Unknown · CVSS Not scored
GL.iNET GL-AR750S-Ext firmware v3.215 uses an insecure protocol in its communications which allows attackers to eavesdrop via a man-in-the-middle attack.
Published Jun 13, 2023 · Updated Jul 5, 2026
Critical · CVSS 9.8
A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server.
Published Jun 13, 2023 · Updated Jul 5, 2026
Medium · CVSS 5.5
Buffer Overflow vulnerability found in Libtiff V.4.0.7 allows a local attacker to cause a denial of service via the tiffcp function in tiffcp.c.
Published May 9, 2023 · Updated Jul 5, 2026
High · CVSS 7.5
An access control issue in Makves DCAP v3.0.0.122 allows unauthenticated attackers to obtain cleartext credentials via a crafted web request to the product API.
Published Jun 21, 2023 · Updated Jul 5, 2026
High · CVSS 7.2
A command injection vulnerability was found in the ping functionality of the MitraStar GPT-2741GNAC router (firmware version AR_g5.8_110WVN0b7_2). The vulnerability allows an authenticated user to execute arbitrary OS commands by sending specially crafted input to the router via the ping function.
Published Jun 6, 2023 · Updated Jul 5, 2026
High · CVSS 7.8
Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the component NativePushService. This vulnerability allows attackers to launch processes with elevated privileges.
Published May 23, 2023 · Updated Jul 5, 2026
High · CVSS 7.5
An issue in Deviniti Issue Sync Synchronization v3.5.2 for Jira allows attackers to obtain the login credentials of a user via a crafted request sent to /rest/synchronizer/1.0/technicalUser.
Published May 31, 2023 · Updated Jul 5, 2026
Medium · CVSS 5.5
An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via a crafted payload.
Published May 12, 2023 · Updated Jul 5, 2026
Medium · CVSS 5.5
An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via the default allowlist feature being stored as non-admin.
Published May 12, 2023 · Updated Jul 5, 2026
Medium · CVSS 4.6
The AES Key-IV pair used by the TP-Link TAPO C200 camera V3 (EU) on firmware version 1.1.22 Build 220725 is reused across all cameras. An attacker with physical access to a camera is able to extract and decrypt sensitive data containing the Wifi password and the TP-LINK account credential of the victim.
Published Jun 6, 2023 · Updated Jul 5, 2026
Medium · CVSS 5.4
Multiple stored cross-site scripting (XSS) vulnerabilities in FICO Origination Manager Decision Module 4.8.1 allow attackers to execute arbitrary web scripts or HTML via a crafted payload.
Published May 9, 2023 · Updated Jul 5, 2026
High · CVSS 7.5
A session takeover vulnerability exists in FICO Origination Manager Decision Module 4.8.1 due to insufficient protection of the JSESSIONID cookie.
Published May 9, 2023 · Updated Jul 5, 2026
Critical · CVSS 9.8
Medical Systems Co. Medisys Weblab Products v19.4.03 was discovered to contain a SQL injection vulnerability via the tem:statement parameter in the WSDL files.
Published May 11, 2023 · Updated Jul 5, 2026
Medium · CVSS 6.1
Reflected Cross Site Scripting (XSS) in Intermesh BV Group-Office version 6.6.145, allows attackers to gain escalated privileges and gain sensitive information via the GO_LANGUAGE cookie.
Published Apr 27, 2023 · Updated Jul 5, 2026
Medium · CVSS 5.4
A stored HTML injection vulnerability in LiveAction LiveSP v21.1.2 allows attackers to execute arbitrary code via a crafted payload.
Published Apr 12, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
Judging Management System 1.0 was discovered to contain an arbitrary file upload vulnerability via the component edit_organizer.php.
Published Feb 23, 2023 · Updated Jul 5, 2026
Medium · CVSS 5.5
An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to access sensitive information via the EXE installer. NOTE: the vendor's perspective is that this is not a separate vulnerability relative to CVE-2023-29818 and CVE-2023-29819.
Published May 12, 2023 · Updated Jul 5, 2026
High · CVSS 8.8
AhnLab EPP 1.0.15 is vulnerable to SQL Injection via the "preview parameter."
Published Oct 27, 2025 · Updated Jul 5, 2026
High · CVSS 8.8
An issue in user interface in Kyocera Command Center RX EXOSYS M5521cdn allows remote to obtain sensitive information via inspecting sent packages by user.
Published Sep 18, 2025 · Updated Jul 5, 2026
High · CVSS 7.1
A cross-site scripting (XSS) vulnerability in the component /Login.php of c3crm up to v3.0.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the login_error parameter.
Published Jun 25, 2025 · Updated Jul 5, 2026
High · CVSS 8.9
The NextEPC MME <= 1.0.1 (fixed in commit a8492c9c5bc0a66c6999cb5a263545b32a4109df) contains a stack-based buffer overflow vulnerability in the Emergency Number List decoding method. An attacker may send a NAS message containing an oversized Emergency Number List value to the MME to overwrite the stack with arbitrary bytes. An attacker with a cellphone connection to any base station managed by the MME may exploit this vulnerability without having to authenticate with the LTE core.
Published Jan 22, 2025 · Updated Jul 5, 2026
Medium · CVSS 6.6
RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing execution of any commands on the remote system.
Published Oct 15, 2024 · Updated Jul 5, 2026
Medium · CVSS 5.4
A reflected Cross-Site Scripting (XSS) vulnerability was found on Temenos T24 Browser R19.40 that enables a remote attacker to execute arbitrary JavaScript code via the skin parameter in the about.jsp and genrequest.jsp components.
Published Sep 23, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.8
TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi.
Published May 18, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
A memory leak in the component CConsole::Chain of Teeworlds v0.7.5 allows attackers to cause a Denial of Service (DoS) via opening a crafted file.
Published May 23, 2023 · Updated Jul 5, 2026
High · CVSS 7.5
TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.
Published Jan 9, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.1
Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the name parameter of the Profile and Exclusion List page(s).
Published Jan 9, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.8
An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted file.
Published Jan 9, 2024 · Updated Jul 5, 2026
Medium · CVSS 5.4
Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the creator parameter of the Alert Configuration page.
Published Jan 9, 2024 · Updated Jul 5, 2026
Unknown · CVSS Not scored
The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions through 3.17.02, allows remote authenticated users to execute arbitrary commands.
Published Dec 7, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions before 3.17.02, allows remote authenticated users to execute arbitrary commands via a crafted request targeting vulnerable cgi endpoints.
Published Dec 7, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions up to 3.17.02, allows remote unauthenticated users to perform directory traversal, potentially disclosing sensitive information.
Published Dec 7, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
Zumtobel Netlink CCD Onboard v3.74 - Firmware v3.80 was discovered to contain a buffer overflow via the component NetlinkWeb::Information::SetDeviceIdentification.
Published Nov 29, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
In instances where the screen is visible and remote mouse connection is enabled, KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 can be exploited to achieve local code execution at the root level.
Published Aug 9, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device. This vulnerability involves extracting the connection confirmation code remotely, bypassing the need to obtain it directly from the physical screen.
Published Aug 9, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via crafted JavaScript file.
Published Aug 14, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
Published Aug 14, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
Published Aug 14, 2023 · Updated Jul 5, 2026
Medium · CVSS 6.5
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request.
Published Mar 31, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
Bluetens Electrostimulation Device BluetensQ device app version 4.3.15 is vulnerable to Man-in-the-middle attacks in the BLE channel. It allows attackers to decrease or increase the intensity of the stimulator by hijacking the BLE communication.
Published Aug 3, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
Alteryx Server 2022.1.1.42590 does not employ file type verification for uploaded files. This vulnerability allows attackers to upload arbitrary files (e.g., JavaScript content for stored XSS) via the type field in a JSON document within a PUT /gallery/api/media request.
Published Aug 8, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts on shared computers.
Published Jul 12, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
An issue found in Inageya v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp Inageya function.
Published Jul 13, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
An issue found in DERICIA Co. Ltd, DELICIA v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp DELICIA function.
Published Jul 13, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
An issue found in Marui Co Marui Official app v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp Marui Official Store function.
Published Jul 13, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
An issue found in Entetsu Store v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp Entetsu Store function.
Published Jul 13, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
An issue found in ALBIS Co. ALBIS v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp ALBIS function.
Published Jul 13, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
An issue found in Shizutetsu Store v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.
Published Jul 13, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
An issue found in KEISEI STORE Co, Ltd. LIVRE KEISEI v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.
Published Jul 13, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
An issue found in Marukyu Line v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.
Published Jul 11, 2023 · Updated Jul 5, 2026