CVE Database

CVE-2023-39169CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

The affected devices use publicly available default credentials with administrative privileges.

CVE-2023-49425CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterCfg .

CVE-2023-49426CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg.

CVE-2023-49428CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.

CVE-2023-49437CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.

CVE-2023-49429CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDeviceInfo' feature through the 'mac' parameter at /goform/setModules.

CVE-2023-49430CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetStaticRouteCfg.

CVE-2023-49431CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.

CVE-2023-49432CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'deviceList' parameter at /goform/setMacFilterCfg.

CVE-2023-49433CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetVirtualServerCfg.

CVE-2023-49434CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetNetControlList.

CVE-2023-49435CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Tenda AX9 V22.03.01.46 is vulnerable to command injection.

CVE-2023-49436CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.

CVE-2023-49402CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function localMsg.

CVE-2023-49403CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setFixTools.

CVE-2023-49410CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function via the function set_wan_status.

CVE-2023-49999CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setUmountUSBPartition.

CVE-2023-50000CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formResetMeshNode.

CVE-2023-50001CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formUpgradeMeshOnline.

CVE-2023-50002CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formRebootMeshNode.

CVE-2023-40300CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key.

CVE-2023-40301CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

NETSCOUT nGeniusPULSE 3.8 has a Command Injection Vulnerability.

CVE-2023-49404CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formAdvancedSetListSet.

CVE-2023-49405CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function UploadCfg.

CVE-2023-49406CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Tenda W30E V16.01.0.12(4843) was discovered to contain a Command Execution vulnerability via the function /goform/telnet.

CVE-2023-49408CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the function set_device_name.

CVE-2023-49409CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Tenda AX3 V16.03.12.11 was discovered to contain a Command Execution vulnerability via the function /goform/telnet.

CVE-2023-49411CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda W30E V16.01.0.12(4843) contains a stack overflow vulnerability via the function formDeleteMeshNode.

CVE-2023-6579CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability, which was classified as critical, has been found in osCommerce 4. Affected by this issue is some unknown functionality of the file /b2b-supermarket/shopping-cart of the component POST Parameter Handler. The manipulation of the argument estimate[country_id] leads to sql injection. The attack may be launched remotely. The identifier of this vulnerability is VDB-247160. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-6581CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability has been found in D-Link DAR-7000 up to 20231126 and classified as critical. This vulnerability affects unknown code of the file /user/inc/workidajax.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-247162 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-5008CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Student Information System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'regno' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control.

CVE-2023-43742CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

An authentication bypass in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an unauthenticated attacker to obtain an administrative session via a protection mechanism failure in the authentication function. In normal operation, the Zultys MX Administrator Windows client connects to port 7505 and attempts authentication, submitting the administrator username and password to the server. Upon authentication failure, the server sends a login failure message prompting the client to disconnect. However, if the client ignores the failure message instead and attempts to continue, the server does not forcibly close the connection and processes all subsequent requests from the client as if authentication had been successful.

CVE-2023-48929CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-384

Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Session Fixation. The 'sid' parameter in the group_status.asp resource allows an attacker to escalate privileges and obtain sensitive information.

CVE-2023-49007CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

In Netgear Orbi RBR750 firmware before V7.2.6.21, there is a stack-based buffer overflow in /usr/sbin/httpd.

CVE-2023-49443CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

DoraCMS v2.1.8 was discovered to re-use the same code for verification of valid usernames and passwords. This vulnerability allows attackers to gain access to the application via a bruteforce attack.

CVE-2023-48423CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

In dhcp4_SetPDNAddress of dhcp4_Main.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-6612CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

A vulnerability was found in Totolink X5000R 9.1.0cu.2300_B20230112. It has been rated as critical. This issue affects the function setDdnsCfg/setDynamicRoute/setFirewallType/setIPSecCfg/setIpPortFilterRules/setLancfg/setLoginPasswordCfg/setMacFilterRules/setMtknatCfg/setNetworkConfig/setPortForwardRules/setRemoteCfg/setSSServer/setScheduleCfg/setSmartQosCfg/setStaticDhcpRules/setStaticRoute/setVpnAccountCfg/setVpnPassCfg/setVpnUser/setWiFiAclAddConfig/setWiFiEasyGuestCfg/setWiFiGuestCfg/setWiFiRepeaterConfig/setWiFiScheduleCfg/setWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to os command injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-247247. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-6617CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been classified as critical. Affected is an unknown function of the file attendance.php. The manipulation of the argument class_id leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-247254 is the identifier assigned to this vulnerability.

CVE-2023-6619CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /modals/class_form.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247256.

CVE-2024-25897CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

ChurchCRM 5.5.0 FRCatalog.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.

CVE-2023-46498CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information and execute arbitrary code via the /deleteCustomer/route.json file.

CVE-2023-46932CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Heap Buffer Overflow vulnerability in GPAC version 2.3-DEV-rev617-g671976fcc-master, allows attackers to execute arbitrary code and cause a denial of service (DoS) via str2ulong class in src/media_tools/avilib.c in gpac/MP4Box.

CVE-2023-47254CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An OS Command Injection in the CLI interface on DrayTek Vigor167 version 5.2.2, allows remote attackers to execute arbitrary system commands and escalate privileges via any account created within the web interface.

CVE-2023-6647CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability, which was classified as critical, has been found in AMTT HiBOS 1.0. Affected by this issue is some unknown functionality. The manipulation of the argument Type leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247340. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-6648CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A vulnerability, which was classified as critical, was found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of the file password-recovery.php. The manipulation of the argument username/contactno leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2023-6651CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in code-projects Matrimonial Site 1.0. It has been classified as critical. Affected is an unknown function of the file /auth/auth.php?user=1. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247344.

CVE-2023-6652CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in code-projects Matrimonial Site 1.0. It has been declared as critical. Affected by this vulnerability is the function register of the file /register.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247345 was assigned to this vulnerability.

CVE-2023-6657CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability classified as critical has been found in SourceCodester Simple Student Attendance System 1.0. This affects an unknown part of the file /modals/student_form.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-247365 was assigned to this vulnerability.

CVE-2023-6658CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability classified as critical was found in SourceCodester Simple Student Attendance System 1.0. This vulnerability affects unknown code of the file ajax-api.php?action=save_attendance. The manipulation of the argument class_id leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-247366 is the identifier assigned to this vulnerability.

CVE-2023-48417CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-862

Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application

← PreviousPage 540 / 7034Next →