Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 3, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 3, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 3, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 3, 2024
Unknown · CVSS Not scored
In music service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 3, 2024
Unknown · CVSS Not scored
In music service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 3, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 3, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 3, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 3, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 3, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 3, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 3, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 3, 2024
Critical · CVSS 9.1
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). The uninstall-app App-name parameter in the web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.
Published Jul 11, 2023 · Updated Dec 2, 2024
High · CVSS 7.5
NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause execution with unnecessary privileges by leveraging a weakness whereby proper input parameter validation is not performed. A successful exploit of this vulnerability may lead to denial of service, information disclosure, and data tampering.
Published Jul 3, 2023 · Updated Nov 27, 2024
Unknown · CVSS Not scored
AnyDesk 7.0.8 allows remote Denial of Service.
Published Jul 3, 2023 · Updated Nov 27, 2024
Unknown · CVSS Not scored
Cross Site Scripting vulnerability in Maxsite CMS v.108.7 allows a remote attacker to execute arbitrary code via the f_content parameter in the admin/page_new file.
Published Jul 3, 2023 · Updated Nov 27, 2024
Medium · CVSS 6.5
A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of sensitive information.
Published Jul 11, 2023 · Updated Nov 27, 2024
Medium · CVSS 4.4
In iwnpi server, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.
Published Jul 12, 2023 · Updated Nov 27, 2024
Unknown · CVSS Not scored
Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally.
Published Jul 6, 2023 · Updated Nov 27, 2024
Unknown · CVSS Not scored
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
Published Jul 17, 2023 · Updated Nov 27, 2024
Unknown · CVSS Not scored
Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the viewid parameter of the view-pass-detail.php file.
Published Jul 28, 2023 · Updated Nov 27, 2024
Unknown · CVSS Not scored
FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.<constructor>. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple third parties because there are no realistic use cases in which FFmpeg.java uses untrusted input for the path of the executable file.
Published Jul 28, 2023 · Updated Nov 27, 2024
Medium · CVSS 5.9
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). The affected devices are configured to offer weak ciphers by default. This could allow an unauthorized attacker in a man-in-the-middle position to read and modify any data
passed over to and from the affected device.
Published Jul 11, 2023 · Updated Nov 27, 2024
High · CVSS 7.4
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). The webserver of the affected devices support insecure TLS 1.0 protocol. An attacker could achieve a man-in-the-middle attack and compromise confidentiality and integrity of data.
Published Jul 11, 2023 · Updated Nov 27, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) in Sophos Sophos iView (The EOL was December 31st 2020) in grpname parameter that allows arbitrary script to be executed.
Published Jul 5, 2023 · Updated Nov 26, 2024
Unknown · CVSS Not scored
In apu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629578; Issue ID: ALPS07629578.
Published Jul 4, 2023 · Updated Nov 26, 2024
Medium · CVSS 6.7
Memory corruption in Linux when the file upload API is called with parameters having large buffer.
Published Jul 4, 2023 · Updated Nov 26, 2024
Unknown · CVSS Not scored
The CF7 Google Sheets Connector WordPress plugin before 5.0.2, cf7-google-sheets-connector-pro WordPress plugin through 5.0.2 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Published Jul 4, 2023 · Updated Nov 26, 2024
Unknown · CVSS Not scored
All versions of @fastify/oauth2 used a statically generated state parameter at startup time and were used across all requests for all users. The purpose of the Oauth2 state parameter is to prevent Cross-Site-Request-Forgery attacks. As such, it should be unique per user and should be connected to the user's session in some way that will allow the server to validate it.
v7.2.0 changes the default behavior to store the state in a cookie with the http-only and same-site=lax attributes set. The state is now by default generated for every user. Note that this contains a breaking change in the checkStateFunction function, which now accepts the full Request object.
Published Jul 4, 2023 · Updated Nov 26, 2024