CVE Database

CVE-2023-30131CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue discovered in IXP EasyInstall 6.6.14884.0 allows attackers to run arbitrary commands, gain escalated privilege, and cause other unspecified impacts via unauthenticated API calls.

CVE-2023-45379CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

In the module "Rotator Img" (posrotatorimg) in versions at least up to 1.1 from PosThemes for PrestaShop, a guest can perform SQL injection.

CVE-2023-45384CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

KnowBand supercheckout > 5.0.7 and < 6.0.7 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the module "Module One Page Checkout, Social Login & Mailchimp" (supercheckout), a guest can upload files with extensions .php

CVE-2023-35182CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability can be abused by unauthenticated users on SolarWinds ARM Server.

CVE-2023-35184CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse a SolarWinds service resulting in a remote code execution.

CVE-2023-35187CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability allows an unauthenticated user to achieve the Remote Code Execution.

CVE-2023-43986CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

DM Concept configurator before v4.9.4 was discovered to contain a SQL injection vulnerability via the component ConfiguratorAttachment::getAttachmentByToken.

CVE-2023-45381CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

In the module "Creative Popup" (creativepopup) up to version 1.6.9 from WebshopWorks for PrestaShop, a guest can perform SQL injection via `cp_download_popup().`

CVE-2023-38584CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

In Weintek's cMT3000 HMI Web CGI device, the cgi-bin command_wb.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to hijack control flow and bypass login authentication.

CVE-2023-43492CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

In Weintek's cMT3000 HMI Web CGI device, the cgi-bin codesys.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to hijack control flow and bypass login authentication.

CVE-2023-45376CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

In the module "Carousels Pack - Instagram, Products, Brands, Supplier" (hicarouselspack) for PrestaShop up to version 1.5.0 from HiPresta for PrestaShop, a guest can perform SQL injection via HiCpProductGetter::getViewedProduct().`

CVE-2023-34051CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-863

VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.

CVE-2020-36706CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

The Simple:Press – WordPress Forum Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~/admin/resources/jscript/ajaxupload/sf-uploader.php file in versions up to, and including, 6.6.0. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

CVE-2023-39680CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Sollace Unicopia version 1.1.1 and before was discovered to deserialize untrusted data, allowing attackers to execute arbitrary code.

CVE-2023-4402CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_products function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

CVE-2023-4488CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-98

The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via the editor-view.php file. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVE-2023-50073CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

EmpireCMS v7.5 was discovered to contain a SQL injection vulnerability via the ftppassword parameter at SetEnews.php.

CVE-2023-5533CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-862

The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks on the corresponding functions in versions up to, and including, 4.8.9 as well as 4.9.2. This makes it possible for unauthenticated attackers to perform some of those actions that were intended for higher privileged users.

CVE-2023-37824CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Sitolog sitologapplicationconnect v7.8.a and before was discovered to contain a SQL injection vulnerability via the component /activate_hook.php.

CVE-2023-5682CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability has been found in Tongda OA 2017 and classified as critical. This vulnerability affects unknown code of the file general/hr/training/record/delete.php. The manipulation of the argument RECORD_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. VDB-243058 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-45666CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

stb_image is a single file MIT licensed library for processing images. It may look like `stbi__load_gif_main` doesn’t give guarantees about the content of output value `*delays` upon failure. Although it sets `*delays` to zero at the beginning, it doesn’t do it in case the image is not recognized as GIF and a call to `stbi__load_gif_main_outofmem` only frees possibly allocated memory in `*delays` without resetting it to zero. Thus it would be fair to say the caller of `stbi__load_gif_main` is responsible to free the allocated memory in `*delays` only if `stbi__load_gif_main` returns a non null value. However at the same time the function may return null value, but fail to free the memory in `*delays` if internally `stbi__convert_format` is called and fails. Thus the issue may lead to a memory leak if the caller chooses to free `delays` only when `stbi__load_gif_main` didn’t fail or to a double-free if the `delays` is always freed

CVE-2023-5684CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

A vulnerability was found in Byzoro Smart S85F Management Platform up to 20231012. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /importexport.php. The manipulation leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243061 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-46300CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-116

iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to tmux integration.

CVE-2023-46301CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-116

iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to upload.

CVE-2023-5693CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in CodeAstro Internet Banking System 1.0 and classified as critical. This issue affects some unknown processing of the file pages_reset_pwd.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-243131.

CVE-2023-46321CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs. They may have shell metacharacters for a /usr/bin/man command line.

CVE-2023-46322CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs. The hostname's initial character may be non-alphanumeric. The hostname's other characters may be outside the set of alphanumeric characters, dash, and period.

CVE-2023-5700CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. Affected is an unknown function of the file /protocol/iscgwtunnel/uploadiscgwrouteconf.php. The manipulation of the argument GWLinkId leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-243138 is the identifier assigned to this vulnerability.

CVE-2023-27152CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentication.

CVE-2023-37635CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the application.

CVE-2023-28805CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An Improper Input Validation vulnerability in Zscaler Client Connector on Linux allows Privilege Escalation. This issue affects Client Connector: before 1.4.0.105

CVE-2022-22466CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 225222.

CVE-2023-30912CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

A remote code execution issue exists in HPE OneView.

CVE-2023-31581CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Dromara Sureness before v1.0.8 was discovered to use a hardcoded key.

CVE-2023-37283CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter

CVE-2023-49701CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

Memory Corruption in SIM management while USIMPhase2init

CVE-2023-39930CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-288

A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via a maliciously crafted RADIUS client request.

CVE-2023-42489CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-732

EisBaer Scada - CWE-732: Incorrect Permission Assignment for Critical Resource

CVE-2023-44794CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL.

CVE-2023-45554CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the imageext parameter from jpg, jpeg,gif, and png to jpg, jpeg,gif, png, pphphp.

CVE-2023-46010CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.

CVE-2023-46158CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-613

IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expected security due to improper resource expiration handling. IBM X-Force ID: 268775.

CVE-2023-46358CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

In the module "Referral and Affiliation Program" (referralbyphone) version 3.5.1 and before from Snegurka for PrestaShop, a guest can perform SQL injection. Method `ReferralByPhoneDefaultModuleFrontController::ajaxProcessCartRuleValidate` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

CVE-2023-46369CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda W18E V16.01.0.8(1576) contains a stack overflow vulnerability via the portMirrorMirroredPorts parameter in the formSetNetCheckTools function.

CVE-2023-46370CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Tenda W18E V16.01.0.8(1576) has a command injection vulnerability via the hostName parameter in the formSetNetCheckTools function.

CVE-2023-46371CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TP-Link device TL-WDR7660 2.0.30 and TL-WR886N 2.0.12 has a stack overflow vulnerability via the function upgradeInfoJsonToBin.

CVE-2023-46373CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TP-Link TL-WDR7660 2.0.30 has a stack overflow vulnerability via the function deviceInfoJsonToBincauses.

CVE-2023-46518CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Mercury A15 V1.0 20230818_1.0.3 was discovered to contain a command execution vulnerability via the component cloudDeviceTokenSuccCB.

CVE-2023-46520CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function uninstallPluginReqHandle.

CVE-2023-46521CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function RegisterRegister.

← PreviousPage 529 / 7034Next →