CVE Database

CVE-2023-43013CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Asset Management System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'email' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control.

CVE-2023-5004CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI.

CVE-2023-5053CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI.

CVE-2023-43739CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The 'bookisbn' parameter of the cart.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-44163CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The 'search' parameter of the process_search.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-44164CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The 'Email' parameter of the process_login.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-44166CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The 'age' parameter of the process_registration.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-5258CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability classified as critical has been found in OpenRapid RapidCMS 1.3.1. This affects an unknown part of the file /resource/addgood.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240867.

CVE-2023-5260CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability, which was classified as critical, has been found in SourceCodester Simple Membership System 1.0. This issue affects some unknown processing of the file group_validator.php. The manipulation of the argument club_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240869 was assigned to this vulnerability.

CVE-2023-5261CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability, which was classified as critical, was found in Tongda OA 2017. Affected is an unknown function of the file general/hr/manage/staff_title_evaluation/delete.php. The manipulation of the argument EVALUATION_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. VDB-240870 is the identifier assigned to this vulnerability.

CVE-2023-5288CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-284

A remote unauthorized attacker may connect to the SIM1012, interact with the device and change configuration settings. The adversary may also reset the SIM and in the worst case upload a new firmware version to the device.

CVE-2023-5265CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability, which was classified as critical, has been found in Tongda OA 2017. Affected by this issue is some unknown functionality of the file general/hr/manage/staff_transfer/delete.php. The manipulation of the argument TRANSFER_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. VDB-240878 is the identifier assigned to this vulnerability.

CVE-2023-5267CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability has been found in Tongda OA 2017 and classified as critical. This vulnerability affects unknown code of the file general/hr/recruit/hr_pool/delete.php. The manipulation of the argument EXPERT_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-240880.

CVE-2023-5276CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability classified as critical was found in SourceCodester Engineers Online Portal 1.0. This vulnerability affects unknown code of the file downloadable_student.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The identifier of this vulnerability is VDB-240904.

CVE-2023-5277CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

A vulnerability, which was classified as critical, has been found in SourceCodester Engineers Online Portal 1.0. This issue affects some unknown processing of the file student_avatar.php. The manipulation of the argument change leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240905 was assigned to this vulnerability.

CVE-2023-5278CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability, which was classified as critical, was found in SourceCodester Engineers Online Portal 1.0. Affected is an unknown function of the file login.php. The manipulation of the argument username/password leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-240906 is the identifier assigned to this vulnerability.

CVE-2023-5279CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability has been found in SourceCodester Engineers Online Portal 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file my_classmates.php. The manipulation of the argument teacher_class_student_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240907.

CVE-2023-5280CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in SourceCodester Engineers Online Portal 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file my_students.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240908.

CVE-2023-5281CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been classified as critical. This affects an unknown part of the file remove_inbox_message.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240909 was assigned to this vulnerability.

CVE-2023-5282CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been declared as critical. This vulnerability affects unknown code of the file seed_message_student.php. The manipulation of the argument teacher_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-240910 is the identifier assigned to this vulnerability.

CVE-2023-5227CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Unrestricted Upload of File with Dangerous Type in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

CVE-2023-5300CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability classified as critical has been found in TTSPlanning up to 20230925. This affects an unknown part. The manipulation of the argument uid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240939.

CVE-2023-20819CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

In CDMA PPP protocol, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: MOLY01068234; Issue ID: ALPS08010003.

CVE-2015-10124CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in Most Popular Posts Widget Plugin up to 0.8 on WordPress. It has been classified as critical. Affected is the function add_views/show_views of the file functions.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. Upgrading to version 0.9 is able to address this issue. The patch is identified as a99667d11ac8d320006909387b100e9a8b5c12e1. It is recommended to upgrade the affected component. VDB-241026 is the identifier assigned to this vulnerability.

CVE-2023-4659CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-352

Cross-Site Request Forgery vulnerability, whose exploitation could allow an attacker to perform different actions on the platform as an administrator, simply by changing the token value to "admin". It is also possible to perform POST, GET and DELETE requests without any token value. Therefore, an unprivileged remote user is able to create, delete and modify users within theapplication.

CVE-2023-44008CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function.

CVE-2023-44009CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function.

CVE-2023-43891CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password function. This vulnerability is exploited via a crafted payload.

CVE-2023-43892CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the Hostname parameter within the WAN settings. This vulnerability is exploited via a crafted payload.

CVE-2023-43893CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeup_mac parameter in the Wake-On-LAN (WoL) function. This vulnerability is exploited via a crafted payload.

CVE-2023-44011CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.master skin file at the Skin management component.

CVE-2023-43980CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Presto Changeo testsitecreator up to v1.1.1 was discovered to contain a SQL injection vulnerability via the component disable_json.php.

CVE-2023-22385CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-126

Memory Corruption in Data Modem while making a MO call or MT VOLTE call.

CVE-2023-24855CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-823

Memory corruption in Modem while processing security related configuration before AS Security Exchange.

CVE-2023-33028CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.

CVE-2023-3656CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by an unauthenticated remote code execution vulnerability. This vulnerability can be triggered by an HTTP endpoint exposed to the network.

CVE-2023-3654CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-346

cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by a origin bypass via the host header in an HTTP request. This vulnerability can be triggered by an HTTP endpoint exposed to the network.

CVE-2022-47893CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

There is a remote code execution vulnerability that affects all versions of NetMan 204. A remote attacker could upload a firmware file containing a webshell, that could allow him to execute arbitrary code as root.

CVE-2023-47397CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.

CVE-2023-40830CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Tenda AC6 v15.03.05.19 is vulnerable to Buffer Overflow as the Index parameter does not verify the length.

CVE-2023-33268CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An issue was discovered in DTS Monitoring 3.57.0. The parameter port within the SSL Certificate check function is vulnerable to OS command injection (blind).

CVE-2023-33269CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An issue was discovered in DTS Monitoring 3.57.0. The parameter options within the WGET check function is vulnerable to OS command injection (blind).

CVE-2023-33270CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the Curl check function is vulnerable to OS command injection (blind).

CVE-2023-33271CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An issue was discovered in DTS Monitoring 3.57.0. The parameter common_name within the SSL Certificate check function is vulnerable to OS command injection (blind).

CVE-2023-33272CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An issue was discovered in DTS Monitoring 3.57.0. The parameter ip within the Ping check function is vulnerable to OS command injection (blind).

CVE-2023-33273CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the WGET check function is vulnerable to OS command injection (blind).

CVE-2023-39645CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Improper neutralization of SQL parameter in Theme Volty CMS Payment Icon module for PrestaShop. In the module “Theme Volty CMS Payment Icon” (tvcmspaymenticon) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.

CVE-2023-44973CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

CVE-2023-44974CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

CVE-2023-39646CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Improper neutralization of SQL parameter in Theme Volty CMS Category Chain Slider module for PrestaShop. In the module “Theme Volty CMS Category Chain Slide"(tvcmscategorychainslider) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.

← PreviousPage 525 / 7034Next →