CVE Database

CVE-2023-40163CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An out-of-bounds write vulnerability exists in the allocate_buffer_for_jpeg_decoding functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-43141CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control.

CVE-2023-4521CRITICALnone
CVSS 9.8
EPSS
Priority 0

The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue (https://wpscan.com/vulnerability/d4220025-2272-4d5f-9703-4b2ac4a51c42) and not deleting the created files when releasing the new version.

CVE-2023-39640CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

UpLight cookiebanner before 1.5.1 was discovered to contain a SQL injection vulnerability via the component Hook::getHookModuleExecList().

CVE-2023-43644CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

Sing-box is an open source proxy system. Affected versions are subject to an authentication bypass when specially crafted requests are sent to sing-box. This affects all SOCKS5 inbounds with user authentication and an attacker may be able to bypass authentication. Users are advised to update to sing-box 1.4.4 or to 1.5.0-rc.4. Users unable to update should not expose the SOCKS5 inbound to insecure environments.

CVE-2023-43457CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/admin/?page=user/ endpoint.

CVE-2021-38243CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

xunruicms up to v4.5.1 was discovered to contain a remote code execution (RCE) vulnerability in /index.php. This vulnerability allows attackers to execute arbitrary code via a crafted GET request.

CVE-2023-42580CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

Improper URL validation from MCSLaunch deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to install APK from Galaxy Store.

CVE-2023-35071CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MRV Tech Logging Administration Panel allows SQL Injection. This issue affects Logging Administration Panel: before 20230915 .

CVE-2023-3767CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An OS command injection vulnerability has been found on EasyPHP Webserver affecting version 14.1. This vulnerability could allow an attacker to get full access to the system by sending a specially crafted exploit to the /index.php?zone=settings parameter.

CVE-2023-39375CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-274

SiberianCMS - CWE-274: Improper Handling of Insufficient Privileges

CVE-2023-40400CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

This issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. A remote user may cause an unexpected app termination or arbitrary code execution.

CVE-2023-43291CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Deserialization of Untrusted Data in emlog pro v.2.1.15 and earlier allows a remote attacker to execute arbitrary code via the cache.php component.

CVE-2023-41320CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. UI layout preferences management can be hijacked to lead to SQL injection. This injection can be use to takeover an administrator account. Users are advised to upgrade to version 10.0.10. There are no known workarounds for this vulnerability.

CVE-2023-41878CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

MeterSphere is a one-stop open source continuous testing platform, covering functions such as test tracking, interface testing, UI testing and performance testing. The Selenium VNC config used in Metersphere is using a weak password by default, attackers can login to vnc and obtain high permissions. This issue has been addressed in version 2.10.7 LTS. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2023-42461CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. The ITIL actors input field from the Ticket form can be used to perform a SQL injection. Users are advised to upgrade to version 10.0.10. There are no known workarounds for this vulnerability.

CVE-2023-43154CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-843

In Macrob7 Macs Framework Content Management System (CMS) 1.1.4f, loose comparison in "isValidLogin()" function during login attempt results in PHP type confusion vulnerability that leads to authentication bypass and takeover of the administrator account.

CVE-2023-43187CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-91

A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted XML-RPC requests.

CVE-2023-43216CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.

CVE-2023-43222CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.

CVE-2023-43234CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

DedeBIZ v6.2.11 was discovered to contain multiple remote code execution (RCE) vulnerabilities at /admin/file_manage_control.php via the $activepath and $filename parameters.

CVE-2023-44013CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the list parameter in the fromSetIpMacBind function.

CVE-2023-44014CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain multiple stack overflows in the formSetMacFilterCfg function via the macFilterType and deviceList parameters.

CVE-2023-44015CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the schedEndTime parameter in the setSchedWifi function.

CVE-2023-44016CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function.

CVE-2023-44017CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the timeZone parameter in the fromSetSysTime function.

CVE-2023-44018CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the domain parameter in the add_white_node function.

CVE-2023-44019CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the mac parameter in the GetParentControlInfo function.

CVE-2023-44020CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the security parameter in the formWifiBasicSet function.

CVE-2023-44021CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the formSetClientState function.

CVE-2023-44022CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.

CVE-2023-44023CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.

CVE-2023-44171CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php.

CVE-2023-44169CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php.

CVE-2023-44170CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php.

CVE-2023-4737CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hedef Tracking Admin Panel allows SQL Injection. This issue affects Admin Panel: before 1.2.

CVE-2023-5168CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVE-2023-5172CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

A hashtable in the Ion Engine could have been mutated while there was a live interior reference, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 118.

CVE-2023-5174CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free and a potentially exploitable crash. *This bug only affects Firefox on Windows when run in non-standard configurations (such as using `runas`). Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVE-2023-5175CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

During process shutdown, it was possible that an `ImageBitmap` was created that would later be used after being freed from a different codepath, leading to a potentially exploitable crash. This vulnerability affects Firefox < 118.

CVE-2023-5176CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVE-2023-5221CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

A vulnerability classified as critical has been found in ForU CMS. This affects an unknown part of the file /install/index.php. The manipulation of the argument db_name leads to code injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The associated identifier of this vulnerability is VDB-240363. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-20252CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-862

A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could allow an unauthenticated, remote attacker to gain unauthorized access to the application as an arbitrary user. This vulnerability is due to improper authentication checks for SAML APIs. An attacker could exploit this vulnerability by sending requests directly to the SAML API. A successful exploit could allow the attacker to generate an authorization token sufficient to gain access to the application.

CVE-2023-42818CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

JumpServer is an open source bastion host. When users enable MFA and use a public key for authentication, the Koko SSH server does not verify the corresponding SSH private key. An attacker could exploit a vulnerability by utilizing a disclosed public key to attempt brute-force authentication against the SSH service This issue has been patched in versions 3.6.5 and 3.5.6. Users are advised to upgrade. There are no known workarounds for this issue.

CVE-2023-44080CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue in PGYER codefever v.2023.8.14-2ce4006 allows a remote attacker to execute arbitrary code via a crafted request to the branchList component.

CVE-2023-41449CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-918

An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.

CVE-2023-38870CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A SQL injection vulnerability exists in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1. The cash book has a feature to list accomplishments by category, and the 'category_id' parameter is vulnerable to SQL Injection.

CVE-2023-44273CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA signatures does not ensure that the data is in a certain interval.

CVE-2023-43869CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWAN_Wizard56 function.

CVE-2023-30415CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Sourcecodester Packers and Movers Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /inquiries/view_inquiry.php.

← PreviousPage 524 / 7034Next →