CVE Database

CVE-2023-27971CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Elevation of Privilege.

CVE-2023-27972CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Remote Code Execution.

CVE-2023-27973CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Certain HP LaserJet Pro print products are potentially vulnerable to Heap Overflow and/or Remote Code Execution.

CVE-2023-26781CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search.

CVE-2023-1966CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-250

Instruments with Illumina Universal Copy Service v1.x and v2.x contain an unnecessary privileges vulnerability. An unauthenticated malicious actor could upload and execute code remotely at the operating system level, which could allow an attacker to change settings, configurations, software, or access sensitive data on the affected product.

CVE-2021-46887CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

Lack of length check vulnerability in the HW_KEYMASTER module. Successful exploitation of this vulnerability may cause out-of-bounds read.

CVE-2023-26813CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in com.xnx3.wangmarket.plugin.dataDictionary.controller.DataDictionaryPluginController.java in wangmarket CMS 4.10 allows remote attackers to run arbitrary SQL commands via the TableName parameter to /plugin/dataDictionary/tableView.do.

CVE-2023-31470CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

SmartDNS through 41 before 56d0332 allows an out-of-bounds write because of a stack-based buffer overflow in the _dns_encode_domain function in the dns.c file, via a crafted DNS request.

CVE-2023-2420CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in MLECMS 3.0. It has been rated as critical. This issue affects the function get_url in the library /upload/inc/lib/admin of the file upload\inc\include\common.func.php. The manipulation of the argument $_SERVER['REQUEST_URI'] leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227717 was assigned to this vulnerability.

CVE-2023-2429CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-284

Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.13.

CVE-2015-10105CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

A vulnerability, which was classified as critical, was found in IP Blacklist Cloud Plugin up to 3.42 on WordPress. This affects the function valid_js_identifier of the file ip_blacklist_cloud.php of the component CSV File Import. The manipulation of the argument filename leads to path traversal. It is possible to initiate the attack remotely. Upgrading to version 3.43 is able to address this issue. The identifier of the patch is 6e6fe8c6fda7cbc252eef083105e08d759c07312. It is recommended to upgrade the affected component. The identifier VDB-227757 was assigned to this vulnerability.

CVE-2023-30859CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-419

Triton is a Minecraft plugin for Spigot and BungeeCord that helps you translate your Minecraft server. The CustomPayload packet allows you to execute commands on the spigot/bukkit console. When you enable bungee mode in the config it will enable the bungee bridge and the server will begin to broadcast the 'triton:main' plugin channel. Using this plugin channel you are able to send a payload packet containing a byte (2) and a string (any spigot command). This could be used to make yourself a server operator and be used to extract other user information through phishing (pretending to be an admin), many servers use essentials so the /geoip command could be available to them, etc. This could also be modified to allow you to set the servers language, set another players language, etc. This issue affects those who have bungee enabled in config. This issue has been fixed in version 3.8.4.

CVE-2022-45802CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later

CVE-2023-29635CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

File upload vulnerability in Antabot White-Jotter v0.2.2, allows remote attackers to execute malicious code via the file parameter to function coversUpload.

CVE-2023-2451CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in SourceCodester Online DJ Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/bookings/view_details.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227795.

CVE-2022-35898CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows any authenticated user to change the password of any other user, including the Administrator account.

CVE-2023-1730CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks

CVE-2023-29856CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

D-Link DIR-868L Hardware version A1, firmware version 1.12 is vulnerable to Buffer Overflow. The vulnerability is in scandir.sgi binary.

CVE-2023-2479CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

OS Command Injection in GitHub repository appium/appium-desktop prior to v1.22.3-4.

CVE-2023-26089CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5.

CVE-2023-29778CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.

CVE-2023-30135CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Tenda AC18 v15.03.05.19(6318_)_cn was discovered to contain a command injection vulnerability via the deviceName parameter in the setUsbUnload function.

CVE-2023-25826CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameters and execute malicious code on the OpenTSDB host system. This exploit exists due to an incomplete fix that was made when this vulnerability was previously disclosed as CVE-2020-35476. Regex validation that was implemented to restrict allowed input to the query API does not work as intended, allowing crafted commands to bypass validation.

CVE-2023-30204CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the judge_id parameter at /php-jms/edit_judge.php.

CVE-2022-47757CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

In imo.im 2022.11.1051, a path traversal vulnerability delivered via an unsanitized deeplink can force the application to write a file into the application's data directory. This may allow an attacker to save a shared library under a special directory which the app uses to dynamically load modules. Loading the library can lead to arbitrary code execution.

CVE-2023-30077CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Judging Management System v1.0 by oretnom23 was discovered to vulnerable to SQL injection via /php-jms/review_result.php?mainevent_id=, mainevent_id.

CVE-2023-30331CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

An issue in the render function of beetl v3.15.0 allows attackers to execute server-side template injection (SSTI) via a crafted payload.

CVE-2023-2524CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-425

A vulnerability classified as critical has been found in Control iD RHiD 23.3.19.0. This affects an unknown part of the file /v2/#/. The manipulation leads to direct request. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-228015. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-29827CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter. NOTE: this is disputed by the vendor because the render function is not intended to be used with untrusted input.

CVE-2023-2519CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability has been found in Caton CTP Relay Server 1.2.9 and classified as critical. This vulnerability affects unknown code of the file /server/api/v1/login of the component API. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. VDB-228010 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-2520CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

A vulnerability was found in Caton Prime 2.1.2.51.e8d7225049(202303031001) and classified as critical. This issue affects some unknown processing of the file cgi-bin/tools_ping.cgi?action=Command of the component Ping Handler. The manipulation of the argument Destination leads to command injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-228011. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-30203CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the event_id parameter at /php-jms/result_sheet.php.

CVE-2023-20126CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to a missing authentication process within the firmware upgrade function. An attacker could exploit this vulnerability by upgrading an affected device to a crafted version of firmware. A successful exploit could allow the attacker to execute arbitrary code on the affected device with full privileges. Cisco has not released firmware updates to address this vulnerability.

CVE-2023-23059CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-276

An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions within the default installation and allows attackers to execute arbitrary code and gain escalated privileges.

CVE-2023-30264CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via application/admin/controller/Template.php:update.

CVE-2023-30268CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

CLTPHP <=6.0 is vulnerable to Improper Input Validation.

CVE-2023-21494CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Potential buffer overflow vulnerability in auth api in mm_Authentication.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.

CVE-2023-21503CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Potential buffer overflow vulnerability in mm_LteInterRatManagement.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.

CVE-2023-21504CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Potential buffer overflow vulnerability in mm_Plmncoordination.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.

CVE-2023-30328CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

An issue in the helper tool of Mailbutler GmbH Shimo VPN Client for macOS v5.0.4 allows attackers to bypass authentication via PID re-use.

CVE-2023-2531CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

Improper Restriction of Excessive Authentication Attempts in GitHub repository azuracast/azuracast prior to 0.18.3.

CVE-2023-30122CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

An arbitrary file upload vulnerability in the component /admin/ajax.php?action=save_menu of Online Food Ordering System v2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

CVE-2023-30013CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter.

CVE-2023-30053CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

TOTOLINK A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection.

CVE-2023-30054CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

TOTOLINK A7100RU V7.4cu.2313_B20191024 has a Command Injection vulnerability. An attacker can obtain a stable root shell through a specially constructed payload.

CVE-2016-15031CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in PHP-Login 1.0. It has been declared as critical. This vulnerability affects the function checkLogin of the file login/scripts/class.loginscript.php of the component POST Parameter Handler. The manipulation of the argument myusername leads to sql injection. The attack can be initiated remotely. Upgrading to version 2.0 is able to address this issue. The patch is identified as 0083ec652786ddbb81335ea20da590df40035679. It is recommended to upgrade the affected component. VDB-228022 is the identifier assigned to this vulnerability.

CVE-2023-31047CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.

CVE-2023-29944CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Metersphere v1.20.20-lts-79d354a6 is vulnerable to Remote Command Execution. The system command reverse-shell can be executed at the custom code snippet function of the metersphere system workbench

CVE-2023-30185CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.

CVE-2023-30018CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Judging Management System v1.0 is vulnerable to SQL Injection. via /php-jms/review_se_result.php?mainevent_id=.

← PreviousPage 496 / 7034Next →