Vulnerabilites CVE
Base de donnees CVE enrichie avec CISA KEV et NVD
| CVE ID | CVSS | Severite | KEV | Observations |
|---|---|---|---|---|
| CVE-2023-28343 OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-28371 In Stellarium through 1.2, attackers can write to files that are typically unintended, such as ones with absolute pathnames or .. directory traversal. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-1529 Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a malicious HID device. (Chromium security severity:... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-21689 Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | 9.8 | CRITICAL | — | 0 |
| CVE-2023-34849 An unauthorized command injection vulnerability exists in the ActionLogin function of the webman.lua file in Ikuai router OS through 3.7.1. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-23415 Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability | 9.8 | CRITICAL | — | 0 |
| CVE-2023-21716 Microsoft Word Remote Code Execution Vulnerability | 9.8 | CRITICAL | — | 0 |
| CVE-2023-21803 Windows iSCSI Discovery Service Remote Code Execution Vulnerability | 9.8 | CRITICAL | — | 0 |
| CVE-2023-25668 TensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not in the control of user, leading to a crash or remot... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-24838 HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulnerability to obtain the administrator's credential. This credential can then be u... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-27757 An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to execute arbitrary code via a crafted JPG file. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-1788 Insufficient Session Expiration in GitHub repository firefly-iii/firefly-iii prior to 6. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-23392 HTTP Protocol Stack Remote Code Execution Vulnerability | 9.8 | CRITICAL | — | 0 |
| CVE-2023-21708 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 9.8 | CRITICAL | — | 0 |
| CVE-2023-1050 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in As Koc Energy Web Report System allows SQL Injection.This issue affects Web Report System: before ... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-27074 BP Monitoring Management System v1.0 was discovered to contain a SQL injection vulnerability via the emailid parameter in the login page. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-25330 A SQL injection vulnerability in Mybatis plus below 3.5.3.1 allows remote attackers to execute arbitrary SQL commands via the tenant ID valuer. NOTE: the vendor's position is that this can only occur ... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-28437 Dataease is an open source data visualization and analysis tool. The blacklist for SQL injection protection is missing entries. This vulnerability has been fixed in version 1.18.5. There are no known ... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-1537 Authentication Bypass by Capture-replay in GitHub repository answerdev/answer prior to 1.0.6. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-1153 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pacsrapor allows SQL Injection, Command Line Execution through SQL Injection.This issue affects Pa... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-1765 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Akbim Computer Panon allows SQL Injection.This issue affects Panon: before 1.0.2. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-26119 Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-26800 Ruijie Networks RG-EW1200 Wireless Routers EW_3.0(1)B11P204 was discovered to contain a command injetion vulnerability via the params.path parameter in the upgradeConfirm function. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-25909 HGiga OAKlouds file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable fi... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-27583 PanIndex is a network disk directory index. In Panindex prior to version 3.1.3, a hard-coded JWT key `PanIndex` is used. An attacker can use the hard-coded JWT key to sign JWT token and perform any a... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-0345 The Akuvox E11 secure shell (SSH) server is enabled by default and can be accessed by the root user. This password cannot be changed by the user. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-27394 Osprey Pump Controller version 1.01 is vulnerable an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through a HTTP GET paramet... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-27886 Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through a HTTP POST par... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-28398 Osprey Pump Controller version 1.01 could allow an unauthenticated user to create an account and bypass authentication, thereby gaining unauthorized access to the system. A threat actor could exploit ... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-28654 Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full access to the web management interface configuration. The user is not visible i... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-48328 app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-1198 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saysis Starcities allows SQL Injection.This issue affects Starcities: through 1.3. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-1789 Improper Input Validation in GitHub repository firefly-iii/firefly-iii prior to 6.0.0. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-25805 versionn, software for changing version information across multiple files, has a command injection vulnerability in all versions prior to version 1.1.0. This issue is patched in version 1.1.0. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-28843 PrestaShop/paypal is an open source module for the PrestaShop web commerce ecosystem which provides paypal payment support. A SQL injection vulnerability found in the PrestaShop paypal module from rel... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-33256 Memory corruption due to improper validation of array index in Multi-mode call processor. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-26959 Phpgurukul Park Ticketing Management System 1.0 is vulnerable to SQL Injection via the User Name parameter. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-1133 Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified ... | 9.8 | CRITICAL | — | 0 |
| CVE-2021-33360 An issue found in Stoqey gnuplot v.0.0.3 and earlier allows attackers to execute arbitrary code via the src/index.ts, plotCallack, child_process, and/or filePath parameter(s). | 9.8 | CRITICAL | — | 0 |
| CVE-2023-1136 In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a valid token, which would lead to authentication bypass. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-1091 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alpata Licensed Warehousing Automation System allows Command Line Execution through SQL Injection.... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-1307 Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-22344 Use of hard-coded credentials vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to obtain the password of the debug tool and exe... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-22336 Path traversal vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to upload a specially crafted file to an arbitrary directory. A... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-42888 Unauth. Privilege Escalation vulnerability in ARMember premium plugin <= 5.5.1 on WordPress. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-45359 Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-36972 This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific flaw exists within the ProfileDaoImpl class. A crafted reques... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-22920 A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a factory default misconfiguration intended for testing purposes. A remote attacker c... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-36974 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the ex... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-36975 This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific flaw exists within the ProfileDaoImpl class. A crafted reques... | 9.8 | CRITICAL | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.