Weekly Vulnerabilities Reports > April 3 to 9, 2023

Overview

553 new vulnerabilities reported during this period, including 103 critical vulnerabilities and 139 high severity vulnerabilities. This weekly summary report vulnerabilities in 454 products from 224 vendors including Google, Cisco, Tenda, Debian, and Fedoraproject. Vulnerabilities are notably categorized as "Out-of-bounds Write", "Cross-site Scripting", "SQL Injection", "Out-of-bounds Read", and "Untrusted Search Path".

  • 461 reported vulnerabilities are remotely exploitables.
  • 2 reported vulnerabilities have public exploit available.
  • 125 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
  • 306 reported vulnerabilities are exploitable by an anonymous user.
  • Google has the most reported vulnerabilities, with 44 reported vulnerabilities.
  • Tenda has the most reported critical vulnerabilities, with 21 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

103 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2023-04-04 CVE-2023-1748 Getnexx Use of Hard-coded Credentials vulnerability in Getnexx products

The listed versions of Nexx Smart Home devices use hard-coded credentials.

10.0
2023-04-09 CVE-2012-10011 Contus Unspecified vulnerability in Contus HD FLV Player

A vulnerability was found in HD FLV PLayer Plugin up to 1.7 on WordPress.

9.8
2023-04-09 CVE-2023-27718 Dlink Out-of-bounds Write vulnerability in Dlink Dir878 Firmware 1.30B08

D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_498308 function.

9.8
2023-04-09 CVE-2023-27719 Dlink Out-of-bounds Write vulnerability in Dlink Dir878 Firmware 1.30B08

D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_478360 function.

9.8
2023-04-09 CVE-2023-27720 Dlink Out-of-bounds Write vulnerability in Dlink Dir-878 Firmware 1.30B08

D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_48d630 function.

9.8
2023-04-09 CVE-2023-1962 Best Online News Portal Project Unspecified vulnerability in Best Online News Portal Project Best Online News Portal 1.0

A vulnerability classified as critical was found in SourceCodester Best Online News Portal 1.0.

9.8
2023-04-09 CVE-2023-1963 Phpgurukul SQL Injection vulnerability in PHPgurukul Bank Locker Management System 1.0

A vulnerability was found in PHPGurukul Bank Locker Management System 1.0.

9.8
2023-04-08 CVE-2023-1958 Oretnom23 Unspecified vulnerability in Oretnom23 Online Computer and Laptop Store 1.0

A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0.

9.8
2023-04-08 CVE-2023-1955 Oretnom23 Unspecified vulnerability in Oretnom23 Online Computer and Laptop Store 1.0

A vulnerability classified as critical has been found in SourceCodester Online Computer and Laptop Store 1.0.

9.8
2023-04-08 CVE-2013-10023 Editorial Calendar Project Unspecified vulnerability in Editorial Calendar Project Editorial Calendar

A vulnerability was found in Editorial Calendar Plugin up to 2.6 on WordPress.

9.8
2023-04-08 CVE-2023-1952 Oretnom23 Unspecified vulnerability in Oretnom23 Online Computer and Laptop Store 1.0

A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0.

9.8
2023-04-08 CVE-2023-1949 Phpgurukul Unspecified vulnerability in PHPgurukul BP Monitoring Management System 1.0

A vulnerability, which was classified as critical, was found in PHPGurukul BP Monitoring Management System 1.0.

9.8
2023-04-08 CVE-2023-1950 Phpgurukul Unspecified vulnerability in PHPgurukul BP Monitoring Management System 1.0

A vulnerability has been found in PHPGurukul BP Monitoring Management System 1.0 and classified as critical.

9.8
2023-04-08 CVE-2023-1951 Oretnom23 SQL Injection vulnerability in Oretnom23 Online Computer and Laptop Store 1.0

A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical.

9.8
2023-04-07 CVE-2023-1947 Taogogo Code Injection vulnerability in Taogogo Taocms 3.0.2

A vulnerability was found in taoCMS 3.0.2.

9.8
2023-04-07 CVE-2023-27033 Cdesigner Project Unrestricted Upload of File with Dangerous Type vulnerability in Cdesigner Project Cdesigner 3.1.3/3.2.1

Prestashop cdesigner v3.1.3 to v3.1.8 was discovered to contain a code injection vulnerability via the component CdesignerSaverotateModuleFrontController::initContent().

9.8
2023-04-07 CVE-2023-1941 Simple AND Beautiful Shopping Cart System Project Unspecified vulnerability in Simple and Beautiful Shopping Cart System Project Simple and Beautiful Shopping Cart System 1.0

A vulnerability, which was classified as critical, has been found in SourceCodester Simple and Beautiful Shopping Cart System 1.0.

9.8
2023-04-07 CVE-2023-1942 Oretnom23 Unspecified vulnerability in Oretnom23 Online Computer and Laptop Store 1.0

A vulnerability has been found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical.

9.8
2023-04-07 CVE-2023-28706 Apache Code Injection vulnerability in Apache Airflow Hive Provider

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 6.0.0.

9.8
2023-04-07 CVE-2023-26978 Totolink Command Injection vulnerability in Totolink A7100Ru Firmware 7.4Cu.2313B20191024

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pppoeAcName parameter at /setting/setWanIeCfg.

9.8
2023-04-07 CVE-2023-29478 Bibliocraftmod Path Traversal vulnerability in Bibliocraftmod Bibliocraft

BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on the filesystem.

9.8
2023-04-07 CVE-2023-26848 Totolink Command Injection vulnerability in Totolink A7100Ru Firmware 7.4Cu.2313B20191024

TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the org parameter at setting/delStaticDhcpRules.

9.8
2023-04-07 CVE-2023-24797 Dlink Out-of-bounds Write vulnerability in Dlink Dir-882 A1 Firmware 110B02

D-Link DIR882 DIR882A1_FW110B02 was discovered to contain a stack overflow in the sub_48AC20 function.

9.8
2023-04-07 CVE-2023-24798 Dlink Out-of-bounds Write vulnerability in Dlink Dir-878 Firmware 1.20B05

D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_475FB0 function.

9.8
2023-04-07 CVE-2023-24799 Dlink Out-of-bounds Write vulnerability in Dlink Dir-878 Firmware 1.20B05

D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_48AF78 function.

9.8
2023-04-07 CVE-2023-24800 Dlink Out-of-bounds Write vulnerability in Dlink Dir-878 Firmware 1.20B05

D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_495220 function.

9.8
2023-04-07 CVE-2023-25210 Tenda Out-of-bounds Write vulnerability in Tenda AC5 Firmware 15.03.06.28

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the fromSetSysTime function.

9.8
2023-04-07 CVE-2023-25211 Tenda Out-of-bounds Write vulnerability in Tenda AC5 Firmware 15.03.06.28

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the R7WebsSecurityHandler function.

9.8
2023-04-07 CVE-2023-25212 Tenda Out-of-bounds Write vulnerability in Tenda AC5 Firmware 15.03.06.28

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the fromSetWirelessRepeat function.

9.8
2023-04-07 CVE-2023-25213 Tenda Out-of-bounds Write vulnerability in Tenda AC5 Firmware 15.03.06.28

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the check_param_changed function.

9.8
2023-04-07 CVE-2023-25214 Tenda Out-of-bounds Write vulnerability in Tenda AC5 Firmware 15.03.06.28

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the setSchedWifi function.

9.8
2023-04-07 CVE-2023-25215 Tenda Out-of-bounds Write vulnerability in Tenda AC5 Firmware 15.03.06.28

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the saveParentControlInfo function.

9.8
2023-04-07 CVE-2023-25216 Tenda Out-of-bounds Write vulnerability in Tenda AC5 Firmware 15.03.06.28

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the formSetFirewallCfg function.

9.8
2023-04-07 CVE-2023-25217 Tenda Out-of-bounds Write vulnerability in Tenda AC5 Firmware 15.03.06.28

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the formWifiBasicSet function.

9.8
2023-04-07 CVE-2023-25218 Tenda Out-of-bounds Write vulnerability in Tenda AC5 Firmware 15.03.06.28

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the form_fast_setting_wifi_set function.

9.8
2023-04-07 CVE-2023-25219 Tenda Out-of-bounds Write vulnerability in Tenda AC5 Firmware 15.03.06.28

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the fromDhcpListClient function.

9.8
2023-04-07 CVE-2023-25220 Tenda Out-of-bounds Write vulnerability in Tenda AC5 Firmware 15.03.06.28

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the add_white_node function.

9.8
2023-04-07 CVE-2023-27012 Tenda Out-of-bounds Write vulnerability in Tenda Ac10 Firmware 16.03.10.13Cn

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the setSchedWifi function.

9.8
2023-04-07 CVE-2023-27013 Tenda Out-of-bounds Write vulnerability in Tenda Ac10 Firmware 16.03.10.13Cn

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the get_parentControl_list_Info function.

9.8
2023-04-07 CVE-2023-27014 Tenda Out-of-bounds Write vulnerability in Tenda Ac10 Firmware 16.03.10.13Cn

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_46AC38 function.

9.8
2023-04-07 CVE-2023-27015 Tenda Out-of-bounds Write vulnerability in Tenda Ac10 Firmware 16.03.10.13Cn

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_4A75C0 function.

9.8
2023-04-07 CVE-2023-27016 Tenda Out-of-bounds Write vulnerability in Tenda Ac10 Firmware 16.03.10.13Cn

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the R7WebsSecurityHandler function.

9.8
2023-04-07 CVE-2023-27017 Tenda Out-of-bounds Write vulnerability in Tenda Ac10 Firmware 16.03.10.13Cn

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45DC58 function.

9.8
2023-04-07 CVE-2023-27018 Tenda Out-of-bounds Write vulnerability in Tenda Ac10 Firmware 16.03.10.13Cn

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45EC1C function.

9.8
2023-04-07 CVE-2023-27019 Tenda Out-of-bounds Write vulnerability in Tenda Ac10 Firmware 16.03.10.13Cn

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_458FBC function.

9.8
2023-04-07 CVE-2023-27020 Tenda Out-of-bounds Write vulnerability in Tenda Ac10 Firmware 16.03.10.13Cn

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the saveParentControlInfo function.

9.8
2023-04-07 CVE-2023-27021 Tenda Out-of-bounds Write vulnerability in Tenda Ac10 Firmware 16.03.10.13Cn

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the formSetFirewallCfg function.

9.8
2023-04-06 CVE-2023-29473 Atos Command Injection vulnerability in Atos Unify Openscape 4000 and Unify Openscape 4000 Manager

webservice in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve administrative access, aka OSFOURK-23710.

9.8
2023-04-06 CVE-2023-29474 Atos Command Injection vulnerability in Atos Unify Openscape 4000 and Unify Openscape 4000 Manager

inventory in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve administrative access, aka OSFOURK-23552.

9.8
2023-04-06 CVE-2023-29475 Atos Command Injection vulnerability in Atos Unify Openscape 4000 and Unify Openscape 4000 Manager

inventory in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve administrative access, aka OSFOURK-23543.

9.8
2023-04-06 CVE-2023-28500 Adobe Deserialization of Untrusted Data vulnerability in Adobe Livecycle ES4

A Java insecure deserialization vulnerability in Adobe LiveCycle ES4 version 11.0 and earlier allows unauthenticated remote attackers to gain operating system code execution by submitting specially crafted Java serialized objects to a specific URL.

9.8
2023-04-06 CVE-2023-29017 VM2 Project Unspecified vulnerability in VM2 Project VM2

vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules.

9.8
2023-04-06 CVE-2023-0580 ABB Insecure Storage of Sensitive Information vulnerability in ABB MY Control System 5.0/5.13

Insecure Storage of Sensitive Information vulnerability in ABB My Control System (on-premise) allows an attacker who successfully exploited this vulnerability to gain access to the secure application data or take control of the application. Of the services that make up the My Control System (on-premise) application, the following ones are affected by this vulnerability: User Interface System Monitoring1 Asset Inventory This issue affects My Control System (on-premise): from 5.0;0 through 5.13.

9.8
2023-04-06 CVE-2023-24538 Golang Code Injection vulnerability in Golang GO

Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected.

9.8
2023-04-06 CVE-2023-0750 Lynx Technik Missing Encryption of Sensitive Data vulnerability in Lynx-Technik Yellobrik PEC 1864 Firmware

Yellobrik PEC-1864 implements authentication checks via javascript in the frontend interface.  When the device can be accessed over the network an attacker could bypass authentication. This would allow an attacker to : - Change the password, resulting in a DOS of the users - Change the streaming source, compromising the integrity of the stream - Change the streaming destination, compromising the confidentiality of the stream This issue affects Yellowbrik: PEC 1864.

9.8
2023-04-06 CVE-2023-1908 Simple Mobile Comparison Website Project Unspecified vulnerability in Simple Mobile Comparison Website Project Simple Mobile Comparison Website 1.0

A vulnerability was found in SourceCodester Simple Mobile Comparison Website 1.0.

9.8
2023-04-05 CVE-2022-31890 Enhancesoft SQL Injection vulnerability in Enhancesoft Audit LOG

SQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae via the order parameter to the getOrder function.

9.8
2023-04-05 CVE-2023-1708 Gitlab Command Injection vulnerability in Gitlab

An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 where non-printable characters gets copied from clipboard, allowing unexpected commands to be executed on victim machine.

9.8
2023-04-05 CVE-2023-1782 Hashicorp Missing Authorization vulnerability in Hashicorp Nomad 1.5.0

HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled.

9.8
2023-04-05 CVE-2023-24720 Readium Unrestricted Upload of File with Dangerous Type vulnerability in Readium Readium-Js 0.32.0

An arbitrary file upload vulnerability in readium-js v0.32.0 allows attackers to execute arbitrary code via uploading a crafted EPUB file.

9.8
2023-04-05 CVE-2022-4939 Wclovers Unspecified vulnerability in Wclovers Wcfm Membership

THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, due to a missing capability check on the wp_ajax_nopriv_wcfm_ajax_controller AJAX action that controls membership settings.

9.8
2023-04-05 CVE-2023-1877 Microweber Unspecified vulnerability in Microweber

Command Injection in GitHub repository microweber/microweber prior to 1.3.3.

9.8
2023-04-05 CVE-2023-1886 Phpmyfaq Unspecified vulnerability in PHPmyfaq

Authentication Bypass by Capture-replay in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

9.8
2023-04-05 CVE-2023-1788 Firefly III Unspecified vulnerability in Firefly-Iii Firefly III

Insufficient Session Expiration in GitHub repository firefly-iii/firefly-iii prior to 6.

9.8
2023-04-05 CVE-2023-20073 Cisco Unrestricted Upload of File with Dangerous Type vulnerability in Cisco products

A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device.

9.8
2023-04-05 CVE-2023-25330 Mybatis SQL Injection vulnerability in Mybatis

A SQL injection vulnerability in Mybatis plus below 3.5.3.1 allows remote attackers to execute arbitrary SQL commands via the tenant ID valuer.

9.8
2023-04-05 CVE-2023-1849 Online Payroll System Project Unspecified vulnerability in Online Payroll System Project Online Payroll System 1.0

A vulnerability was found in SourceCodester Online Payroll System 1.0.

9.8
2023-04-05 CVE-2023-1850 Online Payroll System Project SQL Injection vulnerability in Online Payroll System Project Online Payroll System 1.0

A vulnerability was found in SourceCodester Online Payroll System 1.0.

9.8
2023-04-05 CVE-2023-1854 Online Graduate Tracer System Project Unspecified vulnerability in Online Graduate Tracer System Project Online Graduate Tracer System 1.0

A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0.

9.8
2023-04-05 CVE-2023-1856 AIR Cargo Management System Project SQL Injection vulnerability in AIR Cargo Management System Project AIR Cargo Management System 1.0

A vulnerability has been found in SourceCodester Air Cargo Management System 1.0 and classified as critical.

9.8
2023-04-05 CVE-2023-1845 Online Payroll System Project Unspecified vulnerability in Online Payroll System Project Online Payroll System 1.0

A vulnerability, which was classified as critical, was found in SourceCodester Online Payroll System 1.0.

9.8
2023-04-05 CVE-2023-1846 Online Payroll System Project Unspecified vulnerability in Online Payroll System Project Online Payroll System 1.0

A vulnerability has been found in SourceCodester Online Payroll System 1.0 and classified as critical.

9.8
2023-04-05 CVE-2023-1847 Online Payroll System Project Unspecified vulnerability in Online Payroll System Project Online Payroll System 1.0

A vulnerability was found in SourceCodester Online Payroll System 1.0 and classified as critical.

9.8
2023-04-05 CVE-2023-1848 Online Payroll System Project Unspecified vulnerability in Online Payroll System Project Online Payroll System 1.0

A vulnerability was found in SourceCodester Online Payroll System 1.0.

9.8
2023-04-05 CVE-2023-29374 Langchain Injection vulnerability in Langchain

In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec method.

9.8
2023-04-04 CVE-2023-27488 Envoyproxy Unspecified vulnerability in Envoyproxy Envoy

Envoy is an open source edge and service proxy designed for cloud-native applications.

9.8
2023-04-04 CVE-2023-28613 Samsung Integer Overflow or Wraparound vulnerability in Samsung products

An issue was discovered in Samsung Exynos Mobile Processor and Baseband Modem Processor for Exynos 1280, Exynos 2200, and Exynos Modem 5300.

9.8
2023-04-04 CVE-2020-19279 Wide Project Path Traversal vulnerability in Wide Project Wide

Directory Traversal vulnerability found in B3log Wide allows a an attacker to escalate privileges via symbolic links.

9.8
2023-04-04 CVE-2020-19692 Nginx Classic Buffer Overflow vulnerability in Nginx NJS 20190627

Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_module.c file.

9.8
2023-04-04 CVE-2020-19693 Espruino Out-of-bounds Write vulnerability in Espruino 20190628

An issue found in Espruino Espruino 6ea4c0a allows an attacker to execute arbitrrary code via oldFunc parameter of the jswrap_object.c:jswrap_function_replacewith endpoint.

9.8
2023-04-04 CVE-2020-19695 Nginx Classic Buffer Overflow vulnerability in Nginx NJS

Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vm.c function.

9.8
2023-04-04 CVE-2020-20913 Mingsoft SQL Injection vulnerability in Mingsoft Mcms 4.7.2

SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basic_title parameter.

9.8
2023-04-04 CVE-2020-20914 Publiccms SQL Injection vulnerability in Publiccms 4.0

SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter.

9.8
2023-04-04 CVE-2020-20915 Publiccms SQL Injection vulnerability in Publiccms 4.0

SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminControl.

9.8
2023-04-04 CVE-2021-28235 Etcd Improper Authentication vulnerability in Etcd 3.4.10

Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.

9.8
2023-04-04 CVE-2021-31707 Kitesky Unrestricted Upload of File with Dangerous Type vulnerability in Kitesky Kitecms

Permissions vulnerability found in KiteCMS allows a remote attacker to execute arbitrary code via the upload file type.

9.8
2023-04-04 CVE-2023-26921 Quectel OS Command Injection vulnerability in Quectel Ag550Qcn Firmware

OS Command Injection vulnerability in quectel AG550QCN allows attackers to execute arbitrary commands via ql_atfwd.

9.8
2023-04-04 CVE-2020-29312 Zend Deserialization of Untrusted Data vulnerability in Zend Framework

An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function.

9.8
2023-04-04 CVE-2023-26750 Yiiframework SQL Injection vulnerability in Yiiframework YII

SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function.

9.8
2023-04-04 CVE-2023-26866 Greenpacket Command Injection vulnerability in Greenpacket Ot-235 Firmware and Wr-1200 Firmware

GreenPacket OH736's WR-1200 Indoor Unit, OT-235 with firmware versions M-IDU-1.6.0.3_V1.1 and MH-46360-2.0.3-R5-GP respectively are vulnerable to remote command injection.

9.8
2023-04-04 CVE-2023-1827 Centralized Covid Vaccination Records System Project Unspecified vulnerability in Centralized Covid Vaccination Records System Project Centralized Covid Vaccination Records System 1.0

A vulnerability has been found in SourceCodester Centralized Covid Vaccination Records System 1.0 and classified as critical.

9.8
2023-04-04 CVE-2023-1671 Sophos Command Injection vulnerability in Sophos web Appliance

A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.

9.8
2023-04-04 CVE-2023-1826 Oretnom23 Unspecified vulnerability in Oretnom23 Online Computer and Laptop Store 1.0

A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0.

9.8
2023-04-03 CVE-2022-43939 Hitachi Unspecified vulnerability in Hitachi Vantara Pentaho Business Analytics Server 9.4.0.0

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented. 

9.8
2023-04-03 CVE-2022-38922 ISS Oberlausitz SQL Injection vulnerability in Iss-Oberlausitz Bluepage CMS 3.9

BluePage CMS thru 3.9 processes an insufficiently sanitized HTTP Header Cookie value allowing MySQL Injection in the 'users-cookie-settings' token using a Time-based blind SLEEP payload.

9.8
2023-04-03 CVE-2022-38923 ISS Oberlausitz SQL Injection vulnerability in Iss-Oberlausitz Bluepage CMS 3.9

BluePage CMS thru v3.9 processes an insufficiently sanitized HTTP Header allowing MySQL Injection in the 'User-Agent' field using a Time-based blind SLEEP payload.

9.8
2023-04-03 CVE-2023-26119 Htmlunit Unspecified vulnerability in Htmlunit

Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage.

9.8
2023-04-04 CVE-2020-21487 Netgate Cross-site Scripting vulnerability in Netgate Pfsense and Pfsense Acme Package

Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php.

9.6
2023-04-09 CVE-2023-1964 Phpgurukul Unspecified vulnerability in PHPgurukul Bank Locker Management System 1.0

A vulnerability classified as critical has been found in PHPGurukul Bank Locker Management System 1.0.

9.1
2023-04-07 CVE-2023-1940 Simple AND Beautiful Shopping Cart System Project Unspecified vulnerability in Simple and Beautiful Shopping Cart System Project Simple and Beautiful Shopping Cart System 1.0

A vulnerability classified as critical was found in SourceCodester Simple and Beautiful Shopping Cart System 1.0.

9.1
2023-04-04 CVE-2023-27493 Envoyproxy HTTP Request Smuggling vulnerability in Envoyproxy Envoy

Envoy is an open source edge and service proxy designed for cloud-native applications.

9.1
2023-04-04 CVE-2023-27491 Envoyproxy HTTP Request Smuggling vulnerability in Envoyproxy Envoy

Envoy is an open source edge and service proxy designed for cloud-native applications.

9.1
2023-04-04 CVE-2023-27487 Envoyproxy Unspecified vulnerability in Envoyproxy Envoy

Envoy is an open source edge and service proxy designed for cloud-native applications.

9.1

139 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2023-04-09 CVE-2012-10010 Bestwebsoft Unspecified vulnerability in Bestwebsoft Contact Form 3.21

A vulnerability was found in BestWebSoft Contact Form 3.21.

8.8
2023-04-08 CVE-2013-10025 Exit Strategy Project Unspecified vulnerability in Exit Strategy Project Exit Strategy 1.55

A vulnerability was found in Exit Strategy Plugin 1.55 on WordPress and classified as problematic.

8.8
2023-04-08 CVE-2023-1960 Oretnom23 Unspecified vulnerability in Oretnom23 Online Computer and Laptop Store 1.0

A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical.

8.8
2023-04-08 CVE-2023-1957 Oretnom23 Unspecified vulnerability in Oretnom23 Online Computer and Laptop Store 1.0

A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0.

8.8
2023-04-08 CVE-2023-1959 Oretnom23 SQL Injection vulnerability in Oretnom23 Online Computer and Laptop Store 1.0

A vulnerability has been found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical.

8.8
2023-04-08 CVE-2023-1953 Oretnom23 Unspecified vulnerability in Oretnom23 Online Computer and Laptop Store 1.0

A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0.

8.8
2023-04-08 CVE-2023-1954 Oretnom23 Unspecified vulnerability in Oretnom23 Online Computer and Laptop Store 1.0

A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0.

8.8
2023-04-08 CVE-2023-1956 Oretnom23 Unspecified vulnerability in Oretnom23 Online Computer and Laptop Store 1.0

A vulnerability classified as critical was found in SourceCodester Online Computer and Laptop Store 1.0.

8.8
2023-04-07 CVE-2023-26817 Pgyer Unspecified vulnerability in Pgyer Codefever

codefever before 2023.2.7-commit-b1c2e7f was discovered to contain a remote code execution (RCE) vulnerability via the component /controllers/api/user.php.

8.8
2023-04-06 CVE-2023-29008 Svelte Cross-Site Request Forgery (CSRF) vulnerability in Svelte Sveltekit 1.15.0/1.15.1

The SvelteKit framework offers developers an option to create simple REST APIs.

8.8
2023-04-06 CVE-2020-36071 Tailor Management System Project SQL Injection vulnerability in Tailor Management System Project Tailor Management System 1.0

SQL injection vulnerability found in Tailor Management System v.1 allows a remote authenticated attacker to execute arbitrary code via the customer parameter of the email.php page.

8.8
2023-04-06 CVE-2020-36072 Tailor Management System Project SQL Injection vulnerability in Tailor Management System Project Tailor Management System 1.0

SQL injection vulnerability found in Tailor Management System v.1 allows a remote attacker to execute arbitrary code via the id parameter.

8.8
2023-04-06 CVE-2020-36073 Tailor Management System Project SQL Injection vulnerability in Tailor Management System Project Tailor Management System 1.0

SQL injection vulnerability found in Tailor Management System v.1 allows a remote attacker to execute arbitrary code via the detail parameter of the document.php page.

8.8
2023-04-06 CVE-2020-36074 Tailor Mangement System Project SQL Injection vulnerability in Tailor Mangement System Project Tailor Mangement System 1.0

SQL injection vulnerability found in Tailor Mangement System v.1 allows a remote attacker to execute arbitrary code via the title parameter.

8.8
2023-04-06 CVE-2022-46793 Adtribes Unspecified vulnerability in Adtribes Product Feed PRO for Woocommerce

Cross-Site Request Forgery (CSRF) vulnerability in AdTribes.Io Product Feed PRO for WooCommerce plugin <= 12.4.4 versions.

8.8
2023-04-06 CVE-2023-23801 Hasthemes Unspecified vulnerability in Hasthemes Really Simple Google TAG Manager

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Really Simple Google Tag Manager plugin <= 1.0.6 versions.

8.8
2023-04-06 CVE-2023-29421 Bzip3 Project Out-of-bounds Write vulnerability in Bzip3 Project Bzip3

An issue was discovered in libbzip3.a in bzip3 before 1.2.3.

8.8
2023-04-05 CVE-2022-31888 Enhancesoft Session Fixation vulnerability in Enhancesoft Osticket

Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.

8.8
2023-04-05 CVE-2022-4941 Wclovers Unspecified vulnerability in Wclovers Wcfm Membership

The WCFM Membership plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.10 due to missing nonce checks on various AJAX actions.

8.8
2023-04-05 CVE-2023-20102 Cisco Deserialization of Untrusted Data vulnerability in Cisco products

A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system.

8.8
2023-04-05 CVE-2023-1522 Genetec SQL Injection vulnerability in Genetec Security Center 5.11.2

SQL Injection in the Hardware Inventory report of Security Center 5.11.2.

8.8
2023-04-05 CVE-2023-29006 Glpi Project Unspecified vulnerability in Glpi-Project Order

The Order GLPI plugin allows users to manage order management within GLPI.

8.8
2023-04-05 CVE-2022-4935 Wclovers Missing Authorization vulnerability in Wclovers Wcfm Marketplace

The WCFM Marketplace plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 3.4.11 due to missing capability checks on various AJAX actions.

8.8
2023-04-05 CVE-2022-4936 Wclovers Unspecified vulnerability in Wclovers Wcfm Marketplace

The WCFM Marketplace plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.11 due to missing nonce checks on various AJAX actions.

8.8
2023-04-05 CVE-2022-4937 Wclovers Missing Authorization vulnerability in Wclovers Frontend Manager for Woocommerce Along With Bookings Subscription Listings Compatible

The WCFM Frontend Manager plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 6.6.0 due to missing capability checks on various AJAX actions.

8.8
2023-04-05 CVE-2022-4938 Wclovers Unspecified vulnerability in Wclovers Frontend Manager for Woocommerce Along With Bookings Subscription Listings Compatible

The WCFM Frontend Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.6.0 due to missing nonce checks on various AJAX actions.

8.8
2023-04-05 CVE-2023-28634 Glpi Project Unspecified vulnerability in Glpi-Project Glpi

GLPI is a free asset and IT management software package.

8.8
2023-04-04 CVE-2023-0480 Vitalpbx Cross-Site Request Forgery (CSRF) vulnerability in Vitalpbx 3.2.3

VitalPBX version 3.2.3-8 allows an unauthenticated external attacker to obtain the instance administrator's account.

8.8
2023-04-04 CVE-2023-0265 Uvdesk Unrestricted Upload of File with Dangerous Type vulnerability in Uvdesk Community-Skeleton 1.1.1

Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server.

8.8
2023-04-04 CVE-2023-29003 Svelte Cross-Site Request Forgery (CSRF) vulnerability in Svelte Sveltekit 1.15.0

SvelteKit is a web development framework.

8.8
2023-04-04 CVE-2023-1810 Google
Fedoraproject
Debian
Out-of-bounds Write vulnerability in multiple products

Heap buffer overflow in Visuals in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

8.8
2023-04-04 CVE-2023-1811 Google
Fedoraproject
Debian
Use After Free vulnerability in multiple products

Use after free in Frames in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page.

8.8
2023-04-04 CVE-2023-1812 Google
Fedoraproject
Debian
Out-of-bounds Write vulnerability in multiple products

Out of bounds memory access in DOM Bindings in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.

8.8
2023-04-04 CVE-2023-1815 Google
Fedoraproject
Debian
Use After Free vulnerability in multiple products

Use after free in Networking APIs in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page.

8.8
2023-04-04 CVE-2023-1818 Google
Fedoraproject
Debian
Use After Free vulnerability in multiple products

Use after free in Vulkan in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

8.8
2023-04-04 CVE-2023-1820 Google
Fedoraproject
Debian
Out-of-bounds Write vulnerability in multiple products

Heap buffer overflow in Browser History in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page.

8.8
2023-04-04 CVE-2020-19278 MM Wiki Project Cross-Site Request Forgery (CSRF) vulnerability in Mm-Wiki Project Mm-Wiki 0.1.2

Cross Site Request Forgery vulnerability found in Phachon mm-wiki v.0.1.2 allows a remote attacker to execute arbitrary code via the system/user/save parameter.

8.8
2023-04-04 CVE-2020-21060 Phpmywind SQL Injection vulnerability in PHPmywind 5.6

SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote attacker to gain privileges via the delete function of the administrator management page.

8.8
2023-04-04 CVE-2020-21514 Fluentd Unspecified vulnerability in Fluentd and Fluentd-Ui

An issue was discovered in Fluent Fluentd v.1.8.0 and Fluent-ui v.1.2.2 allows attackers to gain escalated privileges and execute arbitrary code due to a default password.

8.8
2023-04-04 CVE-2023-25355 Coredial Incorrect Default Permissions vulnerability in Coredial Sipxcom

CoreDial sipXcom up to and including 21.04 is vulnerable to Insecure Permissions.

8.8
2023-04-04 CVE-2023-25356 Coredial Argument Injection or Modification vulnerability in Coredial Sipxcom

CoreDial sipXcom up to and including 21.04 is vulnerable to Improper Neutralization of Argument Delimiters in a Command.

8.8
2023-04-04 CVE-2022-41633 Peepso Unspecified vulnerability in Peepso

Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin <= 6.0.2.0 versions.

8.8
2023-04-03 CVE-2022-43938 Hitachi Code Injection vulnerability in Hitachi Vantara Pentaho Business Analytics Server 9.4.0.0

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of Pentaho Reports (*.prpt) through the JVM script manager. 

8.8
2023-04-03 CVE-2022-43940 Hitachi Incorrect Authorization vulnerability in Hitachi Vantara Pentaho Business Analytics Server 9.4.0.0

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly perform an authorization check in the data source management service. 

8.8
2023-04-03 CVE-2023-28854 Nophp Project Unspecified vulnerability in Nophp Project Nophp

nophp is a PHP web framework.

8.8
2023-04-03 CVE-2022-43773 Hitachi Incorrect Permission Assignment for Critical Resource vulnerability in Hitachi Vantara Pentaho Business Analytics Server 9.4.0.0

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x is installed with a sample HSQLDB data source configured with stored procedures enabled. 

8.8
2023-04-03 CVE-2022-38072 Admesh Project
Slic3R
Improper Validation of Array Index vulnerability in multiple products

An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4.

8.8
2023-04-03 CVE-2023-0820 Bestwebsoft Unspecified vulnerability in Bestwebsoft User Role

The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrary privilege escalation of any role.

8.8
2023-04-04 CVE-2023-28840 Mobyproject Unspecified vulnerability in Mobyproject Moby

Moby is an open source container framework developed by Docker Inc.

8.7
2023-04-04 CVE-2023-0835 Markdown PDF Project Cross-site Scripting vulnerability in Markdown-Pdf Project Markdown-Pdf 11.0.0

markdown-pdf version 11.0.0 allows an external attacker to remotely obtain arbitrary local files.

8.2
2023-04-04 CVE-2023-27089 Ehuacui BBS Project Cross-site Scripting vulnerability in Ehuacui-Bbs Project Ehuacui-Bbs

Cross Site Scripting vulnerability found in Ehuacui BBS allows attackers to cause a denial of service via a crafted payload in the login parameter.

8.2
2023-04-07 CVE-2022-33959 IBM Unspecified vulnerability in IBM Sterling Order Management 10

IBM Sterling Order Management 10.0 could allow a user to bypass validation and perform unauthorized actions on behalf of other users.

8.1
2023-04-05 CVE-2023-28838 Glpi Project Unspecified vulnerability in Glpi-Project Glpi

GLPI is a free asset and IT management software package.

8.1
2023-04-05 CVE-2023-28632 Glpi Project Unspecified vulnerability in Glpi-Project Glpi

GLPI is a free asset and IT management software package.

8.1
2023-04-07 CVE-2023-28051 Dell Unspecified vulnerability in Dell Power Manager 3.10/3.3

Dell Power Manager, versions 3.10 and prior, contains an Improper Access Control vulnerability.

7.8
2023-04-06 CVE-2023-20655 Google Improper Privilege Management vulnerability in Google Android

In mmsdk, there is a possible escalation of privilege due to a parcel format mismatch.

7.8
2023-04-06 CVE-2023-0652 Cloudflare Link Following vulnerability in Cloudflare Warp

Due to a hardlink created in the ProgramData folder during the repair process of the software, the installer (MSI) of WARP Client for Windows (<= 2022.12.582.0) allowed a malicious attacker to forge the destination of the hardlink and escalate privileges, overwriting SYSTEM protected files. As Cloudflare WARP client for Windows (up to version 2022.5.309.0) allowed creation of mount points from its ProgramData folder, during installation of the WARP client, it was possible to escalate privileges and overwrite SYSTEM protected files.

7.8
2023-04-06 CVE-2023-25542 Dell Unspecified vulnerability in Dell Trusted Device Agent

Dell Trusted Device Agent, versions prior to 5.3.0, contain(s) an improper installation permissions vulnerability.

7.8
2023-04-05 CVE-2023-20122 Cisco OS Command Injection vulnerability in Cisco Identity Services Engine 3.2

Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system.

7.8
2023-04-05 CVE-2022-43664 Justsystems Unspecified vulnerability in Justsystems Ichitaro 2022 1.0.1.57600

A use-after-free vulnerability exists within the way Ichitaro Word Processor 2022, version 1.0.1.57600, processes protected documents.

7.8
2023-04-05 CVE-2022-45115 Justsystems Unspecified vulnerability in Justsystems Ichitaro 2022 1.0.1.57600

A buffer overflow vulnerability exists in the Attribute Arena functionality of Ichitaro 2022 1.0.1.57600.

7.8
2023-04-05 CVE-2023-22291 Justsystems Unspecified vulnerability in Justsystems Ichitaro 2022 1.0.1.57600

An invalid free vulnerability exists in the Frame stream parser functionality of Ichitaro 2022 1.0.1.57600.

7.8
2023-04-05 CVE-2023-22660 Justsystems Unspecified vulnerability in Justsystems Ichitaro 2022 1.0.1.57600

A heap-based buffer overflow vulnerability exists in the way Ichitaro version 2022 1.0.1.57600 processes certain LayoutBox stream record types.

7.8
2023-04-05 CVE-2023-1412 Cloudflare Link Following vulnerability in Cloudflare Warp

An unprivileged (non-admin) user can exploit an Improper Access Control vulnerability in the Cloudflare WARP Client for Windows (<= 2022.12.582.0) to perform privileged operations with SYSTEM context by working with a combination of opportunistic locks (oplock) and symbolic links (which can both be created by an unprivileged user). After installing the Cloudflare WARP Client (admin privileges required), an MSI-Installer is placed under C:\Windows\Installer.

7.8
2023-04-04 CVE-2023-29323 Openbsd
Opensmtpd
ascii_load_sockaddr in smtpd in OpenBSD before 7.1 errata 024 and 7.2 before errata 020, and OpenSMTPD Portable before 7.0.0-portable commit f748277, can abort upon a connection from a local, scoped IPv6 address.
7.8
2023-04-04 CVE-2022-48222 Gbgplc Uncontrolled Search Path Element vulnerability in Gbgplc Acuant Acufill SDK

An issue was discovered in Acuant AcuFill SDK before 10.22.02.03.

7.8
2023-04-04 CVE-2022-48227 Gbgplc Improper Privilege Management vulnerability in Gbgplc Acuant Asureid Sentinel

An issue was discovered in Acuant AsureID Sentinel before 5.2.149.

7.8
2023-04-04 CVE-2022-48226 Gbgplc Improper Privilege Management vulnerability in Gbgplc Acuant Acufill SDK

An issue was discovered in Acuant AcuFill SDK before 10.22.02.03.

7.8
2023-04-04 CVE-2023-26733 Tinytiff Project Classic Buffer Overflow vulnerability in Tinytiff Project Tinytiff 3.0.0.0

Buffer Overflow vulnerability found in tinyTIFF v.3.0 allows a local attacker to cause a denial of service via the TinyTiffReader_readNextFrame function in tinytiffreader.c file.

7.8
2023-04-04 CVE-2023-26991 Swftools Use After Free vulnerability in Swftools 0.9.2

SWFTools v0.9.2 was discovered to contain a stack-use-after-scope in the swf_ReadSWF2 function in lib/rfxswf.c.

7.8
2023-04-04 CVE-2023-27759 Wondershare Untrusted Search Path vulnerability in Wondershare Edrawmind 10.0.6

An issue found in Wondershare Technology Co, Ltd Edrawmind v.10.0.6 allows a remote attacker to executea arbitrary commands via the WindowsCodescs.dll file.

7.8
2023-04-04 CVE-2023-27760 Wondershare Untrusted Search Path vulnerability in Wondershare Filmora 12.0.9

An issue found in Wondershare Technology Co, Ltd Filmora v.12.0.9 allows a remote attacker to execute arbitrary commands via the filmora_setup_full846.exe.

7.8
2023-04-04 CVE-2023-27761 Wondershare Untrusted Search Path vulnerability in Wondershare Uniconverter 14.0.0

An issue found in Wondershare Technology Co., Ltd UniConverter v.14.0.0 allows a remote attacker to execute arbitrary commands via the uniconverter14_64bit_setup_full14204.exe file.

7.8
2023-04-04 CVE-2023-27762 Wondershare Untrusted Search Path vulnerability in Wondershare Democreator 6.0.0

An issue found in Wondershare Technology Co., Ltd DemoCreator v.6.0.0 allows a remote attacker to execute arbitrary commands via the democreator_setup_full7743.exe file.

7.8
2023-04-04 CVE-2023-27763 Wondershare Untrusted Search Path vulnerability in Wondershare Mobiletrans 4.0.2

An issue found in Wondershare Technology Co.,Ltd MobileTrans v.4.0.2 allows a remote attacker to execute arbitrary commands via the mobiletrans_setup_full5793.exe file.

7.8
2023-04-04 CVE-2023-27764 Wondershare Untrusted Search Path vulnerability in Wondershare Repairit 3.5.4

An issue found in Wondershare Technology Co.,Ltd Repairit v.3.5.4 allows a remote attacker to execute arbitrary commands via the repairit_setup_full5913.exe file.

7.8
2023-04-04 CVE-2023-27765 Wondershare Untrusted Search Path vulnerability in Wondershare Recoverit 10.6.3

An issue found in Wondershare Technology Co.,Ltd Recoverit v.10.6.3 allows a remote attacker to execute arbitrary commands via the recoverit_setup_full4134.exe file.

7.8
2023-04-04 CVE-2023-27766 Wondershare Untrusted Search Path vulnerability in Wondershare Anireel 1.5.4

An issue found in Wondershare Technology Co.,Ltd Anireel 1.5.4 allows a remote attacker to execute arbitrary commands via the anireel_setup_full9589.exe file.

7.8
2023-04-04 CVE-2023-27767 Wondershare Untrusted Search Path vulnerability in Wondershare Dr.Fone 12.4.9

An issue found in Wondershare Technology Co.,Ltd Dr.Fone v.12.4.9 allows a remote attacker to execute arbitrary commands via the drfone_setup_full3360.exe file.

7.8
2023-04-04 CVE-2023-27768 Wondershare Untrusted Search Path vulnerability in Wondershare Pdfelement 9.1.1

An issue found in Wondershare Technology Co.,Ltd PDFelement v9.1.1 allows a remote attacker to execute arbitrary commands via the pdfelement-pro_setup_full5239.exe file.

7.8
2023-04-04 CVE-2023-27769 Wondershare Untrusted Search Path vulnerability in Wondershare PDF Reader 1.0.1

An issue found in Wondershare Technology Co.,Ltd PDF Reader v.1.0.1 allows a remote attacker to execute arbitrary commands via the pdfreader_setup_full13143.exe file.

7.8
2023-04-04 CVE-2023-27770 Wondershare Untrusted Search Path vulnerability in Wondershare Edraw-Max 12.0.4

An issue found in Wondershare Technology Co.,Ltd Edraw-max v.12.0.4 allows a remote attacker to execute arbitrary commands via the edraw-max_setup_full5371.exe file.

7.8
2023-04-04 CVE-2023-27771 Wondershare Untrusted Search Path vulnerability in Wondershare Creative Centerr 1.0.8

An issue found in Wondershare Technology Co.,Ltd Creative Centerr v.1.0.8 allows a remote attacker to execute arbitrary commands via the wondershareCC_setup_full10819.exe file.

7.8
2023-04-04 CVE-2023-26775 Monitorr Unrestricted Upload of File with Dangerous Type vulnerability in Monitorr 1.7.6M

File Upload vulnerability found in Monitorr v.1.7.6 allows a remote attacker t oexecute arbitrary code via a crafted file upload to the assets/php/upload.php endpoint.

7.8
2023-04-04 CVE-2023-25941 Dell Unspecified vulnerability in Dell EMC Powerscale Onefs

Dell PowerScale OneFS versions 8.2.x-9.5.0.x contain an elevation of privilege vulnerability.

7.8
2023-04-04 CVE-2023-25940 Dell Unspecified vulnerability in Dell EMC Powerscale Onefs 9.5.0.0

Dell PowerScale OneFS version 9.5.0.0 contains improper link resolution before file access vulnerability in isi_gather_info.

7.8
2023-04-03 CVE-2023-1579 GNU Out-of-bounds Write vulnerability in GNU Binutils 2.39

Heap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64.

7.8
2023-04-03 CVE-2023-0975 Trellix Improper Preservation of Permissions vulnerability in Trellix Agent 5.7.7/5.7.8

A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to replace one of the Agent’s executables before it can be executed.

7.8
2023-04-03 CVE-2023-26269 Apache Unspecified vulnerability in Apache James

Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default.

7.8
2023-04-09 CVE-2023-27727 F5 Out-of-bounds Read vulnerability in F5 NJS 0.7.10

Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_function_frame at src/njs_function.h.

7.5
2023-04-09 CVE-2023-27728 F5 Out-of-bounds Read vulnerability in F5 NJS 0.7.10

Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_dump_is_recursive at src/njs_vmcode.c.

7.5
2023-04-09 CVE-2023-27729 F5 Unspecified vulnerability in F5 NJS 0.7.10

Nginx NJS v0.7.10 was discovered to contain an illegal memcpy via the function njs_vmcode_return at src/njs_vmcode.c.

7.5
2023-04-09 CVE-2023-27730 F5 Out-of-bounds Read vulnerability in F5 NJS 0.7.10

Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_lvlhsh_find at src/njs_lvlhsh.c.

7.5
2023-04-08 CVE-2013-10024 Exit Strategy Project Unspecified vulnerability in Exit Strategy Project Exit Strategy 1.55

A vulnerability has been found in Exit Strategy Plugin 1.55 on WordPress and classified as problematic.

7.5
2023-04-07 CVE-2023-27180 Gdidees Unspecified vulnerability in Gdidees CMS 3.9.1

GDidees CMS v3.9.1 was discovered to contain a source code disclosure vulnerability by the backup feature which is accessible via /_admin/backup.php.

7.5
2023-04-07 CVE-2023-28707 Apache Improper Input Validation vulnerability in Apache Apache-Airflow-Providers-Apache-Drill

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects Apache Airflow Drill Provider: before 2.3.2.

7.5
2023-04-07 CVE-2023-28710 Apache Improper Input Validation vulnerability in Apache Apache-Airflow-Providers-Apache-Spark

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Spark Provider.This issue affects Apache Airflow Spark Provider: before 4.0.1.

7.5
2023-04-07 CVE-2022-34333 IBM Unspecified vulnerability in IBM Sterling Order Management 10

IBM Sterling Order Management 10.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

7.5
2023-04-07 CVE-2023-26820 Siteproxy Project Path Traversal vulnerability in Siteproxy Project Siteproxy 1.0

siteproxy v1.0 was discovered to contain a path traversal vulnerability via the component index.js.

7.5
2023-04-06 CVE-2020-19678 Oisf
Pfsense
Path Traversal vulnerability in multiple products

Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a remote attacker to obtain sensitive information via the file parameter to suricata/suricata_logs_browser.php.

7.5
2023-04-06 CVE-2023-24537 Golang Integer Overflow or Wraparound vulnerability in Golang GO

Calling any of the Parse functions on Go source code which contains //line directives with very large line numbers can cause an infinite loop due to integer overflow.

7.5
2023-04-06 CVE-2023-24534 Golang Resource Exhaustion vulnerability in Golang GO

HTTP and MIME header parsing can allocate large amounts of memory, even when parsing small inputs, potentially leading to a denial of service.

7.5
2023-04-06 CVE-2023-24536 Golang Allocation of Resources Without Limits or Throttling vulnerability in Golang GO

Multipart form parsing can consume large amounts of CPU and memory when processing form inputs containing very large numbers of parts.

7.5
2023-04-06 CVE-2023-1802 Docker Cleartext Transmission of Sensitive Information vulnerability in Docker Desktop 4.17.0/4.17.1

In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the HTTPS health check has failed. A targeted network sniffing attack can lead to a disclosure of sensitive information.

7.5
2023-04-05 CVE-2023-1733 Gitlab Unspecified vulnerability in Gitlab

A denial of service condition exists in the Prometheus server bundled with GitLab affecting all versions from 11.10 to 15.8.5, 15.9 to 15.9.4 and 15.10 to 15.10.1.

7.5
2023-04-05 CVE-2023-28342 Zohocorp Unspecified vulnerability in Zohocorp Manageengine Adselfservice Plus

Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.

7.5
2023-04-05 CVE-2023-20051 Cisco Unspecified vulnerability in Cisco Packet Data Network Gateway 21.26.0/21.27.0

A vulnerability in the Vector Packet Processor (VPP) of Cisco Packet Data Network Gateway (PGW) could allow an unauthenticated, remote attacker to stop ICMP traffic from being processed over an IPsec connection.

7.5
2023-04-05 CVE-2023-1858 Earnings AND Expense Tracker APP Project Unspecified vulnerability in Earnings and Expense Tracker APP Project Earnings and Expense Tracker APP 1.0

A vulnerability was found in SourceCodester Earnings and Expense Tracker App 1.0.

7.5
2023-04-04 CVE-2023-27496 Envoyproxy Unspecified vulnerability in Envoyproxy Envoy

Envoy is an open source edge and service proxy designed for cloud-native applications.

7.5
2023-04-04 CVE-2020-23257 Espruino Classic Buffer Overflow vulnerability in Espruino 2.05.41

Buffer Overflow vulnerability found in Espruino 2v05.41 allows an attacker to cause a denial of service via the function jsvGarbageCollectMarkUsed in file src/jsvar.c.

7.5
2023-04-04 CVE-2020-23258 Jsish Out-of-bounds Write vulnerability in Jsish 3.0.11

An issue found in Jsish v.3.0.11 allows a remote attacker to cause a denial of service via the Jsi_ValueIsNumber function in ./src/jsiValue.c file.

7.5
2023-04-04 CVE-2020-23259 Jsish NULL Pointer Dereference vulnerability in Jsish

An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the Jsi_Strlen function in the src/jsiChar.c file.

7.5
2023-04-04 CVE-2020-23260 Jsish Out-of-bounds Write vulnerability in Jsish

An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the StringReplaceCmd function in the src/jsiChar.c file.

7.5
2023-04-04 CVE-2022-48221 Gbgplc Race Condition vulnerability in Gbgplc Acuant Acufill SDK

An issue was discovered in Acuant AcuFill SDK before 10.22.02.03.

7.5
2023-04-04 CVE-2023-26855 Churchcrm Use of Insufficiently Random Values vulnerability in Churchcrm 4.5.3

The hashing algorithm of ChurchCRM v4.5.3 utilizes a non-random salt value which allows attackers to use precomputed hash tables or dictionary attacks to crack the hashed passwords.

7.5
2023-04-04 CVE-2023-26976 Tenda Out-of-bounds Write vulnerability in Tenda AC6 Firmware 15.03.05.09

Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.

7.5
2023-04-03 CVE-2023-29218 Twitter Unspecified vulnerability in Twitter Recommendation Algorithm 20230331

The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputation score) by arranging for multiple Twitter accounts to coordinate negative signals regarding a target account, such as unfollowing, muting, blocking, and reporting, as exploited in the wild in March and April 2023.

7.5
2023-04-03 CVE-2022-36440 Frrouting
Fedoraproject
Debian
Reachable Assertion vulnerability in multiple products

A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function.

7.5
2023-04-03 CVE-2023-28625 Openidc Unspecified vulnerability in Openidc MOD Auth Openidc

mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality.

7.5
2023-04-04 CVE-2022-48224 Gbgplc Uncontrolled Search Path Element vulnerability in Gbgplc Acuant Acufill SDK

An issue was discovered in Acuant AcuFill SDK before 10.22.02.03.

7.3
2023-04-04 CVE-2022-48225 Gbgplc Uncontrolled Search Path Element vulnerability in Gbgplc Acuant Acufill SDK

An issue was discovered in Acuant AcuFill SDK before 10.22.02.03.

7.3
2023-04-05 CVE-2023-0670 Ulearn Project Unrestricted Upload of File with Dangerous Type vulnerability in Ulearn Project Ulearn

Ulearn version a5a7ca20de859051ea0470542844980a66dfc05d allows an attacker with administrator permissions to obtain remote code execution on the server through the image upload functionality.

7.2
2023-04-05 CVE-2023-20103 Cisco Improper Input Validation vulnerability in Cisco Secure Network Analytics 2.1.1/7.4.1

A vulnerability in Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbitrary code as a root user on an affected device.

7.2
2023-04-05 CVE-2023-20117 Cisco OS Command Injection vulnerability in Cisco Rv320 Firmware and Rv325 Firmware

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device.

7.2
2023-04-05 CVE-2023-20124 Cisco Command Injection vulnerability in Cisco products

A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device.

7.2
2023-04-05 CVE-2023-20128 Cisco OS Command Injection vulnerability in Cisco Rv320 Firmware and Rv325 Firmware

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device.

7.2
2023-04-05 CVE-2023-26856 Dynamic Transaction Queuing System Project SQL Injection vulnerability in Dynamic Transaction Queuing System Project Dynamic Transaction Queuing System 1.0

Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/ajax.php?action=login.

7.2
2023-04-05 CVE-2023-26857 Dynamic Transaction Queuing System Project Unrestricted Upload of File with Dangerous Type vulnerability in Dynamic Transaction Queuing System Project Dynamic Transaction Queuing System 1.0

An arbitrary file upload vulnerability in /admin/ajax.php?action=save_uploads of Dynamic Transaction Queuing System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

7.2
2023-04-04 CVE-2023-27091 Teacms Project Improper Authentication vulnerability in Teacms Project Teacms 2.3.3

An unauthorized access issue found in XiaoBingby TeaCMS 2.3.3 allows attackers to escalate privileges via the id and keywords parameter(s).

7.2
2023-04-04 CVE-2021-3267 Kitesky Unrestricted Upload of File with Dangerous Type vulnerability in Kitesky Kitecms 1.1

File Upload vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the uploadFile function.

7.2
2023-04-04 CVE-2022-4934 Sophos Command Injection vulnerability in Sophos web Appliance

A post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to execute arbitrary code.

7.2
2023-04-03 CVE-2022-43769 Hitachi Code Injection vulnerability in Hitachi Vantara Pentaho Business Analytics Server 9.4.0.0

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream. 

7.2
2023-04-03 CVE-2023-1124 Wpeasycart Unspecified vulnerability in Wpeasycart WP Easycart

The Shopping Cart & eCommerce Store WordPress plugin before 5.4.3 does not validate HTTP requests, allowing authenticated users with admin privileges to perform LFI attacks.

7.2
2023-04-07 CVE-2023-27876 IBM Unspecified vulnerability in IBM Tririga Application Platform 4.0

IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data.

7.1
2023-04-06 CVE-2023-28046 Dell Unspecified vulnerability in Dell Display Manager 2.0.0/2.1.0

Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder deletion vulnerability during uninstallation A local low privilege attacker could potentially exploit this vulnerability, leading to the deletion of arbitrary files on the operating system with high privileges.

7.1
2023-04-05 CVE-2023-1838 Linux
Netapp
Use After Free vulnerability in multiple products

A use-after-free flaw was found in vhost_net_set_backend in drivers/vhost/net.c in virtio network subcomponent in the Linux kernel due to a double fget.

7.1
2023-04-04 CVE-2023-1750 Getnexx Authorization Bypass Through User-Controlled Key vulnerability in Getnexx products

The listed versions of Nexx Smart Home devices lack proper access control when executing actions.

7.1
2023-04-04 CVE-2023-25303 Atlauncher Path Traversal vulnerability in Atlauncher

ATLauncher <= 3.4.26.0 is vulnerable to Directory Traversal.

7.1
2023-04-04 CVE-2023-25305 Polymc Path Traversal vulnerability in Polymc

PolyMC Launcher <= 1.4.3 is vulnerable to Directory Traversal.

7.1

306 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2023-04-05 CVE-2023-29389 Toyota Injection vulnerability in Toyota Rav4 Firmware 2021

Toyota RAV4 2021 vehicles automatically trust messages from other ECUs on a CAN bus, which allows physically proximate attackers to drive a vehicle by accessing the control CAN bus after pulling the bumper away and reaching the headlight connector, and then sending forged "Key is validated" messages via CAN Injection, as exploited in the wild in (for example) July 2022.

6.8
2023-04-04 CVE-2023-28841 Mobyproject Unspecified vulnerability in Mobyproject Moby

Moby is an open source container framework developed by Docker Inc.

6.8
2023-04-04 CVE-2023-28842 Mobyproject Unspecified vulnerability in Mobyproject Moby

Moby) is an open source container framework developed by Docker Inc.

6.8
2023-04-06 CVE-2022-32599 Google Out-of-bounds Write vulnerability in Google Android

In rpmb, there is a possible out of bounds write due to a logic error.

6.7
2023-04-06 CVE-2023-20652 Google Out-of-bounds Write vulnerability in Google Android

In keyinstall, there is a possible out of bounds write due to a missing bounds check.

6.7
2023-04-06 CVE-2023-20653 Google Out-of-bounds Write vulnerability in Google Android

In keyinstall, there is a possible out of bounds write due to a missing bounds check.

6.7
2023-04-06 CVE-2023-20654 Google Out-of-bounds Write vulnerability in Google Android

In keyinstall, there is a possible out of bounds write due to a missing bounds check.

6.7
2023-04-06 CVE-2023-20656 Google Out-of-bounds Write vulnerability in Google Android

In geniezone, there is a possible out of bounds write due to a logic error.

6.7
2023-04-06 CVE-2023-20657 Google Out-of-bounds Write vulnerability in Google Android

In mtee, there is a possible out of bounds write due to a missing bounds check.

6.7
2023-04-06 CVE-2023-20658 Google Out-of-bounds Write vulnerability in Google Android 12.0/13.0

In isp, there is a possible out of bounds write due to a missing bounds check.

6.7
2023-04-06 CVE-2023-20659 Google
Yoctoproject
Linux
Out-of-bounds Write vulnerability in multiple products

In wlan, there is a possible out of bounds write due to a missing bounds check.

6.7
2023-04-06 CVE-2023-20661 Google
Yoctoproject
Linux
Integer Overflow or Wraparound vulnerability in multiple products

In wlan, there is a possible out of bounds write due to an integer overflow.

6.7
2023-04-06 CVE-2023-20662 Google
Yoctoproject
Linux
Integer Overflow or Wraparound vulnerability in multiple products

In wlan, there is a possible out of bounds write due to an integer overflow.

6.7
2023-04-06 CVE-2023-20663 Google
Yoctoproject
Linux
Integer Overflow or Wraparound vulnerability in multiple products

In wlan, there is a possible out of bounds write due to an integer overflow.

6.7
2023-04-06 CVE-2023-20664 Google Use After Free vulnerability in Google Android

In gz, there is a possible double free due to a use after free.

6.7
2023-04-06 CVE-2023-20666 Google Out-of-bounds Write vulnerability in Google Android 12.0/13.0

In display drm, there is a possible out of bounds write due to a missing bounds check.

6.7
2023-04-06 CVE-2023-20670 Google Out-of-bounds Write vulnerability in Google Android 12.0/13.0

In audio, there is a possible out of bounds write due to a missing bounds check.

6.7
2023-04-06 CVE-2023-20680 Google Unspecified vulnerability in Google Android 11.0/12.0/13.0

In adsp, there is a possible out of bounds write due to improper input validation.

6.7
2023-04-06 CVE-2023-20681 Google Out-of-bounds Write vulnerability in Google Android 12.0/13.0

In adsp, there is a possible out of bounds write due to improper input validation.

6.7
2023-04-06 CVE-2023-20682 Google
Yoctoproject
Linux
Integer Overflow or Wraparound vulnerability in multiple products

In wlan, there is a possible out of bounds write due to an integer overflow.

6.7
2023-04-05 CVE-2023-20121 Cisco OS Command Injection vulnerability in Cisco Identity Services Engine and Prime Infrastructure

Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system.

6.7
2023-04-05 CVE-2023-20153 Cisco OS Command Injection vulnerability in Cisco Identity Services Engine 3.2

Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root.

6.7
2023-04-05 CVE-2023-20152 Cisco OS Command Injection vulnerability in Cisco Identity Services Engine 3.2

Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root.

6.7
2023-04-05 CVE-2023-20022 Cisco OS Command Injection vulnerability in Cisco Identity Services Engine 3.2

Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root.

6.7
2023-04-05 CVE-2023-20023 Cisco OS Command Injection vulnerability in Cisco Identity Services Engine 3.2

Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root.

6.7
2023-04-05 CVE-2023-20021 Cisco OS Command Injection vulnerability in Cisco Identity Services Engine 3.2

Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root.

6.7
2023-04-04 CVE-2022-48223 Gbgplc Uncontrolled Search Path Element vulnerability in Gbgplc Acuant Acufill SDK

An issue was discovered in Acuant AcuFill SDK before 10.22.02.03.

6.7
2023-04-08 CVE-2023-24626 GNU Unspecified vulnerability in GNU Screen

socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target process.

6.5
2023-04-07 CVE-2023-1801 Tcpdump Out-of-bounds Write vulnerability in Tcpdump 4.99.3

The SMB protocol decoder in tcpdump version 4.99.3 can perform an out-of-bounds write when decoding a crafted network packet.

6.5
2023-04-07 CVE-2023-1909 Phpgurukul Unspecified vulnerability in PHPgurukul BP Monitoring Management System 1.0

A vulnerability, which was classified as critical, was found in PHPGurukul BP Monitoring Management System 1.0.

6.5
2023-04-07 CVE-2022-43928 IBM Unspecified vulnerability in IBM DB2 Mirror for I 7.4/7.5

The IBM Toolbox for Java (Db2 Mirror for i 7.4 and 7.5) could allow a user to obtain sensitive information, caused by utilizing a Java string for processing.

6.5
2023-04-06 CVE-2023-29010 Budibase Unspecified vulnerability in Budibase

Budibase is a low code platform for creating internal tools, workflows, and admin panels.

6.5
2023-04-06 CVE-2023-29415 Bzip3 Project
Debian
An issue was discovered in libbzip3.a in bzip3 before 1.3.0.
6.5
2023-04-06 CVE-2023-29416 Bzip3 Project Out-of-bounds Write vulnerability in Bzip3 Project Bzip3

An issue was discovered in libbzip3.a in bzip3 before 1.3.0.

6.5
2023-04-06 CVE-2023-29417 Bzip3 Project Out-of-bounds Read vulnerability in Bzip3 Project Bzip3 1.2.2

An issue was discovered in libbzip3.a in bzip3 1.2.2.

6.5
2023-04-06 CVE-2023-29418 Bzip3 Project Out-of-bounds Read vulnerability in Bzip3 Project Bzip3

An issue was discovered in libbzip3.a in bzip3 before 1.2.3.

6.5
2023-04-06 CVE-2023-29419 Bzip3 Project Out-of-bounds Read vulnerability in Bzip3 Project Bzip3

An issue was discovered in libbzip3.a in bzip3 before 1.2.3.

6.5
2023-04-06 CVE-2023-29420 Bzip3 Project Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Bzip3 Project Bzip3

An issue was discovered in libbzip3.a in bzip3 before 1.2.3.

6.5
2023-04-05 CVE-2023-0959 Imaworldhealth Improper Privilege Management vulnerability in Imaworldhealth Bhima 1.27.0

Bhima version 1.27.0 allows a remote attacker to update the privileges of any account registered in the application via a malicious link sent to an administrator.

6.5
2023-04-05 CVE-2023-0967 Imaworldhealth Authorization Bypass Through User-Controlled Key vulnerability in Imaworldhealth Bhima 1.27.0

Bhima version 1.27.0 allows an attacker authenticated with normal user permissions to view sensitive data of other application users and data that should only be viewed by the administrator.

6.5
2023-04-05 CVE-2022-4940 Wclovers Unspecified vulnerability in Wclovers Wcfm Membership

The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks on various AJAX actions.

6.5
2023-04-05 CVE-2023-28855 Teclib Edition Improper Privilege Management vulnerability in Teclib-Edition Fields

Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms.

6.5
2023-04-05 CVE-2023-20127 Cisco Unspecified vulnerability in Cisco Prime Infrastructure

Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks.

6.5
2023-04-05 CVE-2023-20129 Cisco Path Traversal vulnerability in Cisco Prime Infrastructure

Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks.

6.5
2023-04-05 CVE-2023-20130 Cisco Cross-Site Request Forgery (CSRF) vulnerability in Cisco Prime Infrastructure

Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks.

6.5
2023-04-05 CVE-2023-20134 Cisco Unrestricted Upload of File with Dangerous Type vulnerability in Cisco Webex Meetings

Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack or upload arbitrary files as recordings.

6.5
2023-04-05 CVE-2023-1865 Plugin Unspecified vulnerability in Plugin Yourchannel 1.2.3

The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when resetting plugin settings via the yrc_nuke GET parameter in versions up to, and including, 1.2.3.

6.5
2023-04-05 CVE-2023-0382 M Files Resource Exhaustion vulnerability in M-Files Server

User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.

6.5
2023-04-04 CVE-2023-1813 Google
Fedoraproject
Debian
Inappropriate implementation in Extensions in Google Chrome prior to 112.0.5615.49 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page.
6.5
2023-04-04 CVE-2023-1814 Google
Fedoraproject
Debian
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass download checking via a crafted HTML page.
6.5
2023-04-04 CVE-2023-1816 Google
Fedoraproject
Debian
Incorrect security UI in Picture In Picture in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially perform navigation spoofing via a crafted HTML page.
6.5
2023-04-04 CVE-2023-1817 Google
Fedoraproject
Debian
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
6.5
2023-04-04 CVE-2023-1819 Google
Fedoraproject
Debian
Out-of-bounds Read vulnerability in multiple products

Out of bounds read in Accessibility in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

6.5
2023-04-04 CVE-2023-1821 Google
Fedoraproject
Debian
Inappropriate implementation in WebShare in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially hide the contents of the Omnibox (URL bar) via a crafted HTML page.
6.5
2023-04-04 CVE-2023-1822 Google
Fedoraproject
Debian
Incorrect security UI in Navigation in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
6.5
2023-04-04 CVE-2023-1823 Google
Fedoraproject
Debian
Inappropriate implementation in FedCM in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
6.5
2023-04-04 CVE-2023-28853 Joinmastodon Unspecified vulnerability in Joinmastodon Mastodon

Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication.

6.5
2023-04-04 CVE-2023-27492 Envoyproxy Unspecified vulnerability in Envoyproxy Envoy

Envoy is an open source edge and service proxy designed for cloud-native applications.

6.5
2023-04-04 CVE-2023-1749 Getnexx Authorization Bypass Through User-Controlled Key vulnerability in Getnexx products

The listed versions of Nexx Smart Home devices lack proper access control when executing actions.

6.5
2023-04-04 CVE-2020-19850 Monospace Resource Exhaustion vulnerability in Monospace Directus 2.2.0

An issue found in Directus API v.2.2.0 allows a remote attacker to cause a denial of service via a great amount of HTTP requests.

6.5
2023-04-04 CVE-2023-28997 Nextcloud Unspecified vulnerability in Nextcloud Desktop

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server.

6.5
2023-04-04 CVE-2023-29000 Nextcloud Unspecified vulnerability in Nextcloud Desktop

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server.

6.5
2023-04-04 CVE-2023-25942 Dell Unspecified vulnerability in Dell EMC Powerscale Onefs

Dell PowerScale OneFS versions 8.2.x-9.4.x contain an uncontrolled resource consumption vulnerability.

6.5
2023-04-03 CVE-2023-0614 Samba Cleartext Storage of Sensitive Information vulnerability in Samba

The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD DC.

6.5
2023-04-03 CVE-2022-43771 Hitachi Path Traversal vulnerability in Hitachi Vantara Pentaho Business Analytics Server

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x, using the Pentaho Data Access plugin exposes a service endpoint for CSV import which allows a user supplied path to access resources that are out of bounds.

6.5
2023-04-03 CVE-2022-43772 Hitachi Information Exposure Through Log Files vulnerability in Hitachi Vantara Pentaho Business Analytics Server

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Data Plugin expose the username and password of clusters in clear text into system logs. 

6.5
2023-04-03 CVE-2022-43941 Hitachi XXE vulnerability in Hitachi Vantara Pentaho Business Analytics Server 9.4.0.0

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis service endpoint of the data access plugin against out-of-band XML External Entity Reference. 

6.5
2023-04-03 CVE-2023-0977 Trellix Out-of-bounds Write vulnerability in Trellix Agent 5.7.7/5.7.8

A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote user to alter the page heap in the macmnsvc process memory block resulting in the service becoming unavailable.

6.5
2023-04-03 CVE-2023-1330 Inisev Unspecified vulnerability in Inisev Redirection

The Redirection WordPress plugin before 1.1.4 does not add nonce verification in place when adding the redirect, which could allow attackers to add redirects via a CSRF attack.

6.5
2023-04-06 CVE-2023-20684 Google Race Condition vulnerability in Google Android 12.0/13.0

In vdec, there is a possible use after free due to a race condition.

6.4
2023-04-06 CVE-2023-20685 Google Race Condition vulnerability in Google Android 12.0/13.0

In vdec, there is a possible use after free due to a race condition.

6.4
2023-04-06 CVE-2023-20686 Google Race Condition vulnerability in Google Android 12.0/13.0

In display drm, there is a possible double free due to a race condition.

6.4
2023-04-06 CVE-2023-20687 Google Race Condition vulnerability in Google Android 12.0/13.0

In display drm, there is a possible double free due to a race condition.

6.4
2023-04-04 CVE-2023-28999 Nextcloud Missing Encryption of Sensitive Data vulnerability in Nextcloud Desktop

Nextcloud is an open-source productivity platform.

6.4
2023-04-05 CVE-2023-1855 Linux
Debian
Use After Free vulnerability in multiple products

A use-after-free flaw was found in xgene_hwmon_remove in drivers/hwmon/xgene-hwmon.c in the Hardware Monitoring Linux Kernel Driver (xgene-hwmon).

6.3
2023-04-03 CVE-2023-1611 Fedoraproject
Linux
Use After Free vulnerability in multiple products

A use-after-free flaw was found in btrfs_search_slot in fs/btrfs/ctree.c in btrfs in the Linux Kernel.This flaw allows an attacker to crash the system and possibly cause a kernel information lea

6.3
2023-04-03 CVE-2022-3960 Hitachi Code Injection vulnerability in Hitachi Vantara Pentaho Business Analytics Server 9.4.0.0

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of the Community Dashboard Editor (CDE) plugin. 

6.3
2023-04-09 CVE-2014-125095 Bestwebsoft Unspecified vulnerability in Bestwebsoft Contact Form 1.3.4

A vulnerability was found in BestWebSoft Contact Form Plugin 1.3.4 on WordPress and classified as problematic.

6.1
2023-04-08 CVE-2023-1961 Oretnom23 Unspecified vulnerability in Oretnom23 Online Computer and Laptop Store 1.0

A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0.

6.1
2023-04-08 CVE-2015-10098 Wpmudev Unspecified vulnerability in Wpmudev Broken Link Checker

A vulnerability was found in Broken Link Checker Plugin up to 1.10.5 on WordPress.

6.1
2023-04-08 CVE-2023-1948 Phpgurukul Unspecified vulnerability in PHPgurukul BP Monitoring Management System 1.0

A vulnerability, which was classified as problematic, has been found in PHPGurukul BP Monitoring Management System 1.0.

6.1
2023-04-07 CVE-2023-1946 Survey Application System Project Unspecified vulnerability in Survey Application System Project Survey Application System 1.0

A vulnerability was found in SourceCodester Survey Application System 1.0 and classified as problematic.

6.1
2023-04-07 CVE-2023-28781 Cimatti Unspecified vulnerability in Cimatti Wordpress Contact Forms

Unauth.

6.1
2023-04-07 CVE-2023-28789 Cimatti Unspecified vulnerability in Cimatti Wordpress Contact Forms

Unauth.

6.1
2023-04-07 CVE-2023-28792 I13Websolution Unspecified vulnerability in I13Websolution Continuous Image Carosel With Lightbox

Unauth.

6.1
2023-04-07 CVE-2023-29171 Magic Post Thumbnail Unspecified vulnerability in Magic-Post-Thumbnail Magic Post Thumbnail

Unauth.

6.1
2023-04-07 CVE-2023-29172 WP Property Hive Unspecified vulnerability in Wp-Property-Hive Propertyhive

Unauth.

6.1
2023-04-07 CVE-2023-29388 Implecode Unspecified vulnerability in Implecode Product Catalog Simple

Unauth.

6.1
2023-04-07 CVE-2023-25711 Wpglobus Unspecified vulnerability in Wpglobus Translate Options

Unauth.

6.1
2023-04-07 CVE-2023-25713 Fullworksplugins Unspecified vulnerability in Fullworksplugins Quick Paypal Payments

Unauth.

6.1
2023-04-07 CVE-2023-25020 Kibokolabs Unspecified vulnerability in Kibokolabs Arigato Autoresponder and Newsletter

Unauth.

6.1
2023-04-07 CVE-2023-25041 Cththemes Unspecified vulnerability in Cththemes Monolit

Unauth.

6.1
2023-04-07 CVE-2023-28993 Albo Pretorio ON Line Project Unspecified vulnerability in Albo Pretorio on Line Project Albo Pretorio on Line

Unauth.  Reflected Cross-Site Scripting (XSS) vulnerability in Ignazio Scimone Albo Pretorio On Line plugin <= 4.6.1 versions.

6.1
2023-04-07 CVE-2023-29236 Cththemes Unspecified vulnerability in Cththemes Outdoor

Unauth.

6.1
2023-04-06 CVE-2014-125094 Phpminiadmin Project Unspecified vulnerability in PHPminiadmin Project PHPminiadmin 1.7.110429/1.7.111025/1.8.120510

A vulnerability classified as problematic was found in phpMiniAdmin up to 1.8.120510.

6.1
2023-04-06 CVE-2023-29014 Intranda Unspecified vulnerability in Intranda Goobi Viewer Core

The Goobi viewer is a web application that allows digitised material to be displayed in a web browser.

6.1
2023-04-06 CVE-2023-29015 Intranda Unspecified vulnerability in Intranda Goobi Viewer Core

The Goobi viewer is a web application that allows digitised material to be displayed in a web browser.

6.1
2023-04-06 CVE-2023-29016 Intranda Unspecified vulnerability in Intranda Goobi Viewer Core

The Goobi viewer is a web application that allows digitised material to be displayed in a web browser.

6.1
2023-04-06 CVE-2023-1912 Limit Login Attempts Project Unspecified vulnerability in Limit Login Attempts Project Limit Login Attempts

The Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lock logging feature in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping.

6.1
2023-04-06 CVE-2023-22985 Simple Guestbook Management System Project Cross-site Scripting vulnerability in Simple Guestbook Management System Project Simple Guestbook Management System 1.0

Sourcecodester Simple Guestbook Management System version 1 is vulnerable to Cross Site Scripting (XSS) via Name, Referrer, Location, and Comments.

6.1
2023-04-06 CVE-2023-23979 Fullworksplugins Unspecified vulnerability in Fullworksplugins Quick Event Manager

Unauth.

6.1
2023-04-05 CVE-2022-31889 Enhancesoft Cross-site Scripting vulnerability in Enhancesoft Audit LOG

Cross Site Scripting (XSS) vulnerability in audit/templates/auditlogs.tmpl.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae.

6.1
2023-04-05 CVE-2022-3513 Gitlab Cross-site Scripting vulnerability in Gitlab

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1.

6.1
2023-04-05 CVE-2023-0523 Gitlab Cross-site Scripting vulnerability in Gitlab

An issue has been discovered in GitLab affecting all versions starting from 15.6 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1.

6.1
2023-04-05 CVE-2023-20137 Cisco Cross-site Scripting vulnerability in Cisco products

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.

6.1
2023-04-05 CVE-2023-20138 Cisco Cross-site Scripting vulnerability in Cisco products

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.

6.1
2023-04-05 CVE-2023-20139 Cisco Cross-site Scripting vulnerability in Cisco products

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.

6.1
2023-04-05 CVE-2023-20140 Cisco Cross-site Scripting vulnerability in Cisco products

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.

6.1
2023-04-05 CVE-2023-20141 Cisco Cross-site Scripting vulnerability in Cisco products

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.

6.1
2023-04-05 CVE-2023-20142 Cisco Cross-site Scripting vulnerability in Cisco products

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.

6.1
2023-04-05 CVE-2023-20143 Cisco Cross-site Scripting vulnerability in Cisco products

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.

6.1
2023-04-05 CVE-2023-20144 Cisco Cross-site Scripting vulnerability in Cisco products

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.

6.1
2023-04-05 CVE-2023-20145 Cisco Cross-site Scripting vulnerability in Cisco products

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.

6.1
2023-04-05 CVE-2023-20146 Cisco Cross-site Scripting vulnerability in Cisco products

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.

6.1
2023-04-05 CVE-2023-20147 Cisco Cross-site Scripting vulnerability in Cisco products

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.

6.1
2023-04-05 CVE-2023-20148 Cisco Cross-site Scripting vulnerability in Cisco products

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.

6.1
2023-04-05 CVE-2023-20149 Cisco Cross-site Scripting vulnerability in Cisco products

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.

6.1
2023-04-05 CVE-2023-20150 Cisco Cross-site Scripting vulnerability in Cisco products

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.

6.1
2023-04-05 CVE-2023-20151 Cisco Cross-site Scripting vulnerability in Cisco products

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.

6.1
2023-04-05 CVE-2023-28639 Glpi Project Unspecified vulnerability in Glpi-Project Glpi

GLPI is a free asset and IT management software package.

6.1
2023-04-05 CVE-2023-1880 Phpmyfaq Unspecified vulnerability in PHPmyfaq

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

6.1
2023-04-05 CVE-2023-1884 Phpmyfaq Unspecified vulnerability in PHPmyfaq

Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

6.1
2023-04-05 CVE-2023-20068 Cisco Cross-site Scripting vulnerability in Cisco Prime Infrastructure

A vulnerability in the web-based management interface of Cisco Prime Infrastructure Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface on an affected device.

6.1
2023-04-05 CVE-2023-26789 Veritas Cross-site Scripting vulnerability in Veritas Netbackup Opscenter 9.1.0.1

Veritas NetBackUp OpsCenter Version 9.1.0.1 is vulnerable to Reflected Cross-site scripting (XSS).

6.1
2023-04-05 CVE-2013-10022 Bestwebsoft Unspecified vulnerability in Bestwebsoft Contact Form 3.51

A vulnerability, which was classified as problematic, has been found in BestWebSoft Contact Form Plugin 3.51 on WordPress.

6.1
2023-04-05 CVE-2023-1860 Keysight Unspecified vulnerability in Keysight Hawkeye 3.3.16.28

A vulnerability was found in Keysight IXIA Hawkeye 3.3.16.28.

6.1
2023-04-05 CVE-2023-1851 Online Payroll System Project Unspecified vulnerability in Online Payroll System Project Online Payroll System 1.0

A vulnerability classified as problematic has been found in SourceCodester Online Payroll System 1.0.

6.1
2023-04-05 CVE-2023-1852 Online Payroll System Project Unspecified vulnerability in Online Payroll System Project Online Payroll System 1.0

A vulnerability classified as problematic was found in SourceCodester Online Payroll System 1.0.

6.1
2023-04-05 CVE-2023-1853 Online Payroll System Project Unspecified vulnerability in Online Payroll System Project Online Payroll System 1.0

A vulnerability, which was classified as problematic, has been found in SourceCodester Online Payroll System 1.0.

6.1
2023-04-05 CVE-2023-1857 Oretnom23 Unspecified vulnerability in Oretnom23 Online Computer and Laptop Store 1.0

A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0 and classified as problematic.

6.1
2023-04-04 CVE-2023-0357 Helpy IO Cross-site Scripting vulnerability in Helpy.Io Helpy 2.8.0

Helpy version 2.8.0 allows an unauthenticated remote attacker to exploit an XSS stored in the application.

6.1
2023-04-04 CVE-2023-0486 Vitalpbx Cross-site Scripting vulnerability in Vitalpbx 3.2.3

VitalPBX version 3.2.3-8 allows an unauthenticated external attacker to obtain the instance's administrator account via a malicious link.

6.1
2023-04-04 CVE-2023-0738 Orangescrum Cross-site Scripting vulnerability in Orangescrum 2.0.11

OrangeScrum version 2.0.11 allows an external attacker to obtain arbitrary user accounts from the application.

6.1
2023-04-04 CVE-2023-0325 Uvdesk Cross-site Scripting vulnerability in Uvdesk Community-Skeleton 1.1.1

Uvdesk version 1.1.1 allows an unauthenticated remote attacker to exploit a stored XSS in the application.

6.1
2023-04-04 CVE-2020-19697 Ipandao Cross-site Scripting vulnerability in Ipandao Editor.Md 1.5.0

Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script in the <iframe>src parameter.

6.1
2023-04-04 CVE-2020-19698 Ipandao Cross-site Scripting vulnerability in Ipandao Editor.Md 1.5.0

Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the editor parameter.

6.1
2023-04-04 CVE-2020-19699 Kiftd Project Cross-site Scripting vulnerability in Kiftd Project Kiftd 1.0.18

Cross Site Scripting vulnerability found in KOHGYLW Kiftd v.1.0.18 allows a remote attacker to execute arbitrary code via the <ifram> tag in the upload file page.

6.1
2023-04-04 CVE-2020-20521 Kitesky Cross-site Scripting vulnerability in Kitesky Kitecms 1.1.1

Cross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the comment parameter.

6.1
2023-04-04 CVE-2020-20522 Kitesky Cross-site Scripting vulnerability in Kitesky Kitecms 1.1

Cross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the registering user parameter.

6.1
2023-04-04 CVE-2020-22533 Easycorp Cross-site Scripting vulnerability in Easycorp Zentao

Cross Site Scripting vulnerability found in Zentao allows a remote attacker to execute arbitrary code via the lang parameter

6.1
2023-04-04 CVE-2020-23327 Zblogcn Cross-site Scripting vulnerability in Zblogcn Zblogphp 1.0

Cross Site Scripting vulnerability found in ZblogCN ZblogPHP v.1.0 allows a local attacker to execute arbitrary code via a crafted payload in title parameter of the module management model.

6.1
2023-04-04 CVE-2023-26777 Uptime Kuma Project Cross-site Scripting vulnerability in Uptime Kuma Project Uptime Kuma 1.19.6

Cross Site Scripting vulnerability found in : louislam Uptime Kuma v.1.19.6 and before allows a remote attacker to execute arbitrary commands via the description, title, footer, and incident creation parameter of the status_page.js endpoint.

6.1
2023-04-04 CVE-2023-26776 Monitorr Cross-site Scripting vulnerability in Monitorr 1.7.6M

Cross Site Scripting vulnerability found in Monitorr v.1.7.6 allows a remote attacker to execute arbitrary code via the title parameter of the post_receiver-services.php file.

6.1
2023-04-04 CVE-2022-47870 RED Gate Cross-site Scripting vulnerability in Red-Gate SQL Monitor 12.1.31.893

A Cross Site Scripting (XSS) vulnerability in the web SQL monitor login page in Redgate SQL Monitor 12.1.31.893 allows remote attackers to inject arbitrary web Script or HTML via the returnUrl parameter.

6.1
2023-04-04 CVE-2023-28998 Nextcloud Unspecified vulnerability in Nextcloud Desktop

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server.

6.1
2023-04-03 CVE-2022-4771 Hitachi Cross-site Scripting vulnerability in Hitachi Vantara Pentaho Business Analytics Server 9.4.0.0

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow a malicious URL to inject content into the Pentaho User Console through session variables. 

6.1
2023-04-03 CVE-2023-1377 Solidres Unspecified vulnerability in Solidres

The Solidres WordPress plugin through 0.9.4 does not sanitise and escape numerous parameter before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

6.1
2023-04-03 CVE-2023-1766 Akbim Unspecified vulnerability in Akbim Panon

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Akbim Computer Panon allows Reflected XSS.This issue affects Panon: before 1.0.2.

6.1
2023-04-03 CVE-2022-27665 Progress Cross-site Scripting vulnerability in Progress WS FTP Server 8.6.0

Reflected XSS (via AngularJS sandbox escape expressions) exists in Progress Ipswitch WS_FTP Server 8.6.0.

6.1
2023-04-05 CVE-2023-20030 Cisco XXE vulnerability in Cisco Identity Services Engine

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information, conduct a server-side request forgery (SSRF) attack through an affected device, or negatively impact the responsiveness of the web-based management interface itself.

6.0
2023-04-03 CVE-2023-0922 Samba Cleartext Transmission of Sensitive Information vulnerability in Samba

The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-only connection.

5.9
2023-04-03 CVE-2023-26112 Configobj Project Unspecified vulnerability in Configobj Project Configobj

All versions of the package configobj are vulnerable to Regular Expression Denial of Service (ReDoS) via the validate function, using (.+?)\((.*)\). **Note:** This is only exploitable in the case of a developer, putting the offending value in a server side configuration file.

5.9
2023-04-07 CVE-2022-43309 Supermicro Incorrect Permission Assignment for Critical Resource vulnerability in Supermicro products

Supermicro X11SSL-CF HW Rev 1.01, BMC firmware v1.63 was discovered to contain insecure permissions.

5.5
2023-04-07 CVE-2020-11935 Canonical
Debian
It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method.
5.5
2023-04-06 CVE-2023-29465 Sagemath Unspecified vulnerability in Sagemath Flintqs 1.0

SageMath FlintQS 1.0 relies on pathnames under TMPDIR (typically world-writable), which (for example) allows a local user to overwrite files with the privileges of a different user (who is running FlintQS).

5.5
2023-04-04 CVE-2023-26974 Irfanview Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview 4.62

Irfanview v4.62 allows a user-mode write access violation via a crafted JPEG 2000 file starting at JPEG2000+0x0000000000001bf0.

5.5
2023-04-04 CVE-2022-48228 Gbgplc Information Exposure Through Log Files vulnerability in Gbgplc Acuant Asureid Sentinel

An issue was discovered in Acuant AsureID Sentinel before 5.2.149.

5.5
2023-04-04 CVE-2023-27734 EDB Debugger Project Unspecified vulnerability in Edb-Debugger Project Edb-Debugger 1.3.0

An issue found in Eteran edb-debugger v.1.3.0 allows a local attacker to causea denial of service via the collect_symbols function in plugins/BinaryInfo/symbols.cpp.

5.5
2023-04-07 CVE-2022-43914 IBM Unspecified vulnerability in IBM Tririga Application Platform

IBM TRIRIGA Application Platform 4.0 is vulnerable to cross-site scripting.

5.4
2023-04-07 CVE-2023-27620 Robogallery Unspecified vulnerability in Robogallery Robo Gallery

Auth.

5.4
2023-04-07 CVE-2023-23885 Fullworksplugins Unspecified vulnerability in Fullworksplugins Quick Contact Form

Auth.

5.4
2023-04-07 CVE-2023-25061 Kibokolabs Unspecified vulnerability in Kibokolabs Arigato Autoresponder and Newsletter

Auth.

5.4
2023-04-06 CVE-2023-23891 Oceanwp Unspecified vulnerability in Oceanwp Ocean Extra

Auth.

5.4
2023-04-06 CVE-2023-24374 Material Design Icons FOR Page Builders Project Unspecified vulnerability in Material Design Icons for Page Builders Project Material Design Icons for Page Builders

Auth.

5.4
2023-04-06 CVE-2023-24378 Codeat Unspecified vulnerability in Codeat Glossary

Auth.

5.4
2023-04-06 CVE-2023-23898 Creativethemes Unspecified vulnerability in Creativethemes Blocksy Companion

Auth.

5.4
2023-04-06 CVE-2023-24411 Bnecreative Cross-site Scripting vulnerability in Bnecreative BNE Testimonials

Auth.

5.4
2023-04-06 CVE-2023-24003 Timersys Unspecified vulnerability in Timersys WP Popups

Auth.

5.4
2023-04-06 CVE-2023-23815 Multi Column TAG MAP Project Unspecified vulnerability in Multi-Column TAG MAP Project Multi-Column TAG MAP

Auth.

5.4
2023-04-05 CVE-2023-24747 Jflyfox Cross-site Scripting vulnerability in Jflyfox Jfinal CMS 5.1

Jfinal CMS v5.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/dict/list.

5.4
2023-04-05 CVE-2023-20096 Cisco Cross-site Scripting vulnerability in Cisco Unified Contact Center Express

A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack.

5.4
2023-04-05 CVE-2023-28849 Glpi Project Unspecified vulnerability in Glpi-Project Glpi

GLPI is a free asset and IT management software package.

5.4
2023-04-05 CVE-2023-20131 Cisco Cross-site Scripting vulnerability in Cisco Prime Infrastructure

Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks.

5.4
2023-04-05 CVE-2023-20132 Cisco Cross-site Scripting vulnerability in Cisco Webex Meetings

Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack or upload arbitrary files as recordings.

5.4
2023-04-05 CVE-2023-1878 Phpmyfaq Unspecified vulnerability in PHPmyfaq

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

5.4
2023-04-05 CVE-2023-1879 Phpmyfaq Unspecified vulnerability in PHPmyfaq

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

5.4
2023-04-05 CVE-2023-1881 Microweber Unspecified vulnerability in Microweber

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.3.

5.4
2023-04-05 CVE-2023-1882 Phpmyfaq Cross-site Scripting vulnerability in PHPmyfaq

Cross-site Scripting (XSS) - DOM in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

5.4
2023-04-05 CVE-2023-1883 Phpmyfaq Unspecified vulnerability in PHPmyfaq

Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

5.4
2023-04-05 CVE-2023-1885 Phpmyfaq Unspecified vulnerability in PHPmyfaq

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

5.4
2023-04-05 CVE-2023-1757 Phpmyfaq Unspecified vulnerability in PHPmyfaq

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

5.4
2023-04-05 CVE-2023-1758 Phpmyfaq Unspecified vulnerability in PHPmyfaq

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

5.4
2023-04-05 CVE-2023-28633 Glpi Project Unspecified vulnerability in Glpi-Project Glpi

GLPI is a free asset and IT management software package.

5.4
2023-04-05 CVE-2023-1756 Phpmyfaq Unspecified vulnerability in PHPmyfaq

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

5.4
2023-04-05 CVE-2023-26536 Followmedarling Unspecified vulnerability in Followmedarling Spotify-Play-Button-For-Wordpress

Auth.

5.4
2023-04-05 CVE-2023-28069 Dell Unspecified vulnerability in Dell Streaming Data Platform

Dell Streaming Data Platform prior to 1.4 contains Open Redirect vulnerability.

5.4
2023-04-04 CVE-2020-19277 MM Wiki Project Cross-site Scripting vulnerability in Mm-Wiki Project Mm-Wiki 0.1.2

Cross Site Scripting vulnerability found in Phachon mm-wiki v.0.1.2 allows a remote attacker to execute arbitrary code via javascript code in the markdown editor.

5.4
2023-04-04 CVE-2023-28848 Nextcloud Unspecified vulnerability in Nextcloud User Oidc

user_oidc is the OIDC connect user backend for Nextcloud, an open source collaboration platform.

5.4
2023-04-04 CVE-2023-23977 Heateor Unspecified vulnerability in Heateor Social Comments

Auth.

5.4
2023-04-04 CVE-2023-23685 Radiustheme Unspecified vulnerability in Radiustheme Portfolio

Auth.

5.4
2023-04-04 CVE-2023-23686 Simple Staff List Project Unspecified vulnerability in Simple Staff List Project Simple Staff List

Auth.

5.4
2023-04-04 CVE-2023-23878 Flippercode Unspecified vulnerability in Flippercode WP Google MAP

Auth.

5.4
2023-04-04 CVE-2020-36692 Sophos Cross-site Scripting vulnerability in Sophos web Appliance

A reflected XSS via POST vulnerability in report scheduler of Sophos Web Appliance versions older than 4.3.10.4 allows execution of JavaScript code in the victim browser via a malicious form that must be manually submitted by the victim while logged in to SWA.

5.4
2023-04-03 CVE-2023-24724 SAS Cross-site Scripting vulnerability in SAS web Administration Interface 9.4

A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Console, due to insufficient validation and sanitization of data input into the user creation and editing form fields.

5.4
2023-04-03 CVE-2023-28850 Pimcore Unspecified vulnerability in Pimcore Perspective Editor

Pimcore Perspective Editor provides an editor for Pimcore that allows users to add/remove/edit custom views and perspectives.

5.4
2023-04-03 CVE-2023-28851 Bigfork Cross-site Scripting vulnerability in Bigfork Silverstripe Form Capture

Silverstripe Form Capture provides a method to capture simple silverstripe forms and an admin interface for users.

5.4
2023-04-03 CVE-2023-28836 Torchbox Unspecified vulnerability in Torchbox Wagtail

Wagtail is an open source content management system built on Django.

5.4
2023-04-03 CVE-2023-0399 Image Over Image FOR Wpbakery Page Builder Project Unspecified vulnerability in Image Over Image for Wpbakery Page Builder Project Image Over Image for Wpbakery Page Builder

The Image Over Image For WPBakery Page Builder WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

5.4
2023-04-07 CVE-2023-23761 Github Improper Authentication vulnerability in Github Enterprise Server

An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to modify other users' secret gists by authenticating through an SSH certificate authority.

5.3
2023-04-07 CVE-2023-23762 Github Incorrect Comparison vulnerability in Github Enterprise Server

An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff.

5.3
2023-04-05 CVE-2023-1167 Gitlab Missing Authorization vulnerability in Gitlab

Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to security reports in MR.

5.3
2023-04-05 CVE-2023-1710 Gitlab Unspecified vulnerability in Gitlab

A sensitive information disclosure vulnerability in GitLab affecting all versions from 15.0 prior to 15.8.5, 15.9 prior to 15.9.4 and 15.10 prior to 15.10.1 allows an attacker to view the count of internal notes for a given issue.

5.3
2023-04-05 CVE-2023-1787 Gitlab Unspecified vulnerability in Gitlab

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1.

5.3
2023-04-05 CVE-2023-0319 Gitlab Incorrect Authorization vulnerability in Gitlab

An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1, allowing to read environment names supposed to be restricted to project memebers only.

5.3
2023-04-05 CVE-2023-0842 Xml2Js Project Unspecified vulnerability in Xml2Js Project Xml2Js 0.4.23

xml2js version 0.4.23 allows an external attacker to edit or add new properties to an object.

5.3
2023-04-05 CVE-2023-1868 Plugin Unspecified vulnerability in Plugin Yourchannel 1.2.3

The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when clearing the plugin cache via the yrc_clear_cache GET parameter in versions up to, and including, 1.2.3.

5.3
2023-04-04 CVE-2023-1751 Getnexx Unspecified vulnerability in Getnexx products

The listed versions of Nexx Smart Home devices use a WebSocket server that does not validate if the bearer token in the Authorization header belongs to the device attempting to associate.

5.3
2023-04-04 CVE-2023-26437 Powerdns Unspecified vulnerability in Powerdns Recursor

Denial of service vulnerability in PowerDNS Recursor allows authoritative servers to be marked unavailable.This issue affects Recursor: through 4.6.5, through 4.7.4 , through 4.8.3.

5.3
2023-04-04 CVE-2023-1768 Tribe29
Checkmk
Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk 1.6.0 causes the symmetric encryption of agent data to fail silently and transmit the data in plaintext in certain configurations.
5.3
2023-04-03 CVE-2023-26916 Cesnet
Fedoraproject
NULL Pointer Dereference vulnerability in multiple products

libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lys_parse_mem at lys_parse_mem.c.

5.3
2023-04-07 CVE-2023-27801 H3C Out-of-bounds Write vulnerability in H3C Magic R100 Firmware V100R005

H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the DelDNSHnList interface at /goform/aspForm.

4.9
2023-04-07 CVE-2023-27802 H3C Out-of-bounds Write vulnerability in H3C Magic R100 Firmware V100R005

H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the EditvsList parameter at /goform/aspForm.

4.9
2023-04-07 CVE-2023-27803 H3C Out-of-bounds Write vulnerability in H3C Magic R100 Firmware V100R005

H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the EdittriggerList interface at /goform/aspForm.

4.9
2023-04-07 CVE-2023-27804 H3C Out-of-bounds Write vulnerability in H3C Magic R100 Firmware V100R005

H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the DelvsList interface at /goform/aspForm.

4.9
2023-04-07 CVE-2023-27805 H3C Out-of-bounds Write vulnerability in H3C Magic R100 Firmware V100R005

H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the EditSTList interface at /goform/aspForm.

4.9
2023-04-07 CVE-2023-27806 H3C Out-of-bounds Write vulnerability in H3C Magic R100 Firmware V100R005

H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the ipqos_lanip_dellist interface at /goform/aspForm.

4.9
2023-04-07 CVE-2023-27807 H3C Out-of-bounds Write vulnerability in H3C Magic R100 Firmware V100R005

H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the Delstlist interface at /goform/aspForm.

4.9
2023-04-07 CVE-2023-27808 H3C Out-of-bounds Write vulnerability in H3C Magic R100 Firmware V100R005

H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the DeltriggerList interface at /goform/aspForm.

4.9
2023-04-07 CVE-2023-27810 H3C Out-of-bounds Write vulnerability in H3C Magic R100 Firmware V100R005

H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the ipqos_lanip_editlist interface at /goform/aspForm.

4.9
2023-04-05 CVE-2023-1098 Gitlab Unspecified vulnerability in Gitlab

An information disclosure vulnerability has been discovered in GitLab EE/CE affecting all versions starting from 11.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 will allow an admin to leak password from repository mirror configuration.

4.9
2023-04-03 CVE-2023-28837 Torchbox Unspecified vulnerability in Torchbox Wagtail

Wagtail is an open source content management system built on Django.

4.9
2023-04-07 CVE-2023-29170 Piwebsolution Unspecified vulnerability in Piwebsolution Product Enquiry for Woocommerce 2.2.7

Auth.

4.8
2023-04-07 CVE-2023-23799 Easy Panorama Project Unspecified vulnerability in Easy Panorama Project Easy Panorama

Auth.

4.8
2023-04-07 CVE-2023-25442 Zeno Font Resizer Project Unspecified vulnerability in Zeno Font Resizer Project Zeno Font Resizer

Auth.

4.8
2023-04-07 CVE-2023-25464 Streamweasels Unspecified vulnerability in Streamweasels Twitch Player 2.0.9/2.1.0

Auth.

4.8
2023-04-07 CVE-2023-25702 Fullworksplugins Unspecified vulnerability in Fullworksplugins Quick Paypal Payments

Auth.

4.8
2023-04-07 CVE-2023-25705 Goprayer Unspecified vulnerability in Goprayer WP Prayer

Auth.

4.8
2023-04-07 CVE-2023-25712 WP Buddy Cross-site Scripting vulnerability in Wp-Buddy Google Analytics Opt-Out

Auth.

4.8
2023-04-07 CVE-2023-29094 Piwebsolution Unspecified vulnerability in Piwebsolution Product Page Shipping Calculator for Woocommerce

Auth.

4.8
2023-04-07 CVE-2023-23994 Auto Hide Admin BAR Project Unspecified vulnerability in Auto Hide Admin BAR Project Auto Hide Admin BAR

Auth.

4.8
2023-04-07 CVE-2023-25031 Kibokolabs Unspecified vulnerability in Kibokolabs Arigato Autoresponder and Newsletter

Auth.

4.8
2023-04-07 CVE-2023-25049 Implecode Unspecified vulnerability in Implecode Ecommerce Product Catalog

Auth.

4.8
2023-04-07 CVE-2023-25716 Announce From THE Dashboard Project Cross-site Scripting vulnerability in Announce From the Dashboard Project Announce From the Dashboard

Auth (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gqevu6bsiz Announce from the Dashboard plugin <= 1.5.1 versions.

4.8
2023-04-07 CVE-2023-25022 Kibokolabs Unspecified vulnerability in Kibokolabs Watu Quiz

Auth.

4.8
2023-04-07 CVE-2023-25023 Saleswonder Cross-site Scripting vulnerability in Saleswonder Webinar Ignition

Auth.

4.8
2023-04-07 CVE-2023-25024 Icegram Unspecified vulnerability in Icegram Collect

Auth.

4.8
2023-04-07 CVE-2023-25027 Kibokolabs Unspecified vulnerability in Kibokolabs Chained Quiz

Auth.

4.8
2023-04-07 CVE-2023-24398 Snapcreek Unspecified vulnerability in Snapcreek EZP Coming Soon Page 1.0.7.3

Auth.

4.8
2023-04-07 CVE-2023-25046 Podlove Unspecified vulnerability in Podlove Podcast Publisher

Auth.

4.8
2023-04-07 CVE-2023-24402 Wpbookingsystem Unspecified vulnerability in Wpbookingsystem WP Booking System

Auth.

4.8
2023-04-07 CVE-2023-25059 Avalex Unspecified vulnerability in Avalex

Auth.

4.8
2023-04-06 CVE-2023-1913 Webfactoryltd Unspecified vulnerability in Webfactoryltd Maps Widget for Google Maps

The Maps Widget for Google Maps for WordPress is vulnerable to Stored Cross-Site Scripting via widget settings in versions up to, and including, 4.24 due to insufficient input sanitization and output escaping.

4.8
2023-04-06 CVE-2023-24396 Vikwp Cross-site Scripting vulnerability in Vikwp Vikbooking Hotel Booking Engine & PMS

Auth.

4.8
2023-04-06 CVE-2023-25062 Pinpoint Unspecified vulnerability in Pinpoint Booking System

Auth.

4.8
2023-04-06 CVE-2023-24383 Kibokolabs Unspecified vulnerability in Kibokolabs Namaste! LMS

Auth.

4.8
2023-04-06 CVE-2023-24387 Wpdevart Unspecified vulnerability in Wpdevart Organization Chart

Auth.

4.8
2023-04-06 CVE-2023-24403 Wpforthewin Unspecified vulnerability in Wpforthewin Bbpress Voting

Auth.

4.8
2023-04-06 CVE-2023-24002 Wpdevart Unspecified vulnerability in Wpdevart Youtube Embed, Playlist and Popup

Auth.

4.8
2023-04-06 CVE-2023-24004 Wpdevart Unspecified vulnerability in Wpdevart Download Image and Video Lightbox, Image Popup

Auth.

4.8
2023-04-06 CVE-2023-23980 Mailoptin Unspecified vulnerability in Mailoptin

Auth.

4.8
2023-04-06 CVE-2023-23996 Properfraction Cross-site Scripting vulnerability in Properfraction Profilepress

Auth.

4.8
2023-04-06 CVE-2023-23998 E4Jconnect Unspecified vulnerability in E4Jconnect Vikrentcar

Auth.

4.8
2023-04-06 CVE-2023-24001 Modal Dialog Project Unspecified vulnerability in Modal Dialog Project Modal Dialog

Auth.

4.8
2023-04-06 CVE-2023-24006 Linksoftwarellc Unspecified vulnerability in Linksoftwarellc WP Terms Popup

Auth.

4.8
2023-04-06 CVE-2023-23971 Codepeople Unspecified vulnerability in Codepeople WP Time Slots Booking Form

Auth.

4.8
2023-04-06 CVE-2023-23972 Wpdevart Unspecified vulnerability in Wpdevart Social Like BOX and Page

Auth.

4.8
2023-04-06 CVE-2023-23987 Wpeverest Unspecified vulnerability in Wpeverest User Registration

Auth.

4.8
2023-04-06 CVE-2023-23981 Quantumcloud Unspecified vulnerability in Quantumcloud Conversational Forms for Chatbot

Auth.

4.8
2023-04-06 CVE-2023-23982 Wpfrom Email Project Unspecified vulnerability in Wpfrom Email Project Wpfrom Email

Auth.

4.8
2023-04-05 CVE-2023-28636 Glpi Project Unspecified vulnerability in Glpi-Project Glpi

GLPI is a free asset and IT management software package.

4.8
2023-04-05 CVE-2023-28852 Glpi Project Unspecified vulnerability in Glpi-Project Glpi

GLPI is a free asset and IT management software package.

4.8
2023-04-05 CVE-2023-1869 Plugin Cross-site Scripting vulnerability in Plugin Yourchannel 1.2.3

The YourChannel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping.

4.8
2023-04-04 CVE-2023-1840 Followmedarling Unspecified vulnerability in Followmedarling Spotify-Play-Button-For-Wordpress

The Sp*tify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.07 due to insufficient input sanitization and output escaping.

4.8
2023-04-04 CVE-2023-23870 Wpdevart Unspecified vulnerability in Wpdevart Responsive Vertical Icon Menu

Auth.

4.8
2023-04-04 CVE-2023-23821 Interactive Polish MAP Project Unspecified vulnerability in Interactive Polish MAP Project Interactive Polish MAP

Auth.

4.8
2023-04-03 CVE-2023-26529 Dupeoff Project Unspecified vulnerability in Dupeoff Project Dupeoff

Auth.

4.8
2023-04-05 CVE-2023-1582 Linux Race Condition vulnerability in Linux Kernel

A race problem was found in fs/proc/task_mmu.c in the memory management sub-component in the Linux kernel.

4.7
2023-04-05 CVE-2023-0450 Gitlab Unspecified vulnerability in Gitlab

An issue has been discovered in GitLab affecting all versions starting from 8.1 to 15.8.5, and from 15.9 to 15.9.4, and from 15.10 to 15.10.1.

4.6
2023-04-05 CVE-2023-20123 Cisco Authentication Bypass by Capture-replay vulnerability in Cisco DUO and DUO Authentication for Windows Logon and RDP

A vulnerability in the offline access mode of Cisco Duo Two-Factor Authentication for macOS and Duo Authentication for Windows Logon and RDP could allow an unauthenticated, physical attacker to replay valid user session credentials and gain unauthorized access to an affected macOS or Windows device.

4.6
2023-04-06 CVE-2023-20660 Google
Yoctoproject
Linux
Integer Overflow or Wraparound vulnerability in multiple products

In wlan, there is a possible out of bounds read due to an integer overflow.

4.4
2023-04-06 CVE-2023-20665 Google Out-of-bounds Read vulnerability in Google Android 12.0/13.0

In ril, there is a possible out of bounds read due to a missing bounds check.

4.4
2023-04-06 CVE-2023-20674 Google
Yoctoproject
Linux
Out-of-bounds Read vulnerability in multiple products

In wlan, there is a possible out of bounds read due to a missing bounds check.

4.4
2023-04-06 CVE-2023-20675 Google
Yoctoproject
Linux
Out-of-bounds Read vulnerability in multiple products

In wlan, there is a possible out of bounds read due to a missing bounds check.

4.4
2023-04-06 CVE-2023-20676 Google
Yoctoproject
Linux
Out-of-bounds Read vulnerability in multiple products

In wlan, there is a possible out of bounds read due to a missing bounds check.

4.4
2023-04-06 CVE-2023-20679 Google
Yoctoproject
Linux
Out-of-bounds Read vulnerability in multiple products

In wlan, there is a possible out of bounds read due to a missing bounds check.

4.4
2023-04-06 CVE-2023-20688 Google Out-of-bounds Read vulnerability in Google Android 11.0/12.0/13.0

In power, there is a possible out of bounds read due to a missing bounds check.

4.4
2023-04-06 CVE-2023-20677 Google
Yoctoproject
Linux
Out-of-bounds Read vulnerability in multiple products

In wlan, there is a possible out of bounds read due to a missing bounds check.

4.4
2023-04-08 CVE-2023-30450 Redpanda Unspecified vulnerability in Redpanda

rpk in Redpanda before 23.1.2 mishandles the redpanda.rpc_server_tls field, leading to (for example) situations in which there is a data type mismatch that cannot be automatically fixed by rpk, and instead a user must reconfigure (while a cluster is turned off) in order to have TLS on broker RPC ports.

4.3
2023-04-07 CVE-2023-1937 MY Blog Project Unspecified vulnerability in My-Blog Project My-Blog

A vulnerability, which was classified as problematic, was found in zhenfeng13 My-Blog.

4.3
2023-04-06 CVE-2023-1927 Wpfastestcache Unspecified vulnerability in Wpfastestcache WP Fastest Cache

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2.

4.3
2023-04-06 CVE-2023-1928 Wpfastestcache Unspecified vulnerability in Wpfastestcache WP Fastest Cache

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the wpfc_preload_single_callback function in versions up to, and including, 1.1.2.

4.3
2023-04-06 CVE-2023-1929 Wpfastestcache Unspecified vulnerability in Wpfastestcache WP Fastest Cache

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the wpfc_purgecache_varnish_callback function in versions up to, and including, 1.1.2.

4.3
2023-04-06 CVE-2023-1930 Wpfastestcache Unspecified vulnerability in Wpfastestcache WP Fastest Cache

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the wpfc_clear_cache_of_allsites_callback function in versions up to, and including, 1.1.2.

4.3
2023-04-06 CVE-2023-1931 Wpfastestcache Unspecified vulnerability in Wpfastestcache WP Fastest Cache

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the deleteCssAndJsCacheToolbar function in versions up to, and including, 1.1.2.

4.3
2023-04-06 CVE-2023-1918 Wpfastestcache Unspecified vulnerability in Wpfastestcache WP Fastest Cache

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2.

4.3
2023-04-06 CVE-2023-1919 Wpfastestcache Unspecified vulnerability in Wpfastestcache WP Fastest Cache

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2.

4.3
2023-04-06 CVE-2023-1920 Wpfastestcache Unspecified vulnerability in Wpfastestcache WP Fastest Cache

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2.

4.3
2023-04-06 CVE-2023-1921 Wpfastestcache Unspecified vulnerability in Wpfastestcache WP Fastest Cache

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2.

4.3
2023-04-06 CVE-2023-1922 Wpfastestcache Unspecified vulnerability in Wpfastestcache WP Fastest Cache

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2.

4.3
2023-04-06 CVE-2023-1923 Wpfastestcache Cross-Site Request Forgery (CSRF) vulnerability in Wpfastestcache WP Fastest Cache

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2.

4.3
2023-04-06 CVE-2023-1924 Wpfastestcache Unspecified vulnerability in Wpfastestcache WP Fastest Cache

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2.

4.3
2023-04-06 CVE-2023-1925 Wpfastestcache Unspecified vulnerability in Wpfastestcache WP Fastest Cache

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2.

4.3
2023-04-06 CVE-2023-1926 Wpfastestcache Unspecified vulnerability in Wpfastestcache WP Fastest Cache

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2.

4.3
2023-04-05 CVE-2023-1071 Gitlab Incorrect Authorization vulnerability in Gitlab

An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1.

4.3
2023-04-05 CVE-2023-1417 Gitlab Incorrect Authorization vulnerability in Gitlab

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1.

4.3
2023-04-05 CVE-2023-0944 Imaworldhealth Incorrect Permission Assignment for Critical Resource vulnerability in Imaworldhealth Bhima 1.27.0

Bhima version 1.27.0 allows an authenticated attacker with regular user permissions to update arbitrary user session data such as username, email and password.

4.3
2023-04-05 CVE-2023-1887 Phpmyfaq Unspecified vulnerability in PHPmyfaq

Business Logic Errors in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

4.3
2023-04-05 CVE-2023-1866 Plugin Unspecified vulnerability in Plugin Yourchannel 1.2.3

The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3.

4.3
2023-04-05 CVE-2023-1867 Plugin Unspecified vulnerability in Plugin Yourchannel 1.2.3

The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3.

4.3
2023-04-05 CVE-2023-1870 Plugin Unspecified vulnerability in Plugin Yourchannel 1.2.3

The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3.

4.3
2023-04-05 CVE-2023-1871 Plugin Unspecified vulnerability in Plugin Yourchannel 1.2.3

The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3.

4.3
2023-04-04 CVE-2023-1752 Getnexx Improper Authentication vulnerability in Getnexx products

The listed versions of Nexx Smart Home devices could allow any user to register an already registered alarm or associated device with only the device’s MAC address.

4.3
2023-04-03 CVE-2023-0225 Samba Incorrect Permission Assignment for Critical Resource vulnerability in Samba

A flaw was found in Samba.

4.3
2023-04-03 CVE-2022-4769 Hitachi Information Exposure Through an Error Message vulnerability in Hitachi Vantara Pentaho Business Analytics Server

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the target path on host when a file is uploaded with an invalid character in its name. 

4.3
2023-04-03 CVE-2022-4770 Hitachi Information Exposure Through an Error Message vulnerability in Hitachi Vantara Pentaho Business Analytics Server

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the full parametrized SQL query in an error message when an invalid character is used within a Pentaho Report (*.prpt). 

4.3
2023-04-03 CVE-2023-28834 Nextcloud Unspecified vulnerability in Nextcloud Server

Nextcloud Server is an open source personal cloud server.

4.3

5 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2023-04-05 CVE-2023-0838 Gitlab Unspecified vulnerability in Gitlab

An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1.

3.8
2023-04-05 CVE-2022-3375 Gitlab Unspecified vulnerability in Gitlab

An issue has been discovered in GitLab affecting all versions starting from 11.10 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1.

3.7
2023-04-06 CVE-2022-46781 ARM Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in ARM products

An issue was discovered in the Arm Mali GPU Kernel Driver.

3.3
2023-04-06 CVE-2023-26083 ARM Memory Leak vulnerability in ARM products

Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from r41p0 - r42p0 allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata.

3.3
2023-04-04 CVE-2022-48435 Jetbrains Unspecified vulnerability in Jetbrains PHPstorm 2021.3.1

In JetBrains PhpStorm before 2023.1 source code could be logged in the local idea.log file

3.3