Vulnerabilites CVE
Base de donnees CVE enrichie avec CISA KEV et NVD
| CVE ID | CVSS | Severite | KEV | Observations |
|---|---|---|---|---|
| CVE-2023-35138 A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauth... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-3741 An OS Command injection vulnerability in NEC Platforms DT900 and DT900S Series all versions allows an attacker to execute any command on the device. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-48423 In dhcp4_SetPDNAddress of dhcp4_Main.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. ... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-42268 Jeecg boot up to v3.5.3 was discovered to contain a SQL injection vulnerability via the component /jeecg-boot/jmreport/show. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-46435 Sourcecodester Packers and Movers Management System v1.0 is vulnerable to SQL Injection via mpms/?p=services/view_service&id. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-49043 Buffer Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the wpapsk_crypto parameter in the function fromSetWirelessRepeat. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-49693 NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticated users, allowing attackers to execute arbitrary c... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-42540 Elevation of privilege | 9.8 | CRITICAL | — | 0 |
| CVE-2022-42538 Elevation of privilege | 9.8 | CRITICAL | — | 0 |
| CVE-2023-49405 Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function UploadCfg. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-42537 Remote code execution | 9.8 | CRITICAL | — | 0 |
| CVE-2022-42536 Remote code execution | 9.8 | CRITICAL | — | 0 |
| CVE-2023-46454 In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package information functionality. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-42277 hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonObject.putByPath. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-49656 Jenkins MATLAB Plugin 2.11.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-49654 Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file from the Jenkins controller file system. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-49046 Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the devName parameter in the function formAddMacfilterRule. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-41998 Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows an attacker to upload and execute arbitrary files. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-43979 ETS Soft ybc_blog before v4.4.0 was discovered to contain a SQL injection vulnerability via the component Ybc_blogBlogModuleFrontController::getPosts(). | 9.8 | CRITICAL | — | 0 |
| CVE-2023-5777 Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the crash report transmission is finished, the private key is exposed to the public, wh... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-26352 An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows direc... | 9.8 | CRITICAL | KEV | 0 |
| CVE-2023-45484 Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWifiGuestBasic. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-45483 Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the time parameter in the function compare_parentcontrol_time. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-45482 Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-45480 Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the src parameter in the function sub_47D878. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-45479 Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the list parameter in the function sub_49E098. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-47462 Insecure Permissions vulnerability in GL.iNet AX1800 v.3.215 and before allows a remote attacker to execute arbitrary code via the file sharing function. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-36140 In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-23325 Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain a command injection vulnerability via the NetHostname parameter. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-49040 An issue in Tneda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the adslPwd parameter in the form_fast_setting_internet_set function. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-42796 An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticated arbitrary commands to be executed. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-47308 In the module "Newsletter Popup PRO with Voucher/Coupon code" (newsletterpop) before version 2.6.1 from Active Design for PrestaShop, a guest can perform SQL injection in affected versions. The method... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-49436 Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-46498 An issue in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information and execute arbitrary code via the /deleteCustomer/route.json file. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-49435 Tenda AX9 V22.03.01.46 is vulnerable to command injection. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-3533 Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to perform stored cross-site scripting attacks... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-3368 Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special c... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-46584 SQL Injection vulnerability in PHPGurukul Nipah virus (NiV) " Testing Management System v.1.0 allows a remote attacker to escalate privileges via a crafted request to the new-user-testing.php endpoint... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-30967 Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbitrary files on the file system. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-47503 An issue in jflyfox jfinalCMS v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the login.jsp component in the template management module. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-41012 An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the authentication mechanism. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-41442 An issue in Kloudq Technologies Limited Tor Equip 1.0, Tor Loco Mini 1.0 through 3.1 allows a remote attacker to execute arbitrary code via a crafted request to the MQTT component. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-46789 Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'filename' attribute of the 'pic1' multipart parameter of the functions.php resource does n... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-47213 First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are p... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-46788 Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter in the 'uploadphoto()' function of the functions.php resource does not valid... | 9.8 | CRITICAL | — | 0 |
| CVE-2021-33635 When malicious images are pulled by isula pull, attackers can execute arbitrary code. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-6018 An attacker can overwrite any file on the server hosting MLflow without any authentication. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-5761 The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'url' parameter in versions 1.4.0 to 1.4.6.1 (free) and versions 1.4.0 to 1.... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-5838 Insufficient Session Expiration in GitHub repository linkstackorg/linkstack prior to v4.2.9. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-46353 In the module "Product Tag Icons Pro" (ticons) before 1.8.4 from MyPresta.eu for PrestaShop, a guest can perform SQL injection. The method TiconProduct::getTiconByProductAndTicon() has sensitive SQL c... | 9.8 | CRITICAL | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.