Latest CVE Feed
-
9.8
CRITICALCVE-2023-21287
In multiple locations, there is a possible code execution due to type confusion. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. ... Read more
Affected Products : android- Published: Aug. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39659
An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted script to the PythonAstREPLTool._run component.... Read more
Affected Products : langchain- Published: Aug. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-38863
An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the ifname and mac parameters in the sub_410074 function at bin/webmgnt.... Read more
- Published: Aug. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4329
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard SESSIONID cookie with SameSite attribute... Read more
- Published: Aug. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4337
Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installation... Read more
Affected Products : raid_controller_web_interface- Published: Aug. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39670
Tenda AC6 _US_AC6V1.0BR_V15.03.05.16 was discovered to contain a buffer overflow via the function fgets.... Read more
- Published: Aug. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4448
A vulnerability was found in OpenRapid RapidCMS 1.3.1 and classified as critical. This issue affects some unknown processing of the file admin/run-movepass.php. The manipulation of the argument password/password2 leads to weak password recovery. The attac... Read more
Affected Products : rapidcms- Published: Aug. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39660
An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt function.... Read more
Affected Products : pandasai- Published: Aug. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-45611
An issue was discovered in Fresenius Kabi PharmaHelp 5.1.759.0 allows attackers to gain escalated privileges via via capture of user login information.... Read more
- Published: Aug. 22, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-40893
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter time at /goform/PowerSaveSet.... Read more
- Published: Aug. 24, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-40894
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetStaticRouteCfg.... Read more
- Published: Aug. 24, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-5982
SQL Injection exists in the Advertisement Board 3.1.0 component for Joomla! via a task=show_rss_categories&catname= request.... Read more
Affected Products : advertisement_board- Published: Feb. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-40895
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetVirtualServerCfg.... Read more
- Published: Aug. 24, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-40898
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter timeZone at /goform/SetSysTimeCfg.... Read more
- Published: Aug. 24, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-40904
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at /goform/setMacFilterCfg.... Read more
- Published: Aug. 24, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4420
A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK LMS5xx. This lack of encryption in the communication channel can lead to the unauthorized disclosur... Read more
- Published: Aug. 24, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6394
SQL Injection exists in the InviteX 3.0.5 component for Joomla! via the invite_type parameter in a view=invites action.... Read more
Affected Products : invitex- Published: Feb. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6584
SQL Injection exists in the DT Register 3.2.7 component for Joomla! via a task=edit&id= request.... Read more
Affected Products : dt_register- Published: Feb. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7179
SQL Injection exists in the SquadManagement 1.0.3 component for Joomla! via the id parameter.... Read more
Affected Products : squadmanagement- Published: Feb. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4545
A vulnerability was found in IBOS OA 4.5.5. It has been classified as critical. Affected is an unknown function of the file ?r=recruit/bgchecks/export&checkids=x. The manipulation leads to sql injection. It is possible to launch the attack remotely. The e... Read more
Affected Products : ibos- Published: Aug. 26, 2023
- Modified: Nov. 21, 2024