Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-49235 1 Trendnet 2 Tv-ip1314pi, Tv-ip1314pi Firmware 2024-01-12 N/A 9.8 CRITICAL
An issue was discovered in libremote_dbg.so on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Filtering of debug information is mishandled during use of popen. Consequently, an attacker can bypass validation and execute a shell command.
CVE-2023-50643 1 Evernote 1 Evernote 2024-01-12 N/A 9.8 CRITICAL
An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.
CVE-2023-25775 1 Intel 1 Ethernet Controller Rdma Driver For Linux 2024-01-11 N/A 9.8 CRITICAL
Improper access control in the Intel(R) Ethernet Controller RDMA driver for linux before version 1.9.30 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
CVE-2018-25095 1 Snapcreek 1 Duplicator 2024-01-11 N/A 9.8 CRITICAL
The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script is left on the site after use, it could be use to run arbitrary code on the server.
CVE-2023-51277 1 Tinowagner 1 Jupyter Notebook Viewer 2024-01-11 N/A 9.8 CRITICAL
nbviewer-app (aka Jupyter Notebook Viewer) before 0.1.6 has the get-task-allow entitlement for release builds.
CVE-2024-22216 1 Microchip 1 Maxview Storage Manager 2024-01-11 N/A 9.1 CRITICAL
In default installations of Microchip maxView Storage Manager (for Adaptec Smart Storage Controllers) where Redfish server is configured for remote system management, unauthorized access can occur, with data modification and information disclosure. This affects 3.00.23484 through 4.14.00.26064 (except for the patched versions 3.07.23980 and 4.07.00.25339).
CVE-2023-29357 1 Microsoft 1 Sharepoint Server 2024-01-11 N/A 9.8 CRITICAL
Microsoft SharePoint Server Elevation of Privilege Vulnerability
CVE-2023-46741 1 Linuxfoundation 1 Cubefs 2024-01-10 N/A 9.8 CRITICAL
CubeFS is an open-source cloud-native file storage system. A vulnerability was found in CubeFS prior to version 3.3.1 that could allow users to read sensitive data from the logs which could allow them escalate privileges. CubeFS leaks configuration keys in plaintext format in the logs. These keys could allow anyone to carry out operations on blobs that they otherwise do not have permissions for. For example, an attacker that has succesfully retrieved a secret key from the logs can delete blogs from the blob store. The attacker can either be an internal user with limited privileges to read the log, or they can be an external user who has escalated privileges sufficiently to access the logs. The vulnerability has been patched in v3.3.1. There is no other mitigation than upgrading.
CVE-2023-51154 1 Jizhicms 1 Jizhicms 2024-01-10 N/A 9.8 CRITICAL
Jizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsController.php.
CVE-2023-51812 1 Tenda 2 Ax3, Ax3 Firmware 2024-01-10 N/A 9.8 CRITICAL
Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList.
CVE-2023-50921 1 Gl-inet 24 Gl-a1300, Gl-a1300 Firmware, Gl-ar300m and 21 more 2024-01-10 N/A 9.8 CRITICAL
An issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system module to gain root privileges. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.
CVE-2023-48659 1 Misp-project 1 Malware Information Sharing Platform 2024-01-10 N/A 9.8 CRITICAL
An issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing.
CVE-2023-48656 1 Misp-project 1 Malware Information Sharing Platform 2024-01-10 N/A 9.8 CRITICAL
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses.
CVE-2023-48658 1 Misp-project 1 Malware Information Sharing Platform 2024-01-10 N/A 9.8 CRITICAL
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, underscore, dash, period, and space.
CVE-2023-48657 1 Misp-project 1 Malware Information Sharing Platform 2024-01-10 N/A 9.8 CRITICAL
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters.
CVE-2023-48655 1 Misp-project 1 Malware Information Sharing Platform 2024-01-10 N/A 9.8 CRITICAL
An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters.
CVE-2023-52262 1 Outdoorbits 1 Little Backup Box 2024-01-09 N/A 9.8 CRITICAL
outdoorbits little-backup-box (aka Little Backup Box) before f39f91c allows remote attackers to execute arbitrary code because the PHP extract function is used for untrusted input.
CVE-2023-50090 1 Ureport2 Project 1 Ureport2 2024-01-09 N/A 9.8 CRITICAL
Arbitrary File Write vulnerability in the saveReportFile method of ureport2 2.2.9 and before allows attackers to write arbitrary files and run arbitrary commands via crafted POST request.
CVE-2023-50351 1 Hcltech 1 Dryice Myxalytics 2024-01-09 N/A 9.1 CRITICAL
HCL DRYiCE MyXalytics is impacted by the use of an insecure key rotation mechanism which can allow an attacker to compromise the confidentiality or integrity of data.
CVE-2022-28995 1 Yogeshojha 1 Rengine 2024-01-09 7.5 HIGH 9.8 CRITICAL
Rengine v1.0.2 was discovered to contain a remote code execution (RCE) vulnerability via the yaml configuration function.
CVE-2023-4280 1 Silabs 1 Gecko Software Development Kit 2024-01-09 N/A 9.8 CRITICAL
An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker to access the trusted region of memory from the untrusted region.
CVE-2023-48419 1 Google 8 Home, Home Firmware, Home Mini and 5 more 2024-01-09 N/A 9.8 CRITICAL
An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege 
CVE-2023-51673 1 Stylishpricelist 1 Stylish Price List 2024-01-09 N/A 9.8 CRITICAL
Cross-Site Request Forgery (CSRF) vulnerability in Designful Stylish Price List – Price Table Builder & QR Code Restaurant Menu.This issue affects Stylish Price List – Price Table Builder & QR Code Restaurant Menu: from n/a through 7.0.17.
CVE-2023-0558 1 Contentstudio 1 Contentstudio 2024-01-09 N/A 9.8 CRITICAL
The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to an unsecure token check that is susceptible to type juggling in versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to execute functions intended for use by users with proper API keys.
CVE-2023-40397 3 Apple, Webkitgtk, Wpewebkit 3 Macos, Webkitgtk, Wpe Webkit 2024-01-05 N/A 9.8 CRITICAL
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5. A remote attacker may be able to cause arbitrary javascript code execution.
CVE-2023-23424 1 Hihonor 2 Nth-an00, Nth-an00 Firmware 2024-01-04 N/A 9.8 CRITICAL
Some Honor products are affected by file writing vulnerability, successful exploitation could cause code execution
CVE-2023-7163 1 Dlink 1 D-view 8 2024-01-04 N/A 9.8 CRITICAL
A security issue exists in D-Link D-View 8 v2.0.2.89 and prior that could allow an attacker to manipulate the probe inventory of the D-View service. This could result in the disclosure of information from other probes, denial of service conditions due to the probe inventory becoming full, or the execution of tasks on other probes.
CVE-2020-1467 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2024-01-04 7.2 HIGH 10.0 CRITICAL
<p>An elevation of privilege vulnerability exists when Windows improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status.</p> <p>To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.</p> <p>The security update addresses the vulnerability by correcting how Windows handles hard links.</p>
CVE-2023-48654 1 Oneidentity 1 Password Manager 2024-01-03 N/A 9.8 CRITICAL
One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape sequence is: go to the Google ReCAPTCHA section, click on the Privacy link, observe that there is a new browser window, navigate to any website that offers file upload, navigate to cmd.exe from the file explorer window, and launch cmd.exe as NT AUTHORITY\SYSTEM.
CVE-2023-7039 1 Byzoro 2 Smart S210, Smart S210 Firmware 2024-01-03 N/A 9.8 CRITICAL
A vulnerability classified as critical has been found in Beijing Baichuo S210 up to 20231210. Affected is an unknown function of the file /importexport.php. The manipulation of the argument sql leads to injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-248688.
CVE-2022-2421 1 Socket 1 Socket.io-parser 2024-01-02 N/A 9.8 CRITICAL
Due to improper type validation in attachment parsing the Socket.io js library, it is possible to overwrite the _placeholder object which allows an attacker to place references to functions at arbitrary places in the resulting query object.
CVE-2023-49032 1 Ltb-project 1 Self Service Password 2024-01-02 N/A 9.8 CRITICAL
An issue in LTB Self Service Password before v.1.5.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via hijack of the SMS verification code function to arbitrary phone.
CVE-2022-21797 3 Debian, Fedoraproject, Joblib Project 3 Debian Linux, Fedora, Joblib 2024-01-02 N/A 9.8 CRITICAL
The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.
CVE-2023-45887 1 Nintendo 1 Ds Wireless Communication 2024-01-02 N/A 9.8 CRITICAL
DS Wireless Communication (DWC) with DWC_VERSION_3 and DWC_VERSION_11 allows remote attackers to execute arbitrary code on a game-playing client's machine via a modified GPCM message.
CVE-2020-17051 1 Microsoft 4 Windows Server 2008, Windows Server 2012, Windows Server 2016 and 1 more 2023-12-31 10.0 HIGH 9.8 CRITICAL
Windows Network File System Remote Code Execution Vulnerability
CVE-2020-17142 1 Microsoft 1 Exchange Server 2023-12-30 6.5 MEDIUM 9.1 CRITICAL
Microsoft Exchange Remote Code Execution Vulnerability
CVE-2020-17132 1 Microsoft 1 Exchange Server 2023-12-30 6.5 MEDIUM 9.1 CRITICAL
Microsoft Exchange Remote Code Execution Vulnerability
CVE-2021-24077 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2023-12-29 7.5 HIGH 9.8 CRITICAL
Windows Fax Service Remote Code Execution Vulnerability
CVE-2021-24094 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2023-12-29 7.5 HIGH 9.8 CRITICAL
Windows TCP/IP Remote Code Execution Vulnerability
CVE-2021-24078 1 Microsoft 4 Windows Server 2008, Windows Server 2012, Windows Server 2016 and 1 more 2023-12-29 7.5 HIGH 9.8 CRITICAL
Windows DNS Server Remote Code Execution Vulnerability
CVE-2021-24074 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2023-12-29 7.5 HIGH 9.8 CRITICAL
Windows TCP/IP Remote Code Execution Vulnerability
CVE-2021-26877 1 Microsoft 4 Windows Server 2008, Windows Server 2012, Windows Server 2016 and 1 more 2023-12-29 7.5 HIGH 9.8 CRITICAL
Windows DNS Server Remote Code Execution Vulnerability
CVE-2021-26894 1 Microsoft 4 Windows Server 2008, Windows Server 2012, Windows Server 2016 and 1 more 2023-12-29 10.0 HIGH 9.8 CRITICAL
Windows DNS Server Remote Code Execution Vulnerability
CVE-2021-26867 1 Microsoft 2 Windows 10, Windows Server 2016 2023-12-29 7.2 HIGH 9.9 CRITICAL
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2021-26897 1 Microsoft 4 Windows Server 2008, Windows Server 2012, Windows Server 2016 and 1 more 2023-12-29 10.0 HIGH 9.8 CRITICAL
Windows DNS Server Remote Code Execution Vulnerability
CVE-2021-26895 1 Microsoft 4 Windows Server 2008, Windows Server 2012, Windows Server 2016 and 1 more 2023-12-29 10.0 HIGH 9.8 CRITICAL
Windows DNS Server Remote Code Execution Vulnerability
CVE-2021-26893 1 Microsoft 4 Windows Server 2008, Windows Server 2012, Windows Server 2016 and 1 more 2023-12-29 7.5 HIGH 9.8 CRITICAL
Windows DNS Server Remote Code Execution Vulnerability
CVE-2021-27080 1 Microsoft 1 Azure Sphere 2023-12-29 7.2 HIGH 9.3 CRITICAL
Azure Sphere Unsigned Code Execution Vulnerability
CVE-2021-27078 1 Microsoft 1 Exchange Server 2023-12-29 6.5 MEDIUM 9.1 CRITICAL
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26412 1 Microsoft 1 Exchange Server 2023-12-29 6.5 MEDIUM 9.1 CRITICAL
Microsoft Exchange Server Remote Code Execution Vulnerability