Vulnerabilidades CVE
Base de dados CVE enriquecida com CISA KEV e NVD
| CVE ID | CVSS | Severidade | KEV | Avistamentos |
|---|---|---|---|---|
| CVE-2023-43457 An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/admin/?page=user/ endpoint. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-48312 capsule-proxy is a reverse proxy for the capsule operator project. Affected versions are subject to a privilege escalation vulnerability which is based on a missing check if the user is authenticated ... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-48930 xinhu xinhuoa 2.2.1 contains a File upload vulnerability. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-22524 Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and Mac... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-45347 Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_verified' parameter of the routers/user-router.php resource does not validate the chara... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-48849 Ruijie EG Series Routers version EG_3.0(1)B11P216 and before allows unauthenticated attackers to remotely execute arbitrary code due to incorrect filtering. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-46773 Permission management vulnerability in the PMS module. Successful exploitation of this vulnerability may cause privilege escalation. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-45019 Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'category' parameter of the category.php resource does not validate the characters received ... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-45797 A Buffer overflow vulnerability in DreamSecurity MagicLine4NX versions 1.0.0.1 to 1.0.0.26 allows an attacker to remotely execute code. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-45336 Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'password' parameter of the routers/router.php resource does not validate the characters r... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-36655 The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login and obtain an authentication token by specifying a u... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-46353 In the module "Product Tag Icons Pro" (ticons) before 1.8.4 from MyPresta.eu for PrestaShop, a guest can perform SQL injection. The method TiconProduct::getTiconByProductAndTicon() has sensitive SQL c... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-5761 The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'url' parameter in versions 1.4.0 to 1.4.6.1 (free) and versions 1.4.0 to 1.... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-52262 outdoorbits little-backup-box (aka Little Backup Box) before f39f91c allows remote attackers to execute arbitrary code because the PHP extract function is used for untrusted input. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-50589 Grupo Embras GEOSIAP ERP v2.2.167.02 was discovered to contain a SQL injection vulnerability via the codLogin parameter on the login page. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-51136 TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formRebootSchedule. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-51135 TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formPasswordSetup. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-35071 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MRV Tech Logging Administration Panel allows SQL Injection.This issue affects Logging Administrati... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-47204 Unsafe YAML deserialization in yaml.Loader in transmute-core before 1.13.5 allows attackers to execute arbitrary Python code. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-33635 When malicious images are pulled by isula pull, attackers can execute arbitrary code. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-48823 A Blind SQL injection issue in ajax.php in GaatiTrack Courier Management System 1.0 allows an unauthenticated attacker to inject a payload via the email parameter during login. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-51133 TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formRoute. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-52252 Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow-Origin for the Remote upload endpoint. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-49624 Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cancelid' parameter of the material_bill.php resource does not validate the characters received and ... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-5838 Insufficient Session Expiration in GitHub repository linkstackorg/linkstack prior to v4.2.9. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-3767 An OS command injection vulnerability has been found on EasyPHP Webserver affecting version 14.1. This vulnerability could allow an attacker to get full access to the system by sending a specially cr... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-48860 TOTOLINK N300RT version 3.2.4-B20180730.0906 has a post-authentication RCE due to incorrect access control, allows attackers can bypass front-end security restrictions and execute arbitrary code. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-35039 Improper Restriction of Excessive Authentication Attempts vulnerability in Be Devious Web Development Password Reset with Code for WordPress REST API allows Authentication Abuse.This issue affects Pas... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-49424 Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-41544 SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport/loadTableData component. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-41543 SQL injection vulnerability in jeecg-boot v3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the component /sys/replicate/check. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-41542 SQL injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the jmreport/qurestSql component. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-49633 Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'buyer_address' parameter of the buyer_detail_submit.php resource does not validate the characters re... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-49425 Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterCfg . | 9.8 | CRITICAL | — | 0 |
| CVE-2023-45018 Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the includes/login.php resource does not validate the characters rec... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-5991 The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-45015 Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'date' parameter of the bus_info.php resource does not validate the characters received and ... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-45323 Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'name' parameter of the routers/add-item.php resource does not validate the characters rec... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-45012 Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'user_email' parameter of the bus_info.php resource does not validate the characters receive... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-45325 Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'address' parameter of the routers/add-users.php resource does not validate the characters... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-49426 Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-49428 Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-51102 Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formWifiMacFilterSet. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-51100 Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formGetDiagnoseInfo . | 9.8 | CRITICAL | — | 0 |
| CVE-2023-51099 Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formexeCommand . | 9.8 | CRITICAL | — | 0 |
| CVE-2023-45334 Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'status' parameter of the routers/edit-orders.php resource does not validate the character... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-51098 Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formSetDiagnoseInfo . | 9.8 | CRITICAL | — | 0 |
| CVE-2023-51093 Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function fromSetLocalVlanInfo. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-51092 Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function upgrade. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-46570 An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32 function of libr/arch/p/nds32/nds32-dis.h. | 9.8 | CRITICAL | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.