CVE Database

CVE-2023-0789CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Command Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

CVE-2022-48322CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

NETGEAR Nighthawk WiFi Mesh systems and routers are affected by a stack-based buffer overflow vulnerability. This affects MR60 before 1.1.7.132, MS60 before 1.1.7.132, R6900P before 1.3.3.154, R7000P before 1.3.3.154, R7960P before 1.4.4.94, and R8000P before 1.4.4.94.

CVE-2022-4445CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The FL3R FeelBox WordPress plugin through 8.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2022-3089CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker to obtain cleartext usernames and passwords of the SmartServer. If the attacker obtains the file, then the credentials could be used to control the web user interface and file transfer protocol (FTP) server.

CVE-2023-23551CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

Control By Web X-600M devices run Lua scripts and are vulnerable to code injection, which could allow an attacker to remotely execute arbitrary code.

CVE-2023-25718CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-347

In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can be added without invalidating the signature, such as instructions that result in offering the end user a (different) attacker-controlled executable file. It is plausible that the end user may allow the download and execution of this file to proceed. There are ConnectWise Control configuration options that add mitigations.

CVE-2023-24084CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

ChiKoi v1.0 was discovered to contain a SQL injection vulnerability via the load_file function.

CVE-2022-47034CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-697

A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.

CVE-2023-24482CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

A vulnerability has been identified in COMOS V10.2 (All versions), COMOS V10.3.3.1 (All versions < V10.3.3.1.45), COMOS V10.3.3.2 (All versions < V10.3.3.2.33), COMOS V10.3.3.3 (All versions < V10.3.3.3.9), COMOS V10.3.3.4 (All versions < V10.3.3.4.6), COMOS V10.4.0.0 (All versions < V10.4.0.0.31), COMOS V10.4.1.0 (All versions < V10.4.1.0.32), COMOS V10.4.2.0 (All versions < V10.4.2.0.25). Cache validation service in COMOS is vulnerable to Structured Exception Handler (SEH) based buffer overflow. This could allow an attacker to execute arbitrary code on the target system or cause denial of service condition.

CVE-2023-24159CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admpass parameter in the setPasswordCfg function.

CVE-2023-24160CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg function.

CVE-2023-24161CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the webWlanIdx parameter in the setWebWlanIdx function.

CVE-2023-21689CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

CVE-2023-21690CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

CVE-2023-21692CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

CVE-2023-21803CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

Windows iSCSI Discovery Service Remote Code Execution Vulnerability

CVE-2023-23461CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

Libpeconv – access violation, before commit b076013 (30/11/2022).

CVE-2023-23462CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

Libpeconv – integer overflow, before commit 75b1565 (30/11/2022).

CVE-2023-25156CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-770

Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt brute-force attacks against the login page. Users should upgrade to v12.0 or later to receive a patch. As a workaround, users may install and configure a rate-limiting proxy in front of Kiwi TCMS.

CVE-2022-46892CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

In Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root complex.

CVE-2023-22804CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to create users on the PLC. This could allow an attacker to create and use an account with elevated privileges and take control of the device.

CVE-2023-22807CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-284

LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal XGT protocol. An attacker could control and tamper with the PLC by sending the packets to the PLC over its XGT protocol.

CVE-2023-23459CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Priority Windows may allow Command Execution via SQL Injection using an unspecified method.

CVE-2023-23460CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Priority Web version 19.1.0.68, parameter manipulation on an unspecified end-point may allow authentication bypass.

CVE-2020-21119CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection vulnerability in Kliqqi-CMS 2.0.2 in admin/admin_update_module_widgets.php in recordIDValue parameter, allows attackers to gain escalated privileges and execute arbitrary code.

CVE-2020-21120CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection vulnerability in file home\controls\cart.class.php in UQCMS 2.1.3, allows attackers execute arbitrary commands via the cookie_cart parameter to /index.php/cart/num.

CVE-2021-33304CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

Double Free vulnerability in virtualsquare picoTCP v1.7.0 and picoTCP-NG v2.1 in modules/pico_fragments.c in function pico_fragments_reassemble, allows attackers to execute arbitrary code.

CVE-2021-33925CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection vulnerability in nitinparashar30 cms-corephp through commit bdabe52ef282846823bda102728a35506d0ec8f9 (May 19, 2021) allows unauthenticated attackers to gain escilated privledges via a crafted login.

CVE-2023-0849CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

A vulnerability has been found in Netgear WNDR3700v2 1.0.1.14 and classified as critical. This vulnerability affects unknown code of the component Web Interface. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-221152.

CVE-2023-22578CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-790

Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections.

CVE-2023-24236CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the province parameter at setting/delStaticDhcpRules.

CVE-2023-24238CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the city parameter at setting/delStaticDhcpRules.

CVE-2021-42756CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbitrary code execution via specifically crafted HTTP requests.

CVE-2021-42761CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-384

A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 through 6.0.7, 5.9.0 through 5.9.1 may allow a remote, unauthenticated attacker to infer the session identifier of other users and possibly usurp their session.

CVE-2022-38375CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-285

An improper authorization vulnerability [CWE-285]  in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests.

CVE-2022-25987CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

Improper handling of Unicode encoding in source code to be compiled by the Intel(R) C++ Compiler Classic before version 2021.6 for Intel(R) oneAPI Toolkits before version 2022.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2022-26843CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

Insufficient visual distinction of homoglyphs presented to user in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.1 for Intel(R) oneAPI Toolkits before version 2022.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2022-29514CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

Improper access control in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2022-33964CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2021-43529CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures.

CVE-2023-24219CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/UserMapper.xml.

CVE-2023-24220CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/RoleMapper.xml.

CVE-2023-24221CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/DeptMapper.xml.

CVE-2023-0883CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code of the file /php-opos/index.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-221350 is the identifier assigned to this vulnerability.

CVE-2020-29168CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection vulnerability in Projectworlds Online Doctor Appointment Booking System, allows attackers to gain sensitive information via the q parameter to the getuser.php endpoint.

CVE-2021-32163CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-863

Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization.

CVE-2021-33226CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/modules/status.py file. NOTE: this is disputed by third parties because an attacker cannot influence the eval input

CVE-2021-33391CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.

CVE-2021-33948CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in FantasticLBP Hotels Server v1.0 allows attacker to execute arbitrary code via the username parameter.

CVE-2021-33949CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue in FeMiner WMS v1.1 allows attackers to execute arbitrary code via the filename parameter and the exec function.

← PreviousPage 480 / 7034Next →