Search Results (30633 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-28609 1 Ansible-semaphore 1 Ansible Semaphore 2025-02-26 9.8 Critical
api/auth.go in Ansible Semaphore before 2.8.89 mishandles authentication.
CVE-2023-23150 1 Lancombg 2 Sa-wr915nd, Sa-wr915nd Firmware 2025-02-26 9.8 Critical
SA-WR915ND router firmware v17.35.1 was discovered to be vulnerable to code execution.
CVE-2020-22647 1 Smartconrtactgames Project 1 Smartconrtactgames 2025-02-26 9.1 Critical
An issue found in DepositGame v.1.0 allows an attacker to gain sensitive information via the GetBonusWithdraw and withdraw functions.
CVE-2023-21456 1 Samsung 1 Android 2025-02-26 9 Critical
Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid.
CVE-2023-27041 1 School Registration And Fee System Project 1 School Registration And Fee System 2025-02-26 9.8 Critical
School Registration and Fee System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at/bilal final/edit_user.php.
CVE-2023-27040 1 Simple Image Gallery Web App Project 1 Simple Image Gallery Web App 2025-02-26 9.8 Critical
Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username parameter.
CVE-2023-27569 1 Prestashop 1 Eo Tags 2025-02-26 9.8 Critical
The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header.
CVE-2023-27250 1 Online Book Store Project Project 1 Online Book Store Project 2025-02-26 9.8 Critical
Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php.
CVE-2022-45637 1 Megafeis 1 Bofei Dbd\+ 2025-02-26 9.8 Critical
An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via insecure expiry mechanism.
CVE-2023-27570 1 Prestashop 1 Eo Tags 2025-02-26 9.8 Critical
The eo_tags package before 1.4.19 for PrestaShop allows SQL injection via a crafted _ga cookie.
CVE-2023-28725 1 Generalbytes 1 Crypto Application Server 2025-02-26 9.1 Critical
General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary Java code by uploading a Java application to the /batm/app/admin/standalone/deployments directory, aka BATM-4780, as exploited in the wild in March 2023. This is fixed in 20221118.48 and 20230120.44.
CVE-2023-24795 1 Jcgcn.com 2 Jhr-n916r, Jhr-n916r Firmware 2025-02-26 9.8 Critical
Command execution vulnerability was discovered in JHR-N916R router firmware version<=21.11.1.1483.
CVE-2020-19947 1 Markdown Edit Project 1 Markdown Edit 2025-02-26 9.6 Critical
Cross Site Scripting vulnerability found in Markdown Edit allows a remote attacker to execute arbitrary code via the edit parameter of the webpage.
CVE-2023-27874 2 Ibm, Linux 2 Aspera Faspex, Linux Kernel 2025-02-26 9.9 Critical
IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. IBM X-Force ID: 249845.
CVE-2023-26784 1 Tosec 1 Kirin Fortress Machine 2025-02-26 9.8 Critical
SQL Injection vulnerability found in Kirin Fortress Machine v.1.7-2020-0610 allows attackers to execute arbitrary code via the /admin.php?controller=admin_commonuser parameter.
CVE-2023-27638 1 Tshirtecommerce 1 Custom Product Designer 2025-02-26 9.8 Critical
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised tshirtecommerce_design_cart_id GET parameter in order to exploit an insecure parameter in the functions hookActionCartSave and updateCustomizationTable, which could lead to a SQL injection. This is exploited in the wild in March 2023.
CVE-2023-27637 1 Tshirtecommerce 1 Custom Product Designer 2025-02-26 9.8 Critical
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to exploit an insecure parameter in the front controller file designer.php, which could lead to a SQL injection. This is exploited in the wild in March 2023.
CVE-2023-27060 1 Lightcms Project 1 Lightcms 2025-02-26 9.8 Critical
LightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function.
CVE-2022-37337 1 Netgear 2 Rbs750, Rbs750 Firmware 2025-02-26 9.1 Critical
A command execution vulnerability exists in the access control functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
CVE-2023-28610 1 Omicronenergy 2 Stationguard, Stationscout 2025-02-26 9.8 Critical
The update process in OMICRON StationGuard and OMICRON StationScout before 2.21 can be exploited by providing a modified firmware update image. This allows a remote attacker to gain root access to the system.