0.59 | 9.1 | 0.00 | Feb 3, 2023 | Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on diego cells, allowing application ingress without a client certificate. If mTLS route integrity is enabled AND unproxied ports are… | ||
| CVE-2023-23088 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2023 | Buffer OverFlow Vulnerability in Barenboim json-parser master and v1.1.0 fixed in v1.1.1 allows an attacker to execute arbitrary code via the json_value_parse function. | ||
| CVE-2023-23087 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2023 | An issue was found in MojoJson v1.2.3 allows attackers to execute arbitary code via the destroy function. | ||
| CVE-2023-23086 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2023 | Buffer OverFlow Vulnerability in MojoJson v1.2.3 allows an attacker to execute arbitrary code via the SkipString function. | ||
| CVE-2021-37497 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2023 | SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request. | ||
| CVE-2021-37317 | Cri | 0.59 | 9.1 | 0.02 | Feb 3, 2023 | Directory Traversal vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the target for COPY and MOVE operations. | ||
| CVE-2021-37315 | Cri | 0.59 | 9.1 | 0.01 | Feb 3, 2023 | Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the source for COPY and MOVE operations. | ||
| CVE-2021-36503 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2023 | SQL injection vulnerability in native-php-cms 1.0 allows remote attackers to run arbitrary SQL commands via the cat parameter to /list.php file. | ||
| CVE-2021-36484 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2023 | SQL injection vulnerability in JIZHICMS 1.9.5 allows attackers to run arbitrary SQL commands via add or edit article page. | ||
| CVE-2021-36434 | Cri | 0.59 | 9.1 | 0.01 | Feb 3, 2023 | SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check function in jocms/apps/mask/inc/getmask.php. | ||
| CVE-2021-36433 | Cri | 0.59 | 9.1 | 0.01 | Feb 3, 2023 | SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_delete_mask function in jocms/apps/mask/mask.php. | ||
| CVE-2021-36431 | Cri | 0.59 | 9.1 | 0.01 | Feb 3, 2023 | SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check() function in jocms/apps/mask/inc/mask.php. | ||
| CVE-2021-36424 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2023 | An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation. | ||
| CVE-2023-24157 | Cri | 0.64 | 9.8 | 0.02 | Feb 3, 2023 | A command injection vulnerability in the serverIp parameter in the function updateWifiInfo of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet. | ||
| CVE-2023-24156 | Cri | 0.64 | 9.8 | 0.02 | Feb 3, 2023 | A command injection vulnerability in the ip parameter in the function recvSlaveUpgstatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet. | ||
| CVE-2023-24155 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2023 | TOTOLINK T8 V4.1.5cu was discovered to contain a hard code password for the telnet service which is stored in the component /web_cste/cgi-bin/product.ini. | ||
| CVE-2023-24154 | Cri | 0.64 | 9.8 | 0.02 | Feb 3, 2023 | TOTOLINK T8 V4.1.5cu was discovered to contain a command injection vulnerability via the slaveIpList parameter in the function setUpgradeFW. | ||
| CVE-2023-24153 | Cri | 0.64 | 9.8 | 0.02 | Feb 3, 2023 | A command injection vulnerability in the version parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet. | ||
| CVE-2023-24152 | Cri | 0.64 | 9.8 | 0.02 | Feb 3, 2023 | A command injection vulnerability in the serverIp parameter in the function meshSlaveUpdate of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet. | ||
| CVE-2023-24151 | Cri | 0.64 | 9.8 | 0.02 | Feb 3, 2023 | A command injection vulnerability in the ip parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet. | ||
| CVE-2023-24150 | Cri | 0.64 | 9.8 | 0.02 | Feb 3, 2023 | A command injection vulnerability in the serverIp parameter in the function meshSlaveDlfw of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet. | ||
| CVE-2023-24149 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for root which is stored in the component /etc/shadow. | ||
| CVE-2023-24148 | Cri | 0.64 | 9.8 | 0.02 | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadUserData function. | ||
| CVE-2023-24146 | Cri | 0.64 | 9.8 | 0.02 | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the minute parameter in the setRebootScheCfg function. | ||
| CVE-2023-24145 | Cri | 0.64 | 9.8 | 0.02 | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the plugin_version parameter in the setUnloadUserData function. | ||
| CVE-2023-24144 | Cri | 0.64 | 9.8 | 0.02 | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the hour parameter in the setRebootScheCfg function. | ||
| CVE-2023-24143 | Cri | 0.64 | 9.8 | 0.02 | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagTracertHop parameter in the setNetworkDiag function. | ||
| CVE-2023-24142 | Cri | 0.64 | 9.8 | 0.02 | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingSize parameter in the setNetworkDiag function. | ||
| CVE-2023-24141 | Cri | 0.64 | 9.8 | 0.02 | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingTimeOut parameter in the setNetworkDiag function. | ||
| CVE-2023-24140 | Cri | 0.64 | 9.8 | 0.02 | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingNum parameter in the setNetworkDiag function. | ||
| CVE-2023-24139 | Cri | 0.64 | 9.8 | 0.02 | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagHost parameter in the setNetworkDiag function. | ||
| CVE-2023-24138 | Cri | 0.64 | 9.8 | 0.02 | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the host_time parameter in the NTPSyncWithHost function. | ||
| CVE-2023-25139 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2023 | sprintf in the GNU C Library (glibc) 2.37 has a buffer overflow (out-of-bounds write) in some situations with a correct buffer size. This is unrelated to CWE-676. It may write beyond the bounds of the destination buffer when attempting to write a padded, thousands-separated… | ||
| CVE-2023-25135 | Cri | 0.66 | 9.8 | 0.24 | Feb 3, 2023 | vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserialization. This occurs because verify_serialized checks that a value is serialized by calling unserialize and then checking for errors.… | ||
| CVE-2022-48021 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2023 | A vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges via a crafted message sent to the server. | ||
| CVE-2022-22486 | Cri | 0.65 | 10.0 | 0.01 | Feb 3, 2023 | IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 226328. | ||
| CVE-2022-48114 | Cri | 0.64 | 9.8 | 0.01 | Feb 2, 2023 | RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable. | ||
| CVE-2022-48113 | Cri | 0.64 | 9.8 | 0.01 | Feb 2, 2023 | A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet service via a crafted POST request. Attackers are also able to leverage this vulnerability to login as root via hardcoded credentials. | ||
| CVE-2022-48130 | Cri | 0.64 | 9.8 | 0.01 | Feb 2, 2023 | Tenda W20E v15.11.0.6 was discovered to contain multiple stack overflows in the function formSetStaticRoute via the parameters staticRouteNet, staticRouteMask, staticRouteGateway, staticRouteWAN. | ||
| CVE-2022-48082 | Cri | 0.64 | 9.8 | 0.01 | Feb 2, 2023 | Easyone CRM v5.50.02 was discovered to contain a SQL Injection vulnerability via the text parameter at /Services/Misc.asmx/SearchTag. | ||
| CVE-2022-48079 | Cri | 0.64 | 9.8 | 0.01 | Feb 2, 2023 | Monnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execute arbitrary code via uploading a crafted PHP file to the virtual host directory of the system. | ||
| CVE-2023-23076 | Cri | 0.70 | 9.8 | 0.74 | Feb 1, 2023 | OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules. | ||
| CVE-2023-22501 | Cri | 0.60 | 9.1 | 0.16 | Feb 1, 2023 | An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain access to a Jira Service Management instance under certain circumstances_._ With write access to a User Directory and… | ||
| CVE-2023-24997 | Cri | 0.57 | 9.8 | 0.01 | Feb 1, 2023 | Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inlong/pull/7223… | ||
| CVE-2022-47714 | Cri | 0.64 | 9.8 | 0.01 | Feb 1, 2023 | Last Yard 22.09.8-1 does not enforce HSTS headers |
- risk 0.64cvss 9.8epss 0.01
Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at save_ticket.php.
- risk 0.64cvss 9.8epss 0.01
Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at delete_ticket.php.
- risk 0.64cvss 9.8epss 0.01
Raffle Draw System v1.0 was discovered to contain multiple SQL injection vulnerabilities at save_winner.php via the ticket_id and draw parameters.
- risk 0.64cvss 9.8epss 0.01
Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.
- risk 0.64cvss 9.8epss 0.01
Western Digital My Cloud devices before OS5 have a nobody account with a blank password.
- risk 0.59cvss 9.1epss 0.00
Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on diego cells, allowing application ingress without a client certificate. If mTLS route integrity is enabled AND unproxied ports are…
- risk 0.64cvss 9.8epss 0.01
Buffer OverFlow Vulnerability in Barenboim json-parser master and v1.1.0 fixed in v1.1.1 allows an attacker to execute arbitrary code via the json_value_parse function.
- risk 0.64cvss 9.8epss 0.01
An issue was found in MojoJson v1.2.3 allows attackers to execute arbitary code via the destroy function.
- risk 0.64cvss 9.8epss 0.01
Buffer OverFlow Vulnerability in MojoJson v1.2.3 allows an attacker to execute arbitrary code via the SkipString function.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request.
- risk 0.59cvss 9.1epss 0.02
Directory Traversal vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the target for COPY and MOVE operations.
- risk 0.59cvss 9.1epss 0.01
Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the source for COPY and MOVE operations.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in native-php-cms 1.0 allows remote attackers to run arbitrary SQL commands via the cat parameter to /list.php file.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in JIZHICMS 1.9.5 allows attackers to run arbitrary SQL commands via add or edit article page.
- risk 0.59cvss 9.1epss 0.01
SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check function in jocms/apps/mask/inc/getmask.php.
- risk 0.59cvss 9.1epss 0.01
SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_delete_mask function in jocms/apps/mask/mask.php.
- risk 0.59cvss 9.1epss 0.01
SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check() function in jocms/apps/mask/inc/mask.php.
- risk 0.64cvss 9.8epss 0.01
An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation.
- risk 0.64cvss 9.8epss 0.02
A command injection vulnerability in the serverIp parameter in the function updateWifiInfo of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
- risk 0.64cvss 9.8epss 0.02
A command injection vulnerability in the ip parameter in the function recvSlaveUpgstatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK T8 V4.1.5cu was discovered to contain a hard code password for the telnet service which is stored in the component /web_cste/cgi-bin/product.ini.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK T8 V4.1.5cu was discovered to contain a command injection vulnerability via the slaveIpList parameter in the function setUpgradeFW.
- risk 0.64cvss 9.8epss 0.02
A command injection vulnerability in the version parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
- risk 0.64cvss 9.8epss 0.02
A command injection vulnerability in the serverIp parameter in the function meshSlaveUpdate of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
- risk 0.64cvss 9.8epss 0.02
A command injection vulnerability in the ip parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
- risk 0.64cvss 9.8epss 0.02
A command injection vulnerability in the serverIp parameter in the function meshSlaveDlfw of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for root which is stored in the component /etc/shadow.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadUserData function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the minute parameter in the setRebootScheCfg function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the plugin_version parameter in the setUnloadUserData function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the hour parameter in the setRebootScheCfg function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagTracertHop parameter in the setNetworkDiag function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingSize parameter in the setNetworkDiag function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingTimeOut parameter in the setNetworkDiag function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingNum parameter in the setNetworkDiag function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagHost parameter in the setNetworkDiag function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the host_time parameter in the NTPSyncWithHost function.
- risk 0.64cvss 9.8epss 0.01
sprintf in the GNU C Library (glibc) 2.37 has a buffer overflow (out-of-bounds write) in some situations with a correct buffer size. This is unrelated to CWE-676. It may write beyond the bounds of the destination buffer when attempting to write a padded, thousands-separated…
- risk 0.66cvss 9.8epss 0.24
vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserialization. This occurs because verify_serialized checks that a value is serialized by calling unserialize and then checking for errors.…
- risk 0.64cvss 9.8epss 0.01
A vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges via a crafted message sent to the server.
- risk 0.65cvss 10.0epss 0.01
IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 226328.
- risk 0.64cvss 9.8epss 0.01
RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable.
- risk 0.64cvss 9.8epss 0.01
A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet service via a crafted POST request. Attackers are also able to leverage this vulnerability to login as root via hardcoded credentials.
- risk 0.64cvss 9.8epss 0.01
Tenda W20E v15.11.0.6 was discovered to contain multiple stack overflows in the function formSetStaticRoute via the parameters staticRouteNet, staticRouteMask, staticRouteGateway, staticRouteWAN.
- risk 0.64cvss 9.8epss 0.01
Easyone CRM v5.50.02 was discovered to contain a SQL Injection vulnerability via the text parameter at /Services/Misc.asmx/SearchTag.
- risk 0.64cvss 9.8epss 0.01
Monnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execute arbitrary code via uploading a crafted PHP file to the virtual host directory of the system.
- risk 0.70cvss 9.8epss 0.74
OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.
- risk 0.60cvss 9.1epss 0.16
An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain access to a Jira Service Management instance under certain circumstances_._ With write access to a User Directory and…
- risk 0.57cvss 9.8epss 0.01
Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inlong/pull/7223…
- risk 0.64cvss 9.8epss 0.01
Last Yard 22.09.8-1 does not enforce HSTS headers