CVE Database

CVE-2023-48424CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

U-Boot shell vulnerability resulting in Privilege escalation in a production device

CVE-2023-48425CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

U-Boot vulnerability resulting in persistent Code Execution 

CVE-2023-6181CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An oversight in BCB handling of reboot reason that allows for persistent code execution

CVE-2023-49417CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLink A7000R V9.1.0u.6115_B20201022 has a stack overflow vulnerability via setOpModeCfg.

CVE-2023-49418CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLink A7000R V9.1.0u.6115_B20201022has a stack overflow vulnerability via setIpPortFilterRules.

CVE-2023-50245CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

OpenEXR-viewer is a viewer for OpenEXR files with detailed metadata probing. Versions prior to 0.6.1 have a memory overflow vulnerability. This issue is fixed in version 0.6.1.

CVE-2023-49583CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-749

SAP BTP Security Services Integration Library ([Node.js] @sap/xssec - versions < 3.6.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.

CVE-2023-50422CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-749

SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) - versions below 2.17.0 and versions from 3.0.0 to before 3.3.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.

CVE-2023-50423CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-749

SAP BTP Security Services Integration Library ([Python] sap-xssec) - versions < 4.1.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.

CVE-2023-50424CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-749

SAP BTP Security Services Integration Library ([Golang] github.com/sap/cloud-security-client-go) - versions < 0.17.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.

CVE-2023-41117CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-427

An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contain packages, standalone packages, and functions that run SECURITY DEFINER but are inadequately secured against search_path attacks.

CVE-2023-48427CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-295

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of the configured UMC server. This could allow an attacker to intercept credentials that are sent to the UMC server as well as to manipulate responses, potentially allowing an attacker to escalate privileges.

CVE-2023-46454CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package information functionality.

CVE-2023-46456CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionality.

CVE-2023-6593CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-732

Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to the application to execute entries in a SQL data source without restriction.

CVE-2013-2513CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

The flash_tool gem through 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded file.

CVE-2023-43364CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.

CVE-2023-50252CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-15

php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when handling `<use>` tag that references an `<image>` tag, it merges the attributes from the `<use>` tag to the `<image>` tag. The problem pops up especially when the `href` attribute from the `<use>` tag has not been sanitized. This can lead to an unsafe file read that can cause PHAR Deserialization vulnerability in PHP prior to version 8. Version 0.5.1 contains a patch for this issue.

CVE-2023-47577CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-522

An issue discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 allows for unauthorized password changes due to no check for current password.

CVE-2023-6723CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

An unrestricted file upload vulnerability has been identified in Repbox, which allows an attacker to upload malicious files via the transforamationfileupload function, due to the lack of proper file type validation controls, resulting in a full system compromise.

CVE-2023-42495CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Dasan Networks - W-Web versions 1.22-1.27 - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVE-2023-49363CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Rockoa <2.3.3 is vulnerable to SQL Injection. The problem exists in the indexAction method in reimpAction.php.

CVE-2023-6756CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

A vulnerability was found in Thecosy IceCMS 2.0.1. It has been classified as problematic. Affected is an unknown function of the file /login of the component Captcha Handler. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247884.

CVE-2023-6765CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. This issue affects the function prepare of the file email_setup.php. The manipulation of the argument name leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-247895.

CVE-2023-46726CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, on PHP 7.4 only, the LDAP server configuration form can be used to execute arbitrary code previously uploaded as a GLPI document. Version 10.0.11 contains a patch for the issue.

CVE-2023-46727CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, GLPI inventory endpoint can be used to drive a SQL injection attack. Version 10.0.11 contains a patch for the issue. As a workaround, disable native inventory.

CVE-2023-6771CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability, which was classified as critical, has been found in SourceCodester Simple Student Attendance System 1.0. This issue affects the function save_attendance of the file actions.class.php. The manipulation of the argument sid leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-247907.

CVE-2023-40921CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection vulnerability in functions/point_list.php in Common Services soliberte before v4.3.03 allows attackers to obtain sensitive information via the lat and lng parameters.

CVE-2023-49934CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in SchedMD Slurm 23.11.x. There is SQL Injection against the SlurmDBD database. The fixed version is 23.11.1.

CVE-2023-49937CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. Because of a double free, attackers can cause a denial of service or possibly execute arbitrary code. The fixed versions are 22.05.11, 23.02.7, and 23.11.1.

CVE-2023-44709CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

PlutoSVG commit 336c02997277a1888e6ccbbbe674551a0582e5c4 and before was discovered to contain an integer overflow via the component plutosvg_load_from_memory.

CVE-2023-48085CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component command_test.php.

CVE-2023-46348CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL njection vulnerability in SunnyToo sturls before version 1.1.13, allows attackers to escalate privileges and obtain sensitive information via StUrls::hookActionDispatcher and StUrls::getInstanceId methods.

CVE-2023-40629CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQLi vulnerability in LMS Lite component for Joomla.

CVE-2023-40630CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-918

Unauthenticated LFI/SSRF in JCDashboards component for Joomla.

CVE-2023-48925CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in Buy Addons bavideotab before version 1.0.6, allows attackers to escalate privileges and obtain sensitive information via the component BaVideoTabSaveVideoModuleFrontController::run().

CVE-2023-49707CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQLi vulnerability in S5 Register module for Joomla.

CVE-2023-49708CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQLi vulnerability in Starshop component for Joomla.

CVE-2023-0757CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-732

Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the affected device.

CVE-2023-46141CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-732

Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device.

CVE-2023-47261CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Dokmee ECM 7.4.6 allows remote code execution because the response to a GettingStarted/SaveSQLConnectionAsync /#/gettingstarted request contains a connection string for privileged SQL Server database access, and xp_cmdshell can be enabled.

CVE-2023-4489CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1279

The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK v7.18.3 and earlier. This makes the first S0 key generated at startup predictable, potentially allowing network key prediction and unauthorized S0 network access.

CVE-2023-48049CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A SQL injection vulnerability in Cybrosys Techno Solutions Website Blog Search (aka website_search_blog) v. 13.0 through 13.0.1.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the name parameter in controllers/main.py component.

CVE-2023-40954CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12.0 through v12.0.2, v.13.0 through v13.0.2, v.14.0 through v14.0.2.1, v.15.0 through v15.0.2, and v16.0 through v16.0.2.1 allows a remote attacker to gain privileges via the recency parameter in models/web_progress.py component.

CVE-2023-48050CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka odoo-biometric-attendance) v. 13.0 through 16.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the db parameter in the controllers/controllers.py component.

CVE-2023-48371CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

ITPison OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service.

CVE-2023-48372CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

ITPison OMICARD EDM 's SMS-related function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.

CVE-2023-48376CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

SmartStar Software CWS is a web-based integration platform, its file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.

CVE-2023-29234CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 through 3.2.4. Users are recommended to upgrade to the latest version, which fixes the issue.

CVE-2023-46279CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the latest version, which fixes the issue.

← PreviousPage 541 / 7034Next →