Weekly Vulnerabilities Reports > March 13 to 19, 2023
Overview
428 new vulnerabilities reported during this period, including 93 critical vulnerabilities and 162 high severity vulnerabilities. This weekly summary report vulnerabilities in 524 products from 223 vendors including SAP, Dell, Samsung, Akuvox, and Opensips. Vulnerabilities are notably categorized as "Cross-site Scripting", "SQL Injection", "Improper Restriction of Operations within the Bounds of a Memory Buffer", "Out-of-bounds Write", and "Classic Buffer Overflow".
- 348 reported vulnerabilities are remotely exploitables.
- 2 reported vulnerabilities have public exploit available.
- 68 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
- 248 reported vulnerabilities are exploitable by an anonymous user.
- SAP has the most reported vulnerabilities, with 22 reported vulnerabilities.
- Samsung has the most reported critical vulnerabilities, with 7 reported vulnerabilities.
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
EXPLOITABLE
EXPLOITABLE
AVAILABLE
ANONYMOUSLY
WEB APPLICATION
Vulnerability Details
The following table list reported vulnerabilities for the period covered by this report:
93 Critical Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2023-03-16 | CVE-2023-28110 | Fit2Cloud | Unspecified vulnerability in Fit2Cloud Jumpserver and Koko Jumpserver is a popular open source bastion host, and Koko is a Jumpserver component that is the Go version of coco, refactoring coco's SSH/SFTP service and Web Terminal service. | 9.9 |
2023-03-19 | CVE-2023-1498 | Fabianros | Unspecified vulnerability in Fabianros Responsive Hotel Site 1.0 A vulnerability classified as critical has been found in code-projects Responsive Hotel Site 1.0. | 9.8 |
2023-03-19 | CVE-2023-1499 | Code Projects | Unspecified vulnerability in Code-Projects Simple ART Gallery 1.0 A vulnerability classified as critical was found in code-projects Simple Art Gallery 1.0. | 9.8 |
2023-03-19 | CVE-2023-1497 | Simple AND Nice Shopping Cart Script Project | Unspecified vulnerability in Simple and Nice Shopping Cart Script Project Simple and Nice Shopping Cart Script 1.0 A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. | 9.8 |
2023-03-19 | CVE-2023-26805 | Tenda | Out-of-bounds Write vulnerability in Tenda W20E Firmware 15.11.0.6 Tenda W20E v15.11.0.6 (US_W20EV4.0br_v15.11.0.6(1068_1546_841)_CN_TDC) is vulnerable to Buffer Overflow via function formIPMacBindModify. | 9.8 |
2023-03-19 | CVE-2023-26806 | Tenda | Out-of-bounds Write vulnerability in Tenda W20E Firmware 15.11.0.6 Tenda W20E v15.11.0.6(US_W20EV4.0br_v15.11.0.6(1068_1546_841 is vulnerable to Buffer Overflow via function formSetSysTime, | 9.8 |
2023-03-19 | CVE-2023-26905 | Alphaware Simple E Commerce System Project | SQL Injection vulnerability in Alphaware - Simple E-Commerce System Project Alphaware - Simple E-Commerce System 1.0 An issue was discovered in Alphaware - Simple E-Commerce System v1.0. | 9.8 |
2023-03-18 | CVE-2023-1494 | Ibos | Unspecified vulnerability in Ibos 4.5.5 A vulnerability classified as critical has been found in IBOS 4.5.5. | 9.8 |
2023-03-18 | CVE-2023-28609 | Ansible Semaphore | Improper Authentication vulnerability in Ansible-Semaphore Ansible Semaphore api/auth.go in Ansible Semaphore before 2.8.89 mishandles authentication. | 9.8 |
2023-03-18 | CVE-2023-1483 | Teacms Project | Unspecified vulnerability in Teacms Project Teacms 2.0/2.0.1/2.0.2 A vulnerability has been found in XiaoBingBy TeaCMS up to 2.0.2 and classified as critical. | 9.8 |
2023-03-18 | CVE-2023-1484 | Xzjie CMS Project | Unspecified vulnerability in Xzjie CMS Project Xzjie CMS A vulnerability was found in xzjie cms up to 1.0.3 and classified as critical. | 9.8 |
2023-03-18 | CVE-2023-1479 | Simple Music Player Project | Unspecified vulnerability in Simple Music Player Project Simple Music Player 1.0 A vulnerability classified as critical has been found in SourceCodester Simple Music Player 1.0. | 9.8 |
2023-03-18 | CVE-2023-1480 | Monitoring OF Students Cyber Accounts System Project | Unspecified vulnerability in Monitoring of Students Cyber Accounts System Project Monitoring of Students Cyber Accounts System 1.0 A vulnerability classified as critical was found in SourceCodester Monitoring of Students Cyber Accounts System 1.0. | 9.8 |
2023-03-17 | CVE-2023-27595 | Cilium | Unspecified vulnerability in Cilium 1.13.0 Cilium is a networking, observability, and security solution with an eBPF-based dataplane. | 9.8 |
2023-03-17 | CVE-2023-28115 | Knplabs | Unspecified vulnerability in Knplabs Snappy Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. | 9.8 |
2023-03-17 | CVE-2023-28116 | Contiki NG | Out-of-bounds Write vulnerability in Contiki-Ng Contiki-NG is an open-source, cross-platform operating system for internet of things (IoT) devices. | 9.8 |
2023-03-17 | CVE-2023-1474 | Automatic Question Paper Generator System Project | Unspecified vulnerability in Automatic Question Paper Generator System Project Automatic Question Paper Generator System 1.0 A vulnerability classified as critical was found in SourceCodester Automatic Question Paper Generator System 1.0. | 9.8 |
2023-03-17 | CVE-2023-1475 | Canteen Management System Project | Unspecified vulnerability in Canteen Management System Project Canteen Management System 1.0 A vulnerability, which was classified as critical, has been found in SourceCodester Canteen Management System 1.0. | 9.8 |
2023-03-17 | CVE-2023-1464 | Medicine Tracker System Project | Unspecified vulnerability in Medicine Tracker System Project Medicine Tracker System 1.0 A vulnerability, which was classified as critical, was found in SourceCodester Medicine Tracker System 1.0. | 9.8 |
2023-03-17 | CVE-2023-1466 | Oretnom23 | Unspecified vulnerability in Oretnom23 Student Study Center Desk Management System 1.0 A vulnerability was found in SourceCodester Student Study Center Desk Management System 1.0. | 9.8 |
2023-03-17 | CVE-2023-1467 | Oretnom23 | Unspecified vulnerability in Oretnom23 Student Study Center Desk Management System 1.0 A vulnerability classified as critical has been found in SourceCodester Student Study Center Desk Management System 1.0. | 9.8 |
2023-03-17 | CVE-2023-1468 | Oretnom23 | Unspecified vulnerability in Oretnom23 Student Study Center Desk Management System 1.0 A vulnerability classified as critical was found in SourceCodester Student Study Center Desk Management System 1.0. | 9.8 |
2023-03-17 | CVE-2023-1152 | Utarit | SQL Injection vulnerability in Utarit Persolus Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information Technologies Persolus allows SQL Injection. This issue affects Persolus: before 2.03.93. | 9.8 |
2023-03-17 | CVE-2023-1461 | Canteen Management System Project | Unspecified vulnerability in Canteen Management System Project Canteen Management System 1.0 A vulnerability was found in SourceCodester Canteen Management System 1.0. | 9.8 |
2023-03-17 | CVE-2023-1459 | Canteen Management System Project | Unspecified vulnerability in Canteen Management System Project Canteen Management System 1.0 A vulnerability was found in SourceCodester Canteen Management System 1.0 and classified as critical. | 9.8 |
2023-03-17 | CVE-2023-1460 | Online Pizza Ordering System Project | Unspecified vulnerability in Online Pizza Ordering System Project Online Pizza Ordering System 1.0 A vulnerability was found in SourceCodester Online Pizza Ordering System 1.0. | 9.8 |
2023-03-17 | CVE-2023-1439 | Medicine Tracker System Project | Unspecified vulnerability in Medicine Tracker System Project Medicine Tracker System 1.0 A vulnerability, which was classified as critical, has been found in SourceCodester Medicine Tracker System 1.0. | 9.8 |
2023-03-17 | CVE-2023-1441 | Automatic Question Paper Generator System Project | Unspecified vulnerability in Automatic Question Paper Generator System Project Automatic Question Paper Generator System 1.0 A vulnerability has been found in SourceCodester Automatic Question Paper Generator System 1.0 and classified as critical. | 9.8 |
2023-03-17 | CVE-2023-1454 | Jeecg | Unspecified vulnerability in Jeecg Jeecg-Boot 3.5.0 A vulnerability classified as critical has been found in jeecg-boot 3.5.0. | 9.8 |
2023-03-17 | CVE-2023-28531 | Openbsd Netapp | ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. | 9.8 |
2023-03-16 | CVE-2022-43441 | Ghost | Improper Control of Dynamically-Managed Code Resources vulnerability in Ghost Sqlite3 A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1. | 9.8 |
2023-03-16 | CVE-2022-43604 | Opener Project | Unspecified vulnerability in Opener Project Opener An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. | 9.8 |
2023-03-16 | CVE-2022-43605 | Opener Project | Unspecified vulnerability in Opener Project Opener An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. | 9.8 |
2023-03-16 | CVE-2023-21459 | Samsung | Use After Free vulnerability in Samsung Android 11.0/12.0/13.0 Use after free vulnerability in decon driver prior to SMR Mar-2023 Release 1 allows attackers to cause memory access fault. | 9.8 |
2023-03-16 | CVE-2023-0598 | GE | Unspecified vulnerability in GE Ifix 2022/6.1/6.5 GE Digital Proficy iFIX 2022, GE Digital Proficy iFIX v6.1, and GE Digital Proficy iFIX v6.5 are vulnerable to code injection, which may allow an attacker to insert malicious configuration files in the expected web server execution path and gain full control of the HMI software. | 9.8 |
2023-03-16 | CVE-2023-1256 | Aveva | Unspecified vulnerability in Aveva Plant Scada and Telemetry Server The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states. | 9.8 |
2023-03-16 | CVE-2023-27041 | School Registration AND FEE System Project | SQL Injection vulnerability in School Registration and FEE System Project School Registration and FEE System 1.0 School Registration and Fee System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at/bilal final/edit_user.php. | 9.8 |
2023-03-16 | CVE-2023-27040 | Simple Image Gallery WEB APP Project | Injection vulnerability in Simple Image Gallery web APP Project Simple Image Gallery web APP 1.0 Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username parameter. | 9.8 |
2023-03-16 | CVE-2023-1432 | Online Food Ordering System Project | Unspecified vulnerability in Online Food Ordering System Project Online Food Ordering System 2.0 A vulnerability was found in SourceCodester Online Food Ordering System 2.0 and classified as critical. | 9.8 |
2023-03-16 | CVE-2023-27250 | Online Book Store Project Project | SQL Injection vulnerability in Online Book Store Project Online Book Store Project 1.0 Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php. | 9.8 |
2023-03-16 | CVE-2023-23150 | Lancombg | Unspecified vulnerability in Lancombg Sa-Wr915Nd Firmware 17.35.1 SA-WR915ND router firmware v17.35.1 was discovered to be vulnerable to code execution. | 9.8 |
2023-03-16 | CVE-2023-24795 | Jcgcn COM | Unspecified vulnerability in Jcgcn.Com Jhr-N916R Firmware Command execution vulnerability was discovered in JHR-N916R router firmware version<=21.11.1.1483. | 9.8 |
2023-03-16 | CVE-2023-26784 | Tosec | SQL Injection vulnerability in Tosec Kirin Fortress Machine 1.720200610 SQL Injection vulnerability found in Kirin Fortress Machine v.1.7-2020-0610 allows attackers to execute arbitrary code via the /admin.php?controller=admin_commonuser parameter. | 9.8 |
2023-03-16 | CVE-2023-25280 | Dlink | OS Command Injection vulnerability in Dlink Dir820La1 Firmware 105B03 OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp. | 9.8 |
2023-03-15 | CVE-2023-24468 | Microfocus | Unspecified vulnerability in Microfocus Netiq Advanced Authentication Broken access control in Advanced Authentication versions prior to 6.4.1.1 and 6.3.7.2 | 9.8 |
2023-03-15 | CVE-2023-28461 | Arraynetworks | Improper Authentication vulnerability in Arraynetworks Arrayos AG 9.4.0.469/9.4.0.470/9.4.0.481 Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. | 9.8 |
2023-03-15 | CVE-2020-27507 | Kamailio | Classic Buffer Overflow vulnerability in Kamailio The Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a buffer overflow that crashes the server or possibly have unspecified other impact. | 9.8 |
2023-03-15 | CVE-2023-25344 | Swig Templates Project Swig Project | An issue was discovered in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to execute arbitrary code via crafted Object.prototype anonymous function. | 9.8 |
2023-03-15 | CVE-2023-1379 | Friendly Island Pizza Website AND Ordering System Project | Unspecified vulnerability in Friendly Island Pizza Website and Ordering System Project Friendly Island Pizza Website and Ordering System 1.0 A vulnerability was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. | 9.8 |
2023-03-15 | CVE-2023-1416 | Code Projects | Unspecified vulnerability in Code-Projects Simple ART Gallery 1.0 A vulnerability classified as critical has been found in Simple Art Gallery 1.0. | 9.8 |
2023-03-15 | CVE-2023-24726 | Phpgurukul | SQL Injection vulnerability in PHPgurukul ART Gallery Management System 1.0 Art Gallery Management System v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter on the enquiry page. | 9.8 |
2023-03-15 | CVE-2023-27239 | Tenda | Out-of-bounds Write vulnerability in Tenda AX3 Firmware 16.03.12.11 Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the shareSpeed parameter at /goform/WifiGuestSet. | 9.8 |
2023-03-15 | CVE-2023-27240 | Tenda | Command Injection vulnerability in Tenda AX3 Firmware 16.03.12.11 Tenda AX3 V16.03.12.11 was discovered to contain a command injection vulnerability via the lanip parameter at /goform/AdvSetLanip. | 9.8 |
2023-03-15 | CVE-2023-28371 | Stellarium | Path Traversal vulnerability in Stellarium In Stellarium through 1.2, attackers can write to files that are typically unintended, such as ones with absolute pathnames or .. | 9.8 |
2023-03-15 | CVE-2023-27757 | Perfree | Unrestricted Upload of File with Dangerous Type vulnerability in Perfree Perfreeblog 3.1.1 An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to execute arbitrary code via a crafted JPG file. | 9.8 |
2023-03-14 | CVE-2023-1327 | Netgear | Improper Authentication vulnerability in Netgear Rax30 Firmware 1.0.3.64/1.0.4.66/1.0.5.70 Netgear RAX30 (AX2400), prior to version 1.0.6.74, was affected by an authentication bypass vulnerability, allowing an unauthenticated attacker to gain administrative access to the device's web management interface by resetting the admin password. | 9.8 |
2023-03-14 | CVE-2023-26511 | Propius | Use of Hard-coded Credentials vulnerability in Propius Machineselector 6.6.0/6.6.1 A Hard Coded Admin Credentials issue in the Web-UI Admin Panel in Propius MachineSelector 6.6.0 and 6.6.1 allows remote attackers to gain access to the admin panel Propiusadmin.php, which allows taking control of the affected system. | 9.8 |
2023-03-14 | CVE-2023-28343 | Apsystems | OS Command Injection vulnerability in Apsystems Energy Communication Unit Firmware C1.2.5 OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php. | 9.8 |
2023-03-14 | CVE-2023-23397 | Microsoft | Authentication Bypass by Capture-replay vulnerability in Microsoft products Microsoft Outlook Elevation of Privilege Vulnerability | 9.8 |
2023-03-14 | CVE-2022-39216 | Combodo | Unspecified vulnerability in Combodo Itop Combodo iTop is an open source, web-based IT service management platform. | 9.8 |
2023-03-14 | CVE-2023-1391 | Online Tours Travels Management System Project | Unspecified vulnerability in Online Tours & Travels Management System Project Online Tours & Travels Management System 1.0 A vulnerability, which was classified as problematic, was found in SourceCodester Online Tours & Travels Management System 1.0. | 9.8 |
2023-03-14 | CVE-2023-1392 | Online Pizza Ordering System Project | Unspecified vulnerability in Online Pizza Ordering System Project Online Pizza Ordering System 1.0 A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. | 9.8 |
2023-03-14 | CVE-2023-1394 | Online Graduate Tracer System Project | Unspecified vulnerability in Online Graduate Tracer System Project Online Graduate Tracer System 1.0 A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0. | 9.8 |
2023-03-14 | CVE-2023-27074 | Phpgurukul | SQL Injection vulnerability in PHPgurukul BP Monitoring Management System 1.0 BP Monitoring Management System v1.0 was discovered to contain a SQL injection vulnerability via the emailid parameter in the login page. | 9.8 |
2023-03-13 | CVE-2023-27052 | Moosikay Project | SQL Injection vulnerability in Moosikay Project Moosikay 1.0 E-Commerce System v1.0 ws discovered to contain a SQL injection vulnerability via the id parameter at /admin/delete_user.php. | 9.8 |
2023-03-13 | CVE-2023-27582 | Maddy Project | Improper Authentication vulnerability in Maddy Project Maddy maddy is a composable, all-in-one mail server. | 9.8 |
2023-03-13 | CVE-2023-0345 | Akuvox | Unspecified vulnerability in Akuvox E11 Firmware The Akuvox E11 secure shell (SSH) server is enabled by default and can be accessed by the root user. | 9.8 |
2023-03-13 | CVE-2023-0353 | Akuvox | Unspecified vulnerability in Akuvox E11 Firmware Akuvox E11 uses a weak encryption algorithm for stored passwords and uses a hard-coded password for decryption which could allow the encrypted passwords to be decrypted from the configuration file. | 9.8 |
2023-03-13 | CVE-2023-27583 | Panindex Project | Use of Hard-coded Credentials vulnerability in Panindex Project Panindex PanIndex is a network disk directory index. | 9.8 |
2023-03-13 | CVE-2023-25207 | Prestashop | SQL Injection vulnerability in Prestashop DPD France PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php. | 9.8 |
2023-03-13 | CVE-2023-25279 | Dlink | OS Command Injection vulnerability in Dlink Dir-820L Firmware 105B03 OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload. | 9.8 |
2023-03-13 | CVE-2021-45423 | PEV Project | Classic Buffer Overflow vulnerability in PEV Project PEV 0.81 A Buffer Overflow vulnerabilityexists in Pev 0.81 via the pe_exports function from exports.c.. | 9.8 |
2023-03-13 | CVE-2023-1378 | Friendly Island Pizza Website AND Ordering System Project | Unspecified vulnerability in Friendly Island Pizza Website and Ordering System Project Friendly Island Pizza Website and Ordering System 1.0 A vulnerability classified as critical was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. | 9.8 |
2023-03-13 | CVE-2023-0037 | 10Web | Unspecified vulnerability in 10Web MAP Builder for Google Maps The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection | 9.8 |
2023-03-13 | CVE-2023-26076 | Samsung | Classic Buffer Overflow vulnerability in Samsung products An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. | 9.8 |
2023-03-13 | CVE-2023-24762 | Dlink | OS Command Injection vulnerability in Dlink Dir-867 Firmware 1.30B07 OS Command injection vulnerability in D-Link DIR-867 DIR_867_FW1.30B07 allows attackers to execute arbitrary commands via a crafted LocalIPAddress parameter for the SetVirtualServerSettings to HNAP1. | 9.8 |
2023-03-13 | CVE-2023-26073 | Samsung | Out-of-bounds Write vulnerability in Samsung products An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. | 9.8 |
2023-03-13 | CVE-2023-27061 | Tenda | Classic Buffer Overflow vulnerability in Tenda W15E Firmware 15.11.0.14 Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the wifiFilterListRemark parameter in the modifyWifiFilterRules function. | 9.8 |
2023-03-13 | CVE-2023-27063 | Tenda | Classic Buffer Overflow vulnerability in Tenda W15E Firmware 15.11.0.14 Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the DNSDomainName parameter in the formModifyDnsForward function. | 9.8 |
2023-03-13 | CVE-2023-26074 | Samsung | Out-of-bounds Write vulnerability in Samsung products An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123.. | 9.8 |
2023-03-13 | CVE-2023-24033 | Samsung | Unspecified vulnerability in Samsung products The Samsung Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T512 baseband modem chipsets do not properly check format types specified by the Session Description Protocol (SDP) module, which can lead to a denial of service. | 9.8 |
2023-03-13 | CVE-2023-26072 | Samsung | Out-of-bounds Write vulnerability in Samsung products An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. | 9.8 |
2023-03-13 | CVE-2023-1368 | Xhcms Project | Unspecified vulnerability in Xhcms Project Xhcms 1.0 A vulnerability was found in XHCMS 1.0. | 9.8 |
2023-03-13 | CVE-2023-28154 | Webpack JS | Unspecified vulnerability in Webpack.Js Webpack Webpack 5 before 5.76.0 does not avoid cross-realm object access. | 9.8 |
2023-03-16 | CVE-2020-19947 | Markdown Edit Project | Cross-site Scripting vulnerability in Markdown Edit Project Markdown Edit Cross Site Scripting vulnerability found in Markdown Edit allows a remote attacker to execute arbitrary code via the edit parameter of the webpage. | 9.6 |
2023-03-14 | CVE-2023-27501 | SAP | Unspecified vulnerability in SAP Netweaver Application Server Abap SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker to exploit insufficient validation of path information provided by users, thus exploiting a directory traversal flaw in an available service to delete system files. | 9.6 |
2023-03-14 | CVE-2023-27269 | SAP | Unspecified vulnerability in SAP Netweaver Application Server Abap SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker with non-administrative authorizations to exploit a directory traversal flaw in an available service to overwrite the system files. | 9.6 |
2023-03-16 | CVE-2023-21455 | Samsung | Unspecified vulnerability in Samsung Exynos Firmware Improper authorization implementation in Exynos baseband prior to SMR Mar-2023 Release 1 allows incorrect handling of unencrypted message. | 9.1 |
2023-03-16 | CVE-2023-0811 | Omron | Unspecified vulnerability in Omron products Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. | 9.1 |
2023-03-16 | CVE-2020-22647 | Smartconrtactgames Project | Exposure of Resource to Wrong Sphere vulnerability in Smartconrtactgames Project Smartconrtactgames An issue found in DepositGame v.1.0 allows an attacker to gain sensitive information via the GetBonusWithdraw and withdraw functions. | 9.1 |
2023-03-13 | CVE-2023-0349 | Akuvox | Unspecified vulnerability in Akuvox E11 Firmware The Akuvox E11 libvoice library provides unauthenticated access to the camera capture for image and video. | 9.1 |
2023-03-13 | CVE-2023-0352 | Akuvox | Unspecified vulnerability in Akuvox E11 Firmware The Akuvox E11 password recovery webpage can be accessed without authentication, and an attacker could download the device key file. | 9.1 |
2023-03-13 | CVE-2023-0354 | Akuvox | Unspecified vulnerability in Akuvox E11 Firmware The Akuvox E11 web server can be accessed without any user authentication, and this could allow an attacker to access sensitive information, as well as create and download packet captures with known default URLs. | 9.1 |
162 High Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2023-03-19 | CVE-2023-1501 | Rockoa | Unspecified vulnerability in Rockoa 2.3.2 A vulnerability, which was classified as critical, was found in RockOA 2.3.2. | 8.8 |
2023-03-19 | CVE-2023-1495 | Ruifang Tech | SQL Injection vulnerability in Ruifang-Tech Rebuild A vulnerability classified as critical was found in Rebuild up to 3.2.3. | 8.8 |
2023-03-18 | CVE-2023-1482 | Hkcms Project | Unspecified vulnerability in Hkcms Project Hkcms 2.2.4.230206 A vulnerability, which was classified as problematic, was found in HkCms 2.2.4.230206. | 8.8 |
2023-03-17 | CVE-2023-27253 | Netgate | XML Injection (aka Blind XPath Injection) vulnerability in Netgate Pfsense 2.7.0 A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml. | 8.8 |
2023-03-17 | CVE-2022-46854 | Obox | Unspecified vulnerability in Obox Launchpad - Coming Soon & Maintenance Mode Plugin 1.0.13 Cross-Site Request Forgery (CSRF) vulnerability in Obox Themes Launchpad – Coming Soon & Maintenance Mode plugin <= 1.0.13 versions. | 8.8 |
2023-03-17 | CVE-2022-46867 | Universal Star Rating Project | Cross-Site Request Forgery (CSRF) vulnerability in Universal Star Rating Project Universal Star Rating 2.1.0 Cross-Site Request Forgery (CSRF) vulnerability in Chasil Universal Star Rating plugin <= 2.1.0 version. | 8.8 |
2023-03-17 | CVE-2023-1440 | Automatic Question Paper Generator System Project | Unspecified vulnerability in Automatic Question Paper Generator System Project Automatic Question Paper Generator System 1.0 A vulnerability, which was classified as critical, was found in SourceCodester Automatic Question Paper Generator System 1.0. | 8.8 |
2023-03-16 | CVE-2023-28105 | GO Huge Util Project | Unspecified vulnerability in Go-Huge-Util Project Go-Huge-Util go-used-util has commonly used utility functions for Go. | 8.8 |
2023-03-16 | CVE-2023-27037 | Qibosoft | SQL Injection vulnerability in Qibosoft Qibocms V7 Qibosoft QiboCMS v7 was discovered to contain a remote code execution (RCE) vulnerability via the Get_Title function at label_set_rs.php | 8.8 |
2023-03-16 | CVE-2022-38063 | Social Login WP Project | Unspecified vulnerability in Social Login WP Project Social Login WP Cross-Site Request Forgery (CSRF) vulnerability in Social Login WP plugin <= 5.0.0.0 versions. | 8.8 |
2023-03-16 | CVE-2022-4009 | Octopus | Command Injection vulnerability in Octopus Server In affected versions of Octopus Deploy it is possible for a user to introduce code via offline package creation | 8.8 |
2023-03-16 | CVE-2023-24760 | Ofcms Project | Improper Privilege Management vulnerability in Ofcms Project Ofcms 1.1.4 An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController. | 8.8 |
2023-03-15 | CVE-2022-4313 | Tenable | Unspecified vulnerability in Tenable Nessus A vulnerability was reported where through modifying the scan variables, an authenticated user in Tenable products, that has Scan Policy Configuration roles, could manipulate audit policy variables to execute arbitrary commands on credentialed scan targets. | 8.8 |
2023-03-15 | CVE-2023-1389 | TP Link | Command Injection vulnerability in Tp-Link Archer Ax21 Firmware TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. | 8.8 |
2023-03-15 | CVE-2023-28337 | Netgear | Unrestricted Upload of File with Dangerous Type vulnerability in Netgear Rax30 Firmware When uploading a firmware image to a Netgear Nighthawk Wifi6 Router (RAX30), a hidden “forceFWUpdate” parameter may be provided to force the upgrade to complete and bypass certain validation checks. | 8.8 |
2023-03-15 | CVE-2023-25267 | GFI | Out-of-bounds Write vulnerability in GFI Kerio Connect 9.4.1 An issue was discovered in GFI Kerio Connect 9.4.1 patch 1 (fixed in 10.0.0). | 8.8 |
2023-03-15 | CVE-2023-26284 | IBM | Unspecified vulnerability in IBM MQ Certified Container IBM MQ Certified Container 9.3.0.1 through 9.3.0.3 and 9.3.1.0 through 9.3.1.1 could allow authenticated users with the cluster to be granted administration access to the MQ console due to improper access controls. | 8.8 |
2023-03-15 | CVE-2023-1415 | Code Projects | Unspecified vulnerability in Code-Projects Simple ART Gallery 1.0 A vulnerability was found in Simple Art Gallery 1.0. | 8.8 |
2023-03-15 | CVE-2022-44580 | Richplugins | Unspecified vulnerability in Richplugins Plugin for Google Reviews SQL Injection (SQLi) vulnerability in RichPlugins Plugin for Google Reviews plugin <= 2.2.3 versions. | 8.8 |
2023-03-15 | CVE-2023-0100 | Eclipse | Unspecified vulnerability in Eclipse Business Intelligence and Reporting Tools In Eclipse BIRT, starting from version 2.6.2, the default configuration allowed to retrieve a report from the same host using an absolute HTTP path for the report parameter (e.g. | 8.8 |
2023-03-15 | CVE-2023-27103 | Struktur | Out-of-bounds Write vulnerability in Struktur Libde265 1.0.11 Libde265 v1.0.11 was discovered to contain a heap buffer overflow via the function derive_collocated_motion_vectors at motion.cc. | 8.8 |
2023-03-15 | CVE-2023-24728 | Simple Customer Relationship Management System Project | SQL Injection vulnerability in Simple Customer Relationship Management System Project Simple Customer Relationship Management System 1.0 Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the contact parameter in the user profile update function. | 8.8 |
2023-03-15 | CVE-2023-24729 | Simple Customer Relationship Management System Project | SQL Injection vulnerability in Simple Customer Relationship Management System Project Simple Customer Relationship Management System 1.0 Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the address parameter in the user profile update function. | 8.8 |
2023-03-15 | CVE-2023-24730 | Simple Customer Relationship Management System Project | SQL Injection vulnerability in Simple Customer Relationship Management System Project Simple Customer Relationship Management System 1.0 Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the company parameter in the user profile update function. | 8.8 |
2023-03-15 | CVE-2023-24731 | Simple Customer Relationship Management System Project | SQL Injection vulnerability in Simple Customer Relationship Management System Project Simple Customer Relationship Management System 1.0 Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the query parameter in the user profile update function. | 8.8 |
2023-03-15 | CVE-2023-24732 | Simple Customer Relationship Management System Project | SQL Injection vulnerability in Simple Customer Relationship Management System Project Simple Customer Relationship Management System 1.0 Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the gender parameter in the user profile update function. | 8.8 |
2023-03-15 | CVE-2022-47427 | MY Calendar Project | Unspecified vulnerability in MY Calendar Project MY Calendar Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.3.24.1 versions. | 8.8 |
2023-03-15 | CVE-2023-25708 | Rextheme | Unspecified vulnerability in Rextheme WP VR Cross-Site Request Forgery (CSRF) vulnerability in Rextheme WP VR – 360 Panorama and Virtual Tour Builder For WordPress plugin <= 8.2.7 versions. | 8.8 |
2023-03-15 | CVE-2023-25709 | Plainware | Unspecified vulnerability in Plainware Locatoraid Cross-Site Request Forgery (CSRF) vulnerability in Plainware Locatoraid Store Locator plugin <= 3.9.11 versions. | 8.8 |
2023-03-15 | CVE-2023-25968 | Cozmoslabs | Unspecified vulnerability in Cozmoslabs Client Portal Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs, Madalin Ungureanu, Antohe Cristian Client Portal – Private user pages and login plugin <= 1.1.8 versions. | 8.8 |
2023-03-14 | CVE-2023-28339 | Opendoas Project | Unspecified vulnerability in Opendoas Project Opendoas OpenDoas through 6.8.2, when TIOCSTI is available, allows privilege escalation because of sharing a terminal with the original session. | 8.8 |
2023-03-14 | CVE-2023-23413 | Microsoft | Unspecified vulnerability in Microsoft products Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | 8.8 |
2023-03-14 | CVE-2023-25206 | Prestashop | SQL Injection vulnerability in Prestashop Advanced Reviews PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection. | 8.8 |
2023-03-14 | CVE-2023-1299 | Hashicorp | Unspecified vulnerability in Hashicorp Nomad 1.5.0 HashiCorp Nomad and Nomad Enterprise 1.5.0 allow a job submitter to escalate to management-level privileges using workload identity and task API. | 8.8 |
2023-03-14 | CVE-2023-1398 | Teacms Project | Path Traversal vulnerability in Teacms Project Teacms 2.0 A vulnerability classified as critical was found in XiaoBingBy TeaCMS 2.0. | 8.8 |
2023-03-14 | CVE-2023-27309 | Siemens | Unspecified vulnerability in Siemens Ruggedcom Crossbow A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). | 8.8 |
2023-03-14 | CVE-2023-27310 | Siemens | Unspecified vulnerability in Siemens Ruggedcom Crossbow A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). | 8.8 |
2023-03-14 | CVE-2023-27463 | Siemens | Unspecified vulnerability in Siemens Ruggedcom Crossbow 5.2 A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). | 8.8 |
2023-03-14 | CVE-2022-47141 | Seerox | Unspecified vulnerability in Seerox WP Dynamic Keywords Injector Cross-Site Request Forgery (CSRF) vulnerability in Seerox WP Dynamic Keywords Injector plugin <= 2.3.15 versions. | 8.8 |
2023-03-14 | CVE-2022-47143 | Themeisle | Unspecified vulnerability in Themeisle multiple Page Generator Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Multiple Page Generator Plugin – MPG plugin <= 3.3.9 versions. | 8.8 |
2023-03-14 | CVE-2022-47147 | Kesz1 | Unspecified vulnerability in Kesz1 Ipblocklist Cross-Site Request Forgery (CSRF) vulnerability in Kesz1 Technologies ipBlockList plugin <= 1.0 versions. | 8.8 |
2023-03-14 | CVE-2022-47422 | Hmplugin | Unspecified vulnerability in Hmplugin Accept Stripe Donation - Aidwp Cross-Site Request Forgery (CSRF) vulnerability in HM Plugin Accept Stripe Donation – AidWP plugin <= 3.1.5 versions. | 8.8 |
2023-03-14 | CVE-2022-47443 | Multi Rating Project | Unspecified vulnerability in Multi Rating Project Multi Rating Cross-Site Request Forgery (CSRF) vulnerability in Daniel Powney Multi Rating plugin <= 5.0.5 versions. | 8.8 |
2023-03-14 | CVE-2022-47154 | Piwebsolution | Unspecified vulnerability in Piwebsolution CSS JS Manager, Async Javascript, Defer Render Blocking CSS Supports Woocommerce Cross-Site Request Forgery (CSRF) vulnerability in Pi Websolution CSS JS Manager, Async JavaScript, Defer Render Blocking CSS supports WooCommerce plugin <= 2.4.49 versions. | 8.8 |
2023-03-14 | CVE-2022-47155 | Supsystic | Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Slider Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Slider by Supsystic plugin <= 1.8.5 versions. | 8.8 |
2023-03-14 | CVE-2022-47162 | DH Anti Adblocker Project | Unspecified vulnerability in DH - Anti Adblocker Project DH - Anti Adblocker Cross-Site Request Forgery (CSRF) vulnerability in Dannie Herdyawan DH – Anti AdBlocker plugin <= 36 versions. | 8.8 |
2023-03-14 | CVE-2023-27893 | SAP | Unspecified vulnerability in SAP Solution Manager 740 An attacker authenticated as a user with a non-administrative role and a common remote execution authorization in SAP Solution Manager and ABAP managed systems (ST-PI) - versions 2088_1_700, 2008_1_710, 740, can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform. Depending on the function executed, the attack can read or modify any user or application data and can make the application unavailable. | 8.8 |
2023-03-14 | CVE-2023-25616 | SAP | Unspecified vulnerability in SAP Business Objects Business Intelligence Platform 420/430 In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object execution can lead to code injection vulnerability which could allow an attacker to gain access to resources that are allowed by extra privileges. | 8.8 |
2023-03-14 | CVE-2023-25617 | SAP | Unspecified vulnerability in SAP Business Objects Business Intelligence Platform 420/430 SAP Business Object (Adaptive Job Server) - versions 420, 430, allows remote execution of arbitrary commands on Unix, when program objects execution is enabled, to authenticated users with scheduling rights, using the BI Launchpad, Central Management Console or a custom application based on the public java SDK. | 8.8 |
2023-03-13 | CVE-2023-0351 | Akuvox | Command Injection vulnerability in Akuvox E11 Firmware The Akuvox E11 web server backend library allows command injection in the device phone-book contacts functionality. | 8.8 |
2023-03-13 | CVE-2023-27581 | Github Slug Action Project | Unspecified vulnerability in Github-Slug-Action Project Github-Slug-Action github-slug-action is a GitHub Action to expose slug value of GitHub environment variables inside of one's GitHub workflow. | 8.8 |
2023-03-13 | CVE-2023-0477 | CM WP | Unrestricted Upload of File with Dangerous Type vulnerability in Cm-Wp Auto Featured Image The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.16 includes an AJAX endpoint that allows any user with at least Author privileges to upload arbitrary files, such as PHP files. | 8.8 |
2023-03-13 | CVE-2023-25170 | Prestashop | Unspecified vulnerability in Prestashop PrestaShop is an open source e-commerce web application that, prior to version 8.0.1, is vulnerable to cross-site request forgery (CSRF). | 8.8 |
2023-03-13 | CVE-2023-25973 | Autoaffiliatelinks | Unspecified vulnerability in Autoaffiliatelinks Auto Affiliate Links Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3.0.2 versions. | 8.8 |
2023-03-13 | CVE-2022-38074 | Veronalabs | Unspecified vulnerability in Veronalabs WP Statistics SQL Injection vulnerability in VeronaLabs WP Statistics plugin <= 13.2.10 versions. | 8.8 |
2023-03-13 | CVE-2023-25991 | Metagauss | Unspecified vulnerability in Metagauss Registrationmagic Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic plugin <= 5.1.9.2 versions. | 8.8 |
2023-03-13 | CVE-2022-47166 | Voidcoders | Unspecified vulnerability in Voidcoders Void Contact Form 7 Widget for Elementor Page Builder Cross-Site Request Forgery (CSRF) vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder plugin <= 2.1.1 versions. | 8.8 |
2023-03-13 | CVE-2022-47440 | MY Tickets Project | Unspecified vulnerability in MY Tickets Project MY Tickets Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Tickets plugin <= 1.9.10 versions. | 8.8 |
2023-03-14 | CVE-2023-23857 | SAP | Unspecified vulnerability in SAP Netweaver Application Server for Java 7.50 Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and services across systems. | 8.6 |
2023-03-15 | CVE-2023-26484 | Kubevirt | Unspecified vulnerability in Kubevirt KubeVirt is a virtual machine management add-on for Kubernetes. | 8.2 |
2023-03-15 | CVE-2020-4927 | IBM | Unspecified vulnerability in IBM Spectrum Scale A vulnerability in the Spectrum Scale 5.0.5.0 through 5.1.6.1 core component could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. | 8.2 |
2023-03-17 | CVE-2023-28112 | Discourse | Unspecified vulnerability in Discourse Discourse is an open-source discussion platform. | 8.1 |
2023-03-17 | CVE-2023-1455 | Online Pizza Ordering System Project | Unspecified vulnerability in Online Pizza Ordering System Project Online Pizza Ordering System 1.0 A vulnerability classified as critical was found in SourceCodester Online Pizza Ordering System 1.0. | 8.1 |
2023-03-16 | CVE-2023-21457 | Samsung | Unspecified vulnerability in Samsung Android 11.0/12.0/13.0 Improper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers to send file via Bluetooth without related permission. | 8.1 |
2023-03-14 | CVE-2023-27500 | SAP | Path Traversal vulnerability in SAP Netweaver Application Server Abap An attacker with non-administrative authorizations can exploit a directory traversal flaw in program SAPRSBRO to over-write system files. | 8.1 |
2023-03-19 | CVE-2022-48423 | Linux | Out-of-bounds Write vulnerability in Linux Kernel In the Linux kernel before 6.1.3, fs/ntfs3/record.c does not validate resident attribute names. | 7.8 |
2023-03-19 | CVE-2022-48424 | Linux | Unspecified vulnerability in Linux Kernel In the Linux kernel before 6.1.3, fs/ntfs3/inode.c does not validate the attribute name offset. | 7.8 |
2023-03-19 | CVE-2022-48425 | Linux | Release of Invalid Pointer or Reference vulnerability in Linux Kernel In the Linux kernel through 6.2.7, fs/ntfs3/inode.c has an invalid kfree because it does not validate MFT flags before replaying logs. | 7.8 |
2023-03-19 | CVE-2023-28617 | GNU | OS Command Injection vulnerability in GNU ORG Mode org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs allows attackers to execute arbitrary commands via a file name or directory name that contains shell metacharacters. | 7.8 |
2023-03-19 | CVE-2022-48422 | Onlyoffice | Uncontrolled Search Path Element vulnerability in Onlyoffice Document Server ONLYOFFICE Docs through 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libgcc_s.so.1 in the current working directory, which may be any directory in which an ONLYOFFICE document is located. | 7.8 |
2023-03-18 | CVE-2023-1489 | Wisecleaner | Unspecified vulnerability in Wisecleaner Wise System Monitor 1.5.3.54 A vulnerability has been found in Lespeed WiseCleaner Wise System Monitor 1.5.3.54 and classified as critical. | 7.8 |
2023-03-17 | CVE-2023-1448 | Gpac | Unspecified vulnerability in Gpac 2.3 A vulnerability, which was classified as problematic, was found in GPAC 2.3-DEV-rev35-gbbca86917-master. | 7.8 |
2023-03-17 | CVE-2023-1449 | Gpac | Unspecified vulnerability in Gpac 2.3 A vulnerability has been found in GPAC 2.3-DEV-rev35-gbbca86917-master and classified as problematic. | 7.8 |
2023-03-17 | CVE-2023-1452 | Gpac | Unspecified vulnerability in Gpac 2.3 A vulnerability was found in GPAC 2.3-DEV-rev35-gbbca86917-master. | 7.8 |
2023-03-16 | CVE-2023-22883 | Zoom | Unspecified vulnerability in Zoom Meetings Zoom Client for IT Admin Windows installers before version 5.13.5 contain a local privilege escalation vulnerability. | 7.8 |
2023-03-16 | CVE-2023-28108 | Pimcore | Unspecified vulnerability in Pimcore Pimcore is an open source data and experience management platform. | 7.8 |
2023-03-16 | CVE-2021-31637 | Uwamp Project | Uncontrolled Search Path Element vulnerability in Uwamp Project Uwamp An issue found in UwAmp v.1.1, 1.2, 1.3, 2.0, 2.1, 2.2, 2.2.1, 3.0.0, 3.0.1, 3.0.2 allows a remote attacker to execute arbitrary code via a crafted DLL. | 7.8 |
2023-03-16 | CVE-2023-24671 | Vxsearch | Unquoted Search Path or Element vulnerability in Vxsearch VX Search 13.8/14.7 VX Search v13.8 and v14.7 was discovered to contain an unquoted service path vulnerability which allows attackers to execute arbitrary commands at elevated privileges via a crafted executable file. | 7.8 |
2023-03-15 | CVE-2023-24229 | Draytek | Command Injection vulnerability in Draytek Vigor2960 Firmware 1.5.1.4 DrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to inject operating system commands via the mainfunction.cgi 'parameter' parameter. | 7.8 |
2023-03-15 | CVE-2023-27781 | Jpegoptim Project | Out-of-bounds Write vulnerability in Jpegoptim Project Jpegoptim 1.5.2 jpegoptim v1.5.2 was discovered to contain a heap overflow in the optimize function at jpegoptim.c. | 7.8 |
2023-03-14 | CVE-2023-27590 | Rizin | Unspecified vulnerability in Rizin Rizin is a UNIX-like reverse engineering framework and command-line toolset. | 7.8 |
2023-03-14 | CVE-2023-27399 | Siemens | Unspecified vulnerability in Siemens Tecnomatix Plant Simulation 16.0.5/2201.0 A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). | 7.8 |
2023-03-13 | CVE-2023-27010 | Wondershare | Unspecified vulnerability in Wondershare Dr.Fone 12.9.6 Wondershare Dr.Fone v12.9.6 was discovered to contain weak permissions for the service WsDrvInst. | 7.8 |
2023-03-13 | CVE-2023-0628 | Docker | Command Injection vulnerability in Docker Desktop Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking a user to open a crafted malicious docker-desktop:// URL. | 7.8 |
2023-03-18 | CVE-2021-46877 | Fasterxml | Allocation of Resources Without Limits or Throttling vulnerability in Fasterxml Jackson-Databind jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization. | 7.5 |
2023-03-18 | CVE-2023-26113 | Collection JS Project | Unspecified vulnerability in Collection.Js Project Collection.Js Versions of the package collection.js before 6.8.1 are vulnerable to Prototype Pollution via the extend function in Collection.js/dist/node/iterators/extend.js. | 7.5 |
2023-03-17 | CVE-2023-24678 | Centralite | Unspecified vulnerability in Centralite Pearl Firmware 0X04075010 A vulnerability in Centralite Pearl Thermostat 0x04075010 allows attackers to cause a Denial of Service (DoS) via a crafted Zigbee message. | 7.5 |
2023-03-17 | CVE-2023-27591 | Miniflux Project | Unspecified vulnerability in Miniflux Project Miniflux Miniflux is a feed reader. | 7.5 |
2023-03-17 | CVE-2023-28111 | Discourse | Unspecified vulnerability in Discourse Discourse is an open-source discussion platform. | 7.5 |
2023-03-17 | CVE-2023-1443 | Filseclab | Unspecified vulnerability in Filseclab Twister Antivirus 8.0 A vulnerability was found in Filseclab Twister Antivirus 8. | 7.5 |
2023-03-16 | CVE-2022-43606 | Opener Project | Unspecified vulnerability in Opener Project Opener A use-of-uninitialized-pointer vulnerability exists in the Forward Open connection_management_entry functionality of EIP Stack Group OpENer development commit 58ee13c. | 7.5 |
2023-03-16 | CVE-2023-1390 | Linux | Unspecified vulnerability in Linux Kernel A remote denial of service vulnerability was found in the Linux kernel’s TIPC kernel module. | 7.5 |
2023-03-16 | CVE-2023-22880 | Zoom | Unspecified vulnerability in Zoom Rooms, Virtual Desktop Infrastructure and Zoom Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Windows clients before 5.13.1 contain an information disclosure vulnerability. | 7.5 |
2023-03-16 | CVE-2023-22881 | Zoom | Unspecified vulnerability in Zoom Zoom clients before version 5.13.5 contain a STUN parsing vulnerability. | 7.5 |
2023-03-16 | CVE-2023-22882 | Zoom | Unspecified vulnerability in Zoom Zoom clients before version 5.13.5 contain a STUN parsing vulnerability. | 7.5 |
2023-03-16 | CVE-2023-28104 | Silverstripe | Allocation of Resources Without Limits or Throttling vulnerability in Silverstripe Graphql 4.1.1/4.2.2 `silverstripe/graphql` serves Silverstripe data as GraphQL representations. | 7.5 |
2023-03-16 | CVE-2023-26767 | Liblouis | Classic Buffer Overflow vulnerability in Liblouis 3.24.0 Buffer Overflow vulnerability found in Liblouis v.3.24.0 allows a remote attacker to cause a denial of service via the lou_logFile function at logginc.c endpoint. | 7.5 |
2023-03-16 | CVE-2023-26768 | Liblouis | Classic Buffer Overflow vulnerability in Liblouis 3.24.0 Buffer Overflow vulnerability found in Liblouis v.3.24.0 allows a remote attacker to cause a denial of service via the compileTranslationTable.c and lou_setDataPath functions. | 7.5 |
2023-03-16 | CVE-2023-26769 | Liblouis | Classic Buffer Overflow vulnerability in Liblouis 3.24.0 Buffer Overflow vulnerability found in Liblouis Lou_Trace v.3.24.0 allows a remote attacker to cause a denial of service via the resolveSubtable function at compileTranslationTabel.c. | 7.5 |
2023-03-16 | CVE-2023-27783 | Broadcom | Reachable Assertion vulnerability in Broadcom Tcpreplay 4.4.3 An issue found in TCPreplay tcprewrite v.4.4.3 allows a remote attacker to cause a denial of service via the tcpedit_dlt_cleanup function at plugins/dlt_plugins.c. | 7.5 |
2023-03-16 | CVE-2023-27784 | Broadcom | NULL Pointer Dereference vulnerability in Broadcom Tcpreplay 4.4.3 An issue found in TCPReplay v.4.4.3 allows a remote attacker to cause a denial of service via the read_hexstring function at the utils.c:309 endpoint. | 7.5 |
2023-03-16 | CVE-2023-27785 | Broadcom | NULL Pointer Dereference vulnerability in Broadcom Tcpreplay 4.4.3 An issue found in TCPreplay TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse endpoints function. | 7.5 |
2023-03-16 | CVE-2023-27786 | Broadcom | NULL Pointer Dereference vulnerability in Broadcom Tcpreplay 4.4.3 An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the macinstring function. | 7.5 |
2023-03-16 | CVE-2023-27787 | Broadcom | NULL Pointer Dereference vulnerability in Broadcom Tcpreplay 4.4.3 An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse_list function at the list.c:81 endpoint. | 7.5 |
2023-03-16 | CVE-2023-27788 | Broadcom | Reachable Assertion vulnerability in Broadcom Tcpreplay 4.4.3 An issue found in TCPrewrite v.4.4.3 allows a remote attacker to cause a denial of service via the ports2PORT function at the portmap.c:69 endpoint. | 7.5 |
2023-03-16 | CVE-2023-27789 | Broadcom | Reachable Assertion vulnerability in Broadcom Tcpreplay 4.4.3 An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the cidr2cidr function at the cidr.c:178 endpoint. | 7.5 |
2023-03-16 | CVE-2023-27875 | IBM | Unspecified vulnerability in IBM Aspera Faspex 5.0.4 IBM Aspera Faspex 5.0.4 could allow a user to change other user's credentials due to improper access controls. | 7.5 |
2023-03-16 | CVE-2023-25281 | Dlink | Out-of-bounds Write vulnerability in Dlink Dir820La1 Firmware 105B03 A stack overflow vulnerability exists in pingV4Msg component in D-Link DIR820LA1_FW105B03, allows attackers to cause a denial of service via the nextPage parameter to ping.ccp. | 7.5 |
2023-03-15 | CVE-2023-28097 | Opensips | Unspecified vulnerability in Opensips OpenSIPS is a Session Initiation Protocol (SIP) server implementation. | 7.5 |
2023-03-15 | CVE-2023-28098 | Opensips | Unspecified vulnerability in Opensips OpenSIPS is a Session Initiation Protocol (SIP) server implementation. | 7.5 |
2023-03-15 | CVE-2023-28099 | Opensips | Unspecified vulnerability in Opensips OpenSIPS is a Session Initiation Protocol (SIP) server implementation. | 7.5 |
2023-03-15 | CVE-2023-28338 | Netgear | Allocation of Resources Without Limits or Throttling vulnerability in Netgear Rax30 Firmware Any request send to a Netgear Nighthawk Wifi6 Router (RAX30)'s web service containing a “Content-Type” of “multipartboundary=” will result in the request body being written to “/tmp/mulipartFile” on the device itself. | 7.5 |
2023-03-15 | CVE-2023-27600 | Opensips | Unspecified vulnerability in Opensips OpenSIPS is a Session Initiation Protocol (SIP) server implementation. | 7.5 |
2023-03-15 | CVE-2023-27601 | Opensips | Unspecified vulnerability in Opensips OpenSIPS is a Session Initiation Protocol (SIP) server implementation. | 7.5 |
2023-03-15 | CVE-2023-28095 | Opensips | Unspecified vulnerability in Opensips OpenSIPS is a Session Initiation Protocol (SIP) server implementation. | 7.5 |
2023-03-15 | CVE-2023-28096 | Opensips | Unspecified vulnerability in Opensips OpenSIPS, a Session Initiation Protocol (SIP) server implementation, has a memory leak starting in the 2.3 branch and priot to versions 3.1.8 and 3.2.5. | 7.5 |
2023-03-15 | CVE-2023-27596 | Opensips | Allocation of Resources Without Limits or Throttling vulnerability in Opensips OpenSIPS is a Session Initiation Protocol (SIP) server implementation. | 7.5 |
2023-03-15 | CVE-2023-27597 | Opensips | Unspecified vulnerability in Opensips OpenSIPS is a Session Initiation Protocol (SIP) server implementation. | 7.5 |
2023-03-15 | CVE-2023-27598 | Opensips | Use of Uninitialized Resource vulnerability in Opensips OpenSIPS is a Session Initiation Protocol (SIP) server implementation. | 7.5 |
2023-03-15 | CVE-2023-27599 | Opensips | Unspecified vulnerability in Opensips OpenSIPS is a Session Initiation Protocol (SIP) server implementation. | 7.5 |
2023-03-15 | CVE-2023-28450 | Thekelleys | Unspecified vulnerability in Thekelleys Dnsmasq An issue was discovered in Dnsmasq before 2.90. | 7.5 |
2023-03-15 | CVE-2023-25345 | Swig Templates Project Swig Project | Path Traversal vulnerability in multiple products Directory traversal vulnerability in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to read arbitrary files via the include or extends tags. | 7.5 |
2023-03-15 | CVE-2022-38456 | Ajax Search Project | Unspecified vulnerability in Ajax Search Project Ajax Search Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ernest Marcinko Ajax Search Lite plugin <= 4.10.3 versions. | 7.5 |
2023-03-14 | CVE-2023-27588 | Hasura | Path Traversal vulnerability in Hasura Graphql Engine Hasura is an open-source product that provides users GraphQL or REST APIs. | 7.5 |
2023-03-14 | CVE-2023-27585 | Teluu | Unspecified vulnerability in Teluu Pjsip PJSIP is a free and open source multimedia communication library written in C. | 7.5 |
2023-03-14 | CVE-2022-39214 | Combodo | Unspecified vulnerability in Combodo Itop Combodo iTop is an open source, web-based IT service management platform. | 7.5 |
2023-03-14 | CVE-2023-25957 | Mendix | Improper Authentication vulnerability in Mendix Saml A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAML (Mendix 8 compatible) (All versions >= V2.2.0 < V2.3.0), Mendix SAML (Mendix 9 latest compatible, New Track) (All versions >= V3.1.9 < V3.3.1), Mendix SAML (Mendix 9 latest compatible, Upgrade Track) (All versions >= V3.1.8 < V3.3.0), Mendix SAML (Mendix 9.6 compatible, New Track) (All versions >= V3.1.9 < V3.2.7), Mendix SAML (Mendix 9.6 compatible, Upgrade Track) (All versions >= V3.1.8 < V3.2.6). | 7.5 |
2023-03-14 | CVE-2022-47163 | WP CSV TO Database Project | Cross-Site Request Forgery (CSRF) vulnerability in WP CSV to Database Project WP CSV to Database Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, josh401 WP CSV to Database – Insert CSV file content into WordPress plugin <= 2.6 versions. | 7.5 |
2023-03-14 | CVE-2023-27271 | SAP | Unspecified vulnerability in SAP Businessobjects Business Intelligence Platform 420/430 In SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own admintools, leading to a high impact on availability. | 7.5 |
2023-03-14 | CVE-2023-27896 | SAP | Unspecified vulnerability in SAP Businessobjects Business Intelligence 420/430 In SAP BusinessObjects Business Intelligence Platform - version 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own CMS, leading to a high impact on availability. | 7.5 |
2023-03-13 | CVE-2023-0346 | Akuvox | Unspecified vulnerability in Akuvox E11 Firmware Akuvox E11 cloud login is performed through an unencrypted HTTP connection. | 7.5 |
2023-03-13 | CVE-2023-0348 | Akuvox | Unspecified vulnerability in Akuvox E11 Firmware Akuvox E11 allows direct SIP calls. | 7.5 |
2023-03-13 | CVE-2023-0355 | Akuvox | Unspecified vulnerability in Akuvox E11 Firmware Akuvox E11 uses a hard-coded cryptographic key, which could allow an attacker to decrypt sensitive information. | 7.5 |
2023-03-13 | CVE-2023-25802 | Roxy WI | Exposure of Resource to Wrong Sphere vulnerability in Roxy-Wi Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. | 7.5 |
2023-03-13 | CVE-2023-25803 | Roxy WI | Unspecified vulnerability in Roxy-Wi Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. | 7.5 |
2023-03-13 | CVE-2022-31474 | Ithemes | Unspecified vulnerability in Ithemes Backupbuddy 8.5.8.0/8.7.4.1 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in iThemes BackupBuddy allows Path Traversal.This issue affects BackupBuddy: from 8.5.8.0 through 8.7.4.1. | 7.5 |
2023-03-13 | CVE-2023-27062 | Tenda | Classic Buffer Overflow vulnerability in Tenda W15E Firmware 15.11.0.14 Tenda V15V1.0 was discovered to contain a buffer overflow vulnerability via the gotoUrl parameter in the formPortalAuth function. | 7.5 |
2023-03-13 | CVE-2023-27064 | Tenda | Classic Buffer Overflow vulnerability in Tenda W15E Firmware 15.11.0.14 Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the index parameter in the formDelDnsForward function. | 7.5 |
2023-03-13 | CVE-2023-27065 | Tenda | Classic Buffer Overflow vulnerability in Tenda W15E Firmware 15.11.0.14 Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the picName parameter in the formDelWewifiPi function. | 7.5 |
2023-03-13 | CVE-2023-25283 | Dlink | Out-of-bounds Write vulnerability in Dlink Dir-820L Firmware 1.06B02 A stack overflow vulnerability in D-Link DIR820LA1_FW106B02 allows attackers to cause a denial of service via the reserveDHCP_HostName_1.1.1.0 parameter to lan.asp. | 7.5 |
2023-03-13 | CVE-2023-1364 | Online Pizza Ordering System Project | Unspecified vulnerability in Online Pizza Ordering System Project Online Pizza Ordering System 1.0 A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. | 7.5 |
2023-03-13 | CVE-2023-1365 | Online Pizza Ordering System Project | Unspecified vulnerability in Online Pizza Ordering System Project Online Pizza Ordering System 1.0 A vulnerability was found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. | 7.5 |
2023-03-17 | CVE-2021-21548 | Dell | Improper Certificate Validation vulnerability in Dell products Dell EMC Unisphere for PowerMax versions before 9.1.0.27, Dell EMC Unisphere for PowerMax Virtual Appliance versions before 9.1.0.27, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. | 7.4 |
2023-03-14 | CVE-2023-26459 | SAP | Unspecified vulnerability in SAP Netweaver Application Server Abap Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, an attacker authenticated as a non-administrative user can craft a request which will trigger the application server to send a request to an arbitrary URL which can reveal, modify or make unavailable non-sensitive information, leading to low impact on Confidentiality, Integrity and Availability. | 7.4 |
2023-03-17 | CVE-2023-27594 | Cilium | Incorrect Authorization vulnerability in Cilium Cilium is a networking, observability, and security solution with an eBPF-based dataplane. | 7.3 |
2023-03-17 | CVE-2023-1442 | Qykcms | Unspecified vulnerability in Qykcms 4.3.0 A vulnerability was found in Meizhou Qingyunke QYKCMS 4.3.0. | 7.2 |
2023-03-16 | CVE-2023-27707 | Dedecms | SQL Injection vulnerability in Dedecms SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dede/group_store.php endpoint. | 7.2 |
2023-03-16 | CVE-2023-27709 | Dedecms | SQL Injection vulnerability in Dedecms SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dedestory_catalog.php endpoint. | 7.2 |
2023-03-16 | CVE-2023-1433 | Gadget Works Online Ordering System Project | Unspecified vulnerability in Gadget Works Online Ordering System Project Gadget Works Online Ordering System 1.0 A vulnerability was found in SourceCodester Gadget Works Online Ordering System 1.0. | 7.2 |
2023-03-15 | CVE-2023-28460 | Arraynetworks | Command Injection vulnerability in Arraynetworks Array OS A command injection vulnerability was discovered in Array Networks APV products. | 7.2 |
2023-03-15 | CVE-2023-1407 | Oretnom23 | Unspecified vulnerability in Oretnom23 Student Study Center Desk Management System 1.0 A vulnerability classified as critical was found in SourceCodester Student Study Center Desk Management System 1.0. | 7.2 |
2023-03-15 | CVE-2023-27235 | Jizhicms | Unrestricted Upload of File with Dangerous Type vulnerability in Jizhicms 2.4.5 An arbitrary file upload vulnerability in the \admin\c\CommonController.php component of Jizhicms v2.4.5 allows attackers to execute arbitrary code via a crafted phtml file. | 7.2 |
2023-03-14 | CVE-2023-26262 | Sitecore | Unrestricted Upload of File with Dangerous Type vulnerability in Sitecore Experience Manager and Experience Platform An issue was discovered in Sitecore XP/XM 10.3. | 7.2 |
2023-03-14 | CVE-2023-27498 | SAP | Unspecified vulnerability in SAP Host Agent 7.22 SAP Host Agent (SAPOSCOL) - version 7.22, allows an unauthenticated attacker with network access to a server port assigned to the SAP Start Service to submit a crafted request which results in a memory corruption error. | 7.2 |
2023-03-13 | CVE-2023-0888 | Bbraun | Code Injection vulnerability in Bbraun Battery-Pack SP With Wifi Firmware 053L000092/054U000092 An improper neutralization of directives in dynamically evaluated code vulnerability in the WiFi Battery embedded web server in versions L90/U70 and L92/U92 can be used to gain administrative access to the WiFi communication module. | 7.2 |
2023-03-13 | CVE-2023-1366 | Yoga Class Registration System Project | Unspecified vulnerability in Yoga Class Registration System Project Yoga Class Registration System 1.0 A vulnerability was found in SourceCodester Yoga Class Registration System 1.0. | 7.2 |
2023-03-18 | CVE-2023-1486 | Wisecleaner | Unspecified vulnerability in Wisecleaner Wise Force Deleter 1.5.3.54 A vulnerability classified as problematic was found in Lespeed WiseCleaner Wise Force Deleter 1.5.3.54. | 7.1 |
2023-03-17 | CVE-2023-1453 | Watchdog | Unspecified vulnerability in Watchdog Anti-Virus 1.4.214.0 A vulnerability was found in Watchdog Anti-Virus 1.4.214.0. | 7.1 |
2023-03-14 | CVE-2023-23398 | Microsoft | Unspecified vulnerability in Microsoft 365 Apps, Excel and Office Microsoft Excel Spoofing Vulnerability | 7.1 |
2023-03-13 | CVE-2023-0629 | Docker | Unspecified vulnerability in Docker Desktop Docker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions by setting the Docker host to docker.raw.sock, or npipe:////.pipe/docker_engine_linux on Windows, via the -H (--host) CLI flag or the DOCKER_HOST environment variable and launch containers without the additional hardening features provided by ECI. | 7.1 |
2023-03-16 | CVE-2023-28466 | Linux Netapp Debian | NULL Pointer Dereference vulnerability in multiple products do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race condition (with a resultant use-after-free or NULL pointer dereference). | 7.0 |
2023-03-14 | CVE-2023-28144 | Kdab | Race Condition vulnerability in Kdab Hotspot 1.3.0/1.4.0/1.4.1 KDAB Hotspot 1.3.x and 1.4.x through 1.4.1, in a non-default configuration, allows privilege escalation because of race conditions involving symlinks and elevate_perf_privileges.sh chown calls. | 7.0 |
163 Medium Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2023-03-16 | CVE-2022-34423 | Dell | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dell products Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. | 6.7 |
2023-03-16 | CVE-2022-34406 | Dell | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dell products Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. | 6.7 |
2023-03-16 | CVE-2022-34407 | Dell | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dell products Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. | 6.7 |
2023-03-16 | CVE-2022-34408 | Dell | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dell products Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. | 6.7 |
2023-03-16 | CVE-2022-34409 | Dell | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dell products Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. | 6.7 |
2023-03-16 | CVE-2022-34410 | Dell | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dell products Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. | 6.7 |
2023-03-16 | CVE-2022-34411 | Dell | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dell products Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. | 6.7 |
2023-03-16 | CVE-2022-34412 | Dell | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dell products Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. | 6.7 |
2023-03-16 | CVE-2022-34413 | Dell | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dell products Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. | 6.7 |
2023-03-16 | CVE-2022-34414 | Dell | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dell products Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. | 6.7 |
2023-03-16 | CVE-2022-34415 | Dell | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dell products Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. | 6.7 |
2023-03-16 | CVE-2022-34416 | Dell | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dell products Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. | 6.7 |
2023-03-16 | CVE-2022-34417 | Dell | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dell products Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. | 6.7 |
2023-03-16 | CVE-2022-34418 | Dell | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dell products Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. | 6.7 |
2023-03-16 | CVE-2022-34419 | Dell | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dell products Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. | 6.7 |
2023-03-16 | CVE-2022-34420 | Dell | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dell products Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. | 6.7 |
2023-03-16 | CVE-2022-34421 | Dell | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dell products Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. | 6.7 |
2023-03-16 | CVE-2022-34422 | Dell | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dell products Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. | 6.7 |
2023-03-16 | CVE-2023-24571 | Dell | Improper Input Validation vulnerability in Dell Embedded BOX PC 3000 Firmware 1.16.0 Dell BIOS contains an Improper Input Validation vulnerability. | 6.7 |
2023-03-13 | CVE-2023-0978 | Mcafee Trellix | Command Injection vulnerability in multiple products A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands using specially crafted strings. | 6.7 |
2023-03-17 | CVE-2023-1471 | WP Popup Banners Project | Unspecified vulnerability in WP Popup Banners Project WP Popup Banners The WP Popup Banners plugin for WordPress is vulnerable to SQL Injection via the 'banner_id' parameter in versions up to, and including, 1.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 6.5 |
2023-03-17 | CVE-2023-1444 | Filseclab | NULL Pointer Dereference vulnerability in Filseclab Twister Antivirus 8.0 A vulnerability was found in Filseclab Twister Antivirus 8. | 6.5 |
2023-03-16 | CVE-2023-28109 | Play With Docker | Unspecified vulnerability in Play-With-Docker Play With Docker 0.0.1/0.0.2 Play With Docker is a browser-based Docker playground. | 6.5 |
2023-03-16 | CVE-2023-28100 | Flatpak | Unspecified vulnerability in Flatpak Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. | 6.5 |
2023-03-16 | CVE-2023-27095 | Opengoofy | Incorrect Permission Assignment for Critical Resource vulnerability in Opengoofy Hippo4J Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker toescalate privileges via the AddUser method of the UserController function in Tenant Management module. | 6.5 |
2023-03-15 | CVE-2022-46773 | IBM | Unspecified vulnerability in IBM products IBM Robotic Process Automation 21.0.0 - 21.0.7 and 23.0.0 is vulnerable to client-side validation bypass for credential pools. | 6.5 |
2023-03-15 | CVE-2023-25680 | IBM | Unspecified vulnerability in IBM products IBM Robotic Process Automation 21.0.1 through 21.0.5 is vulnerable to insufficiently protecting credentials. | 6.5 |
2023-03-15 | CVE-2022-46774 | IBM | Incorrect Default Permissions vulnerability in IBM Manage Application 8.4.0/8.5.0 IBM Manage Application 8.8.0 and 8.9.0 in the IBM Maximo Application Suite is vulnerable to incorrect default permissions which could give access to a user to actions that they should not have access to. | 6.5 |
2023-03-15 | CVE-2023-22876 | IBM | Unspecified vulnerability in IBM Sterling B2B Integrator IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.1 could allow a privileged user to obtain sensitive information that could aid in further attacks against the system. | 6.5 |
2023-03-15 | CVE-2023-25282 | Dlink | Out-of-bounds Write vulnerability in Dlink Dir-820L Firmware 1.06 A heap overflow vulnerability in D-Link DIR820LA1_FW106B02 allows attackers to cause a denial of service via the config.log_to_syslog and log_opt_dropPackets parameters to mydlink_api.ccp. | 6.5 |
2023-03-15 | CVE-2023-27102 | Struktur | NULL Pointer Dereference vulnerability in Struktur Libde265 1.0.11 Libde265 v1.0.11 was discovered to contain a segmentation violation via the function decoder_context::process_slice_segment_header at decctx.cc. | 6.5 |
2023-03-15 | CVE-2023-27234 | Jizhicms | Cross-Site Request Forgery (CSRF) vulnerability in Jizhicms 2.4.5 A Cross-Site Request Forgery (CSRF) in /Sys/index.html of Jizhicms v2.4.5 allows attackers to arbitrarily make configuration changes within the application. | 6.5 |
2023-03-14 | CVE-2023-27589 | Minio | Unspecified vulnerability in Minio Minio is a Multi-Cloud Object Storage framework. | 6.5 |
2023-03-14 | CVE-2023-23396 | Microsoft | Resource Exhaustion vulnerability in Microsoft Office Online Server and Office web Apps Server Microsoft Excel Denial of Service Vulnerability | 6.5 |
2023-03-14 | CVE-2023-24857 | Microsoft | Unspecified vulnerability in Microsoft products Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 6.5 |
2023-03-14 | CVE-2023-24922 | Microsoft | Unspecified vulnerability in Microsoft Dynamics 365 9.1 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | 6.5 |
2023-03-14 | CVE-2023-27073 | Online Food Ordering System Project | Cross-Site Request Forgery (CSRF) vulnerability in Online Food Ordering System Project Online Food Ordering System 1.0 A Cross-Site Request Forgery (CSRF) in Online Food Ordering System v1.0 allows attackers to change user details and credentials via a crafted POST request. | 6.5 |
2023-03-14 | CVE-2023-24180 | Libelfin Project | Integer Overflow or Wraparound vulnerability in Libelfin Project Libelfin 0.3 Libelfin v0.3 was discovered to contain an integer overflow in the load function at elf/mmap_loader.cc. | 6.5 |
2023-03-14 | CVE-2022-47595 | Codecabin | Unspecified vulnerability in Codecabin WP GO Maps Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Go Maps (formerly WP Google Maps) plugin <= 9.0.15 versions. | 6.5 |
2023-03-14 | CVE-2023-27895 | SAP | Unspecified vulnerability in SAP Authenticator 1.3.0 SAP Authenticator for Android - version 1.3.0, allows the screen to be captured, if an authorized attacker installs a malicious app on the mobile device. | 6.5 |
2023-03-14 | CVE-2023-25618 | SAP | Unspecified vulnerability in SAP Netweaver Application Server Abap SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in an unused class for error handling in which an attacker authenticated as a non-administrative user can craft a request with certain parameters which will consume the server's resources sufficiently to make it unavailable. | 6.5 |
2023-03-14 | CVE-2023-27270 | SAP | Unspecified vulnerability in SAP Netweaver Application Server Abap SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in a class for test purposes in which an attacker authenticated as a non-administrative user can craft a request with certain parameters, which will consume the server's resources sufficiently to make it unavailable. | 6.5 |
2023-03-13 | CVE-2023-27587 | Readtomyshoe Project | Unspecified vulnerability in Readtomyshoe Project Readtomyshoe ReadtoMyShoe, a web app that lets users upload articles and listen to them later, generates an error message containing sensitive information prior to commit 8533b01. | 6.5 |
2023-03-13 | CVE-2023-0350 | Akuvox | Insufficient Verification of Data Authenticity vulnerability in Akuvox E11 Firmware Akuvox E11 does not ensure that a file extension is associated with the file provided. | 6.5 |
2023-03-13 | CVE-2023-0749 | Oceanwp | Unspecified vulnerability in Oceanwp Ocean Extra The Ocean Extra WordPress plugin before 2.1.3 does not ensure that the template to be loaded via a shortcode is actually a template, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, such as draft, private or even password protected ones. | 6.5 |
2023-03-13 | CVE-2023-0772 | Optinmonster | Unspecified vulnerability in Optinmonster The Popup Builder by OptinMonster WordPress plugin before 2.12.2 does not ensure that the campaign to be loaded via some shortcodes is actually a campaign, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, like draft, private or even password protected ones. | 6.5 |
2023-03-13 | CVE-2023-1361 | Bumsys Project | Unspecified vulnerability in Bumsys Project Bumsys SQL Injection in GitHub repository unilogies/bumsys prior to v2.0.2. | 6.5 |
2023-03-17 | CVE-2023-1472 | Rapidload | Cross-Site Request Forgery (CSRF) vulnerability in Rapidload Power-Up for Autoptimize The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. | 6.3 |
2023-03-19 | CVE-2023-1500 | Code Projects | Unspecified vulnerability in Code-Projects Simple ART Gallery 1.0 A vulnerability, which was classified as problematic, has been found in code-projects Simple Art Gallery 1.0. | 6.1 |
2023-03-18 | CVE-2023-1485 | Young Entrepreneur E Negosyo System Project | Unspecified vulnerability in Young Entrepreneur E-Negosyo System Project Young Entrepreneur E-Negosyo System 1.0 A vulnerability classified as problematic has been found in SourceCodester Young Entrepreneur E-Negosyo System 1.0. | 6.1 |
2023-03-18 | CVE-2023-28606 | Misp Project | Cross-site Scripting vulnerability in Misp-Project Malware Information Sharing Platform js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips. | 6.1 |
2023-03-18 | CVE-2023-28607 | Misp Project | Cross-site Scripting vulnerability in Misp-Project Malware Information Sharing Platform js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip. | 6.1 |
2023-03-18 | CVE-2023-1481 | Monitoring OF Students Cyber Accounts System Project | Unspecified vulnerability in Monitoring of Students Cyber Accounts System Project Monitoring of Students Cyber Accounts System 1.0 A vulnerability, which was classified as problematic, has been found in SourceCodester Monitoring of Students Cyber Accounts System 1.0. | 6.1 |
2023-03-18 | CVE-2023-24278 | Squidex IO | Cross-site Scripting vulnerability in Squidex.Io Squidex Squidex before 7.4.0 was discovered to contain a squid.svg cross-site scripting (XSS) vulnerability. | 6.1 |
2023-03-17 | CVE-2023-26040 | Discourse | Unspecified vulnerability in Discourse 3.1.0 Discourse is an open-source discussion platform. | 6.1 |
2023-03-17 | CVE-2022-45817 | GC Testimonials Project | Unspecified vulnerability in GC Testimonials Project GC Testimonials 1.3.2 Cross-Site Scripting (XSS) vulnerability in Erin Garscadden GC Testimonials plugin <= 1.3.2 versions. | 6.1 |
2023-03-17 | CVE-2023-1172 | Booking WP Plugin | Unspecified vulnerability in Booking-Wp-Plugin Bookly The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the full name value in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. | 6.1 |
2023-03-17 | CVE-2023-1447 | Medicine Tracker System Project | Unspecified vulnerability in Medicine Tracker System Project Medicine Tracker System 1.0 A vulnerability, which was classified as problematic, has been found in SourceCodester Medicine Tracker System 1.0. | 6.1 |
2023-03-16 | CVE-2023-27494 | Snowflake | Unspecified vulnerability in Snowflake Streamlit Streamlit, software for turning data scripts into web applications, had a cross-site scripting (XSS) vulnerability in versions 0.63.0 through 0.80.0. | 6.1 |
2023-03-16 | CVE-2021-36821 | Incsub | Unspecified vulnerability in Incsub Forminator Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMU DEV Forminator allows Stored XSS.This issue affects Forminator: from n/a through 1.14.11. | 6.1 |
2023-03-16 | CVE-2023-28155 | Request Project | Server-Side Request Forgery (SSRF) vulnerability in Request Project Request The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). | 6.1 |
2023-03-16 | CVE-2022-40699 | Yasr YET Another Stars Rating Project | Unspecified vulnerability in Yasr - YET Another Stars Rating Project Yasr - YET Another Stars Rating Cross-Site Scripting (XSS) vulnerability in Dario Curvino Yasr – Yet Another Stars Rating plugin <= 3.1.2 versions. | 6.1 |
2023-03-15 | CVE-2023-1421 | Mattermost | Cross-site Scripting vulnerability in Mattermost Server A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behalf of the victim via sharing a crafted link with a malicious state parameter. | 6.1 |
2023-03-15 | CVE-2022-43874 | IBM | Cross-site Scripting vulnerability in IBM APP Connect Enterprise Certified Container IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, 6.2, and 7.0 is vulnerable to cross-site scripting. | 6.1 |
2023-03-15 | CVE-2023-1418 | Friendly Island Pizza Website AND Ordering System Project | Unspecified vulnerability in Friendly Island Pizza Website and Ordering System Project Friendly Island Pizza Website and Ordering System 1.0 A vulnerability classified as problematic was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. | 6.1 |
2023-03-15 | CVE-2023-0322 | Talentyazilim | Cross-site Scripting vulnerability in Talentyazilim Unis Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Talent Software UNIS allows Reflected XSS.This issue affects UNIS: before 28376. | 6.1 |
2023-03-14 | CVE-2023-1395 | Yoga Class Registration System Project | Unspecified vulnerability in Yoga Class Registration System Project Yoga Class Registration System 1.0 A vulnerability was found in SourceCodester Yoga Class Registration System 1.0. | 6.1 |
2023-03-14 | CVE-2023-1396 | Online Tours Travels Management System Project | Unspecified vulnerability in Online Tours & Travels Management System Project Online Tours & Travels Management System 1.0 A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. | 6.1 |
2023-03-14 | CVE-2023-1397 | Online Student Management System Project | Unspecified vulnerability in Online Student Management System Project Online Student Management System 1.0 A vulnerability classified as problematic has been found in SourceCodester Online Student Management System 1.0. | 6.1 |
2023-03-14 | CVE-2021-4195 | Firmanet | Cross-site Scripting vulnerability in Firmanet Customer Relation Manager Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Firmanet Software and Technology Customer Relation Manager allows XSS Targeting HTML Attributes.This issue affects Customer Relation Manager: before 2022.03.13. | 6.1 |
2023-03-14 | CVE-2022-23790 | Firmanet | Cross-site Scripting vulnerability in Firmanet Technology Customer Relation Manager Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Firmanet Software and Technology Customer Relation Manager allows Cross-Site Scripting (XSS).This issue affects Customer Relation Manager: before 2022.03.13. | 6.1 |
2023-03-14 | CVE-2022-23791 | Firmanet | Cross-site Scripting vulnerability in Firmanet Customer Relation Manager Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Firmanet Software and Technology Customer Relation Manager allows Cross-Site Scripting (XSS).This issue affects Customer Relation Manager: before 2022.03.13. | 6.1 |
2023-03-14 | CVE-2023-0021 | SAP | Unspecified vulnerability in SAP Netweaver Due to insufficient encoding of user input, SAP NetWeaver - versions 700, 701, 702, 731, 740, 750, allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password, which could lead to reflected Cross-Site scripting. | 6.1 |
2023-03-14 | CVE-2023-26457 | SAP | Unspecified vulnerability in SAP Content Server 7.53 SAP Content Server - version 7.53, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. | 6.1 |
2023-03-14 | CVE-2023-24279 | Opennetworking | Cross-site Scripting vulnerability in Opennetworking Onos A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter of the API documentation dashboard. | 6.1 |
2023-03-13 | CVE-2023-27093 | MY Blog Project | Cross-site Scripting vulnerability in My-Blog Project My-Blog Cross Site Scripting vulnerability found in My-Blog allows attackers to cause a denial of service via the Post function. | 6.1 |
2023-03-13 | CVE-2023-1372 | Webhostings | Unspecified vulnerability in Webhostings WH Testimonials 3.0.0 The WH Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters such as wh_homepage, wh_text_short, wh_text_full and in versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping. | 6.1 |
2023-03-13 | CVE-2023-1362 | Bumsys Project | Unspecified vulnerability in Bumsys Project Bumsys Improper Restriction of Rendered UI Layers or Frames in GitHub repository unilogies/bumsys prior to v2.0.2. | 6.1 |
2023-03-16 | CVE-2023-28113 | Russh Project | Improper Verification of Cryptographic Signature vulnerability in Russh Project Russh russh is a Rust SSH client and server library. | 5.9 |
2023-03-13 | CVE-2023-27580 | Codeigniter | Unspecified vulnerability in Codeigniter Shield 1.0.0 CodeIgniter Shield provides authentication and authorization for the CodeIgniter 4 PHP framework. | 5.9 |
2023-03-18 | CVE-2023-1492 | Maxpcsecure | Unspecified vulnerability in Maxpcsecure Anti Virus Plus 19.0.2.1 A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1. | 5.5 |
2023-03-18 | CVE-2023-1493 | Maxpcsecure | Unspecified vulnerability in Maxpcsecure Anti Virus Plus 19.0.2.1 A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1. | 5.5 |
2023-03-18 | CVE-2023-1490 | Maxpcsecure | Unspecified vulnerability in Maxpcsecure Anti Virus Plus 19.0.2.1 A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1 and classified as critical. | 5.5 |
2023-03-18 | CVE-2023-1491 | Maxpcsecure | Unspecified vulnerability in Maxpcsecure Anti Virus Plus 19.0.2.1 A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1. | 5.5 |
2023-03-18 | CVE-2023-1487 | Wisecleaner | Unspecified vulnerability in Wisecleaner Wise System Monitor 1.5.3.54 A vulnerability, which was classified as problematic, has been found in Lespeed WiseCleaner Wise System Monitor 1.5.3.54. | 5.5 |
2023-03-18 | CVE-2023-1488 | Wisecleaner | Unspecified vulnerability in Wisecleaner Wise System Monitor 1.5.3.54 A vulnerability, which was classified as problematic, was found in Lespeed WiseCleaner Wise System Monitor 1.5.3.54. | 5.5 |
2023-03-17 | CVE-2023-27593 | Cilium | Unspecified vulnerability in Cilium Cilium is a networking, observability, and security solution with an eBPF-based dataplane. | 5.5 |
2023-03-17 | CVE-2023-1445 | Filseclab | Unspecified vulnerability in Filseclab Twister Antivirus 8.0 A vulnerability classified as problematic has been found in Filseclab Twister Antivirus 8. | 5.5 |
2023-03-17 | CVE-2023-1446 | Watchdog | NULL Pointer Dereference vulnerability in Watchdog Anti-Virus 1.4.214.0 A vulnerability classified as problematic was found in Watchdog Anti-Virus 1.4.214.0. | 5.5 |
2023-03-17 | CVE-2023-1450 | Mp4V2 Project | Unspecified vulnerability in Mp4V2 Project Mp4V2 2.1.2 A vulnerability was found in MP4v2 2.1.2 and classified as problematic. | 5.5 |
2023-03-17 | CVE-2023-1451 | Mp4V2 Project | Unspecified vulnerability in Mp4V2 Project Mp4V2 2.1.2 A vulnerability was found in MP4v2 2.1.2. | 5.5 |
2023-03-16 | CVE-2023-21449 | Samsung | Unspecified vulnerability in Samsung Android 11.0/12.0 Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows local attackers to access sensitive information without proper permission. | 5.5 |
2023-03-16 | CVE-2023-21453 | Samsung | Improper Input Validation vulnerability in Samsung Android 13.0 Improper input validation vulnerability in SoftSim TA prior to SMR Mar-2023 Release 1 allows local attackers access to protected data. | 5.5 |
2023-03-16 | CVE-2023-21456 | Samsung | Path Traversal vulnerability in Samsung Android 11.0/12.0/13.0 Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid. | 5.5 |
2023-03-16 | CVE-2023-21461 | Samsung | Unspecified vulnerability in Samsung Android 11.0/12.0/13.0 Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device off via unprotected activity. | 5.5 |
2023-03-16 | CVE-2023-21465 | Samsung | Unspecified vulnerability in Samsung Bixbytouch Improper access control vulnerability in BixbyTouch prior to version 3.2.02.5 in China models allows untrusted applications access local files. | 5.5 |
2023-03-15 | CVE-2022-45155 | Suse | Improper Handling of Exceptional Conditions vulnerability in Suse Opensuse Factory An Improper Handling of Exceptional Conditions vulnerability in obs-service-go_modules of openSUSE Factory allows attackers that can influence the call to the service to delete files and directories on the system of the victim. | 5.5 |
2023-03-13 | CVE-2023-0973 | Steptools | Unspecified vulnerability in Steptools Ifcmesh Library STEPTools v18SP1 ifcmesh library (v18.1) is affected due to a null pointer dereference, which could allow an attacker to deny application usage when reading a specially constructed file, resulting in an application crash. | 5.5 |
2023-03-13 | CVE-2023-24577 | Mcafee | Link Following vulnerability in Mcafee Total Protection McAfee Total Protection prior to 16.0.50 allows attackers to elevate user privileges due to Improper Link Resolution via registry keys. | 5.5 |
2023-03-13 | CVE-2023-24578 | Mcafee | Uncontrolled Search Path Element vulnerability in Mcafee Total Protection McAfee Total Protection prior to 16.0.49 allows attackers to elevate user privileges due to DLL sideloading. | 5.5 |
2023-03-13 | CVE-2023-24579 | Mcafee | Unspecified vulnerability in Mcafee Total Protection McAfee Total Protection prior to 16.0.51 allows attackers to trick a victim into uninstalling the application via the command prompt. | 5.5 |
2023-03-13 | CVE-2023-1369 | Tgsoft | Unspecified vulnerability in Tgsoft Vir.It Explorer and Viragtlt.Sys A vulnerability was found in TG Soft Vir.IT eXplorer 9.4.86.0. | 5.5 |
2023-03-19 | CVE-2023-1496 | Evilmartians | Unspecified vulnerability in Evilmartians Imgproxy Cross-site Scripting (XSS) - Reflected in GitHub repository imgproxy/imgproxy prior to 3.14.0. | 5.4 |
2023-03-17 | CVE-2023-27592 | Miniflux Project | Unspecified vulnerability in Miniflux Project Miniflux Miniflux is a feed reader. | 5.4 |
2023-03-17 | CVE-2023-25172 | Discourse | Unspecified vulnerability in Discourse Discourse is an open-source discussion platform. | 5.4 |
2023-03-17 | CVE-2022-43461 | Slideshow SE Project | Unspecified vulnerability in Slideshow SE Project Slideshow SE Stored Cross-Site Scripting (XSS) vulnerability in John West Slideshow SE plugin <= 2.5.5 versions. | 5.4 |
2023-03-17 | CVE-2022-45814 | WP Calendar Project | Unspecified vulnerability in WP Calendar Project WP Calendar 1.5.3 Stored Cross-Site Scripting (XSS) vulnerability in Fabian von Allmen WP Calendar plugin <= 1.5.3 versions. | 5.4 |
2023-03-17 | CVE-2023-1463 | Teampass | Unspecified vulnerability in Teampass Authorization Bypass Through User-Controlled Key in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. | 5.4 |
2023-03-16 | CVE-2023-27059 | Churchcrm | Cross-site Scripting vulnerability in Churchcrm 4.5.3 A cross-site scripting (XSS) vulnerability in the Edit Group function of ChurchCRM v4.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit Group Name text field. | 5.4 |
2023-03-16 | CVE-2023-1429 | Pimcore | Unspecified vulnerability in Pimcore Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.19. | 5.4 |
2023-03-16 | CVE-2022-41554 | Slideshow SE Project | Unspecified vulnerability in Slideshow SE Project Slideshow SE Stored Cross-Site Scripting (XSS) vulnerability in John West Slideshow SE plugin <= 2.5.5 versions. | 5.4 |
2023-03-16 | CVE-2022-38971 | Themekraft | Unspecified vulnerability in Themekraft Post Form Registration Form Profile Form for User Profiles and Content Forms Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions. | 5.4 |
2023-03-16 | CVE-2023-26951 | Onekeyadmin | Cross-site Scripting vulnerability in Onekeyadmin 1.3.9 onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Member List module. | 5.4 |
2023-03-14 | CVE-2023-27069 | Totaljs | Cross-site Scripting vulnerability in Totaljs Openplatform 20230216 A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the account name field. | 5.4 |
2023-03-14 | CVE-2023-27070 | Totaljs | Cross-site Scripting vulnerability in Totaljs Openplatform 20230216 A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the platform name field. | 5.4 |
2023-03-13 | CVE-2022-4466 | Connekthq | Unspecified vulnerability in Connekthq Ajax Load More The WordPress Infinite Scroll WordPress plugin before 5.6.0.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | 5.4 |
2023-03-13 | CVE-2022-4652 | Pushlabs | Unspecified vulnerability in Pushlabs Video Background The Video Background WordPress plugin before 2.7.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | 5.4 |
2023-03-13 | CVE-2022-4661 | Themelocation | Unspecified vulnerability in Themelocation Widgets for Woocommerce products on Elementor The Widgets for WooCommerce Products on Elementor WordPress plugin before 1.0.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | 5.4 |
2023-03-13 | CVE-2023-0066 | Codeermeneer | Unspecified vulnerability in Codeermeneer Companion Sitemap Generator The Companion Sitemap Generator WordPress plugin through 4.5.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | 5.4 |
2023-03-13 | CVE-2023-0073 | Client Logo Carousel Project | Unspecified vulnerability in Client Logo Carousel Project Client Logo Carousel 3.0.0 The Client Logo Carousel WordPress plugin through 3.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | 5.4 |
2023-03-13 | CVE-2023-0172 | Saas Group | Unspecified vulnerability in Saas.Group Juicer The Juicer WordPress plugin before 1.11 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | 5.4 |
2023-03-13 | CVE-2023-0219 | Wpmanageninja | Cross-site Scripting vulnerability in Wpmanageninja Fluentsmtp The FluentSMTP WordPress plugin before 2.2.3 does not sanitize or escape email content, making it vulnerable to stored cross-site scripting attacks (XSS) when an administrator views the email logs. | 5.4 |
2023-03-13 | CVE-2023-0538 | Campaign URL Builder Project | Unspecified vulnerability in Campaign URL Builder Project Campaign URL Builder The Campaign URL Builder WordPress plugin before 1.8.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | 5.4 |
2023-03-13 | CVE-2023-1363 | Computer Parts Sales AND Inventory System Project | Unspecified vulnerability in Computer Parts Sales and Inventory System Project Computer Parts Sales and Inventory System 1.0 A vulnerability, which was classified as problematic, was found in SourceCodester Computer Parts Sales and Inventory System 1.0. | 5.4 |
2023-03-16 | CVE-2023-1431 | Tipsandtricks HQ | Unspecified vulnerability in Tipsandtricks-Hq Wordpress Simple Paypal Shopping Cart The WP Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.6.3 due to the plugin saving shopping cart data exports in a publicly accessible location (/wp-content/plugins/wordpress-simple-paypal-shopping-cart/includes/admin/). | 5.3 |
2023-03-16 | CVE-2023-27084 | Dreamer CMS Project | Incorrect Permission Assignment for Critical Resource vulnerability in Dreamer CMS Project Dreamer CMS 4.0.1 Permissions vulnerability found in isoftforce Dreamer CMS v.4.0.1 allows local attackers to obtain sensitive information via the AttachmentController parameter. | 5.3 |
2023-03-16 | CVE-2023-28486 | Sudo Project Netapp | Improper Encoding or Escaping of Output vulnerability in multiple products Sudo before 1.9.13 does not escape control characters in log messages. | 5.3 |
2023-03-16 | CVE-2023-28487 | Sudo Project Netapp | Improper Encoding or Escaping of Output vulnerability in multiple products Sudo before 1.9.13 does not escape control characters in sudoreplay output. | 5.3 |
2023-03-15 | CVE-2023-25804 | Roxy WI | Unspecified vulnerability in Roxy-Wi Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. | 5.3 |
2023-03-15 | CVE-2023-25695 | Apache | Unspecified vulnerability in Apache Airflow Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.5.2. | 5.3 |
2023-03-14 | CVE-2023-1296 | Hashicorp | Missing Authorization vulnerability in Hashicorp Nomad HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.5.0 did not correctly enforce deny policies applied to a workload’s variables. | 5.3 |
2023-03-14 | CVE-2023-27894 | SAP | Unspecified vulnerability in SAP Businessobjects Business Intelligence 420/430 SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. | 5.3 |
2023-03-14 | CVE-2023-24526 | SAP | Unspecified vulnerability in SAP Netweaver Application Server Java 7.50 SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks for functionalities that require user identity, resulting in escalation of privileges. | 5.3 |
2023-03-14 | CVE-2023-26460 | SAP | Unspecified vulnerability in SAP Netweaver Application Server for Java 7.50 Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authentication checks for functionalities that require user identity | 5.3 |
2023-03-14 | CVE-2023-27268 | SAP | Unspecified vulnerability in SAP Netweaver Application Server for Java 7.50 SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a service which will enable them to access but not modify server settings and data with no effect on availability., resulting in escalation of privileges. | 5.3 |
2023-03-13 | CVE-2023-0347 | Akuvox | Unspecified vulnerability in Akuvox E11 Firmware The Akuvox E11 Media Access Control (MAC) address, a primary identifier, combined with the Akuvox E11 IP address, could allow an attacker to identify the device on the Akuvox cloud. | 5.3 |
2023-03-17 | CVE-2023-28107 | Discourse | Unspecified vulnerability in Discourse Discourse is an open-source discussion platform. | 4.9 |
2023-03-14 | CVE-2023-25615 | SAP | Unspecified vulnerability in SAP Abap Platform Due to insufficient input sanitization, SAP ABAP - versions 751, 753, 753, 754, 756, 757, 791, allows an authenticated high privileged user to alter the current session of the user by injecting the malicious database queries over the network and gain access to the unintended data. | 4.9 |
2023-03-14 | CVE-2023-26461 | SAP | Unspecified vulnerability in SAP Netweaver Enterprise Portal 7.50 SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges to access the XML parser which can submit a crafted XML file which when parsed will enable them to access but not modify sensitive files and data. | 4.9 |
2023-03-17 | CVE-2023-1470 | Implecode | Unspecified vulnerability in Implecode Ecommerce Product Catalog The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters in versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. | 4.8 |
2023-03-17 | CVE-2023-1469 | Tipsandtricks HQ | Unspecified vulnerability in Tipsandtricks-Hq WP Express Checkout The WP Express Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pec_coupon[code]’ parameter in versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping. | 4.8 |
2023-03-16 | CVE-2023-28106 | Pimcore | Unspecified vulnerability in Pimcore Pimcore is an open source data and experience management platform. | 4.8 |
2023-03-16 | CVE-2023-27130 | Typecho | Cross-site Scripting vulnerability in Typecho Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via an arbitrarily supplied URL parameter. | 4.8 |
2023-03-16 | CVE-2023-27131 | Typecho | Cross-site Scripting vulnerability in Typecho Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code viathe Post Editorparameter. | 4.8 |
2023-03-16 | CVE-2023-27711 | Typecho | Cross-site Scripting vulnerability in Typecho Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via the Comment Manager /admin/manage-comments.php component. | 4.8 |
2023-03-15 | CVE-2023-26912 | S Mall SSM Project | Cross-site Scripting vulnerability in S-Mall-Ssm Project S-Mall-Ssm Cross site scripting (XSS) vulnerability in xenv S-mall-ssm thru commit 3d9e77f7d80289a30f67aaba1ae73e375d33ef71 on Feb 17, 2020, allows local attackers to execute arbitrary code via the evaluate button. | 4.8 |
2023-03-15 | CVE-2022-37402 | Afsanalytics | Unspecified vulnerability in Afsanalytics AFS Analytics Stored Cross-site Scripting (XSS) vulnerability in AFS Analytics plugin <= 4.18 versions. | 4.8 |
2023-03-15 | CVE-2022-34148 | Jetbackup | Cross-site Scripting vulnerability in Jetbackup Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JetBackup JetBackup – WP Backup, Migrate & Restore plugin <= 1.6.9.0 versions. | 4.8 |
2023-03-14 | CVE-2022-47171 | IP Vault WP Firewall Project | Unspecified vulnerability in IP Vault - WP Firewall Project IP Vault - WP Firewall Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul C. | 4.8 |
2023-03-13 | CVE-2023-0844 | Kibokolabs | Unspecified vulnerability in Kibokolabs Namaste! LMS The Namaste! LMS WordPress plugin before 2.6 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | 4.8 |
2023-03-13 | CVE-2023-1374 | Solidres | Unspecified vulnerability in Solidres The Solidres plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'currency_name' parameter in versions up to, and including, 0.9.4 due to insufficient input sanitization and output escaping. | 4.8 |
2023-03-14 | CVE-2023-23383 | Microsoft | Unspecified vulnerability in Microsoft Azure Service Fabric 9.1 Service Fabric Explorer Spoofing Vulnerability | 4.7 |
2023-03-16 | CVE-2023-21460 | Samsung | Improper Authentication vulnerability in Samsung Android 11.0/12.0/13.0 Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting. | 4.4 |
2023-03-17 | CVE-2023-0027 | Rockwellautomation | Information Exposure vulnerability in Rockwellautomation Modbus TCP Server ADD on Instructions 2.00.00/2.00.03 Rockwell Automation Modbus TCP Server AOI prior to 2.04.00 is vulnerable to an unauthorized user sending a malformed message that could cause the controller to respond with a copy of the most recent response to the last valid request. | 4.3 |
2023-03-17 | CVE-2023-23622 | Discourse | Unspecified vulnerability in Discourse Discourse is an open-source discussion platform. | 4.3 |
2023-03-16 | CVE-2023-23935 | Discourse | Unspecified vulnerability in Discourse Discourse is an open-source messaging platform. | 4.3 |
2023-03-16 | CVE-2023-28101 | Flatpak | Unspecified vulnerability in Flatpak Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. | 4.3 |
2023-03-16 | CVE-2022-26080 | ABB | Use of Insufficiently Random Values vulnerability in ABB products Use of Insufficiently Random Values vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant.This issue affects Pulsar Plus System Controller NE843_S : comcode 150042936; Infinity DC Power Plant: H5692448 G104 G842 G224L G630-4 G451C(2) G461(2) – comcode 150047415. | 4.3 |
2023-03-14 | CVE-2023-27462 | Siemens | Unspecified vulnerability in Siemens Ruggedcom Crossbow 5.2 A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). | 4.3 |
2023-03-13 | CVE-2023-22700 | Pixelyoursite | Unspecified vulnerability in Pixelyoursite Cross-Site Request Forgery (CSRF) vulnerability in PixelYourSite PixelYourSite – Your smart PIXEL (TAG) Manager plugin <= 9.3.0 versions. | 4.3 |
2023-03-13 | CVE-2023-23711 | A2Hosting | Unspecified vulnerability in A2Hosting A2 Optimized Cross-Site Request Forgery (CSRF) vulnerability in A2 Hosting A2 Optimized WP plugin <= 3.0.4 versions. | 4.3 |
2023-03-13 | CVE-2022-2258 | Octopus | Unspecified vulnerability in Octopus Server In affected versions of Octopus Deploy it is possible for a user to view Tagsets without being explicitly assigned permissions to view these items | 4.3 |
2023-03-13 | CVE-2022-2259 | Octopus | Unspecified vulnerability in Octopus Server In affected versions of Octopus Deploy it is possible for a user to view Workerpools without being explicitly assigned permissions to view these items | 4.3 |
10 Low Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2023-03-13 | CVE-2023-1367 | Easyappointments | Code Injection vulnerability in Easyappointments Code Injection in GitHub repository alextselegidis/easyappointments prior to 1.5.0. | 3.8 |
2023-03-15 | CVE-2023-26084 | ARM | Improper Initialization vulnerability in ARM Aarch64Cryptolib The armv8_dec_aes_gcm_full() API of Arm AArch64cryptolib before 86065c6 fails to the verify the authentication tag of AES-GCM protected data, leading to a man-in-the-middle attack. | 3.7 |
2023-03-16 | CVE-2023-21452 | Samsung | Unspecified vulnerability in Samsung Android 11.0/12.0/13.0 Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device. | 3.3 |
2023-03-16 | CVE-2023-21458 | Samsung | Improper Privilege Management vulnerability in Samsung Android 11.0/12.0/13.0 Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn off Do not disturb via unprotected intent. | 3.3 |
2023-03-16 | CVE-2023-21462 | Samsung | Unspecified vulnerability in Samsung Quick Share 3.5.14.18 The sensitive information exposure vulnerability in Quick Share Agent prior to versions 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13 allows to local attacker to access MAC address without related permission. | 3.3 |
2023-03-16 | CVE-2023-21463 | Samsung | Unspecified vulnerability in Samsung Myfiles 12.2.09.0/13.1.03.501 Improper access control vulnerability in MyFiles application prior to versions 12.2.09.0 in Android 11, 13.1.03.501 in Android 12 and 14.1.03.0 in Android 13 allows local attacker to get sensitive information of secret mode in Samsung Internet application with specific conditions. | 3.3 |
2023-03-16 | CVE-2023-21464 | Samsung | Unspecified vulnerability in Samsung Calendar Improper access control in Samsung Calendar prior to versions 12.4.02.9000 in Android 13 and 12.3.08.2000 in Android 12 allows local attacker to configure improper status. | 3.3 |
2023-03-15 | CVE-2020-4556 | IBM | Unspecified vulnerability in IBM Financial Transaction Manager IBM Financial Transaction Manager for High Value Payments for Multi-Platform 3.2.0 through 3.2.10 allows web pages to be stored locally which can be read by another user on the system. | 3.3 |
2023-03-15 | CVE-2023-22591 | IBM | Unspecified vulnerability in IBM products IBM Robotic Process Automation 21.0.1 through 21.0.7 and 23.0.0 through 23.0.1 could allow a user with physical access to the system due to session tokens for not being invalidated after a password reset. | 3.2 |
2023-03-16 | CVE-2023-21454 | Samsung | Unspecified vulnerability in Samsung Android 11.0/12.0/13.0 Improper authorization in Samsung Keyboard prior to SMR Mar-2023 Release 1 allows physical attacker to access users text history on the lockscreen. | 2.4 |