Critical · CVSS 9.8
In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20210009; Issue ID: OSBNB00123234.
Published Feb 6, 2023 · Updated Mar 26, 2025
Medium · CVSS 5.4
Cross Site Scripting (XSS) vulnerability in Teradek Clip all firmware versions allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue.
Published Feb 3, 2023 · Updated Mar 26, 2025
Critical · CVSS 9.8
In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20210009; Issue ID: OSBNB00123234.
Published Feb 6, 2023 · Updated Mar 26, 2025
Critical · CVSS 9.8
In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20210009; Issue ID: OSBNB00123234.
Published Feb 6, 2023 · Updated Mar 26, 2025
High · CVSS 7.5
An Untrusted Pointer Dereference was discovered in function mrb_vm_exec in mruby before 3.1.0-rc. The vulnerability causes a segmentation fault and application crash.
Published Feb 14, 2023 · Updated Mar 20, 2025
Critical · CVSS 9.8
Double Free vulnerability in virtualsquare picoTCP v1.7.0 and picoTCP-NG v2.1 in modules/pico_fragments.c in function pico_fragments_reassemble, allows attackers to execute arbitrary code.
Published Feb 15, 2023 · Updated Mar 20, 2025
Medium · CVSS 6.5
Cross Site Request Forgery (CSRF) vulnerability in baijiacms 4.1.4, allows attackers to change the password or other information of an arbitrary account via index.php.
Published Feb 15, 2023 · Updated Mar 20, 2025
Critical · CVSS 9.8
SQL Injection vulnerability in nitinparashar30 cms-corephp through commit bdabe52ef282846823bda102728a35506d0ec8f9 (May 19, 2021) allows unauthenticated attackers to gain escilated privledges via a crafted login.
Published Feb 15, 2023 · Updated Mar 20, 2025
High · CVSS 7.5
SQL Injection vulnerability in SEO Panel 4.9.0 in api/user.api.php in function getUserName in the username parameter, allows attackers to gain sensitive information.
Published Feb 15, 2023 · Updated Mar 20, 2025
High · CVSS 7.5
SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to /api/sys_msg/list/1/10.
Published Feb 15, 2023 · Updated Mar 20, 2025
Medium · CVSS 6.1
A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script, textarea, noframes, iframe, or xmp in allowed tags the keyword argument strip_comments=False Note: none of the above tags are in the default allowed tags and strip_comments defaults to True.
Published Feb 16, 2023 · Updated Mar 19, 2025
High · CVSS 7.5
SQL Injection vulnerability in Exponent-CMS v.2.6.0 fixed in 2.7.0 allows attackers to gain access to sensitive information via the selectValue function in the expConfig class.
Published Feb 17, 2023 · Updated Mar 19, 2025
Medium · CVSS 5.4
Cross site scripting (XSS) vulnerability in flatCore-CMS 2.2.15 allows attackers to execute arbitrary code via description field on the new page creation form.
Published Feb 16, 2023 · Updated Mar 19, 2025
Critical · CVSS 9.8
Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures.
Published Feb 16, 2023 · Updated Mar 19, 2025
High · CVSS 7.8
Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to escalate privileges via the LibRaw_buffer_datastream::gets(char*, int) in /src/libraw/src/libraw_datastream.cpp.
Published Feb 17, 2023 · Updated Mar 19, 2025
High · CVSS 8.8
An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5.1.2, 5.1.1 5.1, 5.0rc3, 5.0rc2, 5.0rc1, 5.0.9, 5.0.8, 5.0.7, 5.0.6, 5.0.5, 5.0.4, 5.0.3, 5.0.2, 5.0.10, 5.0.1, 5.0, 4.3.9, 4.3.8, 4.3.7, 4.3.6, 4.3.5, 4.3.4, 4.3.3, 4.3.20, 4 allows attacker to access sensitive information via the RSS feed protlet.
Published Feb 17, 2023 · Updated Mar 19, 2025
High · CVSS 8.1
An issue in Php-Fusion v9.03.90 fixed in v9.10.00 allows authenticated attackers to cause a Distributed Denial of Service via the Polling feature.
Published Feb 17, 2023 · Updated Mar 19, 2025
Critical · CVSS 9.8
Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization.
Published Feb 17, 2023 · Updated Mar 18, 2025
Medium · CVSS 5.3
An issue in Schism Tracker v20200412 fixed in v.20200412 allows attacker to obtain sensitive information via the fmt_mtm_load_song function in fmt/mtm.c.
Published Feb 17, 2023 · Updated Mar 18, 2025
Critical · CVSS 9.8
Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/modules/status.py file. NOTE: this is disputed by third parties because an attacker cannot influence the eval input
Published Feb 17, 2023 · Updated Mar 18, 2025
Critical · CVSS 9.8
An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.
Published Feb 17, 2023 · Updated Mar 18, 2025
Critical · CVSS 9.8
SQL injection vulnerability in FantasticLBP Hotels Server v1.0 allows attacker to execute arbitrary code via the username parameter.
Published Feb 17, 2023 · Updated Mar 18, 2025
Critical · CVSS 9.8
An issue in FeMiner WMS v1.1 allows attackers to execute arbitrary code via the filename parameter and the exec function.
Published Feb 17, 2023 · Updated Mar 18, 2025
High · CVSS 7.5
An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function.
Published Feb 17, 2023 · Updated Mar 18, 2025
High · CVSS 7.8
Buffer Overflow vulnerability in Dvidelabs flatcc v.0.6.0 allows local attacker to execute arbitrary code via the fltacc execution of the error_ref_sym function.
Published Feb 17, 2023 · Updated Mar 18, 2025
Critical · CVSS 9.8
File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker to execute arbitrary remote code via the Upfile function of the extend/tools/Ueditor endpoint.
Published Feb 17, 2023 · Updated Mar 18, 2025
High · CVSS 8.8
Permissions vulnerability in LIZHIFAKA v.2.2.0 allows authenticated attacker to execute arbitrary commands via the set password function in the admin/index/email location.
Published Feb 17, 2023 · Updated Mar 18, 2025
Critical · CVSS 9.8
An issue in ttyd v.1.6.3 allows attacker to execute arbitrary code via default configuration permissions.
Published Feb 17, 2023 · Updated Mar 18, 2025
Medium · CVSS 5.6
The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to perform privileged actions.
Published Feb 17, 2023 · Updated Mar 18, 2025
Low · CVSS 2.3
An error related to the 2-factor authorization (2FA) on the RISC Platform prior to the saas-2021-12-29 release can potentially be exploited to bypass the 2FA. The vulnerability requires that the 2FA setup hasn’t been completed.
Published Feb 7, 2025 · Updated Mar 13, 2025
Critical · CVSS 9.6
Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request.
Published Feb 24, 2023 · Updated Mar 12, 2025
Medium · CVSS 4
A vulnerability, which was classified as problematic, has been found in NHN TOAST UI Chart 4.1.4. This issue affects some unknown processing of the component Legend Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 4.2.0 is able to address this issue. The identifier of the patch is 1a3f455d17df379e11b501bb5ba1dd1bcc41d63e. It is recommended to upgrade the affected component. The identifier VDB-221501 was assigned to this vulnerability.
Published Feb 22, 2023 · Updated Mar 12, 2025
High · CVSS 8.8
Cross Site Request Forgery (CSRF) vulnerability in taoCMS 3.0.2 allows remote attackers to gain escalated privileges via taocms/admin/admin.php.
Published Feb 24, 2023 · Updated Mar 12, 2025
High · CVSS 7.5
SQL injection vulnerability in sourcecodester online-book-store 1.0 allows remote attackers to view sensitive information via the id paremeter in application URL.
Published Feb 24, 2023 · Updated Mar 12, 2025
Critical · CVSS 9.8
An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function.
Published Feb 24, 2023 · Updated Mar 12, 2025
Unknown · CVSS Not scored
Buffer Overflow vulnerability in Freeimage v3.18.0 allows attacker to cause a denial of service via a crafted JXR file.
Published Feb 22, 2023 · Updated Mar 12, 2025
Unknown · CVSS Not scored
File Upload vulnerability in balerocms-src 0.8.3 allows remote attackers to run arbitrary code via rich text editor on /admin/main/mod-blog page.
Published Feb 24, 2023 · Updated Mar 12, 2025
Unknown · CVSS Not scored
Arbitrary File Read vulnerability found in Peacexie ImCat v.5.2 fixed in v.5.4 allows attackers to obtain sensitive information via the filtering_get_contents function.
Published Feb 24, 2023 · Updated Mar 12, 2025
Unknown · CVSS Not scored
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in Apple Music 3.5.0 for Android. An attacker in a privileged network position can track a user's activity.
Published Feb 27, 2023 · Updated Mar 11, 2025
Critical · CVSS 9.6
Lack of proper validation in HCI Host stack initialization can cause a crash of the bluetooth stack
Published Feb 26, 2023 · Updated Mar 11, 2025
Medium · CVSS 6.2
HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of HyperKit, `virtio.c` has is a call to `vc_cfgread` that does not check for null which when called makes the host crash. This issue may lead to a guest crashing the host causing a denial of service. This issue is fixed in commit df0e46c7dbfd81a957d85e449ba41b52f6f7beb4.
Published Feb 17, 2023 · Updated Mar 10, 2025
Medium · CVSS 6.2
HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of HyperKit, ` vi_pci_write` has is a call to `vc_cfgwrite` that does not check for null which when called makes the host crash. This issue may lead to a guest crashing the host causing a denial of service. This issue is fixed in commit 451558fe8aaa8b24e02e34106e3bb9fe41d7ad13.
Published Feb 17, 2023 · Updated Mar 10, 2025
High · CVSS 7.7
HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of HyperKit, the implementation of `qnotify` at `pci_vtrnd_notify` fails to check the return value of `vq_getchain`. This leads to `struct iovec iov;` being uninitialized and used to read memory in `len = (int) read(sc->vrsc_fd, iov.iov_base, iov.iov_len);` when an attacker is able to make `vq_getchain` fail. This issue may lead to a guest crashing the host causing a denial of service and, under certain circumstance, memory corruption. This issue is fixed in commit 41272a980197917df8e58ff90642d14dec8fe948.
Published Feb 17, 2023 · Updated Mar 10, 2025
High · CVSS 7.7
HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107, function `pci_vtsock_proc_tx` in `virtio-sock` can lead to to uninitialized memory use. In this situation, there is a check for the return value to be less or equal to `VTSOCK_MAXSEGS`, but that check is not sufficient because the function can return `-1` if it finds an error it cannot recover from. Moreover, the negative return value will be used by `iovec_pull` in a while condition that can further lead to more corruption because the function is not designed to handle a negative `iov_len`. This issue may lead to a guest crashing the host causing a denial of service and, under certain circumstance, memory corruption. This issue is fixed in commit af5eba2360a7351c08dfd9767d9be863a50ebaba.
Published Feb 17, 2023 · Updated Mar 10, 2025
High · CVSS 7.1
HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior, a malicious guest can trigger a vulnerability in the host by abusing the disk driver that may lead to the disclosure of the host memory into the virtualized guest. This issue is fixed in commit cf60095a4d8c3cb2e182a14415467afd356e982f.
Published Feb 20, 2023 · Updated Mar 10, 2025
High · CVSS 7.5
Octobox is software for managing GitHub notifications. Prior to pull request (PR) 2807, a user of the system can provide a specifically crafted search query string that will trigger a ReDoS vulnerability. This issue is fixed in PR 2807.
Published Feb 20, 2023 · Updated Mar 10, 2025
Medium · CVSS 6.1
jQuery MiniColors is a color picker built on jQuery. Prior to version 2.3.6, jQuery MiniColors is prone to cross-site scripting when handling untrusted color names. This issue is patched in version 2.3.6.
Published Feb 20, 2023 · Updated Mar 10, 2025
Medium · CVSS 6.1
Mind-elixir is a free, open source mind map core. Prior to version 0.18.1, mind-elixir is prone to cross-site scripting when handling untrusted menus. This issue is patched in version 0.18.1
Published Feb 20, 2023 · Updated Mar 10, 2025
Medium · CVSS 5.4
Countly, a product analytics solution, is vulnerable to cross-site scripting prior to version 21.11 of the community edition. The victim must follow a malicious link or be redirected there from malicious web site. The attacker must have an account or be able to create one. This issue is patched in version 21.11.
Published Feb 20, 2023 · Updated Mar 10, 2025
Medium · CVSS 6.1
Erxes, an experience operating system (XOS) with a set of plugins, is vulnerable to cross-site scripting in versions 0.22.3 and prior. This results in client-side code execution. The victim must follow a malicious link or be redirected there from malicious web site. There are no known patches.
Published Feb 20, 2023 · Updated Mar 10, 2025