| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-49074 | Hig | 0.49 | 7.4 | 0.13 | Apr 9, 2024 | A denial of service vulnerability exists in the TDDP functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of network requests can lead to reset to factory settings. An attacker can send a sequence of… | ||
| CVE-2023-48724 | Hig | 0.49 | 7.5 | 0.01 | Apr 9, 2024 | A memory corruption vulnerability exists in the web interface functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted HTTP POST request can lead to denial of service of the device's web interface. An attacker… | ||
| CVE-2023-41677 | Hig | 0.49 | 7.5 | 0.01 | Apr 9, 2024 | A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12,… | ||
| CVE-2023-6317 | Hig | 0.47 | 7.2 | 0.01 | Apr 9, 2024 | A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without asking the user for the security PIN. Full versions and TV models affected: webOS 4.9.7 - 5.30.40 running on LG43UM7000PLA … | ||
| CVE-2024-2224 | Hig | 0.53 | 8.1 | 0.01 | Apr 9, 2024 | Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects the following products that include… | ||
| CVE-2024-2223 | Hig | 0.53 | 8.1 | 0.01 | Apr 9, 2024 | An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. This issue affects the following products that include the vulnerable component: Bitdefender Endpoint… | ||
| CVE-2024-3046 | Hig | 0.49 | 7.5 | 0.01 | Apr 9, 2024 | In Eclipse Kura LogServlet component included in versions 5.0.0 to 5.4.1, a specifically crafted request to the servlet can allow an unauthenticated user to retrieve the device logs. Also, downloaded logs may be used by an attacker to perform privilege escalation by using the… | ||
| CVE-2024-31978 | Hig | 0.49 | 7.6 | 0.00 | Apr 9, 2024 | A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP2). Affected devices allow authenticated users to export monitoring data. The corresponding API endpoint is susceptible to path traversal and could allow an authenticated attacker to download files from the… | ||
| CVE-2024-31370 | Hig | 0.55 | 8.5 | 0.01 | Apr 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CodeIsAwesome AIKit aikit-wordpress-ai-writing-assistant-using-gpt3.This issue affects AIKit: from n/a through <= 4.14.1. | ||
| CVE-2024-31367 | Hig | 0.46 | 7.1 | 0.00 | Apr 9, 2024 | Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2. | ||
| CVE-2024-30191 | Hig | 0.55 | 8.4 | 0.00 | Apr 9, 2024 | A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0), SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0), SCALANCE W1788-2 EEC M12 (6GK5788-2GY01-0TA0), SCALANCE W1788-2 M12 (6GK5788-2GY01-0AA0), SCALANCE W1788-2IA… | ||
| CVE-2024-26275 | Hig | 0.51 | 7.8 | 0.00 | Apr 9, 2024 | A vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Parasolid V36.0 (All versions < V36.0.207), Parasolid V36.1 (All versions < V36.1.147), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), Teamcenter… | ||
| CVE-2023-1082 | — | Hig | 0.57 | 8.8 | 0.01 | Apr 9, 2024 | An remote attacker with low privileges can perform a command injection which can lead to root access. | |
| CVE-2024-31366 | Hig | 0.46 | 7.1 | 0.00 | Apr 9, 2024 | Missing Authorization vulnerability in Themify Post Type Builder (PTB).This issue affects Post Type Builder (PTB): from n/a through 2.0.8. | ||
| CVE-2024-31365 | Hig | 0.46 | 7.1 | 0.00 | Apr 9, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Post Type Builder (PTB) allows Reflected XSS.This issue affects Post Type Builder (PTB): from n/a before 2.1.1. | ||
| CVE-2024-1233 | Hig | 0.41 | 7.3 | 0.01 | Apr 9, 2024 | A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or other filtering behavior is performed on the destination URL address, which may result in a server-side request… | ||
| CVE-2024-2975 | Hig | 0.57 | 8.8 | 0.00 | Apr 9, 2024 | A race condition was identified through which privilege escalation was possible in certain configurations. | ||
| CVE-2024-27983 | Hig | 0.60 | 8.2 | 0.87 | Apr 9, 2024 | An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave some data in nghttp2 memory after reset when headers with HTTP/2 CONTINUATION frame are sent to the… | ||
| CVE-2024-27901 | Hig | 0.47 | 7.2 | 0.01 | Apr 9, 2024 | SAP Asset Accounting could allow a high privileged attacker to exploit insufficient validation of path information provided by the users and pass it through to the file API's. Thus, causing a considerable impact on confidentiality, integrity and availability of the application. | ||
| CVE-2024-27899 | Hig | 0.57 | 8.8 | 0.00 | Apr 9, 2024 | Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the newly defined security answer. This can be leveraged by an attacker to cause profound impact on confidentiality and… | ||
| CVE-2024-25646 | Hig | 0.50 | 7.7 | 0.00 | Apr 9, 2024 | Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confidentiality of the application. | ||
| CVE-2024-23084 | Hig | 0.49 | 7.5 | 0.01 | Apr 8, 2024 | Apfloat v1.10.1 was discovered to contain an ArrayIndexOutOfBoundsException via the component org.apfloat.internal.DoubleCRTMath::add(double[], double[]). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of… | ||
| CVE-2024-27632 | Hig | 0.57 | 8.8 | 0.01 | Apr 8, 2024 | An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in the form_header() function. | ||
| CVE-2024-0082 | Hig | 0.53 | 8.2 | 0.00 | Apr 8, 2024 | NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause improper privilege management by sending open file requests to the application. A successful exploit of this vulnerability might lead to local escalation of privileges, information… | ||
| CVE-2024-27630 | Hig | 0.49 | 7.5 | 0.01 | Apr 8, 2024 | Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the trackers_data_delete_file function. | ||
| CVE-2024-24279 | Hig | 0.57 | 8.8 | 0.00 | Apr 8, 2024 | An issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated privileges via vsVerifyPassword and vsSetFingerPrintPower functions. | ||
| CVE-2024-23085 | Hig | 0.49 | 7.5 | 0.01 | Apr 8, 2024 | Apfloat v1.10.1 was discovered to contain a NullPointerException via the component org.apfloat.internal.DoubleScramble::scramble(double[], int, int[]). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a… | ||
| CVE-2024-28270 | Hig | 0.53 | 8.1 | 0.00 | Apr 8, 2024 | An issue discovered in web-flash v3.0 allows attackers to reset passwords for arbitrary users via crafted POST request to /prod-api/user/resetPassword. | ||
| CVE-2023-7164 | Hig | 0.49 | 7.5 | 0.02 | Apr 8, 2024 | The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database. | ||
| CVE-2024-31442 | Hig | 0.00 | 8.8 | 0.01 | Apr 8, 2024 | Redon Hub is a Roblox Product Delivery Bot, also known as a Hub. In all hubs before version 1.0.2, all commands are capable of being ran by all users, including admin commands. This allows users to receive products for free and delete/create/update products/tags/etc. The only… | ||
| CVE-2024-28732 | Hig | 0.49 | 7.5 | 0.01 | Apr 8, 2024 | An issue was discovered in OFPMatch in parser.py in Faucet SDN Ryu version 4.34, allows remote attackers to cause a denial of service (DoS) (infinite loop). | ||
| CVE-2024-31817 | Hig | 0.53 | 7.5 | 0.55 | Apr 8, 2024 | In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg. | ||
| CVE-2024-31816 | Hig | 0.49 | 7.5 | 0.03 | Apr 8, 2024 | In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getEasyWizardCfg. | ||
| CVE-2024-31814 | Hig | 0.58 | 8.8 | 0.09 | Apr 8, 2024 | TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to bypass login through the Form_Login function. | ||
| CVE-2024-31813 | Hig | 0.55 | 8.4 | 0.00 | Apr 8, 2024 | TOTOLINK EX200 V4.0.3c.7646_B20201211 does not contain an authentication mechanism by default. | ||
| CVE-2024-31811 | Hig | 0.52 | 8.0 | 0.01 | Apr 8, 2024 | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLanguageCfg function. | ||
| CVE-2024-31809 | Hig | 0.57 | 8.8 | 0.01 | Apr 8, 2024 | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in the setUpgradeFW function. | ||
| CVE-2024-31808 | Hig | 0.57 | 8.8 | 0.01 | Apr 8, 2024 | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in the setWebWlanIdx function. | ||
| CVE-2024-2834 | Hig | 0.57 | 8.7 | 0.01 | Apr 8, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited. | ||
| CVE-2024-28066 | Hig | 0.57 | 8.8 | 0.00 | Apr 8, 2024 | In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password). | ||
| CVE-2024-3439 | Hig | 0.48 | 7.3 | 0.01 | Apr 8, 2024 | A vulnerability was found in SourceCodester Prison Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /Account/login.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has… | ||
| CVE-2024-26574 | Hig | 0.51 | 7.8 | 0.00 | Apr 8, 2024 | Insecure Permissions vulnerability in Wondershare Filmora v.13.0.51 allows a local attacker to execute arbitrary code via a crafted script to the WSNativePushService.exe | ||
| CVE-2024-3438 | Hig | 0.48 | 7.3 | 0.01 | Apr 8, 2024 | A vulnerability was found in SourceCodester Prison Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /Admin/login.php. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been… | ||
| CVE-2024-27897 | Hig | 0.49 | 7.5 | 0.00 | Apr 8, 2024 | Input verification vulnerability in the call module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-27896 | Hig | 0.49 | 7.5 | 0.00 | Apr 8, 2024 | Input verification vulnerability in the log module. Impact: Successful exploitation of this vulnerability can affect integrity. | ||
| CVE-2024-27895 | Hig | 0.49 | 7.5 | 0.00 | Apr 8, 2024 | Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2023-52386 | Hig | 0.49 | 7.5 | 0.00 | Apr 8, 2024 | Out-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2023-52553 | Hig | 0.48 | 7.4 | 0.00 | Apr 8, 2024 | Race condition vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2023-52552 | Hig | 0.49 | 7.5 | 0.00 | Apr 8, 2024 | Input verification vulnerability in the power module. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2023-52550 | Hig | 0.49 | 7.5 | 0.00 | Apr 8, 2024 | Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. |
- risk 0.49cvss 7.4epss 0.13
A denial of service vulnerability exists in the TDDP functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of network requests can lead to reset to factory settings. An attacker can send a sequence of…
- risk 0.49cvss 7.5epss 0.01
A memory corruption vulnerability exists in the web interface functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted HTTP POST request can lead to denial of service of the device's web interface. An attacker…
- risk 0.49cvss 7.5epss 0.01
A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12,…
- risk 0.47cvss 7.2epss 0.01
A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without asking the user for the security PIN. Full versions and TV models affected: webOS 4.9.7 - 5.30.40 running on LG43UM7000PLA …
- risk 0.53cvss 8.1epss 0.01
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects the following products that include…
- risk 0.53cvss 8.1epss 0.01
An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. This issue affects the following products that include the vulnerable component: Bitdefender Endpoint…
- risk 0.49cvss 7.5epss 0.01
In Eclipse Kura LogServlet component included in versions 5.0.0 to 5.4.1, a specifically crafted request to the servlet can allow an unauthenticated user to retrieve the device logs. Also, downloaded logs may be used by an attacker to perform privilege escalation by using the…
- risk 0.49cvss 7.6epss 0.00
A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP2). Affected devices allow authenticated users to export monitoring data. The corresponding API endpoint is susceptible to path traversal and could allow an authenticated attacker to download files from the…
- risk 0.55cvss 8.5epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CodeIsAwesome AIKit aikit-wordpress-ai-writing-assistant-using-gpt3.This issue affects AIKit: from n/a through <= 4.14.1.
- risk 0.46cvss 7.1epss 0.00
Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2.
- risk 0.55cvss 8.4epss 0.00
A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0), SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0), SCALANCE W1788-2 EEC M12 (6GK5788-2GY01-0TA0), SCALANCE W1788-2 M12 (6GK5788-2GY01-0AA0), SCALANCE W1788-2IA…
- risk 0.51cvss 7.8epss 0.00
A vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Parasolid V36.0 (All versions < V36.0.207), Parasolid V36.1 (All versions < V36.1.147), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), Teamcenter…
- risk 0.57cvss 8.8epss 0.01
An remote attacker with low privileges can perform a command injection which can lead to root access.
- risk 0.46cvss 7.1epss 0.00
Missing Authorization vulnerability in Themify Post Type Builder (PTB).This issue affects Post Type Builder (PTB): from n/a through 2.0.8.
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Post Type Builder (PTB) allows Reflected XSS.This issue affects Post Type Builder (PTB): from n/a before 2.1.1.
- risk 0.41cvss 7.3epss 0.01
A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or other filtering behavior is performed on the destination URL address, which may result in a server-side request…
- risk 0.57cvss 8.8epss 0.00
A race condition was identified through which privilege escalation was possible in certain configurations.
- risk 0.60cvss 8.2epss 0.87
An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave some data in nghttp2 memory after reset when headers with HTTP/2 CONTINUATION frame are sent to the…
- risk 0.47cvss 7.2epss 0.01
SAP Asset Accounting could allow a high privileged attacker to exploit insufficient validation of path information provided by the users and pass it through to the file API's. Thus, causing a considerable impact on confidentiality, integrity and availability of the application.
- risk 0.57cvss 8.8epss 0.00
Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the newly defined security answer. This can be leveraged by an attacker to cause profound impact on confidentiality and…
- risk 0.50cvss 7.7epss 0.00
Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confidentiality of the application.
- risk 0.49cvss 7.5epss 0.01
Apfloat v1.10.1 was discovered to contain an ArrayIndexOutOfBoundsException via the component org.apfloat.internal.DoubleCRTMath::add(double[], double[]). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of…
- risk 0.57cvss 8.8epss 0.01
An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in the form_header() function.
- risk 0.53cvss 8.2epss 0.00
NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause improper privilege management by sending open file requests to the application. A successful exploit of this vulnerability might lead to local escalation of privileges, information…
- risk 0.49cvss 7.5epss 0.01
Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the trackers_data_delete_file function.
- risk 0.57cvss 8.8epss 0.00
An issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated privileges via vsVerifyPassword and vsSetFingerPrintPower functions.
- risk 0.49cvss 7.5epss 0.01
Apfloat v1.10.1 was discovered to contain a NullPointerException via the component org.apfloat.internal.DoubleScramble::scramble(double[], int, int[]). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a…
- risk 0.53cvss 8.1epss 0.00
An issue discovered in web-flash v3.0 allows attackers to reset passwords for arbitrary users via crafted POST request to /prod-api/user/resetPassword.
- risk 0.49cvss 7.5epss 0.02
The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database.
- risk 0.00cvss 8.8epss 0.01
Redon Hub is a Roblox Product Delivery Bot, also known as a Hub. In all hubs before version 1.0.2, all commands are capable of being ran by all users, including admin commands. This allows users to receive products for free and delete/create/update products/tags/etc. The only…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in OFPMatch in parser.py in Faucet SDN Ryu version 4.34, allows remote attackers to cause a denial of service (DoS) (infinite loop).
- risk 0.53cvss 7.5epss 0.55
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg.
- risk 0.49cvss 7.5epss 0.03
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getEasyWizardCfg.
- risk 0.58cvss 8.8epss 0.09
TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to bypass login through the Form_Login function.
- risk 0.55cvss 8.4epss 0.00
TOTOLINK EX200 V4.0.3c.7646_B20201211 does not contain an authentication mechanism by default.
- risk 0.52cvss 8.0epss 0.01
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLanguageCfg function.
- risk 0.57cvss 8.8epss 0.01
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in the setUpgradeFW function.
- risk 0.57cvss 8.8epss 0.01
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in the setWebWlanIdx function.
- risk 0.57cvss 8.7epss 0.01
A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited.
- risk 0.57cvss 8.8epss 0.00
In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).
- risk 0.48cvss 7.3epss 0.01
A vulnerability was found in SourceCodester Prison Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /Account/login.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has…
- risk 0.51cvss 7.8epss 0.00
Insecure Permissions vulnerability in Wondershare Filmora v.13.0.51 allows a local attacker to execute arbitrary code via a crafted script to the WSNativePushService.exe
- risk 0.48cvss 7.3epss 0.01
A vulnerability was found in SourceCodester Prison Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /Admin/login.php. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been…
- risk 0.49cvss 7.5epss 0.00
Input verification vulnerability in the call module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
Input verification vulnerability in the log module. Impact: Successful exploitation of this vulnerability can affect integrity.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
Out-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.48cvss 7.4epss 0.00
Race condition vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.49cvss 7.5epss 0.00
Input verification vulnerability in the power module. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.