Low · CVSS 3.7
An out-of-bounds write vulnerability exists in the URL_decode functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to an out-of-bounds write. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.
Published Feb 4, 2022 · Updated Apr 15, 2025
Critical · CVSS 10
A stack-based buffer overflow vulnerability exists in both the LLMNR functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted network packet can lead to remote code execution. An attacker can send a malicious packet to trigger this vulnerability.
Published Feb 4, 2022 · Updated Apr 15, 2025
Critical · CVSS 10
A stack-based buffer overflow vulnerability exists in the NBNS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted network packet can lead to remote code execution. An attacker can send a malicious packet to trigger this vulnerability.
Published Feb 4, 2022 · Updated Apr 15, 2025
High · CVSS 8.6
A denial of service vulnerability exists in the Modbus configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.
Published Feb 4, 2022 · Updated Apr 15, 2025
High · CVSS 8.6
A denial of service vulnerability exists in the SeaMax remote configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.
Published Feb 4, 2022 · Updated Apr 15, 2025
High · CVSS 8.8
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 11.1.0.52543. A specially-crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially-crafted, malicious site if the browser plugin extension is enabled.
Published Feb 4, 2022 · Updated Apr 15, 2025
High · CVSS 7.7
A misconfiguration exists in the MQTTS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. This misconfiguration significantly simplifies a man-in-the-middle attack, which directly leads to control of device functionality.
Published Feb 4, 2022 · Updated Apr 15, 2025
High · CVSS 8.1
A file write vulnerability exists in the OTA update task functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to arbitrary file overwrite. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.
Published Feb 4, 2022 · Updated Apr 15, 2025
Critical · CVSS 9
A heap-based buffer overflow vulnerability exists in the OTA Update u-download functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A series of specially-crafted MQTT payloads can lead to remote code execution. An attacker must perform a man-in-the-middle attack in order to trigger this vulnerability.
Published Feb 4, 2022 · Updated Apr 15, 2025
High · CVSS 7.8
A heap-based buffer overflow vulnerability exists in the Hword HwordApp.dll functionality of Hancom Office 2020 11.0.0.2353. A specially-crafted malformed file can lead to memory corruption and potential arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published Feb 16, 2022 · Updated Apr 15, 2025
Critical · CVSS 9.6
Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects: ForgeRock Access Management 7.1 versions prior to 7.1.1; 6.5 versions prior to 6.5.4; all previous versions.
Published Feb 14, 2022 · Updated Apr 14, 2025
Critical · CVSS 9.8
SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request.
Published Feb 3, 2023 · Updated Apr 4, 2025
Unknown · CVSS Not scored
A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network attacks.
Published Feb 16, 2022 · Updated Mar 28, 2025
Medium · CVSS 6.5
Buffer Overflow vulnerability in Allegro through 5.2.6 allows attackers to cause a denial of service via crafted PCX/TGA/BMP files to allegro_image addon.
Published Feb 3, 2023 · Updated Mar 27, 2025
High · CVSS 7.5
Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command.
Published Feb 3, 2023 · Updated Mar 27, 2025
Critical · CVSS 9.8
SQL injection vulnerability in native-php-cms 1.0 allows remote attackers to run arbitrary SQL commands via the cat parameter to /list.php file.
Published Feb 3, 2023 · Updated Mar 27, 2025
Critical · CVSS 9.1
Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the source for COPY and MOVE operations.
Published Feb 3, 2023 · Updated Mar 26, 2025
High · CVSS 7.5
SQL injection vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to view sensitive information via /etc/shadow.
Published Feb 3, 2023 · Updated Mar 26, 2025
Medium · CVSS 5.4
Cross Site Scripting (XSS) vulnerability in Teradek Slice 1st generation firmware 7.3.x and earlier allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue.
Published Feb 3, 2023 · Updated Mar 26, 2025
Critical · CVSS 9.1
Directory Traversal vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the target for COPY and MOVE operations.
Published Feb 3, 2023 · Updated Mar 26, 2025
Medium · CVSS 5.4
Cross Site Scripting (XSS) vulnerability in Teradek Cube and Cube Pro firmware version 7.3.x and earlier allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue.
Published Feb 3, 2023 · Updated Mar 26, 2025
High · CVSS 8.8
Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API commands for firmware uploads and installation.
Published Feb 6, 2023 · Updated Mar 26, 2025
Critical · CVSS 9.8
Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.
Published Feb 6, 2023 · Updated Mar 26, 2025
High · CVSS 7.5
Buffer Overflow vulnerability in HDFGroup hdf5-h5dump 1.12.0 through 1.13.0 allows attackers to cause a denial of service via h5tools_str_sprint in /hdf5/tools/lib/h5tools_str.c.
Published Feb 3, 2023 · Updated Mar 26, 2025
High · CVSS 7.5
Buffer Overflow vulnerability in fcitx5 5.0.8 allows attackers to cause a denial of service via crafted message to the application's listening port.
Published Feb 3, 2023 · Updated Mar 26, 2025
High · CVSS 7.5
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: api uri:/sys/user/checkOnlyUser?username=admin.
Published Feb 3, 2023 · Updated Mar 26, 2025
High · CVSS 7.5
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: /sys/user/querySysUser?username=admin.
Published Feb 3, 2023 · Updated Mar 26, 2025
High · CVSS 8.1
Race condition vulnerability discovered in portfolioCMS 1.0 allows remote attackers to run arbitrary code via fileExt parameter to localhost/admin/uploads.php.
Published Feb 3, 2023 · Updated Mar 26, 2025
Medium · CVSS 5.4
Cross Site Scripting (XSS) vulnerability in automad 1.7.5 allows remote attackers to run arbitrary code via the user name field when adding a user.
Published Feb 3, 2023 · Updated Mar 26, 2025
Medium · CVSS 6.1
Universal Cross Site Scripting (UXSS) vulnerability in Vimium Extension 1.66 and earlier allows remote attackers to run arbitrary code via omnibar feature.
Published Feb 3, 2023 · Updated Mar 26, 2025
Medium · CVSS 5.5
Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted authenticattion file.
Published Feb 3, 2023 · Updated Mar 26, 2025
Critical · CVSS 9.8
An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation.
Published Feb 3, 2023 · Updated Mar 26, 2025
Medium · CVSS 5.4
Directory traversal vulnerability in phpcms 1.9.25 allows remote attackers to delete arbitrary files via unfiltered $file parameter to unlink method in include/inc_act/act_ftptakeover.php file.
Published Feb 3, 2023 · Updated Mar 26, 2025
High · CVSS 8.8
File Upload vulnerability in phpwcms 1.9.25 allows remote attackers to run arbitrary code via crafted file upload to include/inc_lib/general.inc.php.
Published Feb 3, 2023 · Updated Mar 26, 2025
Critical · CVSS 9.1
SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check() function in jocms/apps/mask/inc/mask.php.
Published Feb 3, 2023 · Updated Mar 26, 2025
High · CVSS 7.5
SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_set_mask() function in jocms/apps/mask/mask.php.
Published Feb 3, 2023 · Updated Mar 26, 2025
Critical · CVSS 9.1
SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_delete_mask function in jocms/apps/mask/mask.php.
Published Feb 3, 2023 · Updated Mar 26, 2025
Critical · CVSS 9.1
SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check function in jocms/apps/mask/inc/getmask.php.
Published Feb 3, 2023 · Updated Mar 26, 2025
High · CVSS 8.8
Cross Site Request Forgery vulnerability in imcat 5.4 allows remote attackers to escalate privilege via lack of token verification.
Published Feb 3, 2023 · Updated Mar 26, 2025
High · CVSS 8.8
Cross Site Request Forgery (CSRF) vulnerability in imcat 5.4 allows remote attackers to gain escalated privileges via flaws one time token generation on the add administrator page.
Published Feb 3, 2023 · Updated Mar 26, 2025
Critical · CVSS 9.8
SQL injection vulnerability in JIZHICMS 1.9.5 allows attackers to run arbitrary SQL commands via add or edit article page.
Published Feb 3, 2023 · Updated Mar 26, 2025
Medium · CVSS 5.5
Buffer Overflow vulnerability in Cesanta mJS 1.26 allows remote attackers to cause a denial of service via crafted .js file to mjs_set_errorf.
Published Feb 3, 2023 · Updated Mar 26, 2025
Medium · CVSS 5.4
Cross Site Scripting (XSS) vulnerability in Gurock TestRail before 7.1.2 allows remote authenticated attackers to run arbitrary code via the reference field in milestones or description fields in reports.
Published Feb 3, 2023 · Updated Mar 26, 2025
High · CVSS 7.5
Incorrect Access Control issue discovered in tpcms 3.2 allows remote attackers to view sensitive information via path in application URL.
Published Feb 3, 2023 · Updated Mar 26, 2025
Medium · CVSS 5.4
Cross Site Scripting (XSS) vulnerability in tpcms 3.2 allows remote attackers to run arbitrary code via the cfg_copyright or cfg_tel field in Site Configuration page.
Published Feb 3, 2023 · Updated Mar 26, 2025
High · CVSS 7.5
Incorrect Access Control issue discovered in KiteCMS 1.1 allows remote attackers to view sensitive information via path in application URL.
Published Feb 3, 2023 · Updated Mar 26, 2025
High · CVSS 8.8
Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /users/delete/2.
Published Feb 3, 2023 · Updated Mar 26, 2025
High · CVSS 8.8
Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /permissions/delete/2---.
Published Feb 3, 2023 · Updated Mar 26, 2025
Medium · CVSS 6.5
Incorrect Access Control vulnerability in Modern Honey Network commit 0abf0db9cd893c6d5c727d036e1f817c02de4c7b allows remote attackers to view sensitive information via crafted PUT request to Web API.
Published Feb 3, 2023 · Updated Mar 26, 2025
High · CVSS 7.5
An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface.
Published Feb 3, 2023 · Updated Mar 26, 2025