CVE Database

CVE-2023-36548CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.

CVE-2023-36549CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.

CVE-2023-36550CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.

CVE-2023-5495CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in QDocs Smart School 6.4.1. It has been classified as critical. This affects an unknown part of the file /course/filterRecords/ of the component HTTP POST Request Handler. The manipulation of the argument searchdata[0][title]/searchdata[0][searchfield]/searchdata[0][searchvalue] leads to sql injection. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-241647. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-35349CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

CVE-2023-36419CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-611

Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation of Privilege Vulnerability

CVE-2023-36434CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

Windows IIS Server Elevation of Privilege Vulnerability

CVE-2023-4309CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Election Services Co. (ESC) Internet Election Service is vulnerable to SQL injection in multiple pages and parameters. These vulnerabilities allow an unauthenticated, remote attacker to read or modify data for any elections that share the same backend database. ESC deactivated older and unused elections and enabled web application firewall (WAF) protection for current and future elections on or around 2023-08-12.

CVE-2023-35646CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

In TBD of TBD, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-42493CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-256

EisBaer Scada - CWE-256: Plaintext Storage of a Password

CVE-2023-35647CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

In ProtocolEmbmsGlobalCellIdAdapter::Init() of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.

CVE-2023-42494CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-749

EisBaer Scada - CWE-749: Exposed Dangerous Method or Function

CVE-2023-44106CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

API permission management vulnerability in the Fwk-Display module.Successful exploitation of this vulnerability may cause features to perform abnormally.

CVE-2023-5521CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-863

Incorrect Authorization in GitHub repository tiann/kernelsu prior to v0.6.9.

CVE-2023-44105CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-269

Vulnerability of permissions not being strictly verified in the window management module.Successful exploitation of this vulnerability may cause features to perform abnormally.

CVE-2023-44116CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful exploitation of this vulnerability may cause some apps to run without being authorized.

CVE-2023-24479CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-284

An authentication bypass vulnerability exists in the httpd nvram.cgi functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger this vulnerability.

CVE-2023-35648CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

In ProtocolMiscLceIndAdapter::GetConfLevel() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.

CVE-2023-31272CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

A stack-based buffer overflow vulnerability exists in the httpd do_wds functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to stack-based buffer overflow. An attacker can send a network request to trigger this vulnerability.

CVE-2023-32632CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-284

A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.

CVE-2023-32645CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-489

A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to authentication bypass. An attacker can send a network request to trigger this vulnerability.

CVE-2023-34346CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-489

A stack-based buffer overflow vulnerability exists in the httpd gwcfg.cgi get functionality of Yifan YF325 v1.0_20221108. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability.

CVE-2023-34365CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

A stack-based buffer overflow vulnerability exists in the libutils.so nvram_restore functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a buffer overflow. An attacker can send a network request to trigger this vulnerability.

CVE-2023-34426CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

A stack-based buffer overflow vulnerability exists in the httpd manage_request functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to stack-based buffer overflow. An attacker can send a network request to trigger this vulnerability.

CVE-2023-35055CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

A buffer overflow vulnerability exists in the httpd next_page functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.This buffer overflow is in the next_page parameter in the gozila_cgi function.

CVE-2023-35056CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

A buffer overflow vulnerability exists in the httpd next_page functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.This buffer overflow is in the next_page parameter in the cgi_handler function.

CVE-2023-35965CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

Two heap-based buffer overflow vulnerabilities exist in the httpd manage_post functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as argument for the malloc function.

CVE-2023-35966CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

Two heap-based buffer overflow vulnerabilities exist in the httpd manage_post functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as argument for the realloc function.

CVE-2023-35967CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as argument for the malloc function.

CVE-2023-35968CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as argument for the realloc function.

CVE-2023-35662CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

there is a possible out of bounds write due to buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-45132CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-693

NAXSI is an open-source maintenance web application firewall (WAF) for NGINX. An issue present starting in version 1.3 and prior to version 1.6 allows someone to bypass the WAF when a malicious `X-Forwarded-For` IP matches `IgnoreIP` `IgnoreCIDR` rules. This old code was arranged to allow older NGINX versions to also support `IgnoreIP` `IgnoreCIDR` when multiple reverse proxies were present. The issue is patched in version 1.6. As a workaround, do not set any `IgnoreIP` `IgnoreCIDR` for older versions.

CVE-2023-29453CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the action can be used to terminate the literal, injecting arbitrary Javascript code into the Go template. As ES6 template literals are rather complex, and themselves can do string interpolation, the decision was made to simply disallow Go template actions from being used inside of them (e.g., "var a = {{.}}"), since there is no obviously safe way to allow this behavior. This takes the same approach as github.com/google/safehtml. With fix, Template. Parse returns an Error when it encounters templates like this, with an ErrorCode of value 12. This ErrorCode is currently unexported but will be exported in the release of Go 1.21. Users who rely on the previous behavior can re-enable it using the GODEBUG flag jstmpllitinterp=1, with the caveat that backticks will now be escaped. This should be used with caution.

CVE-2023-40833CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue in Thecosy IceCMS v.1.0.0 allows a remote attacker to gain privileges via the Id and key parameters in getCosSetting.

CVE-2023-5554CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-295

Lack of TLS certificate verification in log transmission of a financial module within LINE client for iOS prior to 13.16.0.

CVE-2023-23737CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Unauth. SQL Injection (SQLi) vulnerability in MainWP MainWP Broken Links Checker Extension plugin <= 4.0 versions.

CVE-2023-5045CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology Kayisi allows SQL Injection, Command Line Execution through SQL Injection. This issue affects Kayisi: before 1286.

CVE-2023-5046CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology Procost allows SQL Injection, Command Line Execution through SQL Injection. This issue affects Procost: before 1390.

CVE-2023-41262CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint action generateCSV is vulnerable to SQL injection through the sorting parameter, allowing an unauthenticated user to execute arbitrary SQL statements in the context of the application's backend database server.

CVE-2023-5572CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-918

Server-Side Request Forgery (SSRF) in GitHub repository vriteio/vrite prior to 0.3.0.

CVE-2023-45162CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Affected 1E Platform versions have a Blind SQL Injection vulnerability that can lead to arbitrary code execution.  Application of the relevant hotfix remediates this issue. for v8.1.2 apply hotfix Q23166 for v8.4.1 apply hotfix Q23164 for v9.0.1 apply hotfix Q23169 SaaS implementations on v23.7.1 will automatically have hotfix Q23173 applied. Customers with SaaS versions below this are urged to upgrade urgently - please contact 1E to arrange this

CVE-2023-45465CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ddnsDomainName parameter in the Dynamic DNS settings.

CVE-2023-45466CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the pin_host parameter in the WPS Settings.

CVE-2023-45467CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ntpServIP parameter in the Time Settings.

CVE-2023-4257CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Unchecked user input length in /subsys/net/l2/wifi/wifi_shell.c can cause buffer overflows.

CVE-2023-45853CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.

CVE-2023-30154CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Multiple improper neutralization of SQL parameters in module AfterMail (aftermailpresta) for PrestaShop, before version 2.2.1, allows remote attackers to perform SQL injection attacks via `id_customer`, `id_conf`, `id_product` and `token` parameters in `aftermailajax.php via the 'id_product' parameter in hooks DisplayRightColumnProduct and DisplayProductButtons.

CVE-2023-26155CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

All versions of the package node-qpdf are vulnerable to Command Injection such that the package-exported method encrypt() fails to sanitize its parameter input, which later flows into a sensitive command execution API. As a result, attackers may inject malicious commands once they can specify the input pdf file path.

CVE-2023-45856CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.

CVE-2023-5580CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability classified as critical has been found in SourceCodester Library System 1.0. This affects an unknown part of the file index.php. The manipulation of the argument category leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-242145 was assigned to this vulnerability.

← PreviousPage 527 / 7034Next →