Medium · CVSS 4
A vulnerability was found in Onest CRM 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/project/update/2 of the component Project List Handler. The manipulation of the argument name with the input <script>alert(1)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-232953 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Published Jul 4, 2023 · Updated Oct 28, 2024
Medium · CVSS 5.7
AMI SPx contains a vulnerability in the BMC where an Attacker may cause an improper neutralization of CRLF sequences in HTTP Headers. A successful exploit of this vulnerability may lead to a loss of integrity.
Published Jul 5, 2023 · Updated Oct 28, 2024
Medium · CVSS 4
A vulnerability was found in GZ Scripts Property Listing Script 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /preview.php. The manipulation of the argument page/layout/sort_by leads to cross site scripting. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-233351. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Published Jul 8, 2023 · Updated Oct 28, 2024
Unknown · CVSS Not scored
A remotely exploitable command injection vulnerability was found on the Kratos NGC-IDU 9.1.0.4. An attacker can execute arbitrary Linux commands as root by sending crafted TCP requests to the device.
Published Jul 18, 2023 · Updated Oct 28, 2024
Unknown · CVSS Not scored
ChakraCore branch master cbb9b was discovered to contain a stack overflow vulnerability via the function Js::ScopeSlots::IsDebuggerScopeSlotArray().
Published Jul 18, 2023 · Updated Oct 28, 2024
Unknown · CVSS Not scored
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::DiagScopeVariablesWalker::GetChildrenCount().
Published Jul 18, 2023 · Updated Oct 28, 2024
Unknown · CVSS Not scored
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::ProfilingHelpers::ProfiledNewScArray().
Published Jul 18, 2023 · Updated Oct 28, 2024
Unknown · CVSS Not scored
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::EntryPointInfo::HasInlinees().
Published Jul 18, 2023 · Updated Oct 28, 2024
Unknown · CVSS Not scored
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function BackwardPass::IsEmptyLoopAfterMemOp().
Published Jul 18, 2023 · Updated Oct 28, 2024
Unknown · CVSS Not scored
D-LINK DIR-815 v1.01 was discovered to contain a buffer overflow via the component /web/captcha.cgi.
Published Jul 18, 2023 · Updated Oct 28, 2024
Unknown · CVSS Not scored
goproxy v1.1 was discovered to contain an issue which can lead to a Denial of service (DoS) via unspecified vectors.
Published Jul 18, 2023 · Updated Oct 28, 2024
Unknown · CVSS Not scored
xHTTP 72f812d has a double free in close_connection in xhttp.c via a malformed HTTP request method.
Published Jul 18, 2023 · Updated Oct 28, 2024
Critical · CVSS 10
Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to a remote
code execution vulnerability that could allow an unauthenticated user to
upload a malicious payload and execute it.
Published Jul 18, 2023 · Updated Oct 28, 2024
High · CVSS 7.5
Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to an insecure direct object reference vulnerability that could allow an unauthenticated user to view profile information, including user login names and encrypted passwords.
Published Jul 18, 2023 · Updated Oct 28, 2024
High · CVSS 7.5
Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to a directory traversal vulnerability that could allow an unauthenticated user to directly access any file outside the webroot.
Published Jul 18, 2023 · Updated Oct 28, 2024
Unknown · CVSS Not scored
ngiflib commit 5e7292 was discovered to contain an infinite loop via the function DecodeGifImg at ngiflib.c.
Published Jul 19, 2023 · Updated Oct 28, 2024
High · CVSS 7.5
There is SQL injection vulnerability in Esri ArcGIS Insights 2022.1 for ArcGIS Enterprise and that may allow a remote, authorized attacker to execute arbitrary SQL commands against the back-end database. The effort required to generate the crafted input required to exploit this issue is complex and requires significant effort before a successful attack can be expected.
Published Jul 19, 2023 · Updated Oct 28, 2024
High · CVSS 7.5
Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Feathers socket handler did not catch invalid string conversion errors like `const message = ${{ toString: '' }}` which would cause the NodeJS process to crash when sending an unexpected Socket.io message like `socket.emit('find', { toString: '' })`. A fix has been released in versions 5.0.8 and 4.5.18. Users are advised to upgrade. There is no known workaround for this vulnerability.
Published Jul 19, 2023 · Updated Oct 28, 2024
Medium · CVSS 5.9
DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb into an HTTP response
Published Jul 19, 2023 · Updated Oct 28, 2024
Medium · CVSS 6.5
IBM Sterling Connect:Express for UNIX 1.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 252135.
Published Jul 19, 2023 · Updated Oct 28, 2024
Medium · CVSS 5.3
IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the CouchDB server and collect sensitive information from the database. IBM X-Force ID: 247905.
Published Jul 19, 2023 · Updated Oct 28, 2024
Unknown · CVSS Not scored
XBRL data create application version 7.0 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XBRL file, arbitrary files on the system may be read by an attacker.
Published Jul 19, 2023 · Updated Oct 28, 2024
High · CVSS 7.4
Weintek Weincloud v0.13.6
could allow an attacker to reset a password with the corresponding account’s JWT token only.
Published Jul 19, 2023 · Updated Oct 28, 2024
High · CVSS 7.5
Weintek Weincloud v0.13.6
could allow an attacker to cause a denial-of-service condition for Weincloud by sending a forged JWT token.
Published Jul 19, 2023 · Updated Oct 28, 2024
Medium · CVSS 5.3
Weintek Weincloud v0.13.6
could allow an attacker to efficiently develop a brute force attack on credentials with authentication hints from error message responses.
Published Jul 19, 2023 · Updated Oct 28, 2024
High · CVSS 7.8
In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYSTEM privileges due to an improper path validation, which could result in local privilege escalation or a denial-of-service condition.
Published Jul 19, 2023 · Updated Oct 28, 2024
Unknown · CVSS Not scored
Attackers can exploit an open API listener on SteelSeries GG 36.0.0 to create a sub-application that will be executed automatically from a controlled location, because of a path traversal vulnerability.
Published Jul 20, 2023 · Updated Oct 28, 2024
Unknown · CVSS Not scored
The web interface on multiple Samsung Harman AMX N-Series devices allows directory listing for the /tmp/ directory, without authentication, exposing sensitive information such as the command history and screenshot of the file being processed. This affects N-Series N1115 Wallplate Video Encoder before 1.15.61, N-Series N1x22A Video Encoder/Decoder before 1.15.61, N-Series N1x33A Video Encoder/Decoder before 1.15.61, N-Series N1x33 Video Encoder/Decoder before 1.15.61, N-Series N2x35 Video Encoder/Decoder before 1.15.61, N-Series N2x35A Video Encoder/Decoder before 1.15.61, N-Series N2xx2 Video Encoder/Decoder before 1.15.61, N-Series N2xx2A Video Encoder/Decoder before 1.15.61, N-Series N3000 Video Encoder/Decoder before 2.12.105, and N-Series N4321 Audio Transceiver before 1.00.06.
Published Jul 20, 2023 · Updated Oct 28, 2024
Medium · CVSS 5.5
Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error.
Published Jul 2, 2024 · Updated Oct 28, 2024
Medium · CVSS 5.9
IBM Watson CP4D Data Stores 4.6.0 does not properly allocate resources without limits or throttling which could allow a remote attacker with information specific to the system to cause a denial of service. IBM X-Force ID: 248924.
Published Jul 10, 2023 · Updated Oct 25, 2024
Medium · CVSS 6.5
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 could allow an authenticated user send a specially crafted request that could cause a denial of service. IBM X-Force ID: 251704.
Published Jul 10, 2023 · Updated Oct 25, 2024
Medium · CVSS 5.3
Observable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the FTP server from the response given during a failed login
attempt.
Published Jul 10, 2023 · Updated Oct 25, 2024
Medium · CVSS 5.3
Cleartext Storage on Disk in the SICK ICR890-4 could allow an unauthenticated attacker with local access to the device to disclose sensitive information by accessing a SD card.
Published Jul 10, 2023 · Updated Oct 25, 2024
Medium · CVSS 6.1
Cross site scripting vulnerability in Citrix ADC and Citrix Gateway in allows and attacker to perform cross site scripting
Published Jul 10, 2023 · Updated Oct 25, 2024
Medium · CVSS 6.3
Arbitrary file read in Citrix ADC and Citrix Gateway
Published Jul 10, 2023 · Updated Oct 25, 2024
Medium · CVSS 5.5
A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which the ICA session is launched.
Published Jul 10, 2023 · Updated Oct 25, 2024
High · CVSS 7
There is SQL injection vulnerability in Esri ArcGIS Insights Desktop for Mac and Windows version 2022.1 that may allow a local, authorized attacker to execute arbitrary SQL commands against the back-end database. The effort required to generate the crafted input required to exploit this issue is complex and requires significant effort before a successful attack can be expected.
Published Jul 19, 2023 · Updated Oct 25, 2024
High · CVSS 8.4
A vulnerability was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with versions Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850 Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380 Exynos 1330, Exynos 9110, Exynos W920, Exynos W930, Exynos Modem 5123, Exynos Modem 5300 that allows out-of-bounds access to a heap buffer in the SIM Proactive Command.
Published Jul 9, 2024 · Updated Oct 25, 2024
Medium · CVSS 5.3
Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerability to conduct further attacks. IBM X-Force ID: 247896.
Published Jul 19, 2023 · Updated Oct 25, 2024
High · CVSS 7.3
Spring Security versions 5.8 prior to 5.8.5, 6.0 prior to 6.0.5, and 6.1 prior to 6.1.2 could be susceptible to authorization rule misconfiguration if the application uses requestMatchers(String) and multiple servlets, one of them being Spring MVC’s DispatcherServlet. (DispatcherServlet is a Spring MVC component that maps HTTP endpoints to methods on @Controller-annotated classes.)
Specifically, an application is vulnerable when all of the following are true:
* Spring MVC is on the classpath
* Spring Security is securing more than one servlet in a single application (one of them being Spring MVC’s DispatcherServlet)
* The application uses requestMatchers(String) to refer to endpoints that are not Spring MVC endpoints
An application is not vulnerable if any of the following is true:
* The application does not have Spring MVC on the classpath
* The application secures no servlets other than Spring MVC’s DispatcherServlet
* The application uses requestMatchers(String) only for Spring MVC endpoints
Published Jul 18, 2023 · Updated Oct 25, 2024
High · CVSS 7.5
The Rockwell Automation Kinetix 5700 DC Bus Power Supply Series A is vulnerable to CIP fuzzing. The new ENIP connections cannot be established if impacted by this vulnerability, which prohibits operational capabilities of the device resulting in a denial-of-service attack.
Published Jul 18, 2023 · Updated Oct 25, 2024
High · CVSS 7.5
The vulnerability could be locally exploited to allow escalation of privilege.
Published Jul 18, 2023 · Updated Oct 25, 2024
Medium · CVSS 6.5
The affected TBox RTUs allow low privilege users to access software security tokens of higher privilege. This could allow an attacker with “user” privileges to access files requiring higher privileges by establishing an SSH session and providing the other tokens.
Published Jul 3, 2023 · Updated Oct 25, 2024
Medium · CVSS 5.9
The affected TBox RTUs generate software security tokens using insufficient entropy. The random seed used to generate the software tokens is not initialized correctly, and other parts of the token are generated using predictable time-based values. An attacker with this knowledge could successfully brute force the token and authenticate themselves.
Published Jul 3, 2023 · Updated Oct 25, 2024
Medium · CVSS 6.5
The affected TBox RTUs store hashed passwords using MD5 encryption, which is an insecure encryption algorithm.
Published Jul 3, 2023 · Updated Oct 25, 2024
High · CVSS 8.1
A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external commands used to control the process execution of the .zip application allows an authorized user to obtain control of the .zip application to execute arbitrary commands or obtain elevation of system privileges.
Published Jul 3, 2023 · Updated Oct 25, 2024
Medium · CVSS 4.4
An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and earlier Windows install service (mvagtsce.exe).
The misconfiguration allowed an unauthorized local user to insert arbitrary code into the unquoted service path to obtain privilege escalation and stop antimalware services.
Published Jul 3, 2023 · Updated Oct 25, 2024
High · CVSS 7.8
In Keysight Geolocation Server v2.4.2 and prior, a low privileged attacker could create a local ZIP file containing a malicious script in any location. The attacker could abuse this to load a DLL with SYSTEM privileges.
Published Jul 19, 2023 · Updated Oct 24, 2024
Unknown · CVSS Not scored
Omnis Studio 10.22.00 has incorrect access control. It advertises an irreversible feature for locking classes within Omnis libraries: it should be no longer possible to delete, view, change, copy, rename, duplicate, or print a locked class. Due to implementation issues, locked classes in Omnis libraries can be unlocked, and thus further analyzed and modified by Omnis Studio. This allows for further analyzing and also deleting, viewing, changing, copying, renaming, duplicating, or printing previously locked Omnis classes. This violates the expected behavior of an "irreversible operation."
Published Jul 20, 2023 · Updated Oct 24, 2024
Unknown · CVSS Not scored
Omnis Studio 10.22.00 has incorrect access control. It advertises a feature for making Omnis libraries "always private" - this is supposed to be an irreversible operation. However, due to implementation issues, "always private" Omnis libraries can be opened by the Omnis Studio browser by bypassing specific checks. This violates the expected behavior of an "irreversible operation".
Published Jul 20, 2023 · Updated Oct 24, 2024