CVE Database

CVE-2020-22151CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests parameter of the upload function.

CVE-2020-22597CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue in Jerrscript- project Jerryscrip v. 2.3.0 allows a remote attacker to execute arbitrary code via the ecma_builtin_array_prototype_object_slice parameter.

CVE-2023-36258CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue in LangChain before 0.0.236 allows an attacker to execute arbitrary code because Python code with os.system, exec, or eval can be used.

CVE-2023-30990CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL commands as QUSER, caused by an exploitation of DDM architecture. IBM X-Force ID: 254036.

CVE-2023-21631CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network.

CVE-2023-3504CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

A vulnerability was found in SmartWeb Infotech Job Board 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /settings/account of the component My Profile Page. The manipulation of the argument filename leads to unrestricted upload. The attack may be launched remotely. The identifier of this vulnerability is VDB-232952. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2021-46890CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-863

Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.

CVE-2021-46891CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-200

Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.

CVE-2023-36665CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

"protobuf.js (aka protobufjs) 6.10.0 through 7.x before 7.2.5 allows Prototype Pollution, a different vulnerability than CVE-2022-25878. A user-controlled protobuf message can be used by an attacker to pollute the prototype of Object.prototype by adding and overwriting its data and functions. Exploitation can involve: (1) using the function parse to parse protobuf messages on the fly, (2) loading .proto files by using load/loadSync functions, or (3) providing untrusted input to the functions ReflectionObject.setParsedOption and util.setProperty.

CVE-2020-25969CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

gnuplot v5.5 was discovered to contain a buffer overflow via the function plotrequest().

CVE-2023-34338CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-321

AMI SPx contains a vulnerability in the BMC where an Attacker may cause a use of hard-coded cryptographic key by a hard-coded certificate. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability. 

CVE-2023-35924CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.8, GLPI inventory endpoint can be used to drive a SQL injection attack. By default, GLPI inventory endpoint requires no authentication. Version 10.0.8 has a patch for this issue. As a workaround, one may disable native inventory.

CVE-2023-36808CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.8, Computer Virtual Machine form and GLPI inventory request can be used to perform a SQL injection attack. Version 10.0.8 has a patch for this issue. As a workaround, one may disable native inventory.

CVE-2022-46080CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-863

Nexxt Nebula 1200-AC 15.03.06.60 allows authentication bypass and command execution by using the HTTPD service to enable TELNET.

CVE-2021-46894CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-269

Use After Free (UAF) vulnerability in the uinput module.Successful exploitation of this vulnerability may lead to kernel privilege escalation.

CVE-2022-48510CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-200

Input verification vulnerability in the AMS module. Successful exploitation of this vulnerability will cause unauthorized operations.

CVE-2022-48511CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-843

Use After Free (UAF) vulnerability in the audio PCM driver module under special conditions. Successful exploitation of this vulnerability may cause audio features to perform abnormally.

CVE-2022-48512CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

Use After Free (UAF) vulnerability in the Vdecoderservice service. Successful exploitation of this vulnerability may cause the image decoding feature to perform abnormally.

CVE-2022-48513CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-290

Vulnerability of identity verification being bypassed in the Gallery module. Successful exploitation of this vulnerability may cause out-of-bounds access.

CVE-2023-37242CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-639

Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnerability to rewrite the non-volatile random-access memory (NVRAM), or facilitate the exploitation of other vulnerabilities.

CVE-2020-22336CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered in pdfcrack 0.17 thru 0.18, allows attackers to execute arbitrary code via a stack overflow in the MD5 function.

CVE-2023-36188CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

An issue in langchain v.0.0.64 allows a remote attacker to execute arbitrary code via the PALChain parameter in the Python exec method.

CVE-2023-22319CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A sql injection vulnerability exists in the requestHandlers.js LoginAuth functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to authentication bypass. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2023-22844CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-321

An authentication bypass vulnerability exists in the requestHandlers.js verifyToken functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to authentication bypass. An attacker can send a network request to trigger this vulnerability.

CVE-2023-23902CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

A buffer overflow vulnerability exists in the uhttpd login functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to remote code execution. An attacker can send a network request to trigger this vulnerability.

CVE-2023-29381CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate privileges and obtain sensitive information via the password and 2FA parameters.

CVE-2023-29382CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue in Zimbra Collaboration ZCS v.8.8.15 and v.9.0 allows an attacker to execute arbitrary code via the sfdc_preauth.jsp component.

CVE-2023-3528CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in ThinuTech ThinuCMS 1.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file /category.php. The manipulation of the argument cat_id leads to sql injection. The attack may be launched remotely. The identifier of this vulnerability is VDB-233252.

CVE-2023-29824CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

A use-after-free issue was discovered in Py_FindObjects() function in SciPy versions prior to 1.8.0. NOTE: the vendor and discoverer indicate that this is not a security issue.

CVE-2023-33868CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

The number of login attempts is not limited. This could allow an attacker to perform a brute force on HTTP basic authentication.

CVE-2023-35987CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

PiiGAB M-Bus contains hard-coded credentials which it uses for authentication.

CVE-2023-36859CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

PiiGAB M-Bus SoftwarePack 900S does not correctly sanitize user input, which could allow an attacker to inject arbitrary commands.

CVE-2023-34433CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-916

PiiGAB M-Bus stores passwords using a weak hash algorithm.

CVE-2023-34995CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-521

There are no requirements for setting a complex password for PiiGAB M-Bus, which could contribute to a successful brute force attack if the password is inline with recommended password guidelines.

CVE-2023-37144CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Tenda AC10 v15.03.06.26 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.

CVE-2023-37145CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.

CVE-2023-37146CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.

CVE-2023-37148CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the ussd parameter in the setUssd function.

CVE-2023-37149CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadSetting function.

CVE-2023-27845CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability found in PrestaShop lekerawen_ocs before v.1.4.1 allow a remote attacker to gain privileges via the KerawenHelper::setCartOperationInfo, and KerawenHelper::resetCheckoutSessionData components.

CVE-2023-36993CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-338

The cryptographically insecure random number generator being used in TravianZ 8.3.4 and 8.3.3 in the password reset function allows an attacker to guess the password reset.parameters and to take over accounts.

CVE-2023-36994CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-863

In TravianZ 8.3.4 and 8.3.3, Incorrect Access Control in the installation script allows an attacker to overwrite the server configuration and inject PHP code.

CVE-2023-37170CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.

CVE-2023-37171CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg function.

CVE-2023-37172CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function.

CVE-2023-37173CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg function.

CVE-2023-37286CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code and disrupt service.

CVE-2023-2046CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yontem Informatics Vehicle Tracking System allows SQL Injection. This issue affects Vehicle Tracking System: before 8.

CVE-2023-2852CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Softmed SelfPatron allows SQL Injection. This issue affects SelfPatron : before 2.0.

CVE-2023-37152CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page. Note: This has been disputed as not a valid vulnerability.

← PreviousPage 507 / 7034Next →