CVE Database

CVE-2023-0651CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

A vulnerability was found in FastCMS 0.1.0. It has been classified as critical. Affected is an unknown function of the component Template Management. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-48079CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

Monnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execute arbitrary code via uploading a crafted PHP file to the virtual host directory of the system.

CVE-2022-48082CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Easyone CRM v5.50.02 was discovered to contain a SQL Injection vulnerability via the text parameter at /Services/Misc.asmx/SearchTag.

CVE-2022-48130CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda W20E v15.11.0.6 was discovered to contain multiple stack overflows in the function formSetStaticRoute via the parameters staticRouteNet, staticRouteMask, staticRouteGateway, staticRouteWAN.

CVE-2022-48113CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet service via a crafted POST request. Attackers are also able to leverage this vulnerability to login as root via hardcoded credentials.

CVE-2022-48114CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable.

CVE-2022-48021CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

A vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges via a crafted message sent to the server.

CVE-2023-24144CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the hour parameter in the setRebootScheCfg function.

CVE-2023-25139CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

sprintf in the GNU C Library (glibc) 2.37 has a buffer overflow (out-of-bounds write) in some situations with a correct buffer size. This is unrelated to CWE-676. It may write beyond the bounds of the destination buffer when attempting to write a padded, thousands-separated string representation of a number, if the buffer is allocated the exact size required to represent that number as a string. For example, 1,234,567 (with padding to 13) overflows by two bytes.

CVE-2023-24138CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the host_time parameter in the NTPSyncWithHost function.

CVE-2023-24139CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagHost parameter in the setNetworkDiag function.

CVE-2023-24140CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingNum parameter in the setNetworkDiag function.

CVE-2023-24141CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingTimeOut parameter in the setNetworkDiag function.

CVE-2023-24142CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingSize parameter in the setNetworkDiag function.

CVE-2023-24143CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagTracertHop parameter in the setNetworkDiag function.

CVE-2023-24145CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the plugin_version parameter in the setUnloadUserData function.

CVE-2023-24146CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the minute parameter in the setRebootScheCfg function.

CVE-2023-24148CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadUserData function.

CVE-2023-24149CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for root which is stored in the component /etc/shadow.

CVE-2023-24150CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

A command injection vulnerability in the serverIp parameter in the function meshSlaveDlfw of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.

CVE-2023-24151CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

A command injection vulnerability in the ip parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.

CVE-2023-24152CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

A command injection vulnerability in the serverIp parameter in the function meshSlaveUpdate of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.

CVE-2023-24153CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

A command injection vulnerability in the version parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.

CVE-2023-24154CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK T8 V4.1.5cu was discovered to contain a command injection vulnerability via the slaveIpList parameter in the function setUpgradeFW.

CVE-2023-24155CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

TOTOLINK T8 V4.1.5cu was discovered to contain a hard code password for the telnet service which is stored in the component /web_cste/cgi-bin/product.ini.

CVE-2023-24156CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

A command injection vulnerability in the ip parameter in the function recvSlaveUpgstatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.

CVE-2023-24157CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

A command injection vulnerability in the serverIp parameter in the function updateWifiInfo of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.

CVE-2021-36424CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation.

CVE-2023-23086CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Buffer OverFlow Vulnerability in MojoJson v1.2.3 allows an attacker to execute arbitrary code via the SkipString function.

CVE-2021-37497CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request.

CVE-2023-23088CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Buffer OverFlow Vulnerability in Barenboim json-parser master and v1.1.0 fixed in v1.1.1 allows an attacker to execute arbitrary code via the json_value_parse function.

CVE-2023-23477CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. IBM X-Force ID: 245513.

CVE-2023-24576CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the NetWorker Client execution service (nsrexecd) irrespective of any auth used.

CVE-2013-10015CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability has been found in fanzila WebFinance 0.5 and classified as critical. This vulnerability affects unknown code of the file htdocs/admin/save_Contract_Signer_Role.php. The manipulation of the argument n/v leads to sql injection. The patch is identified as abad81af614a9ceef3f29ab22ca6bae517619e06. It is recommended to apply a patch to fix this issue. VDB-220054 is the identifier assigned to this vulnerability.

CVE-2013-10016CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in fanzila WebFinance 0.5 and classified as critical. This issue affects some unknown processing of the file htdocs/admin/save_taxes.php. The manipulation of the argument id leads to sql injection. The patch is named 306f170ca2a8203ae3d8f51fb219ba9e05b945e1. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-220055.

CVE-2023-0663CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in Calendar Event Management System 2.3.0. It has been rated as critical. This issue affects some unknown processing of the component Login Page. The manipulation of the argument name/pwd leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-220175.

CVE-2013-10017CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in fanzila WebFinance 0.5. It has been classified as critical. Affected is an unknown function of the file htdocs/admin/save_roles.php. The manipulation of the argument id leads to sql injection. The name of the patch is 6cfeb2f6b35c1b3a7320add07cd0493e4f752af3. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-220056.

CVE-2013-10018CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in fanzila WebFinance 0.5. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file htdocs/prospection/save_contact.php. The manipulation of the argument nom/prenom/email/tel/mobile/client/fonction/note leads to sql injection. The identifier of the patch is 165dfcaa0520ee0179b7c1282efb84f5a03df114. It is recommended to apply a patch to fix this issue. The identifier VDB-220057 was assigned to this vulnerability.

CVE-2019-25101CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-113

A vulnerability classified as critical has been found in OnShift TurboGears 1.0.11.10. This affects an unknown part of the file turbogears/controllers.py of the component HTTP Header Handler. The manipulation leads to http response splitting. It is possible to initiate the attack remotely. Upgrading to version 1.0.11.11 is able to address this issue. The patch is named f68bbaba47f4474e1da553aa51564a73e1d92a84. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-220059.

CVE-2014-125084CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability, which was classified as critical, has been found in Gimmie Plugin 1.2.2 on vBulletin. This issue affects some unknown processing of the file trigger_referral.php. The manipulation of the argument referrername leads to sql injection. Upgrading to version 1.3.0 is able to address this issue. The identifier of the patch is 7194a09353dd24a274678383a4418f2fd3fce6f7. It is recommended to upgrade the affected component. The identifier VDB-220205 was assigned to this vulnerability.

CVE-2014-125085CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability, which was classified as critical, was found in Gimmie Plugin 1.2.2 on vBulletin. Affected is an unknown function of the file trigger_ratethread.php. The manipulation of the argument t/postusername leads to sql injection. Upgrading to version 1.3.0 is able to address this issue. The patch is identified as f11a136e9cbd24997354965178728dc22a2aa2ed. It is recommended to upgrade the affected component. VDB-220206 is the identifier assigned to this vulnerability.

CVE-2014-125086CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability has been found in Gimmie Plugin 1.2.2 on vBulletin and classified as critical. Affected by this vulnerability is an unknown functionality of the file trigger_login.php. The manipulation of the argument userid leads to sql injection. Upgrading to version 1.3.0 is able to address this issue. The patch is named fe851002d20a8d6196a5abb68bafec4102964d5b. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-220207.

CVE-2021-36224CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Western Digital My Cloud devices before OS5 have a nobody account with a blank password.

CVE-2021-36226CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-347

Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.

CVE-2023-24198CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Raffle Draw System v1.0 was discovered to contain multiple SQL injection vulnerabilities at save_winner.php via the ticket_id and draw parameters.

CVE-2023-24199CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at delete_ticket.php.

CVE-2023-24200CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at save_ticket.php.

CVE-2023-24201CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at get_ticket.php.

CVE-2023-24202CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php.

CVE-2023-24276CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the country parameter at setting/delStaticDhcpRules.

← PreviousPage 478 / 7034Next →