Medium · CVSS 6.1
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted script to the title parameter in the index.php component.
Published Sep 28, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the index.php component.
Published Sep 27, 2023 · Updated Jul 9, 2026
Medium · CVSS 6.1
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component.
Published Nov 7, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Cross Site Scripting (XSS) in Webmail Calendar in IceWarp 10.3.1 allows remote attackers to inject arbitrary web script or HTML via the "p4" field.
Published Sep 12, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
File Upload vulnerability in adlered bolo-solo v.2.6 allows a remote attacker to execute arbitrary code via a crafted script to the authorization field in the header.
Published Sep 5, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability in the Usermin Configuration function of Webmin v2.100 allows attackers to execute arbitrary web sripts or HTML via a crafted payload injected into the Custom field.
Published Sep 15, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue was discovered in Webmin 2.100. The File Manager functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By providing a malicious payload, an attacker can inject arbitrary code, which is then executed within the context of the victim's browser when any file is searched/replaced.
Published Sep 15, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to execute malicious scripts via injecting a crafted payload into the Replace in Results file.
Published Sep 15, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to execute malicious scripts via injecting a crafted payload into the Find in Results file.
Published Sep 15, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability in Webmin v2.100 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cloned module name parameter.
Published Sep 15, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings.
Published Sep 19, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function.
Published Sep 19, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the login page which means the attacker is able to to steal plaintext credentials.
Published Sep 19, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php
Published Sep 19, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.
Published Aug 28, 2023 · Updated Jul 9, 2026
Critical · CVSS 9.8
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain an OS command injection vulnerability via shell metacharacters in the system_hostname parameter at /manage/network-basic.php.
Published Aug 21, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password that allows attackers to login with root privileges via the SSH service. The cleartext password corresponding to the $1$4Tmm01jl$7HRvcW.bz7uGmX9hiQWvR hash was not determined by the vulnerability discoverer.
Published Aug 21, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a SQL injection vulnerability via the a_passwd parameter at /portal/user-register.php.
Published Aug 21, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.
Published Aug 10, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.
Published Aug 10, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the sscanf function.
Published Aug 21, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the list parameter in the set_qosMib_list function.
Published Aug 21, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the list parameter in the save_virtualser_data function.
Published Aug 21, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis.
Published Sep 12, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
ASUS RT-AC66U B1 3.0.0.4.286_51665 was discovered to transmit sensitive information in cleartext.
Published Aug 8, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Cross Site Request Forgery (CSRF) vulnerability in Chamilo v.1.11 thru v.1.11.20 allows a remote authenticated privileged attacker to execute arbitrary code.
Published Aug 21, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An information leak in THE_B_members card v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
Published Sep 18, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An information leak in Coffee-jumbo v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
Published Sep 18, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An information leak in youmart-tokunaga v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
Published Sep 18, 2023 · Updated Jul 9, 2026
Medium · CVSS 6.5
An information leak in TonTon-Tei_waiting Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
Published Sep 18, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An information leak in YKC Tokushima_awayokocho Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
Published Sep 18, 2023 · Updated Jul 9, 2026
Medium · CVSS 6.5
An information leak in Cheese Cafe Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
Published Sep 18, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An information leak in Camp Style Project Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
Published Sep 18, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which could lead to privilege escalation.
Published Aug 9, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions in the directory /tmp.
Published Aug 9, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open the doors managed by the platform remotely via sending a crafted web request.
Published Aug 3, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload.
Published Aug 3, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses and device names.
Published Aug 3, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability.
Published Aug 3, 2023 · Updated Jul 9, 2026
High · CVSS 7.5
Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due to the fact that session ids are not validated for the type of user accessing the application by default. Privilege restrictions between non-admin and admin users are not enforced and any authenticated user can leverage admin functions without restriction by making direct requests to administrative endpoints.
Published Aug 3, 2023 · Updated Jul 9, 2026
Critical · CVSS 9.8
ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server via crafted requests to /base/sftpsetting/ endpoints that abuse a path traversal issue in the Username field and a lack of input sanitization on the SSH Key field. Overwriting specific files may lead to arbitrary code execution as NT AUTHORITY\SYSTEM.
Published Aug 3, 2023 · Updated Jul 9, 2026
High · CVSS 7.5 · CISA KEV
A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.
Published Aug 3, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrator password via a crafted web request.
Published Aug 3, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SQL injection vulnerability in berkaygediz O_Blog v.1.0 allows a local attacker to escalate privileges via the secure_file_priv component.
Published Aug 21, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A Prototype Pollution issue in Cronvel Tree-kit v.0.7.4 and before allows a remote attacker to execute arbitrary code via the extend function.
Published Aug 16, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.
Published Sep 20, 2023 · Updated Jul 9, 2026
High · CVSS 8.8
File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information via the extension filtering and renaming functions.
Published Sep 20, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.
Published Sep 20, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SQL injection vulnerability in Kidus Minimati v.1.0.0 allows a remote attacker to obtain sensitive information via the edit.php component.
Published Aug 17, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks.
Published Aug 21, 2023 · Updated Jul 9, 2026