CVE Database

CVE-2023-51019CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘key5g’ parameter of the setWiFiExtenderConfig interface of the cstecgi .cgi.

CVE-2023-51020CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘langType’ parameter of the setLanguageCfg interface of the cstecgi .cgi.

CVE-2023-51021CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘merge’ parameter of the setRptWizardCfg interface of the cstecgi .cgi.

CVE-2023-51022CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘langFlag’ parameter of the setLanguageCfg interface of the cstecgi .cgi.

CVE-2023-51033CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi setOpModeCfg interface.

CVE-2023-51034CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi UploadFirmwareFile interface.

CVE-2023-51035CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

TOTOLINK EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution on the cstecgi.cgi NTPSyncWithHost interface.

CVE-2023-6971CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-829

The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'content-dir' HTTP header. This makes it possible for unauthenticated attackers to include remote files on the server, resulting in code execution. NOTE: Successful exploitation of this vulnerability requires that the target server's php.ini is configured with 'allow_url_include' set to 'on'. This feature is deprecated as of PHP 7.4 and is disabled by default, but can still be explicitly enabled in later versions of PHP.

CVE-2023-6972CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifest', or 'content-bmitmp' and 'content-identy' HTTP headers. This makes it possible for unauthenticated attackers to delete arbitrary files, including the wp-config.php file, which can make site takeover and remote code execution possible.

CVE-2023-51763CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1236

csv_builder.rb in ActiveAdmin (aka Active Admin) before 3.2.0 allows CSV injection.

CVE-2023-51714CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

An issue was discovered in the HTTP2 implementation in Qt before 5.15.17, 6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x before 6.6.2. network/access/http2/hpacktable.cpp has an incorrect HPack integer overflow check.

CVE-2023-7095CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

A vulnerability, which was classified as critical, has been found in Totolink A7100RU 7.4cu.2313_B20191024. Affected by this issue is the function main of the file /cgi-bin/cstecgi.cgi?action=login of the component HTTP POST Request Handler. The manipulation of the argument flag leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-248942 is the identifier assigned to this vulnerability.

CVE-2023-7096CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A flaw has been found in code-projects Faculty Management System 1.0. The affected element is an unknown function of the file /admin/php/crud.php. This manipulation of the argument fieldname/tablename causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

CVE-2023-7097CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability classified as critical has been found in code-projects Water Billing System 1.0. This affects an unknown part of the file /addbill.php. The manipulation of the argument owners_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-248949 was assigned to this vulnerability.

CVE-2023-7099CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This issue affects some unknown processing of the file bwdates-report-result.php. The manipulation of the argument fromdate leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-248951.

CVE-2023-7100CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A vulnerability, which was classified as critical, was found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of the file /admin/bwdates-report-details.php. The manipulation of the argument fdate/tdate leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2023-51771CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

In MicroHttpServer (aka Micro HTTP Server) through a8ab029, _ParseHeader in lib/server.c allows a one-byte recv buffer overflow via a long URI.

CVE-2023-48654CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape sequence is: go to the Google ReCAPTCHA section, click on the Privacy link, observe that there is a new browser window, navigate to any website that offers file upload, navigate to cmd.exe from the file explorer window, and launch cmd.exe as NT AUTHORITY\SYSTEM.

CVE-2022-34267CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arbitrary Java code can be uploaded and executed via a .jar archive to the ws-api/v2/customizations/api endpoint.

CVE-2022-34268CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

An issue was discovered in RWS WorldServer before 11.7.3. /clientLogin deserializes Java objects without authentication, leading to command execution on the host.

CVE-2023-31224CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

There is broken access control during authentication in Jamf Pro Server before 10.46.1.

CVE-2023-49954CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The CRM Integration in 3CX before 18.0.9.23 and 20 before 20.0.0.1494 allows SQL Injection via a first name, search string, or email address.

CVE-2023-7111CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability, which was classified as critical, was found in code-projects Library Management System 2.0. Affected is an unknown function of the file index.php. The manipulation of the argument category leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-249006 is the identifier assigned to this vulnerability.

CVE-2023-51095CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formDelWlRfPolicy.

CVE-2023-51090CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formGetWeiXinConfig.

CVE-2023-51091CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function R7WebsSecurityHandler.

CVE-2023-51092CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function upgrade.

CVE-2023-51093CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function fromSetLocalVlanInfo.

CVE-2023-51094CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Tenda M3 V1.0.0.12(4856) was discovered to contain a Command Execution vulnerability via the function TendaTelnet.

CVE-2023-51097CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formSetAutoPing.

CVE-2023-51098CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formSetDiagnoseInfo .

CVE-2023-51099CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formexeCommand .

CVE-2023-51100CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formGetDiagnoseInfo .

CVE-2023-51101CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formSetUplinkInfo.

CVE-2023-51102CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formWifiMacFilterSet.

CVE-2023-5991CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server

CVE-2023-6190CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in İzmir Katip Çelebi University University Information Management System allows Absolute Path Traversal. This issue affects University Information Management System: before 30.11.2023.

CVE-2023-7116CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

A vulnerability, which was classified as critical, has been found in WeiYe-Jing datax-web 2.1.2. Affected by this issue is some unknown functionality of the file /api/log/killJob of the component HTTP POST Request Handler. The manipulation of the argument processId leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-249086 is the identifier assigned to this vulnerability.

CVE-2023-51664CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

tj-actions/changed-files is a Github action to retrieve all files and directories. Prior to 41.0.0, the `tj-actions/changed-files` workflow allows for command injection in changed filenames, allowing an attacker to execute arbitrary code and potentially leak secrets. This issue may lead to arbitrary command execution in the GitHub Runner. This vulnerability has been addressed in version 41.0.0. Users are advised to upgrade.

CVE-2023-51700CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Unofficial Mobile BankID Integration for WordPress lets users employ Mobile BankID to authenticate themselves on your WordPress site. Prior to 1.0.1, WP-Mobile-BankID-Integration is affected by a vulnerability classified as a Deserialization of Untrusted Data vulnerability, specifically impacting scenarios where an attacker can manipulate the database. If unauthorized actors gain access to the database, they could exploit this vulnerability to execute object injection attacks. This could lead to unauthorized code execution, data manipulation, or data exfiltration within the WordPress environment. Users of the plugin should upgrade to version 1.0.1 (or later), where the serialization and deserialization of OrderResponse objects have been switched out to an array stored as JSON. A possible workaround for users unable to upgrade immediately is to enforce stricter access controls on the database, ensuring that only trusted and authorized entities can modify data. Additionally, implementing monitoring tools to detect unusual database activities could help identify and mitigate potential exploitation attempts.

CVE-2023-52077CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-863

Nexkey is a lightweight fork of Misskey v12 optimized for small to medium size servers. Prior to 12.23Q4.5, Nexkey allows external apps using tokens issued by administrators and moderators to call admin APIs. This allows malicious third-party apps to perform operations such as updating server settings, as well as compromise object storage and email server credentials. This issue has been patched in 12.23Q4.5.

CVE-2023-43481CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

An issue in Shenzhen TCL Browser TV Web BrowseHere (aka com.tcl.browser) 6.65.022_dab24cc6_231221_gp allows a remote attacker to execute arbitrary JavaScript code via the com.tcl.browser.portal.browse.activity.BrowsePageActivity component.

CVE-2023-43955CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

The com.phlox.tvwebbrowser TV Bro application through 2.0.0 for Android mishandles external intents through WebView. This allows attackers to execute arbitrary code, create arbitrary files. and perform arbitrary downloads via JavaScript that uses takeBlobDownloadData.

CVE-2023-47883CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

The com.altamirano.fabricio.tvbrowser TV browser application through 4.5.1 for Android is vulnerable to JavaScript code execution via an explicit intent due to an exposed MainActivity.

CVE-2023-51084CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

hyavijava v6.0.07.1 was discovered to contain a stack overflow via the ResultConverter.convert2Xml method.

CVE-2023-49000CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

An issue in ArtistScope ArtisBrowser v.34.1.5 and before allows an attacker to bypass intended access restrictions via interaction with the com.artis.browser.IntentReceiverActivity component. NOTE: this is disputed by the vendor, who indicates that ArtisBrowser 34 does not support CSS3.

CVE-2023-49001CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

An issue in Indi Browser (aka kvbrowser) v.12.11.23 allows an attacker to bypass intended access restrictions via interaction with the com.example.gurry.kvbrowswer.webview component.

CVE-2023-6879CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().

CVE-2023-7123CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability, which was classified as critical, has been found in SourceCodester Medicine Tracking System 1.0. This issue affects some unknown processing of the file /classes/Master.php? f=save_medicine. The manipulation of the argument id/name/description leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249095.

CVE-2023-32513CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Deserialization of Untrusted Data vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform.This issue affects GiveWP – Donation Plugin and Fundraising Platform: from n/a through 2.25.3.

← PreviousPage 545 / 7034Next →