Unknown · CVSS Not scored
TP-LINK Archer C50v2 Archer C50(US)_V2_160801, TP-LINK Archer C20v1 Archer_C20_V1_150707, and TP-LINK Archer C2v1 Archer_C2_US__V1_170228 were discovered to contain a buffer overflow which may lead to a Denial of Service (DoS) when parsing crafted data.
Published Jul 18, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
ASUS SetupAsusServices v1.0.5.1 in Asus Armoury Crate v5.3.4.0 contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.
Published Jul 26, 2023 · Updated Jul 5, 2026
Medium · CVSS 5.4
A stored Cross-site scripting (XSS) vulnerability in Wolters Kluwer TeamMate+ 35.0.11.0 allows remote attackers to inject arbitrary web script or HTML.
Published Jun 16, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
Sage X3 version 12.14.0.50-0 is vulnerable to Cross Site Scripting (XSS). Some parts of the Web application are dynamically built using user's inputs. Yet, those inputs are not verified nor filtered by the application, so they mathed the expected format. Therefore, when HTML/JavaScript code is injected into those fields, this code will be saved by the application and executed by the web browser of the user viewing the web page. Several injection points have been identified on the application. The major one requires the user to be authenticated with a common account, he can then target an Administrator. All others endpoints need the malicious user to be authenticated as an Administrator. Therefore, the impact is diminished.
Published Jun 22, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection.
Published Jun 22, 2023 · Updated Jul 5, 2026
Critical · CVSS 9.8
There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48. If an attacker gains web management privileges, they can inject commands into the post request parameters, thereby gaining shell privileges.
Published Jun 6, 2023 · Updated Jul 5, 2026
High · CVSS 8.8
There is a command injection vulnerability in the Tenda G103 Gigabit GPON Terminal with firmware version V1.0.0.5. If an attacker gains web management privileges, they can inject commands gaining shell privileges.
Published Jun 6, 2023 · Updated Jul 5, 2026
High · CVSS 7.8
Insecure permissions in MobileTrans v4.0.11 allows attackers to escalate privileges to local admin via replacing the executable file.
Published May 24, 2023 · Updated Jul 5, 2026
High · CVSS 7.2
There is a command injection vulnerability in the Linksys WRT54GL router with firmware version 4.30.18.006. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ant, wl_rate, WL_atten_ctl, ttcp_num, ttcp_size in the httpd s Start_EPI() function, thereby gaining shell privileges.
Published May 22, 2023 · Updated Jul 5, 2026
High · CVSS 7.2
There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ssid, wl_ant, wl_rate, WL_atten_ctl, ttcp_num, ttcp_size in the httpd s Start_EPI() function, thereby gaining shell privileges.
Published May 23, 2023 · Updated Jul 5, 2026
High · CVSS 7.2
There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, they can inject commands into the post request parameters WL_atten_bb, WL_atten_radio, and WL_atten_ctl in the apply.cgi interface, thereby gaining shell privileges.
Published May 23, 2023 · Updated Jul 5, 2026
High · CVSS 7.5
IC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control via unauthenticated port access.
Published May 24, 2023 · Updated Jul 5, 2026
High · CVSS 7.5
IC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control via an exposed HTTP channel using VLC network.
Published May 25, 2023 · Updated Jul 5, 2026
Critical · CVSS 9.8
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function.
Published Jun 6, 2023 · Updated Jul 5, 2026
Medium · CVSS 5.5
The BT21 x BTS Wallpaper app 12 for Android allows unauthorized applications to actively request permission to insert data into the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the application is opened. By injecting data, the attacker can force the application to load malicious image URLs and display them in the UI. As the amount of data increases, it will eventually cause the application to trigger an OOM error and crash, resulting in a persistent denial of service attack.
Published Jun 2, 2023 · Updated Jul 5, 2026
High · CVSS 7.8
The BT21 x BTS Wallpaper app 12 for Android allows unauthorized apps to actively request permission to modify data in the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the app is opened. An attacker could tamper with this data to cause an escalation of privilege attack.
Published Jun 2, 2023 · Updated Jul 5, 2026
Critical · CVSS 9.8
An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.
Published May 12, 2023 · Updated Jul 5, 2026
Medium · CVSS 6.1
LavaLite CMS v 9.0.0 was discovered to be vulnerable to a host header injection attack.
Published May 12, 2023 · Updated Jul 5, 2026
Medium · CVSS 5.5
Telegram 9.3.1 and 9.4.0 allows attackers to access restricted files, microphone ,or video recording via the DYLD_INSERT_LIBRARIES flag.
Published May 19, 2023 · Updated Jul 5, 2026
Medium · CVSS 5.4
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the personal notes function.
Published May 9, 2023 · Updated Jul 5, 2026
Medium · CVSS 5.4
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the My Progress function.
Published May 9, 2023 · Updated Jul 5, 2026
Medium · CVSS 4.8
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local authenticated attacker to execute arbitrary code via the homepage function.
Published May 9, 2023 · Updated Jul 5, 2026
Medium · CVSS 5.4
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the course category parameters.
Published May 9, 2023 · Updated Jul 5, 2026
Medium · CVSS 4.8
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the resource sequencing parameters.
Published May 9, 2023 · Updated Jul 5, 2026
Medium · CVSS 5.4
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skype and linedin_url parameters.
Published May 9, 2023 · Updated Jul 5, 2026
Medium · CVSS 6.1
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skills wheel parameter.
Published May 9, 2023 · Updated Jul 5, 2026
Medium · CVSS 5.4
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the forum title parameter.
Published May 9, 2023 · Updated Jul 5, 2026
Medium · CVSS 4.8
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the system annnouncements parameter.
Published May 9, 2023 · Updated Jul 5, 2026
Critical · CVSS 9.8
Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability via the sysCmd parameter in the formSysCmd function. This vulnerability is exploited via a crafted HTTP request.
Published Apr 25, 2023 · Updated Jul 5, 2026
High · CVSS 7.5
Beijing Netcon NS-ASG Application Security Gateway v6.3 is vulnerable to SQL Injection via TunnelId that allows access to sensitive information.
Published May 5, 2023 · Updated Jul 5, 2026
Critical · CVSS 9.8
NS-ASG v6.3 was discovered to contain a SQL injection vulnerability via the component /admin/add_ikev2.php.
Published May 5, 2023 · Updated Jul 5, 2026
High · CVSS 7.8
CyberGhostVPN Windows Client before v8.3.10.10015 was discovered to contain a DLL injection vulnerability via the component Dashboard.exe.
Published May 9, 2023 · Updated Jul 5, 2026
Critical · CVSS 9.8
CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.
Published May 8, 2023 · Updated Jul 5, 2026
Critical · CVSS 9.8
GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.
Published May 2, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function.
Published Apr 13, 2023 · Updated Jul 5, 2026
Critical · CVSS 9.8
AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via the user parameter in the login form.
Published Apr 13, 2023 · Updated Jul 5, 2026
Critical · CVSS 9.8
Auto Dealer Management System v1.0 was discovered to contain a SQL injection vulnerability.
Published Apr 13, 2023 · Updated Jul 5, 2026
Medium · CVSS 6.1
Auto Dealer Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the name parameter at /classes/SystemSettings.php?f=update_settings.
Published Apr 14, 2023 · Updated Jul 5, 2026
High · CVSS 8.8
An issue found in D-Link DSL-3782 v.1.03 allows remote authenticated users to execute arbitrary code as root via the network settings page.
Published Apr 12, 2023 · Updated Jul 5, 2026
Medium · CVSS 5.4
A cross-site scripting (XSS) vulnerability in LiveAction LiveSP v21.1.2 allows attackers to execute arbitrary web scripts or HTML.
Published Apr 10, 2023 · Updated Jul 5, 2026
Medium · CVSS 5.5
swfdump v0.9.2 was discovered to contain a heap buffer overflow in the function swf_GetPlaceObject at swfobject.c.
Published Mar 23, 2023 · Updated Jul 5, 2026
Medium · CVSS 6.5
Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/absence?search_month=1.
Published Mar 29, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
An arbitrary file upload vulnerability in Halo up to v1.6.1 allows attackers to execute arbitrary code via a crafted .md file.
Published Mar 10, 2023 · Updated Jul 5, 2026
Critical · CVSS 9.1
openapi-generator up to v6.4.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/gen/clients/{language}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request.
Published Mar 31, 2023 · Updated Jul 5, 2026
High · CVSS 7.5
Jellyfin up to v10.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /Repositories. This vulnerability allows attackers to access network resources and sensitive information via a crafted POST request.
Published Mar 10, 2023 · Updated Jul 5, 2026
High · CVSS 7.2
forem up to v2022.11.11 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /articles/{id}. This vulnerability allows attackers to access network resources and sensitive information via a crafted POST request.
Published Mar 31, 2023 · Updated Jul 5, 2026
High · CVSS 7.5
Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.
Published Mar 31, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attacker is able to decrypt any connectionstring stored in .mrt files since a static secret is used. The secret does not differ between the tested versions and different operating systems.
Published Mar 27, 2023 · Updated Jul 5, 2026
High · CVSS 7.5
Stimulsoft GmbH Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Server Side Request Forgery (SSRF). TThe Reporting Designer (Web) offers the possibility to embed sources from external locations. If the user chooses an external location, the request to that resource is performed by the server rather than the client. Therefore, the server causes outbound traffic and potentially imports data. An attacker may also leverage this behaviour to exfiltrate data of machines on the internal network of the server hosting the Stimulsoft Reporting Designer (Web).
Published Mar 28, 2023 · Updated Jul 5, 2026
Unknown · CVSS Not scored
Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023.1.4 and Stimulsoft Designer (Web) 2023.1.3 and Stimulsoft Viewer (Web) 2023.1.3. Access to the local file system is not prohibited in any way. Therefore, an attacker may include source code which reads or writes local directories and files. It is also possible for the attacker to prepare a report which has a variable that holds the gathered data and render it in the report.
Published Mar 27, 2023 · Updated Jul 5, 2026