CVE Database

CVE-2023-1958CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0. This affects an unknown part of the file /classes/Master.php?f=delete_sub_category. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-225345 was assigned to this vulnerability.

CVE-2023-1962CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability classified as critical was found in SourceCodester Best Online News Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/forgot-password.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-225361 was assigned to this vulnerability.

CVE-2023-1963CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file index.php of the component Search. The manipulation of the argument searchinput leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-225359.

CVE-2023-27718CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_498308 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-27719CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_478360 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-27720CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_48d630 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2012-10011CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in HD FLV PLayer Plugin up to 1.7 on WordPress. It has been rated as critical. Affected by this issue is the function hd_add_media/hd_update_media of the file functions.php. The manipulation of the argument name leads to sql injection. The attack may be launched remotely. Upgrading to version 1.8 is able to address this issue. The patch is identified as 34d66b9f3231a0e2dc0e536a6fe615d736e863f7. It is recommended to upgrade the affected component. VDB-225350 is the identifier assigned to this vulnerability.

CVE-2023-27602CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recommend users upgrade the version of Linkis to version 1.3.2.  For versions <=1.3.1, we suggest turning on the file path check switch in linkis.properties `wds.linkis.workspace.filesystem.owner.check=true` `wds.linkis.workspace.filesystem.path.check=true`

CVE-2023-27603CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead to a potential RCE vulnerability. We recommend users upgrade the version of Linkis to version 1.3.2.

CVE-2023-29215CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC EengineConn Module will trigger a deserialization vulnerability and eventually lead to remote code execution. Therefore, the parameters in the Mysql JDBC URL should be blacklisted. Versions of Apache Linkis <= 1.3.0 will be affected. We recommend users upgrade the version of Linkis to version 1.3.2.

CVE-2023-29216CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

In Apache Linkis <=1.3.1, because the parameters are not effectively filtered, the attacker uses the MySQL data source and malicious parameters to configure a new data source to trigger a deserialization vulnerability, eventually leading to remote code execution. Versions of Apache Linkis <= 1.3.0 will be affected. We recommend users upgrade the version of Linkis to version 1.3.2.

CVE-2015-10099CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability classified as critical has been found in CP Appointment Calendar Plugin up to 1.1.5 on WordPress. This affects the function dex_process_ready_to_go_appointment of the file dex_appointments.php. The manipulation of the argument itemnumber leads to sql injection. It is possible to initiate the attack remotely. The patch is named e29a9cdbcb0f37d887dd302a05b9e8bf213da01d. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-225351.

CVE-2023-1478CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the page cache module.

CVE-2023-29375CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potentially dangerous file upload through the SharePoint connector.

CVE-2023-1969CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects unknown code of the file /admin/inventory/manage_stock.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-225406 is the identifier assigned to this vulnerability.

CVE-2023-27650CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue found in APUS Group Launcher v.3.10.73 and v.3.10.88 allows a remote attacker to execute arbitrary code via the FONT_FILE parameter.

CVE-2015-10100CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability, which was classified as critical, has been found in Dynamic Widgets Plugin up to 1.5.10 on WordPress. This issue affects some unknown processing of the file classes/dynwid_class.php. The manipulation leads to sql injection. The attack may be initiated remotely. Upgrading to version 1.5.11 is able to address this issue. The identifier of the patch is d0a19c6efcdc86d7093b369bc9e29a0629e57795. It is recommended to upgrade the affected component. The identifier VDB-225353 was assigned to this vulnerability.

CVE-2022-46709CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, iOS 16. An app may be able to execute arbitrary code with kernel privileges

CVE-2023-26063CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-843

Certain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type.

CVE-2023-26064CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.

CVE-2023-26065CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

Certain Lexmark devices through 2023-02-19 have an Integer Overflow.

CVE-2023-26066CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-129

Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.

CVE-2023-26068CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).

CVE-2023-26069CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4).

CVE-2023-26070CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).

CVE-2023-27178CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

An arbitrary file upload vulnerability in the upload function of GDidees CMS 3.9.1 allows attackers to execute arbitrary code via a crafted file.

CVE-2023-27497CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - version 720, allows an attacker to execute malicious scripts on all connected Diagnostics Agents running on Windows. On successful exploitation, the attacker can completely compromise confidentiality, integrity and availability of the system.

CVE-2023-28765CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-200

An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to lcmbiar file and further decrypt the file. After this attacker can gain access to BI user’s passwords and depending on the privileges of the BI user, the attacker can perform operations that can completely compromise the application.

CVE-2023-28489CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). Affected devices are vulnerable to command injection via the web server port 443/tcp, if the parameter “Remote Operation” is enabled. The parameter is disabled by default. The vulnerability could allow an unauthenticated remote attacker to perform arbitrary code execution on the device.

CVE-2023-27645CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue found in POWERAMP audioplayer build 925 bundle play and build 954 allows a remote attacker to gain privileges via the reverb and EQ preset parameters.

CVE-2023-27192CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the key_wifi_safe_net_check_url, KEY_Cirus_scan_whitelist and KEY_AD_NEW_USER_AVOID_TIME parameters.

CVE-2022-41331CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests.

CVE-2023-1983CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/products/manage_product.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-225530 is the identifier assigned to this vulnerability.

CVE-2020-19802CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

File Upload vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the upload file type parameter.

CVE-2023-1984CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability classified as critical was found in SourceCodester Complaint Management System 1.0. This vulnerability affects unknown code of the file /users/check_availability.php of the component POST Parameter Handler. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-225532.

CVE-2023-21554CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

CVE-2023-28250CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-191

Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

CVE-2023-28808CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-284

Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices.

CVE-2023-29799CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.

CVE-2023-29800CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.

CVE-2022-25678CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Memory correction in modem due to buffer overwrite during coap connection

CVE-2022-25740CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Memory corruption in modem due to buffer overwrite while building an IPv6 multicast address based on the MAC address of the iface

CVE-2022-25745CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-670

Memory corruption in modem due to improper input validation while handling the incoming CoAP message

CVE-2022-33211CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

memory corruption in modem due to improper check while calculating size of serialized CoAP message

CVE-2023-27779CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via the user parameter in the login form.

CVE-2022-33259CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Memory corruption due to buffer copy without checking the size of input in modem while decoding raw SMS received.

CVE-2023-29598CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

lmxcms v1.4.1 was discovered to contain a SQL injection vulnerability via the setbook parameter at index.php.

CVE-2023-27667CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Auto Dealer Management System v1.0 was discovered to contain a SQL injection vulnerability.

CVE-2023-27746CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

BlackVue DR750-2CH LTE v.1.012_2022.10.26 was discovered to contain a weak default passphrase which can be easily cracked via a brute force attack if the WPA2 handshake is intercepted.

CVE-2023-29798CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg function.

← PreviousPage 492 / 7034Next →