Unknown · CVSS Not scored
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password that allows attackers to login with root privileges via the SSH service. The cleartext password corresponding to the $1$4Tmm01jl$7HRvcW.bz7uGmX9hiQWvR hash was not determined by the vulnerability discoverer.
Published Aug 21, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a SQL injection vulnerability via the a_passwd parameter at /portal/user-register.php.
Published Aug 21, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.
Published Aug 10, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.
Published Aug 10, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the sscanf function.
Published Aug 21, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the list parameter in the set_qosMib_list function.
Published Aug 21, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the list parameter in the save_virtualser_data function.
Published Aug 21, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis.
Published Sep 12, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
ASUS RT-AC66U B1 3.0.0.4.286_51665 was discovered to transmit sensitive information in cleartext.
Published Aug 8, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Cross Site Request Forgery (CSRF) vulnerability in Chamilo v.1.11 thru v.1.11.20 allows a remote authenticated privileged attacker to execute arbitrary code.
Published Aug 21, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An information leak in THE_B_members card v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
Published Sep 18, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An information leak in Coffee-jumbo v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
Published Sep 18, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An information leak in youmart-tokunaga v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
Published Sep 18, 2023 · Updated Jul 9, 2026
Medium · CVSS 6.5
An information leak in TonTon-Tei_waiting Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
Published Sep 18, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An information leak in YKC Tokushima_awayokocho Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
Published Sep 18, 2023 · Updated Jul 9, 2026
Medium · CVSS 6.5
An information leak in Cheese Cafe Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
Published Sep 18, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An information leak in Camp Style Project Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
Published Sep 18, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which could lead to privilege escalation.
Published Aug 9, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions in the directory /tmp.
Published Aug 9, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open the doors managed by the platform remotely via sending a crafted web request.
Published Aug 3, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload.
Published Aug 3, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses and device names.
Published Aug 3, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability.
Published Aug 3, 2023 · Updated Jul 9, 2026
High · CVSS 7.5
Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due to the fact that session ids are not validated for the type of user accessing the application by default. Privilege restrictions between non-admin and admin users are not enforced and any authenticated user can leverage admin functions without restriction by making direct requests to administrative endpoints.
Published Aug 3, 2023 · Updated Jul 9, 2026
Critical · CVSS 9.8
ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server via crafted requests to /base/sftpsetting/ endpoints that abuse a path traversal issue in the Username field and a lack of input sanitization on the SSH Key field. Overwriting specific files may lead to arbitrary code execution as NT AUTHORITY\SYSTEM.
Published Aug 3, 2023 · Updated Jul 9, 2026
High · CVSS 7.5 · CISA KEV
A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.
Published Aug 3, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrator password via a crafted web request.
Published Aug 3, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SQL injection vulnerability in berkaygediz O_Blog v.1.0 allows a local attacker to escalate privileges via the secure_file_priv component.
Published Aug 21, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A Prototype Pollution issue in Cronvel Tree-kit v.0.7.4 and before allows a remote attacker to execute arbitrary code via the extend function.
Published Aug 16, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.
Published Sep 20, 2023 · Updated Jul 9, 2026
High · CVSS 8.8
File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information via the extension filtering and renaming functions.
Published Sep 20, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.
Published Sep 20, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SQL injection vulnerability in Kidus Minimati v.1.0.0 allows a remote attacker to obtain sensitive information via the edit.php component.
Published Aug 17, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks.
Published Aug 21, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.
Published Aug 14, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability in the new REDCap project creation function of Vanderbilt REDCap 13.1.35 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the project title parameter.
Published Sep 7, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An arbitrary file upload vulnerability in tduck-platform v4.0 allows attackers to execute arbitrary code via a crafted HTML file.
Published Jul 19, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
IceWarp v10.2.1 was discovered to contain cross-site scripting (XSS) vulnerability via the color parameter.
Published Jul 20, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Search Maid page.
Published Aug 8, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Booking Request page.
Published Aug 8, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Admin page.
Published Aug 8, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the View Request of Nurse Page in the Admin portal.
Published Aug 8, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Nurse Page in the Admin portal.
Published Aug 8, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Page of the Admin portal.
Published Aug 8, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Details of the Admin portal.
Published Aug 8, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Profile Page of the Admin.
Published Aug 8, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.
Published Aug 3, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.
Published Jul 31, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in the CAB file extraction function of Bitberry File Opener v23.0 allows attackers to execute a directory traversal.
Published Aug 8, 2023 · Updated Jul 9, 2026
High · CVSS 7.5
An issue in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information because there is an automaticsystems super admin account with astech as its hardcoded password.
Published Jan 3, 2024 · Updated Jul 9, 2026