CVE Database

CVE-2023-37214CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025.

CVE-2023-37215CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

JBL soundbar multibeam 5.1 - CWE-798: Use of Hard-coded Credentials

CVE-2023-4005CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-613

Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5.

CVE-2023-4006CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1236

Improper Neutralization of Formula Elements in a CSV File in GitHub repository thorsten/phpmyfaq prior to 3.1.16.

CVE-2023-35861CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute arbitrary commands as root on the BMC.

CVE-2023-37647CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.

CVE-2020-21662CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in yunyecms 2.0.2 allows remote attackers to run arbitrary SQL commands via XFF.

CVE-2023-34644CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW_3.0(1)B11P204, RG-NBS and RG-S1930 series switches SWITCH_3.0(1)B11P218, RG-EG series business VPN routers EG_3.0(1)B11P216, EAP and RAP series wireless access points AP_3.0(1)B11P218, NBC series wireless controllers AC_3.0(1)B11P86 allows unauthorized remote attackers to gain the highest privileges via crafted POST request to /cgi-bin/luci/api/auth.

CVE-2023-34842CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php.

CVE-2023-36089CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-863

Authentication Bypass vulnerability in D-Link DIR-645 firmware version 1.03 allows remote attackers to gain escalated privileges via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-36090CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-863

Authentication Bypass vulnerability in D-Link DIR-885L FW102b01 allows remote attackers to gain escalated privileges via phpcgi. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-36091CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-863

Authentication Bypass vulnerability in D-Link DIR-895 FW102b07 allows remote attackers to gain escalated privileges via via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-36092CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-863

Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via via phpcgi_main. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-39122CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. This is fixed in 9.0.21 (and is also fixed by a patch for 9.0.20.200).

CVE-2023-37478CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-284

pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry is safe, but when installed via pnpm is malicious, due to how pnpm parses tar archives. This can result in a package that appears safe on the npm registry or when installed via npm being replaced with a compromised or malicious version when installed via pnpm. This issue has been patched in version(s) 7.33.4 and 8.6.8.

CVE-2023-31710CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TP-Link Archer AX21(US)_V3_1.1.4 Build 20230219 and AX21(US)_V3.6_1.1.4 Build 20230219 are vulnerable to Buffer Overflow.

CVE-2023-4056CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVE-2023-4057CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Memory safety bugs present in Firefox 115, Firefox ESR 115.0, and Thunderbird 115.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116, Firefox ESR < 115.1, and Thunderbird < 115.1.

CVE-2023-4058CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Memory safety bugs present in Firefox 115. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116.

CVE-2023-33493CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

An Unrestricted Upload of File with Dangerous Type vulnerability in the Ajaxmanager File and Database explorer (ajaxmanager) module for PrestaShop through 2.3.0, allows remote attackers to upload dangerous files without restrictions.

CVE-2023-36210CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter.

CVE-2023-33561CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Improper input validation of password parameter in PHP Jabbers Time Slots Booking Calendar v 3.3 results in insecure passwords.

CVE-2023-33562CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

User enumeration is found in in PHP Jabbers Time Slots Booking Calendar v3.3. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVE-2023-26443CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitization in place, this can be abused to trigger benign SQL Exceptions but could potentially be escalated to a malicious SQL injection vulnerability. We now properly encode single quotes for SQL FULLTEXT queries. No publicly available exploits are known.

CVE-2023-26317CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external interfaces. Attackers can exploit this vulnerability to gain access to the router by hijacking the ISP or upper-layer routing.

CVE-2022-40609CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. By sending specially-crafted data, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 236069.

CVE-2023-1437CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-822

All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the remote file system and the ability to execute commands and overwrite files.

CVE-2023-33371CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication.

CVE-2023-36082CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-522

An isssue in GatesAIr Flexiva FM Transmitter/Exiter Fax 150W allows a remote attacker to gain privileges via the LDAP and SMTP credentials.

CVE-2023-21408CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-755

Due to insufficient file permissions, unprivileged users could gain access to unencrypted user credentials that are used in the integration interface towards 3rd party systems.

CVE-2023-38954CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability.

CVE-2023-21409CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-755

Due to insufficient file permissions, unprivileged users could gain access to unencrypted administrator credentials allowing the configuration of the application.

CVE-2023-3346CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in MITSUBSHI CNC Series allows a remote unauthenticated attacker to cause Denial of Service (DoS) condition and execute arbitrary code on the product by sending specially crafted packets. In addition, system reset is required for recovery.

CVE-2023-4008CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-708

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to takeover GitLab Pages with unique domain URLs if the random string added was known.

CVE-2023-4120CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230722 and classified as critical. This issue affects some unknown processing of the file importhtml.php. The manipulation of the argument sql leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235967. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-4121CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230722. It has been classified as critical. Affected is an unknown function. The manipulation of the argument file_upload leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235968. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-36213CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in MotoCMS v.3.4.3 allows a remote attacker to gain privileges via the keyword parameter of the search function.

CVE-2023-38942CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Dango-Translator v4.5.5 was discovered to contain a remote command execution (RCE) vulnerability via the component app/config/cloud_config.json.

CVE-2023-33666CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

ai-dev aioptimizedcombinations before v0.1.3 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php.

CVE-2023-41109KEVCRITICALin_the_wild
CVSS 9.8
EPSS
Priority 0

SmartNode SN200 (aka SN200) 3.21.2-23021 allows unauthenticated OS Command Injection.

CVE-2023-33665CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

ai-dev aitable before v0.2.2 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php.

CVE-2023-36131CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation of password parameter.

CVE-2023-36132CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control.

CVE-2023-36133CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change.

CVE-2023-36134CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-345

In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.

CVE-2023-36139CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-345

In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.

CVE-2023-38941CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

django-sspanel v2022.2.2 was discovered to contain a remote command execution (RCE) vulnerability via the component sspanel/admin_view.py -> GoodsCreateView._post.

CVE-2023-36480CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

The Aerospike Java client is a Java application that implements a network protocol to communicate with an Aerospike server. Prior to versions 7.0.0, 6.2.0, 5.2.0, and 4.5.0 some of the messages received from the server contain Java objects that the client deserializes when it encounters them without further validation. Attackers that manage to trick clients into communicating with a malicious server can include especially crafted objects in its responses that, once deserialized by the client, force it to execute arbitrary code. This can be abused to take control of the machine the client is running on. Versions 7.0.0, 6.2.0, 5.2.0, and 4.5.0 contain a patch for this issue.

CVE-2023-33373CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-312

Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and use them to impersonate the devices.

CVE-2023-37470CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3, 1.45.4.3, and 1.46.6.4, a vulnerability could potentially allow remote code execution on one's Metabase server. The core issue is that one of the supported data warehouses (an embedded in-memory database H2), exposes a number of ways for a connection string to include code that is then executed by the process running the embedded database. Because Metabase allows users to connect to databases, this means that a user supplied string can be used to inject executable code. Metabase allows users to validate their connection string before adding a database (including on setup), and this validation API was the primary vector used as it can be called without validation. Versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3, 1.45.4.3, and 1.46.6.4 fix this issue by removing the ability of users to add H2 databases entirely. As a workaround, it is possible to block these vulnerabilities at the network level by blocking the endpoints `POST /api/database`, `PUT /api/database/:id`, and `POST /api/setup/validateuntil`. Those who use H2 as a file-based database should migrate to SQLite.

← PreviousPage 512 / 7034Next →