| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-44618 | Cri | 0.57 | 9.8 | 0.01 | Mar 11, 2022 | A Server-side Template Injection (SSTI) vulnerability exists in Nystudio107 Seomatic 3.4.12 in src/helpers/UrlHelper.php via the host header. | ||
| CVE-2022-0860 | Cri | 0.52 | 9.1 | 0.02 | Mar 11, 2022 | Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2. | ||
| CVE-2022-0871 | Cri | 0.52 | 9.1 | 0.01 | Mar 11, 2022 | Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5. | ||
| CVE-2022-23402 | Cri | 0.64 | 9.8 | 0.01 | Mar 11, 2022 | The following Yokogawa Electric products hard-code the password for CAMS server applications: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00 | ||
| CVE-2022-21194 | Cri | 0.64 | 9.8 | 0.01 | Mar 11, 2022 | The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.0, Exaopc versions from R3.72.00 to R3.79.00. | ||
| CVE-2022-26520 | Cri | 0.64 | 9.8 | 0.03 | Mar 10, 2022 | In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. An example situation is that an attacker could create an executable JSP… | ||
| CVE-2022-26143 | Cri | 0.83 | 9.8 | 0.87 | KEV | Mar 10, 2022 | The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in… | |
| CVE-2022-26131 | Cri | 0.61 | 9.3 | 0.01 | Mar 10, 2022 | Power Line Communications PLC4TRUCKS J2497 trailer receivers are susceptible to remote RF induced signals. | ||
| CVE-2022-26100 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2022 | SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive. As a result, the SAPCAR process may crash, and the attacker may obtain privileged access to the system. | ||
| CVE-2022-24995 | Cri | 0.65 | 9.8 | 0.14 | Mar 10, 2022 | Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the time parameter. | ||
| CVE-2022-24652 | Cri | 0.64 | 9.8 | 0.03 | Mar 10, 2022 | sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in php code execution in /admin/upload/upload. | ||
| CVE-2022-24651 | Cri | 0.64 | 9.8 | 0.03 | Mar 10, 2022 | sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in PHP code execution through /user/upload/upload. | ||
| CVE-2022-24609 | Cri | 0.64 | 9.8 | 0.02 | Mar 10, 2022 | Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attacker can write an arbitrary shell file. | ||
| CVE-2022-24607 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/news/news_ok.php. | ||
| CVE-2022-24606 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/news/sort_ok.php. | ||
| CVE-2022-24605 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php. | ||
| CVE-2022-24604 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php. | ||
| CVE-2022-24603 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/news/sort_mod.php. | ||
| CVE-2022-24602 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php. | ||
| CVE-2022-24600 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection through /admin/login.php. An attacker can log in to the background through SQL injection statements. | ||
| CVE-2022-24193 | Cri | 0.57 | 9.8 | 0.06 | Mar 10, 2022 | CasaOS before v0.2.7 was discovered to contain a command injection vulnerability. | ||
| CVE-2022-23383 | Cri | 0.59 | 9.1 | 0.01 | Mar 10, 2022 | YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home… | ||
| CVE-2022-22814 | Cri | 0.64 | 9.8 | 0.02 | Mar 10, 2022 | The System Diagnosis service of MyASUS before 3.1.2.0 allows privilege escalation. | ||
| CVE-2021-4045 | Cri | 0.72 | 9.8 | 0.72 | Mar 10, 2022 | TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root. The exploitation of this vulnerability allows an attacker to take full control of the camera. | ||
| CVE-2021-44632 | Cri | 0.64 | 9.8 | 0.03 | Mar 10, 2022 | A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/upgrade_info feature, which allows malicious users to execute arbitrary code on the system via a crafted post request. | ||
| CVE-2021-44631 | Cri | 0.64 | 9.8 | 0.03 | Mar 10, 2022 | A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/reset_cloud_pwd feature, which allows malicous users to execute arbitrary code on the system via a crafted post request. | ||
| CVE-2021-44630 | Cri | 0.64 | 9.8 | 0.03 | Mar 10, 2022 | A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/modify_account_pwd feature, which allows malicious users to execute arbitrary code on the system via a crafted post request. | ||
| CVE-2021-44629 | Cri | 0.64 | 9.8 | 0.03 | Mar 10, 2022 | A Buffer Overflow vulnerabilitiy exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/register feature, which allows malicious users to execute arbitrary code on the system via a crafted post request. | ||
| CVE-2021-44628 | Cri | 0.64 | 9.8 | 0.03 | Mar 10, 2022 | A Buffer Overflow vulnerabiltiy exists in TP-LINK WR-886N 20190826 2.3.8 in thee /cloud_config/router_post/login feature, which allows malicious users to execute arbitrary code on the system via a crafted post request. | ||
| CVE-2021-44627 | Cri | 0.64 | 9.8 | 0.03 | Mar 10, 2022 | A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/get_reset_pwd_veirfy_code feature, which allows malicious users to execute arbitrary code on the system via a crafted post request. | ||
| CVE-2021-44626 | Cri | 0.64 | 9.8 | 0.03 | Mar 10, 2022 | A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/get_reg_verify_code feature, which allows malicious users to execute arbitrary code on the system via a crafted post request. | ||
| CVE-2021-44625 | Cri | 0.64 | 9.8 | 0.02 | Mar 10, 2022 | A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in /cloud_config/cloud_device/info interface, which allows a malicious user to executee arbitrary code on the system via a crafted post request. | ||
| CVE-2021-44623 | Cri | 0.64 | 9.8 | 0.02 | Mar 10, 2022 | A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 via the /cloud_config/router_post/check_reset_pwd_verify_code interface. | ||
| CVE-2021-44622 | Cri | 0.64 | 9.8 | 0.03 | Mar 10, 2022 | A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/check_reg_verify_code function which could let a remove malicious user execute arbitrary code via a crafted post request. | ||
| CVE-2021-42854 | Cri | 0.64 | 9.8 | 0.02 | Mar 10, 2022 | It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) PluginServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/plugin/pmx" API. The affected endpoint does not have any input validation of the user's input that allows a… | ||
| CVE-2021-42853 | Cri | 0.59 | 9.1 | 0.02 | Mar 10, 2022 | It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDiagnosticServlet has directory traversal vulnerability at the "/api/appInternals/1.0/agent/diagnostic/logs" API. The affected endpoint does not have any input validation of the user's input… | ||
| CVE-2021-42787 | Cri | 0.61 | 9.4 | 0.01 | Mar 10, 2022 | It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentConfigurationServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/configuration" API. The affected endpoint does not have any input validation of the user's… | ||
| CVE-2021-42786 | Cri | 0.64 | 9.8 | 0.02 | Mar 10, 2022 | It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) has Remote Code Execution vulnerabilities in multiple instances of the API requests. The affected endpoints do not have any input validation of the user's input that allowed a malicious payload to… | ||
| CVE-2021-40053 | Cri | 0.59 | 9.1 | 0.01 | Mar 10, 2022 | There is a permission control vulnerability in the Nearby module.Successful exploitation of this vulnerability will affect availability and integrity. | ||
| CVE-2021-40050 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2022 | There is an out-of-bounds read vulnerability in the IFAA module. Successful exploitation of this vulnerability may cause stack overflow. | ||
| CVE-2021-33293 | Cri | 0.59 | 9.1 | 0.02 | Mar 10, 2022 | Panorama Tools libpano13 v2.9.20 was discovered to contain an out-of-bounds read in the function panoParserFindOLine() in parser.c. | ||
| CVE-2020-14115 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2022 | A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code. | ||
| CVE-2022-0895 | Cri | 0.57 | 9.8 | 0.02 | Mar 10, 2022 | Static Code Injection in GitHub repository microweber/microweber prior to 1.3. | ||
| CVE-2022-22806 | Cri | 0.65 | 9.8 | 0.12 | Mar 9, 2022 | A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a malformed connection is sent. Affected Product: SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and prior), SMC Series (SMC… | ||
| CVE-2022-22805 | Cri | 0.65 | 9.8 | 0.12 | Mar 9, 2022 | A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause remote code execution when an improperly handled TLS packet is reassembled. Affected Product: SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and… | ||
| CVE-2022-0715 | Cri | 0.60 | 9.1 | 0.06 | Mar 9, 2022 | A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leaked and used to upload malicious firmware. Affected Product: APC Smart-UPS Family: SMT Series (SMT Series ID=18: UPS 09.8 and prior… | ||
| CVE-2022-0482 | Cri | 0.59 | 9.1 | 0.44 | Mar 9, 2022 | Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3. | ||
| CVE-2022-26314 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2022 | A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1), Mendix Forgot Password Appstore module (Mendix 7 compatible) (All versions < V3.2.2). Initial passwords are generated in an insecure manner. This could allow an… | ||
| CVE-2022-26313 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2022 | A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1). In certain configurations of the affected product, a threat actor could use the sign up flow to hijack arbitrary user accounts. | ||
| CVE-2021-37208 | Cri | 0.62 | 9.6 | 0.01 | Mar 8, 2022 | A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCOM i803, RUGGEDCOM i803NC, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M2100NC, RUGGEDCOM M2200, RUGGEDCOM M2200F, RUGGEDCOM… |
- risk 0.57cvss 9.8epss 0.01
A Server-side Template Injection (SSTI) vulnerability exists in Nystudio107 Seomatic 3.4.12 in src/helpers/UrlHelper.php via the host header.
- risk 0.52cvss 9.1epss 0.02
Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.
- risk 0.52cvss 9.1epss 0.01
Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5.
- risk 0.64cvss 9.8epss 0.01
The following Yokogawa Electric products hard-code the password for CAMS server applications: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00
- risk 0.64cvss 9.8epss 0.01
The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.0, Exaopc versions from R3.72.00 to R3.79.00.
- risk 0.64cvss 9.8epss 0.03
In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. An example situation is that an attacker could create an executable JSP…
- risk 0.83cvss 9.8epss 0.87
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in…
- risk 0.61cvss 9.3epss 0.01
Power Line Communications PLC4TRUCKS J2497 trailer receivers are susceptible to remote RF induced signals.
- risk 0.64cvss 9.8epss 0.01
SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive. As a result, the SAPCAR process may crash, and the attacker may obtain privileged access to the system.
- risk 0.65cvss 9.8epss 0.14
Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the time parameter.
- risk 0.64cvss 9.8epss 0.03
sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in php code execution in /admin/upload/upload.
- risk 0.64cvss 9.8epss 0.03
sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in PHP code execution through /user/upload/upload.
- risk 0.64cvss 9.8epss 0.02
Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attacker can write an arbitrary shell file.
- risk 0.64cvss 9.8epss 0.01
Luocms v2.0 is affected by SQL Injection in /admin/news/news_ok.php.
- risk 0.64cvss 9.8epss 0.01
Luocms v2.0 is affected by SQL Injection in /admin/news/sort_ok.php.
- risk 0.64cvss 9.8epss 0.01
Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php.
- risk 0.64cvss 9.8epss 0.01
Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php.
- risk 0.64cvss 9.8epss 0.01
Luocms v2.0 is affected by SQL Injection in /admin/news/sort_mod.php.
- risk 0.64cvss 9.8epss 0.01
Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php.
- risk 0.64cvss 9.8epss 0.01
Luocms v2.0 is affected by SQL Injection through /admin/login.php. An attacker can log in to the background through SQL injection statements.
- risk 0.57cvss 9.8epss 0.06
CasaOS before v0.2.7 was discovered to contain a command injection vulnerability.
- risk 0.59cvss 9.1epss 0.01
YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home…
- risk 0.64cvss 9.8epss 0.02
The System Diagnosis service of MyASUS before 3.1.2.0 allows privilege escalation.
- risk 0.72cvss 9.8epss 0.72
TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root. The exploitation of this vulnerability allows an attacker to take full control of the camera.
- risk 0.64cvss 9.8epss 0.03
A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/upgrade_info feature, which allows malicious users to execute arbitrary code on the system via a crafted post request.
- risk 0.64cvss 9.8epss 0.03
A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/reset_cloud_pwd feature, which allows malicous users to execute arbitrary code on the system via a crafted post request.
- risk 0.64cvss 9.8epss 0.03
A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/modify_account_pwd feature, which allows malicious users to execute arbitrary code on the system via a crafted post request.
- risk 0.64cvss 9.8epss 0.03
A Buffer Overflow vulnerabilitiy exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/register feature, which allows malicious users to execute arbitrary code on the system via a crafted post request.
- risk 0.64cvss 9.8epss 0.03
A Buffer Overflow vulnerabiltiy exists in TP-LINK WR-886N 20190826 2.3.8 in thee /cloud_config/router_post/login feature, which allows malicious users to execute arbitrary code on the system via a crafted post request.
- risk 0.64cvss 9.8epss 0.03
A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/get_reset_pwd_veirfy_code feature, which allows malicious users to execute arbitrary code on the system via a crafted post request.
- risk 0.64cvss 9.8epss 0.03
A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/get_reg_verify_code feature, which allows malicious users to execute arbitrary code on the system via a crafted post request.
- risk 0.64cvss 9.8epss 0.02
A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in /cloud_config/cloud_device/info interface, which allows a malicious user to executee arbitrary code on the system via a crafted post request.
- risk 0.64cvss 9.8epss 0.02
A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 via the /cloud_config/router_post/check_reset_pwd_verify_code interface.
- risk 0.64cvss 9.8epss 0.03
A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/check_reg_verify_code function which could let a remove malicious user execute arbitrary code via a crafted post request.
- risk 0.64cvss 9.8epss 0.02
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) PluginServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/plugin/pmx" API. The affected endpoint does not have any input validation of the user's input that allows a…
- risk 0.59cvss 9.1epss 0.02
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDiagnosticServlet has directory traversal vulnerability at the "/api/appInternals/1.0/agent/diagnostic/logs" API. The affected endpoint does not have any input validation of the user's input…
- risk 0.61cvss 9.4epss 0.01
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentConfigurationServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/configuration" API. The affected endpoint does not have any input validation of the user's…
- risk 0.64cvss 9.8epss 0.02
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) has Remote Code Execution vulnerabilities in multiple instances of the API requests. The affected endpoints do not have any input validation of the user's input that allowed a malicious payload to…
- risk 0.59cvss 9.1epss 0.01
There is a permission control vulnerability in the Nearby module.Successful exploitation of this vulnerability will affect availability and integrity.
- risk 0.64cvss 9.8epss 0.01
There is an out-of-bounds read vulnerability in the IFAA module. Successful exploitation of this vulnerability may cause stack overflow.
- risk 0.59cvss 9.1epss 0.02
Panorama Tools libpano13 v2.9.20 was discovered to contain an out-of-bounds read in the function panoParserFindOLine() in parser.c.
- risk 0.64cvss 9.8epss 0.01
A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code.
- risk 0.57cvss 9.8epss 0.02
Static Code Injection in GitHub repository microweber/microweber prior to 1.3.
- risk 0.65cvss 9.8epss 0.12
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a malformed connection is sent. Affected Product: SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and prior), SMC Series (SMC…
- risk 0.65cvss 9.8epss 0.12
A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause remote code execution when an improperly handled TLS packet is reassembled. Affected Product: SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and…
- risk 0.60cvss 9.1epss 0.06
A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leaked and used to upload malicious firmware. Affected Product: APC Smart-UPS Family: SMT Series (SMT Series ID=18: UPS 09.8 and prior…
- risk 0.59cvss 9.1epss 0.44
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.
- risk 0.64cvss 9.8epss 0.01
A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1), Mendix Forgot Password Appstore module (Mendix 7 compatible) (All versions < V3.2.2). Initial passwords are generated in an insecure manner. This could allow an…
- risk 0.64cvss 9.8epss 0.01
A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1). In certain configurations of the affected product, a threat actor could use the sign up flow to hijack arbitrary user accounts.
- risk 0.62cvss 9.6epss 0.01
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCOM i803, RUGGEDCOM i803NC, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M2100NC, RUGGEDCOM M2200, RUGGEDCOM M2200F, RUGGEDCOM…