#ExploitObserverAlert
WLB-2024030020
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to WLB-2024030020. Hitachi NAS SMU Backup And Restore Insecure Direct Object Reference.
WLB-2024030020
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to WLB-2024030020. Hitachi NAS SMU Backup And Restore Insecure Direct Object Reference.
#ExploitObserverAlert
PSS-177523
DESCRIPTION: Exploit Observer has 31 entries in 9 file formats related to PSS-177523. Adobe ColdFusion 2018,15 / 2021,5 Arbitrary File Read. Adobe ColdFusion versions 2018,15 and below and versions 2021,5 and below suffer from an arbitrary file read vulnerability.
PSS-177523
DESCRIPTION: Exploit Observer has 31 entries in 9 file formats related to PSS-177523. Adobe ColdFusion 2018,15 / 2021,5 Arbitrary File Read. Adobe ColdFusion versions 2018,15 and below and versions 2021,5 and below suffer from an arbitrary file read vulnerability.
#ExploitObserverAlert
PSS-177524
DESCRIPTION: Exploit Observer has 23 entries in 8 file formats related to PSS-177524. Sitecore 8.2 Remote Code Execution. Sitecore version 8.2 suffers from a remote code execution vulnerability.
PSS-177524
DESCRIPTION: Exploit Observer has 23 entries in 8 file formats related to PSS-177524. Sitecore 8.2 Remote Code Execution. Sitecore version 8.2 suffers from a remote code execution vulnerability.
#ExploitObserverAlert
PD/http/cves/2023/CVE-2023-5089
DESCRIPTION: Exploit Observer has 9 entries in 4 file formats related to PD/http/cves/2023/CVE-2023-5089. The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled.
PD/http/cves/2023/CVE-2023-5089
DESCRIPTION: Exploit Observer has 9 entries in 4 file formats related to PD/http/cves/2023/CVE-2023-5089. The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled.
#ExploitObserverAlert
WLB-2024030013
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to WLB-2024030013. MongoDB 2.0.1 / 2.1.1 / 2.1.4 / 2.1.5 Local Password Disclosure.
WLB-2024030013
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to WLB-2024030013. MongoDB 2.0.1 / 2.1.1 / 2.1.4 / 2.1.5 Local Password Disclosure.
#ExploitObserverAlert
CVE-2023-49785
DESCRIPTION: Exploit Observer has 2 entries in 1 file formats related to CVE-2023-49785.
FIRST-EPSS: 0.000490000
CVE-2023-49785
DESCRIPTION: Exploit Observer has 2 entries in 1 file formats related to CVE-2023-49785.
FIRST-EPSS: 0.000490000
#ExploitObserverAlert
GHSA-2jx3-fx5f-r2c6
DESCRIPTION: Exploit Observer has 6 entries in 2 file formats related to GHSA-2jx3-fx5f-r2c6.
GHSA-2jx3-fx5f-r2c6
DESCRIPTION: Exploit Observer has 6 entries in 2 file formats related to GHSA-2jx3-fx5f-r2c6.
#ExploitObserverAlert
CVE-2024-27297
DESCRIPTION: Exploit Observer has 3 entries in 2 file formats related to CVE-2024-27297.
FIRST-EPSS: 0.000450000
CVE-2024-27297
DESCRIPTION: Exploit Observer has 3 entries in 2 file formats related to CVE-2024-27297.
FIRST-EPSS: 0.000450000
#ExploitObserverAlert
CVE-2023-36554
DESCRIPTION: Exploit Observer has 3 entries in 1 file formats related to CVE-2023-36554. A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.4.13, 6.2 all versions allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.
CVE-2023-36554
DESCRIPTION: Exploit Observer has 3 entries in 1 file formats related to CVE-2023-36554. A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.4.13, 6.2 all versions allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.
#ExploitObserverAlert
BDU:2015-10403
DESCRIPTION: Exploit Observer has 26 entries in 7 file formats related to BDU:2015-10403. Vulnerability in the Windows Embedded Standard 2009 operating system that allows an attacker to cause a denial of service. The Windows Embedded Standard 2009 operating system contains a vulnerability in the kernel mode driver rdpwd.sys, located in the C:\Windows\System32 directory, which incorrectly handles the dynamic memory allocated to it for storing array elements. By using specially crafted requests sent over the RDP protocol, the attacker can force the driver to release memory twice, which will generally result in a system crash.
BDU:2015-10403
DESCRIPTION: Exploit Observer has 26 entries in 7 file formats related to BDU:2015-10403. Vulnerability in the Windows Embedded Standard 2009 operating system that allows an attacker to cause a denial of service. The Windows Embedded Standard 2009 operating system contains a vulnerability in the kernel mode driver rdpwd.sys, located in the C:\Windows\System32 directory, which incorrectly handles the dynamic memory allocated to it for storing array elements. By using specially crafted requests sent over the RDP protocol, the attacker can force the driver to release memory twice, which will generally result in a system crash.
#ExploitObserverAlert
CVE-2023-47534
DESCRIPTION: Exploit Observer has 3 entries in 1 file formats related to CVE-2023-47534. A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.10, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8 allows attacker to execute unauthorized code or commands via specially crafted packets.
CVE-2023-47534
DESCRIPTION: Exploit Observer has 3 entries in 1 file formats related to CVE-2023-47534. A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.10, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8 allows attacker to execute unauthorized code or commands via specially crafted packets.
#ExploitObserverAlert
BDU:2023-07691
DESCRIPTION: Exploit Observer has 28 entries in 10 file formats related to BDU:2023-07691. Vulnerability in the functions EVP_EncryptInit_ex2(), EVP_DecryptInit_ex2(), EVP_CipherInit_ex2() of the OpenSSL cryptographic library, allowing an attacker to cause a denial of service. The vulnerability in the functions EVP_EncryptInit_ex2(), EVP_DecryptInit_ex2(), EVP_CipherInit_ex2() of the OpenSSL cryptographic library is related to manipulation of the keylen/ivlen argument. Exploiting the vulnerability could allow a remote attacker to cause a denial of service.
BDU:2023-07691
DESCRIPTION: Exploit Observer has 28 entries in 10 file formats related to BDU:2023-07691. Vulnerability in the functions EVP_EncryptInit_ex2(), EVP_DecryptInit_ex2(), EVP_CipherInit_ex2() of the OpenSSL cryptographic library, allowing an attacker to cause a denial of service. The vulnerability in the functions EVP_EncryptInit_ex2(), EVP_DecryptInit_ex2(), EVP_CipherInit_ex2() of the OpenSSL cryptographic library is related to manipulation of the keylen/ivlen argument. Exploiting the vulnerability could allow a remote attacker to cause a denial of service.
#ExploitObserverAlert
EDB-51877
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to EDB-51877. Human Resource Management System 1.0 - 'employeeid' SQL Injection
EDB-51877
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to EDB-51877. Human Resource Management System 1.0 - 'employeeid' SQL Injection
#ExploitObserverAlert
CVE-2023-42789
DESCRIPTION: Exploit Observer has 3 entries in 1 file formats related to CVE-2023-42789. A out-of-bounds write in Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13 allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.
CVE-2023-42789
DESCRIPTION: Exploit Observer has 3 entries in 1 file formats related to CVE-2023-42789. A out-of-bounds write in Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13 allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.
#ExploitObserverAlert
CVE-2024-21334
DESCRIPTION: Exploit Observer has 3 entries in 1 file formats related to CVE-2024-21334. Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
NVD-IS: 5.9
NVD-ES: 3.9
CVE-2024-21334
DESCRIPTION: Exploit Observer has 3 entries in 1 file formats related to CVE-2024-21334. Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
NVD-IS: 5.9
NVD-ES: 3.9
#ExploitObserverAlert
CVE-2023-48788
DESCRIPTION: Exploit Observer has 3 entries in 1 file formats related to CVE-2023-48788. A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.
CVE-2023-48788
DESCRIPTION: Exploit Observer has 3 entries in 1 file formats related to CVE-2023-48788. A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.
#ExploitObserverAlert
CVE-2024-23112
DESCRIPTION: Exploit Observer has 3 entries in 1 file formats related to CVE-2024-23112. An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.1 through 7.0.13, 6.4.7 through 6.4.14, and FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14 SSL-VPN may allow an authenticated attacker to gain access to another user’s bookmark via URL manipulation.
CVE-2024-23112
DESCRIPTION: Exploit Observer has 3 entries in 1 file formats related to CVE-2024-23112. An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.1 through 7.0.13, 6.4.7 through 6.4.14, and FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14 SSL-VPN may allow an authenticated attacker to gain access to another user’s bookmark via URL manipulation.
#ExploitObserverAlert
EDB-51883
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to EDB-51883. SnipeIT 6.2.1 - Stored Cross Site Scripting
EDB-51883
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to EDB-51883. SnipeIT 6.2.1 - Stored Cross Site Scripting
#ExploitObserverAlert
EDB-51880
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to EDB-51880. Client Details System 1.0 - SQL Injection
EDB-51880
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to EDB-51880. Client Details System 1.0 - SQL Injection
#ExploitObserverAlert
EDB-51882
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to EDB-51882. VMware Cloud Director 10.5 - Bypass identity verification
EDB-51882
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to EDB-51882. VMware Cloud Director 10.5 - Bypass identity verification
#ExploitObserverAlert
CVE-2023-42790
DESCRIPTION: Exploit Observer has 3 entries in 1 file formats related to CVE-2023-42790. A stack-based buffer overflow in Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13 allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.
FIRST-EPSS: 0.000430000
CVE-2023-42790
DESCRIPTION: Exploit Observer has 3 entries in 1 file formats related to CVE-2023-42790. A stack-based buffer overflow in Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13 allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.
FIRST-EPSS: 0.000430000