Latest CVE Feed
-
9.8
CRITICALCVE-2023-23080
Certain Tenda products are vulnerable to command injection. This affects Tenda CP7 Tenda CP7<=V11.10.00.2211041403 and Tenda CP3 v.10 Tenda CP3 v.10<=V20220906024_2025 and Tenda IT7-PCS Tenda IT7-PCS<=V2209020914 and Tenda IT7-LCS Tenda IT7-LCS<=V22090209... Read more
Affected Products : it7-lcs_firmware it7-pcs_firmware it7-prs_firmware cp3_firmware cp7_firmware it7-lcs it7-pcs it7-prs cp3 cp7- EPSS Score: %8.02
- Published: Feb. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-23059
An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions within the default installation and allows attackers to execute arbitrary code and gain escalated privileges.... Read more
Affected Products : gv-edge_recording_manager- EPSS Score: %0.12
- Published: May. 04, 2023
- Modified: Jan. 29, 2025
-
9.8
CRITICALCVE-2023-22889
SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users.... Read more
Affected Products : zephyr_enterprise- EPSS Score: %2.98
- Published: Mar. 08, 2023
- Modified: Mar. 05, 2025
-
9.8
CRITICALCVE-2023-22855
Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution. It spawns a web interface listening on port 8088. A user-controllable path is handed to a path-concatenation method (Path.Combine from .NET) without proper sanitisation. This yields ... Read more
Affected Products : kardex_control_center- EPSS Score: %63.40
- Published: Feb. 15, 2023
- Modified: Mar. 19, 2025
-
9.8
CRITICALCVE-2023-22807
LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal XGT protocol. An attacker could control and tamper with the PLC by sending the packets to the PLC over its XGT protocol. ... Read more
- EPSS Score: %0.08
- Published: Feb. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-22900
Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify or delete database.... Read more
Affected Products : efence- EPSS Score: %0.28
- Published: Jan. 31, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-22884
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software Foundation Apache Airflow MySQL Provider.This issue affects Apache Airflow: before 2.5.1; Apach... Read more
- EPSS Score: %63.24
- Published: Jan. 21, 2023
- Modified: Mar. 31, 2025
-
9.8
CRITICALCVE-2023-22920
A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a factory default misconfiguration intended for testing purposes. A remote attacker could leverage this vulnerability to access an affected ... Read more
- EPSS Score: %0.73
- Published: Feb. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-22786
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Succes... Read more
- EPSS Score: %0.88
- Published: May. 08, 2023
- Modified: Jan. 31, 2025
-
9.8
CRITICALCVE-2023-22785
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Succes... Read more
- EPSS Score: %0.88
- Published: May. 08, 2023
- Modified: Jan. 31, 2025
-
9.8
CRITICALCVE-2023-22784
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Succes... Read more
- EPSS Score: %0.88
- Published: May. 08, 2023
- Modified: Jan. 31, 2025
-
9.8
CRITICALCVE-2023-22780
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Succes... Read more
- EPSS Score: %0.88
- Published: May. 08, 2023
- Modified: Jan. 29, 2025
-
9.8
CRITICALCVE-2023-22783
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Succes... Read more
- EPSS Score: %0.88
- Published: May. 08, 2023
- Modified: Jan. 31, 2025
-
9.8
CRITICALCVE-2023-22779
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Succes... Read more
- EPSS Score: %0.88
- Published: May. 08, 2023
- Modified: Jan. 29, 2025
-
9.8
CRITICALCVE-2023-22757
There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated remote code execution by sending specially crafted packets via the PAPI protocol. Successful exploitation of these vulnerabiliti... Read more
- EPSS Score: %2.19
- Published: Mar. 01, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2003-0791
The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.... Read more
- EPSS Score: %1.15
- Published: Oct. 07, 2003
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2023-22781
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Succes... Read more
- EPSS Score: %0.88
- Published: May. 08, 2023
- Modified: Jan. 31, 2025
-
9.8
CRITICALCVE-2023-22754
There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated remote code execution by sending specially crafted packets via the PAPI protocol. Successful exploitation of these vulnerabiliti... Read more
- EPSS Score: %2.19
- Published: Mar. 01, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-22749
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploita... Read more
- EPSS Score: %0.93
- Published: Mar. 01, 2023
- Modified: Mar. 07, 2025
-
9.8
CRITICALCVE-2023-22782
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Succes... Read more
- EPSS Score: %0.88
- Published: May. 08, 2023
- Modified: Jan. 31, 2025