Unknown · CVSS Not scored
CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.
Published Jul 6, 2023 · Updated Nov 19, 2024
Unknown · CVSS Not scored
A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upload function.
Published Jul 6, 2023 · Updated Nov 19, 2024
Unknown · CVSS Not scored
TravianZ through 8.3.4 allows XSS via the Alliance tag/name, the statistics page, the link preferences, the Admin Logs, or the COOKUSR cookie.
Published Jul 6, 2023 · Updated Nov 19, 2024
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability in Bagecms v3.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Settings module.
Published Jul 6, 2023 · Updated Nov 19, 2024
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability in the custom variables module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Published Jul 6, 2023 · Updated Nov 19, 2024
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability in the Column management module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Published Jul 6, 2023 · Updated Nov 19, 2024
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability in the Basic Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Published Jul 6, 2023 · Updated Nov 19, 2024
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability in the Image Upload module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Published Jul 6, 2023 · Updated Nov 19, 2024
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability in the Basic Website Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Published Jul 6, 2023 · Updated Nov 19, 2024
Unknown · CVSS Not scored
Vulnerability of apps' permission to access a certain API being incompletely verified in the wireless projection module. Successful exploitation of this vulnerability may affect some wireless projection features.
Published Jul 6, 2023 · Updated Nov 19, 2024
Unknown · CVSS Not scored
Format string vulnerability in the distributed file system. Attackers who bypass the selinux permission can exploit this vulnerability to crash the program.
Published Jul 6, 2023 · Updated Nov 19, 2024
Unknown · CVSS Not scored
Vulnerability of missing input length verification in the distributed file system. Successful exploitation of this vulnerability may cause out-of-bounds read.
Published Jul 6, 2023 · Updated Nov 19, 2024
Unknown · CVSS Not scored
Input verification vulnerability in the WMS API. Successful exploitation of this vulnerability may cause the device to restart.
Published Jul 6, 2023 · Updated Nov 19, 2024
Unknown · CVSS Not scored
Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnerability to rewrite the non-volatile random-access memory (NVRAM), or facilitate the exploitation of other vulnerabilities.
Published Jul 6, 2023 · Updated Nov 19, 2024
Unknown · CVSS Not scored
Buffer overflow vulnerability in the modem pinctrl module. Successful exploitation of this vulnerability may affect the integrity and availability of the modem.
Published Jul 6, 2023 · Updated Nov 19, 2024
Unknown · CVSS Not scored
Vulnerability of incomplete input parameter verification in the communication framework module. Successful exploitation of this vulnerability may affect availability.
Published Jul 6, 2023 · Updated Nov 19, 2024
Critical · CVSS 9.1
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). The SCEP CA Certificate Name parameter in the web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.
Published Jul 11, 2023 · Updated Nov 19, 2024
Unknown · CVSS Not scored
VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagnostic bundle of the application under VMware SD-WAN Management.
Published Jul 6, 2023 · Updated Nov 14, 2024
Unknown · CVSS Not scored
A Cross-site scripting (XSS) vulnerability in the content editor in Gis3W g3w-suite 3.5 allows remote authenticated users to inject arbitrary web script or HTML and gain privileges via the description parameter.
Published Jul 7, 2023 · Updated Nov 14, 2024
High · CVSS 7.8
Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 package allows users with access to the hacluster to escalate to root
This issue affects openSUSE Tumbleweed.
Published Jul 7, 2023 · Updated Nov 14, 2024
Unknown · CVSS Not scored
GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the BM_ParseIndexValueReplace function at /lib/libgpac.so.
Published Jul 11, 2023 · Updated Nov 14, 2024
Unknown · CVSS Not scored
Authentication bypass vulnerability in Fujitsu network devices Si-R series and SR-M series allows a network-adjacent unauthenticated attacker to obtain, change, and/or reset configuration settings of the affected products. Affected products and versions are as follows: Si-R 30B all versions, Si-R 130B all versions, Si-R 90brin all versions, Si-R570B all versions, Si-R370B all versions, Si-R220D all versions, Si-R G100 V02.54 and earlier, Si-R G200 V02.54 and earlier, Si-R G100B V04.12 and earlier, Si-R G110B V04.12 and earlier, Si-R G200B V04.12 and earlier, Si-R G210 V20.52 and earlier, Si-R G211 V20.52 and earlier, Si-R G120 V20.52 and earlier, Si-R G121 V20.52 and earlier, and SR-M 50AP1 all versions.
Published Jul 26, 2023 · Updated Nov 14, 2024
High · CVSS 7.2
An OS command injection vulnerability exists in the ys_thirdparty system_user_script functionality of Milesight UR32L v32.3.0.5. A specially crafted series of network requests can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.
Published Jul 6, 2023 · Updated Nov 14, 2024
High · CVSS 7.3
A sql injection vulnerability exists in the requestHandlers.js LoginAuth functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to authentication bypass. An attacker can send a malicious packet to trigger this vulnerability.
Published Jul 6, 2023 · Updated Nov 14, 2024
High · CVSS 7.2
An os command injection vulnerability exists in the libzebra.so change_hostname functionality of Milesight UR32L v32.3.0.5. A specially-crafted network packets can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.
Published Jul 6, 2023 · Updated Nov 14, 2024
High · CVSS 7.2
An OS command injection vulnerability exists in the libzebra.so bridge_group functionality of Milesight UR32L v32.3.0.5. A specially crafted network packet can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.
Published Jul 6, 2023 · Updated Nov 14, 2024
Critical · CVSS 9.8
A buffer overflow vulnerability exists in the uhttpd login functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to remote code execution. An attacker can send a network request to trigger this vulnerability.
Published Jul 6, 2023 · Updated Nov 14, 2024
High · CVSS 8.3
authentik is an open-source Identity Provider. Prior to versions 2023.4.3 and 2023.5.5, authentik does not verify the source of the X-Forwarded-For and X-Real-IP headers, both in the Python code and the go code. Only authentik setups that are directly accessible by users without a reverse proxy are susceptible to this. Possible spoofing of IP addresses in logs, downstream applications proxied by (built in) outpost, IP bypassing in custom flows if used.
This poses a possible security risk when someone has flows or policies that check the user's IP address, e.g. when they want to ignore the user's 2 factor authentication when the user is connected to the company network. A second security risk is that the IP addresses in the logfiles and user sessions are not reliable anymore. Anybody can spoof this address and one cannot verify that the user has logged in from the IP address that is in their account's log. A third risk is that this header is passed on to the proxied application behind an outpost. The application may do any kind of verification, logging, blocking or rate limiting based on the IP address, and this IP address can be overridden by anybody that want to.
Versions 2023.4.3 and 2023.5.5 contain a patch for this issue.
Published Jul 6, 2023 · Updated Nov 14, 2024
High · CVSS 8.8
PiiGAB M-Bus
SoftwarePack 900S
does not correctly sanitize user input, which could allow an attacker to inject arbitrary commands.
Published Jul 6, 2023 · Updated Nov 14, 2024
High · CVSS 7.5
PiiGAB M-Bus transmits credentials in plaintext format.
Published Jul 6, 2023 · Updated Nov 14, 2024
High · CVSS 7.5
PiiGAB M-Bus stores passwords using a weak hash algorithm.
Published Jul 6, 2023 · Updated Nov 14, 2024
Unknown · CVSS Not scored
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the ussd parameter in the setUssd function.
Published Jul 7, 2023 · Updated Nov 14, 2024
Unknown · CVSS Not scored
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadSetting function.
Published Jul 7, 2023 · Updated Nov 13, 2024
Unknown · CVSS Not scored
The Call Now Accessibility Button WordPress plugin before 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Published Jul 10, 2023 · Updated Nov 13, 2024
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Group and Description parameters.
Published Jul 11, 2023 · Updated Nov 13, 2024
Unknown · CVSS Not scored
Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via a crafted script to the deleteuser function.
Published Jul 11, 2023 · Updated Nov 13, 2024
Critical · CVSS 9.8
PiiGAB M-Bus contains hard-coded credentials which it uses for authentication.
Published Jul 6, 2023 · Updated Nov 13, 2024
High · CVSS 8
PiiGAB M-Bus does not validate identification strings before processing, which could make it vulnerable to cross-site scripting attacks.
Published Jul 6, 2023 · Updated Nov 13, 2024
High · CVSS 7.5
There are no requirements for setting a complex password for PiiGAB M-Bus, which could contribute to a successful brute force attack if the password is inline with recommended password guidelines.
Published Jul 6, 2023 · Updated Nov 13, 2024
High · CVSS 8.8
PiiGAB M-Bus is vulnerable to cross-site request forgery. An attacker who wants to execute a certain command could send a phishing mail to the owner of the device and hope that the owner clicks on the link. If the owner of the device has a cookie stored that allows the owner to be logged in, then the device could execute the GET or POST link request.
Published Jul 6, 2023 · Updated Nov 13, 2024
Unknown · CVSS Not scored
Cross Site Request Forgery (CSRF) vulnerability in MultiTech Conduit AP MTCAP2-L4E1 MTCAP2-L4E1-868-042A v.6.0.0 allows a remote attacker to execute arbitrary code via a crafted script upload.
Published Jul 7, 2023 · Updated Nov 13, 2024
Unknown · CVSS Not scored
SQL injection vulnerability found in PrestaShop lekerawen_ocs before v.1.4.1 allow a remote attacker to gain privileges via the KerawenHelper::setCartOperationInfo, and KerawenHelper::resetCheckoutSessionData components.
Published Jul 7, 2023 · Updated Nov 13, 2024
Unknown · CVSS Not scored
ai-dev aicombinationsonfly before v0.3.1 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php.
Published Jul 7, 2023 · Updated Nov 13, 2024
Unknown · CVSS Not scored
Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make modifications.
Published Jul 7, 2023 · Updated Nov 13, 2024
Unknown · CVSS Not scored
An issue in JerryscriptProject jerryscript v.3.0.0 allows an attacker to obtain sensitive information via a crafted script to the arrays.
Published Jul 7, 2023 · Updated Nov 13, 2024
Unknown · CVSS Not scored
The Online Examination System Project 1.0 version is vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacker can craft a malicious link that, when clicked by an admin user, will delete a user account from the database without the admin's consent. The email of the user to be deleted is passed as a parameter in the URL, which can be manipulated by the attacker. This could result in a loss of data.
Published Jul 7, 2023 · Updated Nov 13, 2024
Unknown · CVSS Not scored
PHP injection in TravianZ 8.3.4 and 8.3.3 in the config editor in the admin page allows remote attackers to execute PHP code.
Published Jul 7, 2023 · Updated Nov 13, 2024
Unknown · CVSS Not scored
The cryptographically insecure random number generator being used in TravianZ 8.3.4 and 8.3.3 in the password reset function allows an attacker to guess the password reset.parameters and to take over accounts.
Published Jul 7, 2023 · Updated Nov 13, 2024
Unknown · CVSS Not scored
In TravianZ 8.3.4 and 8.3.3, Incorrect Access Control in the installation script allows an attacker to overwrite the server configuration and inject PHP code.
Published Jul 7, 2023 · Updated Nov 13, 2024
Unknown · CVSS Not scored
Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delete user grouplist function.
Published Jul 11, 2023 · Updated Nov 13, 2024