CVE Database

CVE-2023-46522CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TP-LINK device TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin and TL-WDR7660 2.0.30 were discovered to contain a stack overflow via the function deviceInfoRegister.

CVE-2023-46523CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function upgradeInfoRegister.

CVE-2023-46525CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function loginRegister.

CVE-2023-46526CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function resetCloudPwdRegister.

CVE-2023-44267CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Art Gallery v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'lnm' parameter of the header.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-46527CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin and TL-WDR7660 2.0.30 was discovered to contain a stack overflow via the function bindRequestHandle.

CVE-2023-46534CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function modifyAccPwdRegister.

CVE-2023-46535CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function getResetVeriRegister.

CVE-2023-46536CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function chkRegVeriRegister.

CVE-2023-46537CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function getRegVeriRegister.

CVE-2023-46538CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function chkResetVeriRegister.

CVE-2023-39726CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue in Mintty v.3.6.4 and before allows a remote attacker to execute arbitrary code via crafted commands to the terminal.

CVE-2023-46539CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function registerRequestHandle.

CVE-2023-46540CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formNtp.

CVE-2023-46541CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIpv6Setup.

CVE-2023-46542CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMeshUploadConfig.

CVE-2023-46543CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formWlSiteSurvey.

CVE-2023-46544CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formWirelessTbl.

CVE-2023-46545CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formWsc.

CVE-2023-46546CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formStats.

CVE-2023-46547CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formSysLog.

CVE-2023-46548CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formWlanRedirect.

CVE-2023-46549CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formSetLg.

CVE-2023-46550CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMapDelDevice.

CVE-2023-46551CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formReflashClientTbl.

CVE-2023-46552CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMultiAP.

CVE-2023-46553CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formParentControl.

CVE-2023-46554CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMapDel.

CVE-2023-46555CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formPortFw.

CVE-2023-46556CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formFilter.

CVE-2023-46557CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMultiAPVLAN.

CVE-2023-46558CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMapDelDevice.

CVE-2023-46559CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIPv6Addr.

CVE-2023-46560CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formTcpipSetup.

CVE-2023-46562CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDosCfg.

CVE-2023-46563CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIpQoS.

CVE-2023-46564CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDMZ.

CVE-2023-5730CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

CVE-2023-5731CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Memory safety bugs present in Firefox 118. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 119.

CVE-2023-5746CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-134

A vulnerability regarding use of externally-controlled format string is found in the cgi component. This allows remote attackers to execute arbitrary code via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.5-0185 may be affected: BC500 and TC500.

CVE-2023-46408CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ The 41DD80 function.

CVE-2023-46409CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ 41CC04 function.

CVE-2023-46410CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ The 416F60 function.

CVE-2023-46411CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_415258 function.

CVE-2023-46412CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_41D998 function.

CVE-2023-46413CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_4155DC function.

CVE-2023-46414CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ 41D494 function.

CVE-2023-46415CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41E588 function.

CVE-2023-46416CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ The 41A414 function.

CVE-2023-46417CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415498 function.

← PreviousPage 530 / 7034Next →