π¨ CVE-2023-37146
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.
π@cveNotify
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.
π@cveNotify
GitHub
Vulnerability_info/TOTOLINK/lr350/2 at main Β· DaDong-G/Vulnerability_info
ζΌζ΄δΏ‘ζ―. Contribute to DaDong-G/Vulnerability_info development by creating an account on GitHub.
π¨ CVE-2023-37148
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the ussd parameter in the setUssd function.
π@cveNotify
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the ussd parameter in the setUssd function.
π@cveNotify
GitHub
Vulnerability_info/TOTOLINK/lr350/3/README.md at main Β· DaDong-G/Vulnerability_info
ζΌζ΄δΏ‘ζ―. Contribute to DaDong-G/Vulnerability_info development by creating an account on GitHub.
π¨ CVE-2023-37145
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.
π@cveNotify
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.
π@cveNotify
GitHub
Vulnerability_info/TOTOLINK/lr350/1/Readme.md at main Β· DaDong-G/Vulnerability_info
ζΌζ΄δΏ‘ζ―. Contribute to DaDong-G/Vulnerability_info development by creating an account on GitHub.
π¨ CVE-2023-37144
Tenda AC10 v15.03.06.26 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.
π@cveNotify
Tenda AC10 v15.03.06.26 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.
π@cveNotify
GitHub
Vulnerability_info/ac10_command_injection/Readme.md at main Β· DaDong-G/Vulnerability_info
ζΌζ΄δΏ‘ζ―. Contribute to DaDong-G/Vulnerability_info development by creating an account on GitHub.
π¨ CVE-2023-32610
Mailform Pro CGI 4.3.1.2 and earlier allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition.
π@cveNotify
Mailform Pro CGI 4.3.1.2 and earlier allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition.
π@cveNotify
jvn.jp
JVN#70502982: SYNCK GRAPHICA Mailform Pro CGI vulnerable to Regular expression Denial-of-Service (ReDoS)
Japan Vulnerability Notes
π¨ CVE-2022-48506
A flawed pseudorandom number generator in Dominion Voting Systems ImageCast Precinct (ICP and ICP2) and ImageCast Evolution (ICE) scanners allows anyone to determine the order in which ballots were cast from public ballot-level data, allowing deanonymization of voted ballots, in several types of scenarios. This issue was observed for use of the following versions of Democracy Suite: 5.2, 5.4-NM, 5.5, 5.5-A, 5.5-B, 5.5-C, 5.5-D, 5.7-A, 5.10, 5.10A, 5.15. NOTE: the Democracy Suite 5.17 EAC Certificate of Conformance mentions "Improved pseudo random number algorithm," which may be relevant.
π@cveNotify
A flawed pseudorandom number generator in Dominion Voting Systems ImageCast Precinct (ICP and ICP2) and ImageCast Evolution (ICE) scanners allows anyone to determine the order in which ballots were cast from public ballot-level data, allowing deanonymization of voted ballots, in several types of scenarios. This issue was observed for use of the following versions of Democracy Suite: 5.2, 5.4-NM, 5.5, 5.5-A, 5.5-B, 5.5-C, 5.5-D, 5.7-A, 5.10, 5.10A, 5.15. NOTE: the Democracy Suite 5.17 EAC Certificate of Conformance mentions "Improved pseudo random number algorithm," which may be relevant.
π@cveNotify
π¨ CVE-2023-30510
A vulnerability exists in the Aruba EdgeConnect Enterprise web management interface that allows remote authenticated users to issue arbitrary URL requests from the Aruba EdgeConnect Enterprise instance. The impact of this vulnerability is limited to a subset of URLs which can result in the possible disclosure of data due to the network position of the Aruba EdgeConnect Enterprise instance.
π@cveNotify
A vulnerability exists in the Aruba EdgeConnect Enterprise web management interface that allows remote authenticated users to issue arbitrary URL requests from the Aruba EdgeConnect Enterprise instance. The impact of this vulnerability is limited to a subset of URLs which can result in the possible disclosure of data due to the network position of the Aruba EdgeConnect Enterprise instance.
π@cveNotify
π¨ CVE-2023-30509
Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files.
π@cveNotify
Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files.
π@cveNotify
π¨ CVE-2023-30508
Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files.
π@cveNotify
Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files.
π@cveNotify
π¨ CVE-2023-30507
Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files.
π@cveNotify
Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files.
π@cveNotify
π¨ CVE-2023-30506
Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
π@cveNotify
Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
π@cveNotify
π¨ CVE-2023-30505
Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
π@cveNotify
Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
π@cveNotify
π¨ CVE-2023-30504
Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
π@cveNotify
Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
π@cveNotify
π¨ CVE-2023-35987
PiiGAB M-Bus contains hard-coded credentials which it uses for authentication.
π@cveNotify
PiiGAB M-Bus contains hard-coded credentials which it uses for authentication.
π@cveNotify
π¨ CVE-2023-36488
ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to stored Cross Site Scripting (XSS).
π@cveNotify
ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to stored Cross Site Scripting (XSS).
π@cveNotify
π¨ CVE-2023-36467
AWS data.all is an open source development framework to help users build a data marketplace on Amazon Web Services. data.all versions 1.2.0 through 1.5.1 do not prevent remote code execution when a user injects Python commands into the βTemplateβ field when configuring a data pipeline. The issue can only be triggered by authenticated users. A fix for this issue is available in data.all version 1.5.2 and later. There is no recommended work around.
π@cveNotify
AWS data.all is an open source development framework to help users build a data marketplace on Amazon Web Services. data.all versions 1.2.0 through 1.5.1 do not prevent remote code execution when a user injects Python commands into the βTemplateβ field when configuring a data pipeline. The issue can only be triggered by authenticated users. A fix for this issue is available in data.all version 1.5.2 and later. There is no recommended work around.
π@cveNotify
GitHub
data.all vulnerable to RCE through user injection of Python Commands
**Impact**
data.all versions 1.2.0 through 1.5.1 do not prevent remote code execution when a user injects Python commands into the βTemplateβ field when configuring a data pipeline. The issue can ...
data.all versions 1.2.0 through 1.5.1 do not prevent remote code execution when a user injects Python commands into the βTemplateβ field when configuring a data pipeline. The issue can ...
π¨ CVE-2023-3338
A flaw null pointer dereference in the Linux kernel DECnet networking protocol was found. A remote user could use this flaw to crash the system.
π@cveNotify
A flaw null pointer dereference in the Linux kernel DECnet networking protocol was found. A remote user could use this flaw to crash the system.
π@cveNotify
seclists.org
oss-sec: CVE-2023-3338: Linux Kernel NULL Pointer Dereference in DECnet
π¨ CVE-2021-31982
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
π@cveNotify
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
π@cveNotify
π¨ CVE-2021-34475
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
π@cveNotify
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
π@cveNotify
π¨ CVE-2021-34506
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
π@cveNotify
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
π@cveNotify
π¨ CVE-2021-42307
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
π@cveNotify
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
π@cveNotify