Search Results (347766 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-29170 1 Dell 1 Powerscale Onefs 2025-01-08 8.1 High
Dell PowerScale OneFS versions 8.2.x through 9.8.0.x contain a use of hard coded credentials vulnerability. An adjacent network unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure of network traffic and denial of service.
CVE-2024-28237 1 Octoprint 1 Octoprint 2025-01-08 4 Medium
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.9.3 contain a vulnerability that allows malicious admins to configure or talk a victim with administrator rights into configuring a webcam snapshot URL which when tested through the "Test" button included in the web interface will execute JavaScript code in the victims browser when attempting to render the snapshot image. An attacker who successfully talked a victim with admin rights into performing a snapshot test with such a crafted URL could use this to retrieve or modify sensitive configuration settings, interrupt prints or otherwise interact with the OctoPrint instance in a malicious way. The vulnerability is patched in version 1.10.0rc3. OctoPrint administrators are strongly advised to thoroughly vet who has admin access to their installation and what settings they modify based on instructions by strangers.
CVE-2023-46099 1 Siemens 1 Simatic Pcs Neo 2025-01-08 5.4 Medium
A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). There is a stored cross-site scripting vulnerability in the Administration Console of the affected product, that could allow an attacker with high privileges to inject Javascript code into the application that is later executed by another legitimate user.
CVE-2023-46601 1 Siemens 1 Comos 2025-01-08 9.6 Critical
A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in making the SQLServer connection. This could allow an attacker to query the database directly to access information that the user should not have access to.
CVE-2023-43505 1 Siemens 1 Comos 2025-01-08 9.6 Critical
A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in SMB shares. This could allow an attacker to access files that the user should not have access to.
CVE-2024-43996 1 Wpmet 1 Elementskit 2025-01-08 6.5 Medium
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ElementsKit ElementsKit Pro allows PHP Local File Inclusion.This issue affects ElementsKit Pro: from n/a through 3.6.0.
CVE-2023-6125 1 Salesagility 1 Suitecrm 2025-01-08 8.8 High
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
CVE-2023-6126 1 Salesagility 1 Suitecrm 2025-01-08 9.8 Critical
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
CVE-2023-34409 1 Percona 1 Monitoring And Management 2025-01-08 9.8 Critical
In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize and sanitize URL paths to reject path traversal attempts. This allows an unauthenticated remote user, when a crafted POST request is made against unauthenticated API routes, to access otherwise protected API routes leading to escalation of privileges and information disclosure.
CVE-2023-33747 1 Mgt-commerce 1 Cloudpanel 2025-01-08 7.8 High
CloudPanel v2.2.2 allows attackers to execute a path traversal.
CVE-2023-33659 1 Emqx 1 Nanomq 2025-01-08 7.5 High
A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nmq_subinfo_decode() in the file mqtt_parser.c. An attacker could exploit this vulnerability to cause a denial of service attack.
CVE-2023-33653 1 Sitecore 1 Experience Platform 2025-01-08 8.8 High
Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /Applications/Content%20Manager/Execute.aspx?cmd=convert&mode=HTML.
CVE-2023-33533 1 Netgear 8 D6220, D6220 Firmware, D8500 and 5 more 2025-01-08 8.8 High
Netgear D6220 with Firmware Version 1.0.0.80, D8500 with Firmware Version 1.0.3.60, R6700 with Firmware Version 1.0.2.26, and R6900 with Firmware Version 1.0.2.26 are vulnerable to Command Injection. If an attacker gains web management privileges, they can inject commands into the post request parameters, gaining shell privileges.
CVE-2023-33532 1 Netgear 2 R6250, R6250 Firmware 2025-01-08 9.8 Critical
There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48. If an attacker gains web management privileges, they can inject commands into the post request parameters, thereby gaining shell privileges.
CVE-2023-33530 1 Tenda 2 G103, G103 Firmware 2025-01-08 8.8 High
There is a command injection vulnerability in the Tenda G103 Gigabit GPON Terminal with firmware version V1.0.0.5. If an attacker gains web management privileges, they can inject commands gaining shell privileges.
CVE-2023-33477 1 Harmonicinc 2 Nsg 9000-6g, Nsg 9000-6g Firmware 2025-01-08 6.5 Medium
In Harmonic NSG 9000-6G devices, an authenticated remote user can obtain source code by directly requesting a special path.
CVE-2023-33457 1 Sogou 1 C\+\+ Workflow 2025-01-08 8.8 High
In Sogou Workflow v0.10.6, memcpy a negtive size in URIParser::parse , may cause buffer-overflow and crash.
CVE-2023-33381 1 Mitrastar 2 Gpt-2741gnac, Gpt-2741gnac Firmware 2025-01-08 7.2 High
A command injection vulnerability was found in the ping functionality of the MitraStar GPT-2741GNAC router (firmware version AR_g5.8_110WVN0b7_2). The vulnerability allows an authenticated user to execute arbitrary OS commands by sending specially crafted input to the router via the ping function.
CVE-2023-31569 1 Totolink 2 X5000r, X5000r Firmware 2025-01-08 9.8 Critical
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function.
CVE-2023-30863 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-01-08 7.8 High
In Connectivity Service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.