High · CVSS 7.5
Due to insufficient length validation in the Open5GS GTP library versions prior to versions 2.4.13 and 2.5.7, when parsing extension headers in GPRS tunneling protocol (GPTv1-U) messages, a protocol payload with any extension header length set to zero causes an infinite loop. The affected process becomes immediately unresponsive, resulting in denial of service and excessive resource consumption. CVSS3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
Published Feb 1, 2023 · Updated Mar 27, 2025
Medium · CVSS 5.5
Permission control vulnerability in the WindowManagerServices module.Successful exploitation of this vulnerability may affect availability.
Published Feb 18, 2024 · Updated Mar 26, 2025
Medium · CVSS 4.3
An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (outage of reader threads).
Published Feb 28, 2024 · Updated Mar 26, 2025
High · CVSS 7.4
An exploitable firmware modification vulnerability was discovered in certain Netgear products. The data integrity of the uploaded firmware image is ensured with a fixed checksum number. Therefore, an attacker can conduct a MITM attack to modify the user-uploaded firmware image and bypass the checksum verification. This affects WNR612v2 Wireless Routers 1.0.0.3 and earlier, DGN1000v3 Modem Router 1.0.0.22 and earlier, D6100 WiFi DSL Modem Routers 1.0.0.63 and earlier, WNR1000v2 Wireless Routers 1.1.2.60 and earlier, XAVN2001v2 Wireless-N Extenders 0.4.0.7 and earlier, WNR2200 Wireless Routers 1.0.1.102 and earlier, WNR2500 Wireless Routers 1.0.0.34 and earlier, R8900 Smart WiFi Routers 1.0.3.6 and earlier, and R9000 Smart WiFi Routers 1.0.3.6 and earlier.
Published Feb 2, 2023 · Updated Mar 26, 2025
Medium · CVSS 6.3
Cross-site Scripting (XSS) - DOM in GitHub repository microweber/microweber prior to 1.3.2.
Published Feb 1, 2023 · Updated Mar 26, 2025
Medium · CVSS 6.5
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.
Published Feb 1, 2023 · Updated Mar 26, 2025
Medium · CVSS 5.4
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.
Published Feb 1, 2023 · Updated Mar 26, 2025
High · CVSS 8.1
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in platform API of IPMI module. A low-privileged user with permission to read logs on the cluster could potentially exploit this vulnerability, leading to Information disclosure and denial of service.
Published Feb 1, 2023 · Updated Mar 26, 2025
Medium · CVSS 6.7
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629572; Issue ID: ALPS07629572.
Published Feb 6, 2023 · Updated Mar 26, 2025
Medium · CVSS 6.7
In ion, there is a possible out of bounds read due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07560720; Issue ID: ALPS07560720.
Published Feb 6, 2023 · Updated Mar 26, 2025
Medium · CVSS 5.9
The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes Ubiquiti airFiber AF2X Radio firmware version 3.2.2 and earlier vulnerable to firmware modification attacks. An attacker can conduct a man-in-the-middle (MITM) attack to modify the new firmware image and bypass the checksum verification.
Published Feb 2, 2023 · Updated Mar 26, 2025
Medium · CVSS 5.9
The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes TRENDnet TV-IP651WI Network Camera firmware version v1.07.01 and earlier vulnerable to firmware modification attacks. An attacker can conduct a man-in-the-middle (MITM) attack to modify the new firmware image and bypass the checksum verification.
Published Feb 2, 2023 · Updated Mar 26, 2025
Medium · CVSS 6.1
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in login.php.
Published Feb 6, 2023 · Updated Mar 26, 2025
Medium · CVSS 6.1
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in navbar.php.
Published Feb 6, 2023 · Updated Mar 26, 2025
Medium · CVSS 6.8
A vulnerability, which was classified as critical, was found in TRENDnet TEW-811DRU 1.0.10.0. This affects an unknown part of the file wan.asp of the component Web Management Interface. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-220017 was assigned to this vulnerability.
Published Feb 2, 2023 · Updated Mar 26, 2025
Medium · CVSS 6.1
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in index.php.
Published Feb 6, 2023 · Updated Mar 26, 2025
High · CVSS 8.3
A vulnerability was found in TRENDnet TEW-652BRP 3.04b01. It has been classified as critical. Affected is an unknown function of the file ping.ccp of the component Web Interface. The manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220020.
Published Feb 2, 2023 · Updated Mar 26, 2025
Medium · CVSS 6.1
Online Food Ordering System v2 was discovered to contain a SQL injection vulnerability via the id parameter at view_order.php.
Published Feb 6, 2023 · Updated Mar 26, 2025
Medium · CVSS 6.7
In vcu, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519184; Issue ID: ALPS07519184.
Published Feb 6, 2023 · Updated Mar 26, 2025
Critical · CVSS 9.8
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingTimeOut parameter in the setNetworkDiag function.
Published Feb 3, 2023 · Updated Mar 26, 2025
Critical · CVSS 9.8
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingNum parameter in the setNetworkDiag function.
Published Feb 3, 2023 · Updated Mar 26, 2025
Critical · CVSS 9.8
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagHost parameter in the setNetworkDiag function.
Published Feb 3, 2023 · Updated Mar 26, 2025
High · CVSS 7.2
In Progress WS_FTP Server before 8.8, it is possible for a host administrator to elevate their privileges via the administrative interface due to insufficient authorization controls applied on user modification workflows.
Published Feb 3, 2023 · Updated Mar 26, 2025
Medium · CVSS 5.4
In Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim.
Published Feb 3, 2023 · Updated Mar 26, 2025
Medium · CVSS 6.5
On versions beginning in 7.1.5 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client for Windows. User interaction and administrative privileges are required to exploit this vulnerability because the victim user needs to run the executable on the system and the attacker requires administrative privileges for modifying the files in the trusted search path. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published Feb 1, 2023 · Updated Mar 26, 2025
High · CVSS 7.5
On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP AFM NAT policy with a destination NAT rule is configured on a FastL4 virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published Feb 1, 2023 · Updated Mar 26, 2025
High · CVSS 7.8
Dell PowerScale OneFS 9.1.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in change password api. A low privilege local attacker could potentially exploit this vulnerability, leading to system takeover.
Published Feb 1, 2023 · Updated Mar 26, 2025
High · CVSS 8.8
Dell EMC prior to version DDOS 7.9 contain(s) an OS command injection Vulnerability. An authenticated non admin attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application.
Published Feb 1, 2023 · Updated Mar 26, 2025
Critical · CVSS 9.8
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingSize parameter in the setNetworkDiag function.
Published Feb 3, 2023 · Updated Mar 26, 2025
Critical · CVSS 9.8
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagTracertHop parameter in the setNetworkDiag function.
Published Feb 3, 2023 · Updated Mar 26, 2025
Critical · CVSS 9.8
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the hour parameter in the setRebootScheCfg function.
Published Feb 3, 2023 · Updated Mar 26, 2025
Critical · CVSS 9.8
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the plugin_version parameter in the setUnloadUserData function.
Published Feb 3, 2023 · Updated Mar 26, 2025
Critical · CVSS 9.8
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the minute parameter in the setRebootScheCfg function.
Published Feb 3, 2023 · Updated Mar 26, 2025
High · CVSS 7.5
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for the telnet service which is stored in the component /etc/config/product.ini.
Published Feb 3, 2023 · Updated Mar 26, 2025
Medium · CVSS 6.7
In vcu, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519159; Issue ID: ALPS07519159.
Published Feb 6, 2023 · Updated Mar 26, 2025
Critical · CVSS 9.8
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php.
Published Feb 6, 2023 · Updated Mar 26, 2025
Medium · CVSS 6.1
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in signup.php.
Published Feb 6, 2023 · Updated Mar 26, 2025
Medium · CVSS 5.4
In Jellyfin 10.8.x through 10.8.3, the name of a collection is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim.
Published Feb 3, 2023 · Updated Mar 26, 2025
Critical · CVSS 9.8
Buffer OverFlow Vulnerability in Barenboim json-parser master and v1.1.0 fixed in v1.1.1 allows an attacker to execute arbitrary code via the json_value_parse function.
Published Feb 3, 2023 · Updated Mar 26, 2025
Critical · CVSS 9.8
An issue was found in MojoJson v1.2.3 allows attackers to execute arbitary code via the destroy function.
Published Feb 3, 2023 · Updated Mar 26, 2025
Critical · CVSS 9.8
Buffer OverFlow Vulnerability in MojoJson v1.2.3 allows an attacker to execute arbitrary code via the SkipString function.
Published Feb 3, 2023 · Updated Mar 26, 2025
High · CVSS 7.9
Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloudpool. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information disclosure.
Published Feb 1, 2023 · Updated Mar 26, 2025
High · CVSS 8.7
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in celog. A low privileges user could potentially exploit this vulnerability, leading to information disclosure and escalation of privileges.
Published Feb 1, 2023 · Updated Mar 26, 2025
High · CVSS 7.5
On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published Feb 1, 2023 · Updated Mar 26, 2025
High · CVSS 7.5
On version 14.1.x before 14.1.5.3, and all versions of 13.1.x, when the BIG-IP APM system is configured with all the following elements, undisclosed requests may cause the Traffic Management Microkernel (TMM) to terminate:
* An OAuth Server that references an OAuth Provider
* An OAuth profile with the Authorization Endpoint set to '/'
* An access profile that references the above OAuth profile and is associated with an HTTPS virtual server
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published Feb 1, 2023 · Updated Mar 26, 2025
High · CVSS 7.8
In versions beginning with 7.2.2 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client Windows Installer. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published Feb 1, 2023 · Updated Mar 26, 2025
High · CVSS 8.5
A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially execute arbitrary code. In appliance mode BIG-IP, a successful exploit of this vulnerability can allow the attacker to cross a security boundary.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published Feb 1, 2023 · Updated Mar 26, 2025
Medium · CVSS 6.1
On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1.5.3, and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This vulnerability allows an unauthenticated malicious attacker to build an open redirect URI. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published Feb 1, 2023 · Updated Mar 26, 2025
High · CVSS 7.5
On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, when a HTTP profile with the non-default Enforcement options of Enforce HTTP Compliance and Unknown Methods: Reject are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published Feb 1, 2023 · Updated Mar 26, 2025
High · CVSS 7
On F5OS-A beginning in version 1.2.0 to before 1.3.0 and F5OS-C beginning in version 1.3.0 to before 1.5.0, processing F5OS tenant file names may allow for command injection. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published Feb 1, 2023 · Updated Mar 26, 2025