High · CVSS 7.5
The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory access.
Published Jan 6, 2023 · Updated Apr 10, 2025
Medium · CVSS 4
A vulnerability was found in slackero phpwcms up to 1.9.26. It has been classified as problematic. This affects an unknown part of the component SVG File Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.9.27 is able to address this issue. The patch is named b39db9c7ad3800f319195ff0e26a0981395b1c54. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217419.
Published Jan 4, 2023 · Updated Apr 10, 2025
High · CVSS 7.1
DES cipher, which has inadequate encryption strength, is used Hitachi Energy FOXMAN-UN to encrypt user credentials used to access the Network Elements. Successful exploitation allows sensitive information to be decrypted easily. This issue affects
* FOXMAN-UN product: FOXMAN-UN R16A, FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B, FOXMAN-UN R14A, FOXMAN-UN R11B, FOXMAN-UN R11A, FOXMAN-UN R10C, FOXMAN-UN R9C;
* UNEM product: UNEM R16A, UNEM R15B, UNEM R15A, UNEM R14B, UNEM R14A, UNEM R11B, UNEM R11A, UNEM R10C, UNEM R9C.
List of CPEs:
* cpe:2.3:a:hitachienergy:foxman-un:R16A:*:*:*:*:*:*:*
* cpe:2.3:a:hitachienergy:foxman-un:R15B:*:*:*:*:*:*:*
* cpe:2.3:a:hitachienergy:foxman-un:R15A:*:*:*:*:*:*:*
* cpe:2.3:a:hitachienergy:foxman-un:R14B:*:*:*:*:*:*:*
* cpe:2.3:a:hitachienergy:foxman-un:R14A:*:*:*:*:*:*:*
* cpe:2.3:a:hitachienergy:foxman-un:R11B:*:*:*:*:*:*:*
* cpe:2.3:a:hitachienergy:foxman-un:R11A:*:*:*:*:*:*:*
* cpe:2.3:a:hitachienergy:foxman-un:R10C:*:*:*:*:*:*:*
* cpe:2.3:a:hitachienergy:foxman-un:R9C:*:*:*:*:*:*:*
* cpe:2.3:a:hitachienergy:unem:R16A:*:*:*:*:*:*:*
* cpe:2.3:a:hitachienergy:unem:R15B:*:*:*:*:*:*:*
* cpe:2.3:a:hitachienergy:unem:R15A:*:*:*:*:*:*:*
* cpe:2.3:a:hitachienergy:unem:R14B:*:*:*:*:*:*:*
* cpe:2.3:a:hitachienergy:unem:R14A:*:*:*:*:*:*:*
* cpe:2.3:a:hitachienergy:unem:R11B:*:*:*:*:*:*:*
* cpe:2.3:a:hitachienergy:unem:R11A:*:*:*:*:*:*:*
* cpe:2.3:a:hitachienergy:unem:R10C:*:*:*:*:*:*:*
* cpe:2.3:a:hitachienergy:unem:R9C:*:*:*:*:*:*:*
Published Jan 5, 2023 · Updated Apr 10, 2025
Medium · CVSS 5.5
A vulnerability classified as problematic was found in Talend Open Studio for MDM. This vulnerability affects unknown code of the component XML Handler. The manipulation leads to xml external entity reference. The patch is identified as 31d442b9fb1d518128fd18f6e4d54e06c3d67793. It is recommended to apply a patch to fix this issue. VDB-217666 is the identifier assigned to this vulnerability.
Published Jan 9, 2023 · Updated Apr 9, 2025
Critical · CVSS 9.6
usb device bluetooth class includes a buffer overflow related to implementation of net_buf_add_mem.
Published Jan 11, 2023 · Updated Apr 9, 2025
Medium · CVSS 6.1
tag.ex in Phoenix Phoenix.HTML (aka phoenix_html) before 3.0.4 allows XSS in HEEx class attributes.
Published Jan 10, 2023 · Updated Apr 9, 2025
High · CVSS 7.8
Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code execution.
Published Jan 10, 2023 · Updated Apr 9, 2025
Medium · CVSS 5.5
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.
Published Jan 10, 2023 · Updated Apr 9, 2025
Medium · CVSS 4.7
A TOCTOU (time-of-check to time-of-use) vulnerability exists where an attacker may use a compromised BIOS to cause the TEE OS to read memory out of bounds that could potentially result in a denial of service.
Published Jan 10, 2023 · Updated Apr 9, 2025
Medium · CVSS 4.4
Failure to verify the mode of CPU execution at the time of SNP_INIT may lead to a potential loss of memory integrity for SNP guests.
Published Jan 10, 2023 · Updated Apr 9, 2025
Medium · CVSS 5.5
Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in a potential denial-of-service.
Published Jan 10, 2023 · Updated Apr 9, 2025
Medium · CVSS 4.4
Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity in the SNP guest.
Published Jan 10, 2023 · Updated Apr 9, 2025
High · CVSS 7.8
Insufficient bounds checking in SEV-ES may allow an attacker to corrupt Reverse Map table (RMP) memory, potentially resulting in a loss of SNP (Secure Nested Paging) memory integrity.
Published Jan 10, 2023 · Updated Apr 9, 2025
Medium · CVSS 6.1
Insufficient input validation in the ASP may allow an attacker with physical access, unauthorized write access to memory potentially leading to a loss of integrity or denial of service.
Published Jan 10, 2023 · Updated Apr 9, 2025
Medium · CVSS 5.5
Insufficient input validation in SEV firmware may allow an attacker to perform out-of-bounds memory reads within the ASP boot loader, potentially leading to a denial of service.
Published Jan 10, 2023 · Updated Apr 9, 2025
High · CVSS 7.1
Insufficient input validation in SVC_ECC_PRIMITIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure Processor) OS memory which may lead to potential loss of integrity and availability.
Published Jan 10, 2023 · Updated Apr 9, 2025
Medium · CVSS 5.5
Insufficient input validation during parsing of the System Management Mode (SMM) binary may allow a maliciously crafted SMM executable binary to corrupt Dynamic Root of Trust for Measurement (DRTM) user application memory that may result in a potential denial of service.
Published Jan 10, 2023 · Updated Apr 9, 2025
Medium · CVSS 5.5
A vulnerability was found in WebPA up to 3.1.1. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to sql injection. Upgrading to version 3.1.2 is able to address this issue. The identifier of the patch is 8836c4f549181e885a68e0e7ca561fdbcbd04bf0. It is recommended to upgrade the affected component. The identifier VDB-217637 was assigned to this vulnerability.
Published Jan 8, 2023 · Updated Apr 9, 2025
Medium · CVSS 4
A vulnerability, which was classified as problematic, has been found in 01-Scripts 01ACP. This issue affects some unknown processing. The manipulation of the argument $_SERVER['SCRIPT_NAME'] leads to cross site scripting. The attack may be initiated remotely. The identifier of the patch is a16eb7da46ed22bc61067c212635394f2571d3c4. It is recommended to apply a patch to fix this issue. The identifier VDB-217649 was assigned to this vulnerability.
Published Jan 8, 2023 · Updated Apr 9, 2025
Medium · CVSS 6.1
Cross Site Scripting (XSS) in Tasmota firmware 6.5.0 allows remote attackers to inject JavaScript code via a crafted string in the field "Friendly Name 1".
Published Jan 9, 2023 · Updated Apr 9, 2025
High · CVSS 7.8
Insufficient input validation in SYS_KEY_DERIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure Processor) OS memory which may lead to potential arbitrary code execution.
Published Jan 10, 2023 · Updated Apr 9, 2025
Medium · CVSS 5.5
Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure.
Published Jan 10, 2023 · Updated Apr 9, 2025
High · CVSS 7.1
Insufficient bounds checking in ASP (AMD Secure Processor) firmware while handling BIOS mailbox commands, may allow an attacker to write partially-controlled data out-of-bounds to SMM or SEV-ES regions which may lead to a potential loss of integrity and availability.
Published Jan 10, 2023 · Updated Apr 8, 2025
Medium · CVSS 6.5
Insufficient checks in SEV may lead to a malicious hypervisor disclosing the launch secret potentially resulting in compromise of VM confidentiality.
Published Jan 10, 2023 · Updated Apr 8, 2025
Medium · CVSS 5.5
Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure.
Published Jan 10, 2023 · Updated Apr 8, 2025
Medium · CVSS 5.5
A randomly generated Initialization Vector (IV) may lead to a collision of IVs with the same key potentially resulting in information disclosure.
Published Jan 10, 2023 · Updated Apr 8, 2025
High · CVSS 7.8
Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.3 allows API calls to expose credentials in plain text.
Published Jan 13, 2023 · Updated Apr 7, 2025
Medium · CVSS 6.1
An issue was discovered in Nim before 1.6.2. The RST module of the Nim language stdlib, as used in NimForum and other products, permits the javascript: URI scheme and thus can lead to XSS in some applications. (Nim versions 1.6.2 and later are fixed; there may be backports of the fix to some earlier versions. NimForum 2.2.0 is fixed.)
Published Jan 13, 2023 · Updated Apr 7, 2025
High · CVSS 7.5
Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.
Published Jan 18, 2023 · Updated Apr 4, 2025
High · CVSS 8
An issue was discovered in function httpProcDataSrv in TL-WDR7660 2.0.30 that allows attackers to execute arbitrary code.
Published Jan 19, 2023 · Updated Apr 4, 2025
High · CVSS 7.8
When processing files, malloc stores the data of the current line. When processing comments, malloc incorrectly accesses the released memory (use after free).
Published Jan 20, 2023 · Updated Apr 3, 2025
Medium · CVSS 5.3
It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happening only in the situation when zOSMF doesn’t have the APAR PH12143 applied. This issue affects: 1.16 versions to 1.19. What happens is that the services using the ZAAS client or the API ML API to query will be deceived into believing the information in the JWT token is valid when it isn’t. It’s possible to use this to persuade the southbound service that different user is authenticated.
Published Jan 18, 2023 · Updated Apr 3, 2025
High · CVSS 8.8
When uploading an image file to a bulletin board developed with XpressEngine, a vulnerability in which an arbitrary file can be uploaded due to insufficient verification of the file. A remote attacker can use this vulnerability to execute arbitrary code on the server where the bulletin board is running.
Published Jan 20, 2023 · Updated Apr 3, 2025
High · CVSS 8.8
SQL-Injection vulnerability caused by the lack of verification of input values for the table name of DB used by the Mangboard bulletin board. A remote attacker can use this vulnerability to execute arbitrary code on the server where the bulletin board is running.
Published Jan 20, 2023 · Updated Apr 3, 2025
High · CVSS 8.8
Session fixation vulnerability in CuppaCMS thru commit 4c9b742b23b924cf4c1f943f48b278e06a17e297 on November 12, 2019 allows attackers to gain access to arbitrary user sessions.
Published Jan 20, 2023 · Updated Apr 3, 2025
High · CVSS 7.5
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be forged due to a weak default URL signing key.
Published Jan 23, 2023 · Updated Apr 2, 2025
Critical · CVSS 9.8
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An attacker can authenticate with the web socket service of the ONLYOFFICE document editor which is protected by JWT auth by using a default JWT signing key.
Published Jan 23, 2023 · Updated Apr 2, 2025
Medium · CVSS 6.1
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS). The "macros" feature of the document editor allows malicious cross site scripting payloads to be used.
Published Jan 23, 2023 · Updated Apr 2, 2025
High · CVSS 7.5
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the document editor allows attackers to edit documents without authentication.
Published Jan 23, 2023 · Updated Apr 2, 2025
Medium · CVSS 5.3
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Improper Input Validation. A lack of input validation can allow an attacker to spoof the names of users who interact with a document, if the document id is known.
Published Jan 23, 2023 · Updated Apr 2, 2025
High · CVSS 8.1
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Server-Side Request Forgery (SSRF). The document editor service can be abused to read and serve arbitrary URLs as a document.
Published Jan 23, 2023 · Updated Apr 2, 2025
High · CVSS 7.5
The Passster WordPress plugin before 3.5.5.9 does not properly check for password, as well as that the post to be viewed is public, allowing unauthenticated users to bypass the protection offered by the plugin, and access arbitrary posts (such as private) content, by sending a specifically crafted request.
Published Jan 23, 2023 · Updated Apr 2, 2025
Medium · CVSS 5.4
HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced.
User should be locked out for multiple invalid attempts.
Published Jan 19, 2023 · Updated Apr 2, 2025
Medium · CVSS 5.5
When a file is processed, an infinite loop occurs in next_inline() of the more_curly() function.
Published Jan 20, 2023 · Updated Apr 2, 2025
Medium · CVSS 4.2
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 stores potentially sensitive information in log files that could be read by a privileged user. IBM X-Force ID: 213645.
Published Jan 20, 2023 · Updated Apr 2, 2025
Medium · CVSS 5.3
For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invalid Type-Length-Value (TLV) causes the PTP agent to restart. Repeated restarts of the service will make the service unavailable.
Published Jan 24, 2023 · Updated Apr 1, 2025
Medium · CVSS 5.4
Cross Site Scripting (XSS) vulnerability in yapi 1.9.1 allows attackers to execute arbitrary code via the /interface/api edit page.
Published Jan 26, 2023 · Updated Apr 1, 2025
High · CVSS 7.8
Qlik NPrinting Designer through 21.14.3.0 creates a Temporary File in a Directory with Insecure Permissions.
Published Jan 26, 2023 · Updated Apr 1, 2025
High · CVSS 7.8
Qlik QlikView through 12.60.20100.0 creates a Temporary File in a Directory with Insecure Permissions.
Published Jan 26, 2023 · Updated Apr 1, 2025
Medium · CVSS 4.3
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow an authenticated user to obtain sensitive information from a specially crafted HTTP request. IBM X-Force ID: 216387.
Published Jan 20, 2023 · Updated Mar 31, 2025