Unknown · CVSS Not scored
In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary system commands after obtaining authorization.
Published Apr 27, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts.
Published Apr 7, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privileges in Franklin Fueling Systems Colibri Controller Module 1.8.19.8580.
Published Apr 7, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in ZZCMS 2021. There is a cross-site scripting (XSS) vulnerability in ad_manage.php.
Published Apr 8, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in ZZCMS 2021. There is a SQL injection vulnerability in ad_manage.php.
Published Apr 8, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Franklin Fueling Systems FFS T5 Series 1.8.7.7299 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information.
Published Apr 27, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An access control issue in the authentication module of wizplat PD065 v1.19 allows attackers to access sensitive data and cause a Denial of Service (DoS).
Published Apr 13, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Telesquare TLR-2005KSH 1.0.0 is affected by an unauthenticated file download vulnerability that allows a remote attacker to download a full configuration file.
Published Apr 27, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Franklin Fueling Systems FFS TS-550 evo 2.23.4.8936 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information.
Published Apr 27, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication.
Published Apr 27, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated attacker can upload a PHP file and bypass the .htacess configuration to deny execution of .php files in media and files directory by default.
Published Apr 8, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Tp-Link TL-WR840N (EU) v6.20 Firmware (0.9.1 4.17 v0001.0 Build 201124 Rel.64328n) is vulnerable to Buffer Overflow via the Password reset feature.
Published Apr 18, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
It is possible to obtain the first administrator's hash set up on the system in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) as well as other information such as MAC address, internal IP address etc. by performing a request to the /module/api.php?mobile/webNasIPS endpoint.
Published Apr 25, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4., that allows attackers to escalate privileges within the application, since all permission checks are done client-side, not server-side.
Published Apr 5, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending a specifically crafted input to /tos/index.php?app/del.
Published Apr 25, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending specifically crafted input to /tos/index.php?app/app_start_stop.
Published Apr 25, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the user's password hash. Guest users (disabled by default) can be abused using a null/empty hash and allow an unauthenticated attacker to login as guest.
Published Apr 25, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is Improper Handling of Case Sensitivity, which makes password guessing easier.
Published Apr 5, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is storage of Passwords in a Recoverable Format.
Published Apr 5, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is Cleartext Transmission of Sensitive Information.
Published Apr 5, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
It is possible to obtain the first administrator's hash set up in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) on the system as well as other information such as MAC address, internal IP address etc. by performing a request to the /module/api.php?mobile/wapNasIPS endpoint.
Published Apr 25, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An authenticated attacker can execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by injecting a maliciously crafted input in the request through /tos/index.php?app/hand_app.
Published Apr 25, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in COINS Construction Cloud 11.12. Due to an inappropriate use of HTML IFRAME elements, the file upload functionality is vulnerable to a persistent Cross-Site Scripting (XSS) attack.
Published Apr 14, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker who can capture HTCondor network data can interfere with users' jobs and data.
Published Apr 6, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An XSS issue was discovered in COINS Construction Cloud 11.12. Due to insufficient neutralization of user input in the description of a task, it is possible to store malicious JavaScript code in the task description. This is later executed when it is reflected back to the user.
Published Apr 14, 2022 · Updated Aug 4, 2024
High · CVSS 7.1
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to trigger the creation of demonstration data, including user accounts with known credentials.
Published Apr 25, 2023 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker can access files stored in S3 cloud storage that a user has asked HTCondor to transfer.
Published Apr 6, 2022 · Updated Aug 4, 2024
Medium · CVSS 5.3
Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, via crafted uploaded file names.
Published Apr 25, 2023 · Updated Aug 4, 2024
Medium · CVSS 6.5
Cross-site scripting (XSS) issue in Website app of Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, by posting crafted contents.
Published Apr 25, 2023 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of input validation in calls to do_verify in sr_unix/do_verify.c allows attackers to attempt to jump to a NULL pointer by corrupting a function pointer.
Published Apr 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a call to $Extract to force an signed integer holding the size of a buffer to take on a large negative number, which is then used as the length of a memcpy call that occurs on the stack, causing a buffer overflow.
Published Apr 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of NULL checks in trip_gen in sr_port/emit_code.c allows attackers to crash the application by dereferencing a NULL pointer.
Published Apr 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of NULL checks in calls to ious_open in sr_unix/ious_open.c allows attackers to crash the application by dereferencing a NULL pointer.
Published Apr 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can manipulate the value of a function pointer used in op_write in sr_port/op_write.c in order to gain control of the flow of execution.
Published Apr 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c to result in an extremely large value in order to cause a segmentation fault and crash the application. This is a digs-- calculation.
Published Apr 15, 2022 · Updated Aug 4, 2024
High · CVSS 8.7
A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading to privilege escalation.
Published Apr 25, 2023 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c to result in an extremely large value in order to cause a segmentation fault and crash the application.
Published Apr 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause a call to $Extract to force an signed integer holding the size of a buffer to take on a large negative number, which is then used as the length of a memcpy call that occurs on the stack, causing a buffer overflow.
Published Apr 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause an integer underflow of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c in order to cause a segmentation fault and crash the application. This is a "- digs" subtraction.
Published Apr 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of parameter validation in calls to memcpy in str_tok in sr_unix/ztimeoutroutines.c allows attackers to attempt to read from a NULL pointer.
Published Apr 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.
Published Apr 19, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can control the size of a memset that occurs in calls to util_format in sr_unix/util_output.c.
Published Apr 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a size variable, stored as an signed int, to equal an extremely large value, which is interpreted as a negative value during a check. This value is then used in a memcpy call on the stack, causing a memory segmentation fault.
Published Apr 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of input validation in calls to do_verify in sr_unix/do_verify.c allows attackers to attempt to jump to a NULL pointer by corrupting a function pointer.
Published Apr 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause calls to ZRead to crash due to a NULL pointer dereference.
Published Apr 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can control the size and input to calls to memcpy in op_fnfnumber in sr_port/op_fnfnumber.c in order to corrupt memory or crash the application.
Published Apr 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can control the size variable and buffer that is passed to a call to memcpy. An attacker can use this to overwrite key data structures and gain control of the flow of execution.
Published Apr 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c to result in an extremely large value in order to cause a segmentation fault and crash the application. This is a "- (digs < 1 ? 1 : digs)" subtraction.
Published Apr 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause calls to ZRead to crash due to a NULL pointer dereference.
Published Apr 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of NULL checks in calls to ious_open in sr_unix/ious_open.c allows attackers to crash the application by dereferencing a NULL pointer.
Published Apr 15, 2022 · Updated Aug 4, 2024