Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-25119 1 Milesight 2 Ur32l, Ur32l Firmware 2023-08-02 N/A 7.2 HIGH
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_pptp function with the remote_subnet and the remote_mask variables.
CVE-2023-25118 1 Milesight 2 Ur32l, Ur32l Firmware 2023-08-02 N/A 7.2 HIGH
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the username and the password variables.
CVE-2023-25117 1 Milesight 2 Ur32l, Ur32l Firmware 2023-08-02 N/A 7.2 HIGH
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the local_virtual_ip and the local_virtual_mask variables.
CVE-2023-25116 1 Milesight 2 Ur32l, Ur32l Firmware 2023-08-02 N/A 7.2 HIGH
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the local_virtual_ip and the remote_virtual_ip variables.
CVE-2023-25115 1 Milesight 2 Ur32l, Ur32l Firmware 2023-08-02 N/A 7.2 HIGH
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the remote_ip and the port variables.
CVE-2023-25114 1 Milesight 2 Ur32l, Ur32l Firmware 2023-08-02 N/A 7.2 HIGH
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the expert_options variable.
CVE-2023-25113 1 Milesight 2 Ur32l, Ur32l Firmware 2023-08-02 N/A 7.2 HIGH
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_l2tp function with the key variable.
CVE-2023-25124 1 Milesight 2 Ur32l, Ur32l Firmware 2023-08-02 N/A 7.2 HIGH
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the remote_subnet and the remote_mask variables.
CVE-2023-3748 1 Frrouting 1 Frrouting 2023-08-02 N/A 7.5 HIGH
A flaw was found in FRRouting when parsing certain babeld unicast hello messages that are intended to be ignored. This issue may allow an attacker to send specially crafted hello messages with the unicast flag set, the interval field set to 0, or any TLV that contains a sub-TLV with the Mandatory flag set to enter an infinite loop and cause a denial of service.
CVE-2023-3640 2 Linux, Redhat 2 Linux Kernel, Enterprise Linux 2023-08-02 N/A 7.8 HIGH
A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data. Based on the previous CVE-2023-0597, the 'Randomize per-cpu entry area' feature was implemented in /arch/x86/mm/cpu_entry_area.c, which works through the init_cea_offsets() function when KASLR is enabled. However, despite this feature, there is still a risk of per-cpu entry area leaks. This issue could allow a local user to gain access to some important data with memory in an expected location and potentially escalate their privileges on the system.
CVE-2023-3321 1 Abb 1 Zenon 2023-08-02 N/A 8.8 HIGH
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts. This issue affects ABB Ability™ zenon: from 11 build through 11 build 106404.
CVE-2023-27385 1 Omron 1 Cx-drive 2023-08-02 N/A 7.8 HIGH
Heap-based buffer overflow vulnerability exists in CX-Drive All models all versions. By having a user open a specially crafted SDD file, arbitrary code may be executed and/or information may be disclosed.
CVE-2022-2818 1 Agentejo 1 Cockpit 2023-08-02 N/A 8.8 HIGH
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.
CVE-2022-2732 1 Open-emr 1 Openemr 2023-08-02 N/A 8.3 HIGH
Missing Authorization in GitHub repository openemr/openemr prior to 7.0.0.1.
CVE-2022-2054 1 Nuitka 1 Nuitka 2023-08-02 7.2 HIGH 7.8 HIGH
Code Injection in GitHub repository nuitka/nuitka prior to 0.9.
CVE-2022-1316 2 Microsoft, Zerotier 2 Windows, Zerotierone 2023-08-02 7.2 HIGH 7.8 HIGH
Incorrect Permission Assignment for Critical Resource in GitHub repository zerotier/zerotierone prior to 1.8.8. Local Privilege Escalation
CVE-2022-0611 1 Snipeitapp 1 Snipe-it 2023-08-02 6.5 MEDIUM 8.8 HIGH
Missing Authorization in Packagist snipe/snipe-it prior to 5.3.11.
CVE-2022-0580 1 Librenms 1 Librenms 2023-08-02 6.5 MEDIUM 8.8 HIGH
Incorrect Authorization in Packagist librenms/librenms prior to 22.2.0.
CVE-2022-0565 1 Pimcore 1 Pimcore 2023-08-02 5.0 MEDIUM 7.5 HIGH
Cross-site Scripting in Packagist pimcore/pimcore prior to 10.3.1.
CVE-2022-0355 1 Simple-get Project 1 Simple-get 2023-08-02 5.0 MEDIUM 7.5 HIGH
Improper Removal of Sensitive Information Before Storage or Transfer in NPM simple-get prior to 4.0.1.
CVE-2022-0282 1 Microweber 1 Microweber 2023-08-02 5.0 MEDIUM 7.5 HIGH
Cross-site Scripting in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0121 1 Hoppscotch 1 Hoppscotch 2023-08-02 6.0 MEDIUM 8.0 HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hoppscotch hoppscotch/hoppscotch.This issue affects hoppscotch/hoppscotch before 2.1.1.
CVE-2023-34434 1 Apache 1 Inlong 2023-08-02 N/A 7.5 HIGH
Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0.  The attacker could bypass the current logic and achieve arbitrary file reading. To solve it, users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8130 .
CVE-2023-21406 1 Axis 2 A1001, A1001 Firmware 2023-08-02 N/A 8.8 HIGH
Ariel Harush and Roy Hodir from OTORIO have found a flaw in the AXIS A1001 when communicating over OSDP. A heap-based buffer overflow was found in the pacsiod process which is handling the OSDP communication allowing to write outside of the allocated buffer. By appending invalid data to an OSDP message it was possible to write data beyond the heap allocated buffer. The data written outside the buffer could be used to execute arbitrary code.  lease refer to the Axis security advisory for more information, mitigation and affected products and software versions.
CVE-2022-28864 1 Nokia 1 Netact 2023-08-02 N/A 8.8 HIGH
An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parameter in order to include malicious code, which is then downloaded as a .csv or .xlsx file and executed on a victim machine. Here, the /aom/html/EditTemplate.jsf and /aom/html/ViewAllTemplatesPage.jsf templateName parameter is used.
CVE-2022-28863 1 Nokia 1 Netact 2023-08-02 N/A 8.8 HIGH
An issue was discovered in Nokia NetAct 22. A remote user, authenticated to the website, can visit the Site Configuration Tool section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the operation=upload value.
CVE-2022-30280 1 Nokia 1 Netact 2023-08-02 N/A 8.8 HIGH
/SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF. A remote attacker is able to create users with arbitrary privileges, even administrative privileges. The application (even if it implements a CSRF token for the random GET request) does not ever verify a CSRF token. With a little help of social engineering/phishing (such as sending a link via email or chat), an attacker may trick the users of a web application into executing actions of the attacker's choosing. If the victim is a normal user, a successful CSRF attack can force the user to perform state changing requests like transferring funds, changing their email address, and so forth. If the victim is an administrative account, CSRF can compromise the entire web application.
CVE-2023-36854 1 Apple 1 Macos 2023-08-02 N/A 7.8 HIGH
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.8, macOS Ventura 13.5, macOS Big Sur 11.7.9. Processing a file may lead to unexpected app termination or arbitrary code execution.
CVE-2023-32437 1 Apple 2 Ipados, Iphone Os 2023-08-02 N/A 8.6 HIGH
The issue was addressed with improvements to the file handling protocol. This issue is fixed in iOS 16.6 and iPadOS 16.6. An app may be able to break out of its sandbox.
CVE-2023-32433 1 Apple 5 Ipados, Iphone Os, Macos and 2 more 2023-08-02 N/A 7.8 HIGH
A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to execute arbitrary code with kernel privileges.
CVE-2023-32381 1 Apple 5 Ipados, Iphone Os, Macos and 2 more 2023-08-02 N/A 7.8 HIGH
A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.6.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to execute arbitrary code with kernel privileges.
CVE-2023-38285 1 Trustwave 1 Modsecurity 2023-08-02 N/A 7.5 HIGH
Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Complexity.
CVE-2021-31936 1 Microsoft 1 Accessibility Insights For Web 2023-08-02 4.3 MEDIUM 7.4 HIGH
Microsoft Accessibility Insights for Web Information Disclosure Vulnerability
CVE-2021-31214 1 Microsoft 1 Visual Studio Code 2023-08-02 9.3 HIGH 7.8 HIGH
Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-31213 1 Microsoft 1 Remote 2023-08-02 6.8 MEDIUM 7.8 HIGH
Visual Studio Code Remote Containers Extension Remote Code Execution Vulnerability
CVE-2021-31211 1 Microsoft 1 Visual Studio Code 2023-08-02 6.8 MEDIUM 7.8 HIGH
Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-31208 1 Microsoft 2 Windows 10, Windows Server 2016 2023-08-02 4.6 MEDIUM 7.8 HIGH
Windows Container Manager Service Elevation of Privilege Vulnerability
CVE-2021-31200 1 Microsoft 1 Neural Network Intelligence 2023-08-02 6.5 MEDIUM 7.2 HIGH
Common Utilities Remote Code Execution Vulnerability
CVE-2021-31198 1 Microsoft 1 Exchange Server 2023-08-02 6.8 MEDIUM 7.8 HIGH
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-31194 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2023-08-02 6.5 MEDIUM 8.8 HIGH
OLE Automation Remote Code Execution Vulnerability
CVE-2021-31193 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2023-08-02 4.6 MEDIUM 7.8 HIGH
Windows SSDP Service Elevation of Privilege Vulnerability
CVE-2021-31192 1 Microsoft 1 Windows 10 2023-08-02 6.8 MEDIUM 7.3 HIGH
Windows Media Foundation Core Remote Code Execution Vulnerability
CVE-2021-31190 1 Microsoft 2 Windows 10, Windows Server 2019 2023-08-02 4.6 MEDIUM 7.8 HIGH
Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability
CVE-2021-31188 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2023-08-02 2.1 LOW 7.8 HIGH
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2021-31187 1 Microsoft 1 Windows 10 2023-08-02 7.2 HIGH 7.8 HIGH
Windows WalletService Elevation of Privilege Vulnerability
CVE-2021-31186 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2023-08-02 4.3 MEDIUM 7.4 HIGH
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2021-31182 1 Microsoft 7 Windows 10, Windows 7, Windows 8.1 and 4 more 2023-08-02 4.8 MEDIUM 7.1 HIGH
Microsoft Bluetooth Driver Spoofing Vulnerability
CVE-2021-31181 1 Microsoft 3 Sharepoint Enterprise Server, Sharepoint Foundation, Sharepoint Server 2023-08-02 6.5 MEDIUM 8.8 HIGH
Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2021-31179 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2023-08-02 6.8 MEDIUM 7.8 HIGH
Microsoft Office Remote Code Execution Vulnerability
CVE-2021-31176 1 Microsoft 4 365 Apps, Office, Office Online Server and 1 more 2023-08-02 6.8 MEDIUM 7.8 HIGH
Microsoft Office Remote Code Execution Vulnerability