Vulnerabilites CVE
Base de donnees CVE enrichie avec CISA KEV et NVD
| CVE ID | CVSS | Severite | KEV | Observations |
|---|---|---|---|---|
| CVE-2019-12941 AutoPi Wi-Fi/NB and 4G/LTE devices before 2019-10-15 allows an attacker to perform a brute-force attack or dictionary attack to gain access to the WiFi network, which provides root access to the devic... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-4336 IBM Robotic Process Automation with Automation Anywhere 11 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 161411. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-25076 A buffer overflow vulnerability exists in the handling of wildcard backend hosts of SNIProxy 0.6.0-2 and the master branch (commit: 822bb80df9b7b345cc9eba55df74a07b498819ba). A specially crafted HTTP ... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-21058 In lcsm_SendRrAcquiAssist of lcsm_bcm_assist.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges ... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-30547 vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. There exists a vulnerability in exception sanitization of vm2 for versions up to 3.9.16, allowing attackers to ra... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-0297 Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-2138 Use of Hard-coded Credentials in GitHub repository nuxtlabs/github-module prior to 1.6.2. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-1833 Authentication Bypass by Primary Weakness vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass.This issue affects Redline Router: before 7.17. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-30604 It is identified a vulnerability of insufficient authentication in the system configuration interface of Hitron Technologies CODA-5310. An unauthorized remote attacker can exploit this vulnerability t... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-30603 Hitron Technologies CODA-5310 Telnet function with the default account and password, and there is no warning or prompt to ask users to change the default password and account. An unauthenticated remot... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-41903 Git is distributed revision control system. `git log` can display commits in an arbitrary format using its `--format` specifiers. This functionality is also exposed to `git archive` via the `export-su... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-23607 erohtar/Dasherr is a dashboard for self-hosted services. In affected versions unrestricted file upload allows any unauthenticated user to execute arbitrary code on the server. The file /www/include/fi... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-1617 Improper Authentication vulnerability in B&R Industrial Automation B&R VC4 (VNC-Server modules). This vulnerability may allow an unauthenticated network-based attacker to bypass the authentication me... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-28496 TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 discovered to contain a command injection vulnerability in the setPasswordCfg function via the adminuser and adminpassparameter. This vulnerability allow... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-28497 TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the mtd_write_bootloader function via the filename parameter. This vulnerability allows att... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-28493 A vulnerability in TOTOLINK CP900 V6.3c.566 allows attackers to start the Telnet service, | 9.8 | CRITICAL | — | 0 |
| CVE-2023-0452 Econolite EOS versions prior to 3.2.23 use a weak hash algorithm for encrypting privileged user credentials. A configuration file that is accessible without authentication uses MD5 hashes for encrypti... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-28491 TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 contains a command injection vulnerability in the NTPSyncWithHost function via the host_name parameter. This vulnerability allows attackers to execute ar... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-27847 SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges via the xipcategoryclass and xippostsclass components. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-1877 Command Injection in GitHub repository microweber/microweber prior to 1.3.3. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-3000 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Erikoglu Technology ErMon allows Command Line Execution through SQL Injection, Authentication Bypa... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-45597 ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability because the report is only about use of certificates at the application layer (no... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-21890 Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versions that are affected are 7.1.0 and 8.0.0. Easily exploitab... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-28492 TOTOLINK Technology CPE with firmware V6.3c.566 ,allows remote attackers to bypass Login. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-24831 Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana Connector: from 0.13.0 through 0.13.3. Attackers could login without authoriza... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-31039 Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptions::pid_file. An attacker that can influence the ServerOptions pid_file paramete... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-28843 PrestaShop/paypal is an open source module for the PrestaShop web commerce ecosystem which provides paypal payment support. A SQL injection vulnerability found in the PrestaShop paypal module from rel... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-2479 OS Command Injection in GitHub repository appium/appium-desktop prior to v1.22.3-4. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-26119 Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-1788 Insufficient Session Expiration in GitHub repository firefly-iii/firefly-iii prior to 6. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-1537 Authentication Bypass by Capture-replay in GitHub repository answerdev/answer prior to 1.0.6. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-22512 Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-1789 Improper Input Validation in GitHub repository firefly-iii/firefly-iii prior to 6.0.0. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-27017 Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45DC58 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbit... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-1050 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in As Koc Energy Web Report System allows SQL Injection.This issue affects Web Report System: before ... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-28494 TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setUpgradeFW function via the filename parameter. This vulnerability allows attackers t... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-29856 D-Link DIR-868L Hardware version A1, firmware version 1.12 is vulnerable to Buffer Overflow. The vulnerability is in scandir.sgi binary. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-4333 Hardcoded Credentials in multiple SPRECON-E CPU variants of Sprecher Automation allows an remote attacker to take over the device. These accounts should be deactivated according to Sprecher's hardenin... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-28437 Dataease is an open source data visualization and analysis tool. The blacklist for SQL injection protection is missing entries. This vulnerability has been fixed in version 1.18.5. There are no known ... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-28701 ELITE TECHNOLOGY CORP. Web Fax has a vulnerability of SQL Injection. An unauthenticated remote attacker can inject SQL commands into the input field of the login page to perform arbitrary system comma... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-1140 Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker to achieve unauthenticated remote code execution in the context of an administra... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-33963 DataEase is an open source data visualization and analysis tool. Prior to version 1.18.7, a deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-0435 Excessive Attack Surface in GitHub repository pyload/pyload prior to 0.5.0b3.dev41. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-25909 HGiga OAKlouds file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable fi... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-1725 Server-Side Request Forgery (SSRF) vulnerability in Infoline Project Management System allows Server Side Request Forgery.This issue affects Project Management System: before 4.09.31.125. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-47757 In imo.im 2022.11.1051, a path traversal vulnerability delivered via an unsanitized deeplink can force the application to write a file into the application's data directory. This may allow an attacker... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-1136 In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a valid token, which would lead to authentication bypass. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-22741 Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. In affected versions Sofia-SIP **lacks both message length and attributes length checks** when it han... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-27034 PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-1529 Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a malicious HID device. (Chromium security severity:... | 9.8 | CRITICAL | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.