Unknown · CVSS Not scored
Chamilo 1.11.x up to 1.11.20 allows users with an admin privilege account to insert XSS in the languages management section.
Published Jul 7, 2023 · Updated Nov 13, 2024
Unknown · CVSS Not scored
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the classes/usergroups management section.
Published Jul 7, 2023 · Updated Nov 13, 2024
Unknown · CVSS Not scored
Tenda AC10 v15.03.06.26 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.
Published Jul 7, 2023 · Updated Nov 13, 2024
Unknown · CVSS Not scored
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.
Published Jul 7, 2023 · Updated Nov 13, 2024
Unknown · CVSS Not scored
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the course categories' definition.
Published Jul 7, 2023 · Updated Nov 13, 2024
Unknown · CVSS Not scored
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the careers & promotions management section.
Published Jul 7, 2023 · Updated Nov 13, 2024
Unknown · CVSS Not scored
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the extra fields management section.
Published Jul 7, 2023 · Updated Nov 13, 2024
Unknown · CVSS Not scored
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the session category management section.
Published Jul 7, 2023 · Updated Nov 13, 2024
Unknown · CVSS Not scored
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the skills wheel.
Published Jul 7, 2023 · Updated Nov 13, 2024
High · CVSS 7.5
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All versions < V3.3.4), SIMATIC MV550 S (All versions < V3.3.4), SIMATIC MV560 U (All versions < V3.3.4), SIMATIC MV560 X (All versions < V3.3.4). Affected devices cannot properly process specially crafted Ethernet frames sent to the devices. This could allow an unauthenticated remote attacker to cause a denial of service condition. The affected devices must be restarted manually.
Published Jul 11, 2023 · Updated Nov 13, 2024
Unknown · CVSS Not scored
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.
Published Jul 7, 2023 · Updated Nov 12, 2024
Unknown · CVSS Not scored
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.
Published Jul 7, 2023 · Updated Nov 12, 2024
Unknown · CVSS Not scored
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg function.
Published Jul 7, 2023 · Updated Nov 12, 2024
Unknown · CVSS Not scored
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function.
Published Jul 7, 2023 · Updated Nov 12, 2024
Unknown · CVSS Not scored
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg function.
Published Jul 7, 2023 · Updated Nov 12, 2024
Unknown · CVSS Not scored
Sourcecodester Online Pizza Ordering System v1.0 has a Cross-site scripting (XSS) vulnerability in "/admin/index.php?page=categories" Category item.
Published Jul 10, 2023 · Updated Nov 12, 2024
Unknown · CVSS Not scored
KodExplorer 4.51 contains a Cross-Site Scripting (XSS) vulnerability in the Description box of the Light App creation feature. An attacker can exploit this vulnerability by injecting XSS syntax into the Description field.
Published Jul 10, 2023 · Updated Nov 12, 2024
Critical · CVSS 9.8
SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code and disrupt service.
Published Jul 10, 2023 · Updated Nov 12, 2024
Unknown · CVSS Not scored
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.
Published Jul 10, 2023 · Updated Nov 12, 2024
Unknown · CVSS Not scored
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function.
Published Jul 10, 2023 · Updated Nov 12, 2024
Unknown · CVSS Not scored
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the formSetDeviceName function.
Published Jul 10, 2023 · Updated Nov 12, 2024
Unknown · CVSS Not scored
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the formSetClientState function.
Published Jul 10, 2023 · Updated Nov 12, 2024
High · CVSS 7.5
Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message
Published Jul 13, 2023 · Updated Nov 12, 2024
Critical · CVSS 9.9
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of improper access controls in the configuration files that leads to privilege escalation. An attacker could gain admin access with this vulnerability leading to complete device control.
Published Jul 11, 2023 · Updated Nov 12, 2024
Unknown · CVSS Not scored
The Float menu WordPress plugin before 5.0.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Published Jul 10, 2023 · Updated Nov 12, 2024
Unknown · CVSS Not scored
The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both.
Published Jul 10, 2023 · Updated Nov 12, 2024
Medium · CVSS 5.3
In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the Referrer-Policy response header is not implemented, allowing an unauthenticated attacker to obtain referrer details, resulting in information disclosure.
Published Jul 11, 2023 · Updated Nov 12, 2024
High · CVSS 7.2
SAP Solution Manager (Diagnostics agent) - version 7.20, allows an attacker to tamper with headers in a client request. This misleads SAP Diagnostics Agent to serve poisoned content to the server. On successful exploitation, the attacker can cause a limited impact on confidentiality and availability of the application.
Published Jul 11, 2023 · Updated Nov 12, 2024
High · CVSS 7.4
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of an incorrect default value in the SSH configuration. This could allow an attacker to bypass network isolation.
Published Jul 11, 2023 · Updated Nov 12, 2024
High · CVSS 7.5
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All versions < V3.3.4), SIMATIC MV550 S (All versions < V3.3.4), SIMATIC MV560 U (All versions < V3.3.4), SIMATIC MV560 X (All versions < V3.3.4). Affected devices cannot properly process specially crafted IP packets sent to the devices. This could allow an unauthenticated remote attacker to cause a denial of service condition. The affected devices must be restarted manually.
Published Jul 11, 2023 · Updated Nov 12, 2024
High · CVSS 7.2
SAP Solution Manager (Diagnostics agent) - version 7.20, allows an unauthenticated attacker to blindly execute HTTP requests. On successful exploitation, the attacker can cause a limited impact on confidentiality and availability of the application and other applications the Diagnostics Agent can reach.
Published Jul 11, 2023 · Updated Nov 12, 2024
Low · CVSS 3.5
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to leak the email address of a user who created a service desk issue.
Published Jul 11, 2023 · Updated Nov 12, 2024
High · CVSS 8.1
DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an Improper Authentication vulnerability during the firmware update procedure.
Specifically, the firmware update procedure ignores and does not check the validity of the TLS certificate of the HTTPS endpoint from which the firmware update package (.tar.bz2 file) is downloaded.
An attacker with the ability to put himself in a Man-in-the-Middle situation (e.g., DNS poisoning, ARP poisoning, control of a node on the route to the endpoint, etc.) can trick the DroneScout ds230 to install a crafted malicious firmware update containing arbitrary files (e.g., executable and configuration) and gain administrative (root) privileges on the underlying Linux operating system.
This issue affects DroneScout ds230 firmware from version 20211210-1627 through 20230329-1042.
Published Jul 11, 2023 · Updated Nov 12, 2024
Unknown · CVSS Not scored
Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate privileges to the administrator's role.
Published Jul 13, 2023 · Updated Nov 12, 2024
High · CVSS 7.5
Unauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated
remote attacker to retrieve sensitive information about the device via HTTP requests.
Published Jul 10, 2023 · Updated Nov 12, 2024
Unknown · CVSS Not scored
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the entrys parameter in the fromAddressNat function.
Published Jul 10, 2023 · Updated Nov 12, 2024
Unknown · CVSS Not scored
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function.
Published Jul 10, 2023 · Updated Nov 12, 2024
Unknown · CVSS Not scored
Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the wpapsk_crypto parameter in the fromSetWirelessRepeat function.
Published Jul 10, 2023 · Updated Nov 12, 2024
Unknown · CVSS Not scored
Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the deviceId parameter in the saveParentControlInfo function.
Published Jul 10, 2023 · Updated Nov 12, 2024
Unknown · CVSS Not scored
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.
Published Jul 10, 2023 · Updated Nov 12, 2024
Unknown · CVSS Not scored
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromAddressNat function.
Published Jul 10, 2023 · Updated Nov 12, 2024
High · CVSS 7
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 251782.
Published Jul 10, 2023 · Updated Nov 12, 2024
Medium · CVSS 5.9
A missing nullptr-check in handle_ra_input can cause a nullptr-deref.
Published Jul 10, 2023 · Updated Nov 12, 2024
High · CVSS 8.6
Exposure of Sensitive Information to an Unauthorized Actor in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the system.
Published Jul 10, 2023 · Updated Nov 12, 2024
High · CVSS 8.2
Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing
unauthenticated endpoints.
Published Jul 10, 2023 · Updated Nov 12, 2024
High · CVSS 7.5
Cleartext Transmission of Sensitive Information in the SICK ICR890-4 could allow a
remote attacker to gather sensitive information by intercepting network traffic that is not encrypted.
Published Jul 10, 2023 · Updated Nov 12, 2024
High · CVSS 7.5
Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability of the device by changing settings of the device such as the IP
address based on missing access control.
Published Jul 10, 2023 · Updated Nov 12, 2024
Medium · CVSS 5.3
Improper Restriction of Excessive Authentication Attempts in the SICK ICR890-4
could allow a remote attacker to brute-force user credentials.
Published Jul 10, 2023 · Updated Nov 12, 2024
Unknown · CVSS Not scored
The URL Shortify WordPress plugin before 1.7.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Published Jul 10, 2023 · Updated Nov 12, 2024
Unknown · CVSS Not scored
The All In One Redirection WordPress plugin before 2.2.0 does not properly sanitise and escape multiple parameters before using them in an SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
Published Jul 10, 2023 · Updated Nov 12, 2024