High · CVSS 7.5
Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due to the fact that session ids are not validated for the type of user accessing the application by default. Privilege restrictions between non-admin and admin users are not enforced and any authenticated user can leverage admin functions without restriction by making direct requests to administrative endpoints.
Published Aug 3, 2023 · Updated Jul 9, 2026
Critical · CVSS 9.8
ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server via crafted requests to /base/sftpsetting/ endpoints that abuse a path traversal issue in the Username field and a lack of input sanitization on the SSH Key field. Overwriting specific files may lead to arbitrary code execution as NT AUTHORITY\SYSTEM.
Published Aug 3, 2023 · Updated Jul 9, 2026
High · CVSS 7.5 · CISA KEV
A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.
Published Aug 3, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrator password via a crafted web request.
Published Aug 3, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SQL injection vulnerability in berkaygediz O_Blog v.1.0 allows a local attacker to escalate privileges via the secure_file_priv component.
Published Aug 21, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A Prototype Pollution issue in Cronvel Tree-kit v.0.7.4 and before allows a remote attacker to execute arbitrary code via the extend function.
Published Aug 16, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.
Published Sep 20, 2023 · Updated Jul 9, 2026
High · CVSS 8.8
File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information via the extension filtering and renaming functions.
Published Sep 20, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.
Published Sep 20, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SQL injection vulnerability in Kidus Minimati v.1.0.0 allows a remote attacker to obtain sensitive information via the edit.php component.
Published Aug 17, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks.
Published Aug 21, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.
Published Aug 14, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability in the new REDCap project creation function of Vanderbilt REDCap 13.1.35 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the project title parameter.
Published Sep 7, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An arbitrary file upload vulnerability in tduck-platform v4.0 allows attackers to execute arbitrary code via a crafted HTML file.
Published Jul 19, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
IceWarp v10.2.1 was discovered to contain cross-site scripting (XSS) vulnerability via the color parameter.
Published Jul 20, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Search Maid page.
Published Aug 8, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Booking Request page.
Published Aug 8, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Admin page.
Published Aug 8, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the View Request of Nurse Page in the Admin portal.
Published Aug 8, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Nurse Page in the Admin portal.
Published Aug 8, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Page of the Admin portal.
Published Aug 8, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Details of the Admin portal.
Published Aug 8, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Profile Page of the Admin.
Published Aug 8, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.
Published Aug 3, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.
Published Jul 31, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in the CAB file extraction function of Bitberry File Opener v23.0 allows attackers to execute a directory traversal.
Published Aug 8, 2023 · Updated Jul 9, 2026
High · CVSS 7.5
An issue in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information because there is an automaticsystems super admin account with astech as its hardcoded password.
Published Jan 3, 2024 · Updated Jul 9, 2026
High · CVSS 7.5
Directory Traversal in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information via csvServer.php?file= with a .. in the dir parameter.
Published Jan 3, 2024 · Updated Jul 9, 2026
Critical · CVSS 9.8
Insecure Permissions vulnerability in JLINK Unionman Technology Co. Ltd Jlink AX1800 v.1.0 allows a remote attacker to escalate privileges via a crafted command.
Published Jun 17, 2024 · Updated Jul 9, 2026
Critical · CVSS 9.8
An issue in JLINK Unionman Technology Co. Ltd Jlink AX1800 v.1.0 allows a remote attacker to execute arbitrary code via the router's authentication mechanism.
Published Jun 17, 2024 · Updated Jul 9, 2026
Critical · CVSS 9.8
Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter.
Published Sep 5, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path parameter in the URL.
Published Aug 3, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Cross Site Scripting vulnerability in mlogclub bbs-go v. 3.5.5. and before allows a remote attacker to execute arbitrary code via a crafted payload to the announcements parameter in the settings function.
Published Jul 3, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Cross Site Scripting vulnerability in mlogclub bbs-go v. 3.5.5. and before allows a remote attacker to execute arbitrary code via a crafted payload to the comment parameter in the article function.
Published Jul 3, 2023 · Updated Jul 9, 2026
Critical · CVSS 9.8
An issue was discovered in badaix Snapcast version 0.27.0, allows remote attackers to execute arbitrary code and gain sensitive information via crafted request in JSON-RPC-API.
Published Jan 23, 2024 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 1.0 allows remote attackers to run arbitrary code via the First Name, Middle Name and Last Name fields on the Create User page.
Published Aug 3, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Cross Site Scripting (XSS) vulnerability in sourcecodester Toll Tax Management System 1.0 allows remote attackers to run arbitrary code via the First Name and Last Name fields on the My Account page.
Published Aug 3, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A Stored Cross-Site Scripting (XSS) vulnerability was found in Multilaser RE 170 using firmware 2.2.6733.
Published Jun 30, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file of the device, exposing critical information about the device configuration.
Published Jun 30, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Maxprint Maxlink 1200G v3.4.11E has an OS command injection vulnerability in the "Diagnostic tool" functionality of the device.
Published Jun 30, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affected functions include from_math_prompt and from_colored_object_prompt.
Published Aug 5, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Server Side Request Forgery (SSRF) vulnerability in NebulaGraph Studio version 3.7.0, allows remote attackers to gain sensitive information.
Published Sep 1, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An isssue in GatesAIr Flexiva FM Transmitter/Exiter Fax 150W allows a remote attacker to gain privileges via the LDAP and SMTP credentials.
Published Aug 3, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Cross Site Scripting vulnerability in GatesAIr Flexiva FM Transmitter/Exciter v.FAX 150W allows a remote attacker to execute arbitrary code via a crafted script to the web application dashboard.
Published Aug 2, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.
Published Aug 1, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary code via uploading a crafted SVG file.
Published Jun 13, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php.
Published Jul 31, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
angular-ui-notification v0.1.0, v0.2.0, and v0.3.6 was discovered to contain a cross-site scripting (XSS) vulnerability.
Published Jun 30, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
TP-Link Archer AX10(EU)_V1.2_230220 was discovered to contain a buffer overflow via the function FUN_131e8 - 0x132B4.
Published Jun 16, 2023 · Updated Jul 9, 2026
Critical · CVSS 9.8
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.
Published Jun 14, 2023 · Updated Jul 9, 2026