Search Results (102074 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-41031 1 Juplink 2 Rx4-1500, Rx4-1500 Firmware 2024-11-21 8 High
Command injection in homemng.htm in Juplink RX4-1500 versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows remote authenticated attackers to execute commands via specially crafted requests to the vulnerable endpoint.
CVE-2023-41029 1 Juplink 2 Rx4-1500, Rx4-1500 Firmware 2024-11-21 8 High
Command injection vulnerability in the homemng.htm endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows authenticated remote attackers to execute commands as root via specially crafted HTTP requests to the vulnerable endpoint.
CVE-2023-41027 1 Juplink 2 Rx4-1500, Rx4-1500 Firmware 2024-11-21 8 High
Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 and V1.0.5 allows an authenticated attacker to leak the password for the administrative account via requests to the vulnerable endpoint.
CVE-2023-41005 1 Pagekit 1 Pagekit 2024-11-21 7.8 High
An issue in Pagekit pagekit v.1.0.18 alows a remote attacker to execute arbitrary code via thedownloadAction and updateAction functions in UpdateController.php
CVE-2023-40998 1 O-ran-sc 1 Ric Message Router 2024-11-21 7.5 High
Buffer Overflow vulnerability in O-RAN Software Community ric-plt-lib-rmr v.4.9.0 allows a remote attacker to cause a denial of service via the packet size component.
CVE-2023-40997 1 O-ran-sc 1 Ric Message Router 2024-11-21 7.5 High
Buffer Overflow vulnerability in O-RAN Software Community ric-plt-lib-rmr v.4.9.0 allows a remote attacker to cause a denial of service via a crafted packet.
CVE-2023-40970 1 Slims 1 Senayan Library Management System 2024-11-21 8.8 High
Senayan Library Management Systems SLIMS 9 Bulian v 9.6.1 is vulnerable to SQL Injection via admin/modules/circulation/loan_rules.php.
CVE-2023-40968 1 Hzeller 1 Timg 2024-11-21 7.5 High
Buffer Overflow vulnerability in hzeller timg v.1.5.1 and before allows a remote attacker to cause a denial of service via the 0x61200000045c address.
CVE-2023-40958 1 Didotech 1 Engineering \& Lifecycle Management 2024-11-21 8.8 High
A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the query parameter in models/base_client.py component.
CVE-2023-40957 1 Didotech 1 Engineering \& Lifecycle Management 2024-11-21 8.8 High
A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the request parameter in models/base_client.py component.
CVE-2023-40956 1 Cloudroits 1 Wesite Job Search 2024-11-21 8.8 High
A SQL injection vulnerability in Cloudroits Website Job Search v.15.0 allows a remote authenticated attacker to execute arbitrary code via the name parameter in controllers/main.py component.
CVE-2023-40955 1 Didotech 1 Engineering \& Lifecycle Management 2024-11-21 8.8 High
A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the select parameter in models/base_client.py component.
CVE-2023-40953 1 Idreamsoft 1 Icms 2024-11-21 8.8 High
icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF).
CVE-2023-40934 1 Nagios 1 Nagios Xi 2024-11-21 7.2 High
A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings.
CVE-2023-40933 1 Nagios 1 Nagios Xi 2024-11-21 8.8 High
A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function.
CVE-2023-40924 2 Contec, Solar View 3 Solarview Compact, Solarview Compact Firmware, Compact 2024-11-21 7.5 High
SolarView Compact < 6.00 is vulnerable to Directory Traversal.
CVE-2023-40918 1 Knowstreaming Project 1 Knowstreaming 2024-11-21 8.8 High
KnowStreaming 3.3.0 is vulnerable to Escalation of Privileges. Unauthorized users can create a new user with an admin role.
CVE-2023-40915 1 Tenda 2 Ax3, Ax3 Firmware 2024-11-21 7.5 High
Tenda AX3 v16.03.12.11 has a stack buffer overflow vulnerability detected at function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ssid parameter.
CVE-2023-40868 1 Moosocial 1 Moosocial 2024-11-21 8.8 High
Cross Site Request Forgery vulnerability in mooSocial MooSocial Software v.Demo allows a remote attacker to execute arbitrary code via the Delete Account and Deactivate functions.
CVE-2023-40857 1 Virustotal 1 Yara 2024-11-21 8.8 High
Buffer Overflow vulnerability in VirusTotal yara v.4.3.2 allows a remote attacker to execute arbtirary code via the yr_execute_cod function in the exe.c component.