Zeros312
4e466519-fab8-4086-b82f-5e7887cb9916 | https://github.com/0xrobiul/CVE-2023-38646 | CVE-2023-38646 | https://nvd.nist.gov/vuln/detail/CVE-2023-38646 | 2023-07-29 13:07:00 | Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2. | Exploits_CVE_Monitor,Exploits_InTheWild,Exploits_PoC_CVE |
1e30d5bf-ce6a-4262-86b6-725f73d61136 | https://github.com/vchan-in/CVE-2023-35078-Exploit-POC | CVE-2023-35078 | https://nvd.nist.gov/vuln/detail/CVE-2023-35078 | 2023-07-29 05:06:27 | An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication. | Exploits_CVE_Monitor,Exploits_InTheWild,Exploits_PoC_CVE |
cf014e1c-4ed0-442f-9808-35656fd774ac | https://github.com/getgrav/grav/security/advisories/GHSA-9436-3gmp-4f53 | CVE-2023-37897 | https://nvd.nist.gov/vuln/detail/CVE-2023-37897 | 2023-07-28 22:24:00 | Grav is a file-based Web-platform built in PHP. Grav is subject to a server side template injection (SSTI) vulnerability. The fix for another SSTI vulnerability using `|map`, `|filter` and `|reduce` twigs implemented in the commit `71bbed1` introduces bypass of the denylist due to incorrect return value from `isDangerousFunction()`, which allows to execute the payload prepending double backslash (`\\`). The `isDangerousFunction()` check in version 1.7.42 and onwards retuns `false` value instead of `true` when the `\` symbol is found in the `$name`. This vulnerability can be exploited if the attacker has access to: 1. an Administrator account, or 2. a non-administrator, user account that has Admin panel access and Create/Update page permissions. A fix for this vulnerability has been introduced in commit `b4c6210` and is included in release version `1.7.42.2`. Users are advised to upgrade. There are no known workarounds for this vulnerability.
| Exploits_InTheWild,Exploits_NVD |
8f91ccef-13c6-43ca-b3fb-26edb3ac4d9c | https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%2011.pdf | CVE-2023-3879 | https://nvd.nist.gov/vuln/detail/CVE-2023-3879 | 2023-07-28 19:25:00 | A vulnerability was found in Campcodes Beauty Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/del_category.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235241 was assigned to this vulnerability. | Exploits_InTheWild,Exploits_NVD |
a6ac0700-a436-4446-9e3d-9a901b1748cf | https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%2010.pdf | CVE-2023-3878 | https://nvd.nist.gov/vuln/detail/CVE-2023-3878 | 2023-07-28 19:25:00 | A vulnerability was found in Campcodes Beauty Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/about-us.php. The manipulation of the argument pagedes leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235240. | Exploits_InTheWild,Exploits_NVD |
55045c1c-668e-435a-8559-6f0dc05d6b3c | https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%209.pdf | CVE-2023-3877 | https://nvd.nist.gov/vuln/detail/CVE-2023-3877 | 2023-07-28 19:25:00 | A vulnerability was found in Campcodes Beauty Salon Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/add-services.php. The manipulation of the argument cost leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235239. | Exploits_InTheWild,Exploits_NVD |
86b245e8-74e3-4a53-a027-6c40d4cda5f6 | https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%2019.pdf | CVE-2023-3887 | https://nvd.nist.gov/vuln/detail/CVE-2023-3887 | 2023-07-28 19:04:00 | A vulnerability was found in Campcodes Beauty Salon Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/search-appointment.php. The manipulation of the argument searchdata leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235249 was assigned to this vulnerability. | Exploits_InTheWild,Exploits_NVD |
4d6e876d-462b-4d19-b37f-539ce06dbd94 | https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%2018.pdf | CVE-2023-3886 | https://nvd.nist.gov/vuln/detail/CVE-2023-3886 | 2023-07-28 19:03:00 | A vulnerability was found in Campcodes Beauty Salon Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/invoice.php. The manipulation of the argument inv_id leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235248. | Exploits_InTheWild,Exploits_NVD |
f0a847ec-99d2-45a6-905c-635861d8969d | https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%2017.pdf | CVE-2023-3885 | https://nvd.nist.gov/vuln/detail/CVE-2023-3885 | 2023-07-28 19:03:00 | A vulnerability was found in Campcodes Beauty Salon Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /admin/edit_category.php. The manipulation of the argument id leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235247. | Exploits_InTheWild,Exploits_NVD |
b3bb6d60-7baf-4025-8cc1-680d432ec2f1 | https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%2016.pdf | CVE-2023-3884 | https://nvd.nist.gov/vuln/detail/CVE-2023-3884 | 2023-07-28 19:03:00 | A vulnerability has been found in Campcodes Beauty Salon Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/edit_product.php. The manipulation of the argument id leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235246 is the identifier assigned to this vulnerability. | Exploits_InTheWild,Exploits_NVD |
adf45b62-76e4-4445-9932-42bfadc901b3 | https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%2015.pdf | CVE-2023-3883 | https://nvd.nist.gov/vuln/detail/CVE-2023-3883 | 2023-07-28 19:03:00 | A vulnerability, which was classified as problematic, was found in Campcodes Beauty Salon Management System 1.0. This affects an unknown part of the file /admin/add-category.php. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235245 was assigned to this vulnerability. | Exploits_InTheWild,Exploits_NVD |
8a702ac9-bf13-40c9-8a07-4f1f754c5422 | https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%2014.pdf | CVE-2023-3882 | https://nvd.nist.gov/vuln/detail/CVE-2023-3882 | 2023-07-28 19:03:00 | A vulnerability, which was classified as critical, has been found in Campcodes Beauty Salon Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/edit-accepted-appointment.php. The manipulation of the argument contactno leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235244. | Exploits_InTheWild,Exploits_NVD |
0c15fd7c-c0e2-4161-a682-7a92ddcfdb79 | https://github.com/CYN521/cve/blob/main/NS-ASG.md | CVE-2023-3792 | https://nvd.nist.gov/vuln/detail/CVE-2023-3792 | 2023-07-28 19:03:00 | A vulnerability was found in Beijing Netcon NS-ASG 6.3. It has been classified as problematic. This affects an unknown part of the file /admin/test_status.php. The manipulation leads to direct request. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235059. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | Exploits_InTheWild,Exploits_NVD |
ef13e4a4-1492-41ac-83fb-5eaff9697fbf | https://www.whid.ninja/blog/mojobox-yet-another-not-so-smartlock | CVE-2023-34625 | https://nvd.nist.gov/vuln/detail/CVE-2023-34625 | 2023-07-28 19:00:00 | ShowMojo MojoBox Digital Lockbox 1.4 is vulnerable to Authentication Bypass. The implementation of the lock opening mechanism via Bluetooth Low Energy (BLE) is vulnerable to replay attacks. A malicious user is able to intercept BLE requests and replicate them to open the lock at any time. Alternatively, an attacker with physical access to the device on which the Android app is installed, can obtain the latest BLE messages via the app logs and use them for opening the lock. | Exploits_InTheWild,Exploits_NVD |
856a979c-a11b-46af-adb6-538069f59e0e | https://mandomat.github.io/2023-03-15-testing-mojobox-security/ | CVE-2023-34625 | https://nvd.nist.gov/vuln/detail/CVE-2023-34625 | 2023-07-28 19:00:00 | ShowMojo MojoBox Digital Lockbox 1.4 is vulnerable to Authentication Bypass. The implementation of the lock opening mechanism via Bluetooth Low Energy (BLE) is vulnerable to replay attacks. A malicious user is able to intercept BLE requests and replicate them to open the lock at any time. Alternatively, an attacker with physical access to the device on which the Android app is installed, can obtain the latest BLE messages via the app logs and use them for opening the lock. | Exploits_InTheWild,Exploits_NVD |
00d83fee-f54a-418c-9489-27c45ecce7cf | https://github.com/TXPH/CVE/blob/main/sqli-report.pdf | CVE-2023-3839 | https://nvd.nist.gov/vuln/detail/CVE-2023-3839 | 2023-07-28 18:47:00 | A vulnerability, which was classified as problematic, has been found in DedeBIZ 6.2.10. Affected by this issue is some unknown functionality of the file /admin/sys_sql_query.php. The manipulation of the argument sqlquery leads to sql injection. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. VDB-235190 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | Exploits_InTheWild,Exploits_NVD |
f79ea5aa-290d-4665-8a32-466bf12fd364 | https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%2012.pdf | CVE-2023-3880 | https://nvd.nist.gov/vuln/detail/CVE-2023-3880 | 2023-07-28 18:22:00 | A vulnerability classified as critical has been found in Campcodes Beauty Salon Management System 1.0. Affected is an unknown function of the file /admin/del_service.php. The manipulation of the argument editid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-235242 is the identifier assigned to this vulnerability. | Exploits_InTheWild,Exploits_NVD |
ff374611-966c-4f2e-b1d6-acf39801522d | https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%2020.pdf | CVE-2023-3888 | https://nvd.nist.gov/vuln/detail/CVE-2023-3888 | 2023-07-28 18:21:00 | A vulnerability was found in Campcodes Beauty Salon Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-235250 is the identifier assigned to this vulnerability. | Exploits_InTheWild,Exploits_NVD |
4e9527a7-24d3-4ec3-93a3-862879a48236 | https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%2013.pdf | CVE-2023-3881 | https://nvd.nist.gov/vuln/detail/CVE-2023-3881 | 2023-07-28 18:21:00 | A vulnerability classified as critical was found in Campcodes Beauty Salon Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/forgot-password.php. The manipulation of the argument contactno leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235243. | Exploits_InTheWild,Exploits_NVD |
c043df6f-c2be-4287-9197-22fc889c776d | https://github.com/qiuhuihk/cve/blob/main/upload.md | CVE-2023-3836 | https://nvd.nist.gov/vuln/detail/CVE-2023-3836 | 2023-07-28 18:17:00 | A vulnerability classified as critical was found in Dahua Smart Park Management up to 20230713. This vulnerability affects unknown code of the file /emap/devicePoint_addImgIco?hasSubsystem=true. The manipulation of the argument upload leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235162 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | Exploits_InTheWild,Exploits_NVD |
f8d684e7-7716-47da-a487-2f9f8ffcba9d | https://github.com/TXPH/CVE/blob/main/xss-report.pdf | CVE-2023-3837 | https://nvd.nist.gov/vuln/detail/CVE-2023-3837 | 2023-07-28 18:16:00 | A vulnerability classified as problematic has been found in DedeBIZ 6.2.10. Affected is an unknown function of the file /admin/sys_sql_query.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235188. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | Exploits_InTheWild,Exploits_NVD |
ce629dc4-4665-4914-b3d4-0126d7271c5e | https://github.com/TXPH/CVE/blob/main/xss-report2.pdf | CVE-2023-3838 | https://nvd.nist.gov/vuln/detail/CVE-2023-3838 | 2023-07-28 17:55:00 | A vulnerability classified as problematic was found in DedeBIZ 6.2.10. Affected by this vulnerability is an unknown functionality of the file /admin/vote_edit.php. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235189 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | Exploits_InTheWild,Exploits_NVD |
7e21e580-9c6c-40d5-9060-a99b51bfcfe4 | https://youtu.be/XlRVwWXpv4w | CVE-2023-3763 | https://nvd.nist.gov/vuln/detail/CVE-2023-3763 | 2023-07-28 17:51:00 | A vulnerability was found in Intergard SGS 8.7.0. It has been declared as problematic. This vulnerability affects unknown code of the component SQL Query Handler. The manipulation leads to cleartext transmission of sensitive information. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-234448. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | Exploits_InTheWild,Exploits_NVD |
32bb5574-45f0-4115-859b-34f3a1a2b80b | https://youtu.be/yW4tRnjDjhM | CVE-2023-3759 | https://nvd.nist.gov/vuln/detail/CVE-2023-3759 | 2023-07-28 17:51:00 | A vulnerability, which was classified as critical, was found in Intergard SGS 8.7.0. Affected is an unknown function. The manipulation leads to permission issues. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-234444. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | Exploits_InTheWild,Exploits_NVD |
0d5ea219-2fdb-4368-8fdd-db05b7d70b03 | https://github.com/convisolabs/CVE-2022-24834 | CVE-2022-24834 | https://nvd.nist.gov/vuln/detail/CVE-2022-24834 | 2023-07-28 17:42:33 | Redis is an in-memory database that persists on disk. A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson library, and result with heap corruption and potentially remote code execution. The problem exists in all versions of Redis with Lua scripting support, starting from 2.6, and affects only authenticated and authorized users. The problem is fixed in versions 7.0.12, 6.2.13, and 6.0.20. | Exploits_CVE_Monitor,Exploits_InTheWild,Exploits_PoC_CVE |
69258448-b75d-489c-864b-4cd2a82290df | https://github.com/nagenanhai/cve/blob/main/2.pdf | CVE-2023-3872 | https://nvd.nist.gov/vuln/detail/CVE-2023-3872 | 2023-07-28 17:26:00 | A vulnerability classified as critical was found in Campcodes Beauty Salon Management System 1.0. This vulnerability affects unknown code of the file /admin/edit-services.php. The manipulation of the argument editid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235234 is the identifier assigned to this vulnerability. | Exploits_InTheWild,Exploits_NVD |
ea2f066f-d306-4033-9166-425277e48a61 | https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%207.pdf | CVE-2023-3875 | https://nvd.nist.gov/vuln/detail/CVE-2023-3875 | 2023-07-28 17:18:00 | A vulnerability has been found in Campcodes Beauty Salon Management System 0.1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/del_feedback.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235237 was assigned to this vulnerability. | Exploits_InTheWild,Exploits_NVD |
873edffd-349c-42c5-855f-d26c36fdd502 | https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%206.pdf | CVE-2023-3874 | https://nvd.nist.gov/vuln/detail/CVE-2023-3874 | 2023-07-28 17:17:00 | A vulnerability, which was classified as critical, was found in Campcodes Beauty Salon Management System 1.0. Affected is an unknown function of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235236. | Exploits_InTheWild,Exploits_NVD |
e62b8860-a213-457a-acad-317432848c5c | https://github.com/nagenanhai/cve/blob/main/3.pdf | CVE-2023-3873 | https://nvd.nist.gov/vuln/detail/CVE-2023-3873 | 2023-07-28 17:16:00 | A vulnerability, which was classified as critical, has been found in Campcodes Beauty Salon Management System 1.0. This issue affects some unknown processing of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235235. | Exploits_InTheWild,Exploits_NVD |
6d287b36-90c1-45b8-9810-81eef31dd796 | https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%2021.pdf | CVE-2023-3890 | https://nvd.nist.gov/vuln/detail/CVE-2023-3890 | 2023-07-28 17:13:00 | A vulnerability classified as problematic has been found in Campcodes Beauty Salon Management System 1.0. This affects an unknown part of the file /admin/edit-accepted-appointment.php. The manipulation of the argument id leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235251. | Exploits_InTheWild,Exploits_NVD |
36340d1a-05ca-4950-8554-cea866527a2c | https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%208.pdf | CVE-2023-3876 | https://nvd.nist.gov/vuln/detail/CVE-2023-3876 | 2023-07-28 16:57:00 | A vulnerability was found in Campcodes Beauty Salon Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/search-appointment.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-235238 is the identifier assigned to this vulnerability. | Exploits_InTheWild,Exploits_NVD |
b86268dc-2b40-433c-8bdf-0b96afa60425 | https://seclists.org/fulldisclosure/2023/Jul/34 | CVE-2023-3788 | https://nvd.nist.gov/vuln/detail/CVE-2023-3788 | 2023-07-28 16:57:00 | A vulnerability, which was classified as problematic, has been found in ActiveITzone Active Super Shop CMS 2.5. This issue affects some unknown processing of the component Manage Details Page. The manipulation of the argument name/phone/address leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235055. | Exploits_InTheWild,Exploits_NVD |
8227934e-bb8d-415b-9012-691dfc30b44f | https://www.vulnerability-lab.com/get_content.php?id=2278 | CVE-2023-3788 | https://nvd.nist.gov/vuln/detail/CVE-2023-3788 | 2023-07-28 16:57:00 | A vulnerability, which was classified as problematic, has been found in ActiveITzone Active Super Shop CMS 2.5. This issue affects some unknown processing of the component Manage Details Page. The manipulation of the argument name/phone/address leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235055. | Exploits_InTheWild,Exploits_NVD |
709418ff-9fe9-4053-b0f0-b858eeee7d24 | https://github.com/chakra-core/ChakraCore/issues/6887 | CVE-2023-37142 | https://nvd.nist.gov/vuln/detail/CVE-2023-37142 | 2023-07-27 04:00:00 | ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::EntryPointInfo::HasInlinees(). | Exploits_InTheWild,Exploits_NVD |
7838146c-4ffa-4128-b1f8-467e5eab381d | https://github.com/nagenanhai/cve/blob/main/1.pdf | CVE-2023-3871 | https://nvd.nist.gov/vuln/detail/CVE-2023-3871 | 2023-07-28 16:56:00 | A vulnerability classified as critical has been found in Campcodes Beauty Salon Management System 1.0. This affects an unknown part of the file /admin/edit_category.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235233 was assigned to this vulnerability. | Exploits_InTheWild,Exploits_NVD |
68d9912e-01fe-4960-a9a8-351f4e78a264 | http://packetstormsecurity.com/files/173691/mooDating-1.2-Cross-Site-Scripting.html | CVE-2023-3843 | https://nvd.nist.gov/vuln/detail/CVE-2023-3843 | 2023-07-28 16:32:00 | A vulnerability was found in mooSocial mooDating 1.2. It has been classified as problematic. Affected is an unknown function of the file /matchmakings/question of the component URL Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. VDB-235194 is the identifier assigned to this vulnerability. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly. | Exploits_InTheWild,Exploits_NVD |
7487aee2-fc34-497b-8dbd-10a37e2684e8 | https://huntr.dev/bounties/4be5fd63-8a0a-490d-9ee1-f33dc768ed76 | CVE-2023-3765 | https://nvd.nist.gov/vuln/detail/CVE-2023-3765 | 2023-07-28 15:58:00 | Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0. | Exploits_InTheWild,Exploits_NVD |
770df3af-c7db-4d55-9544-dd5fa89e7cd9 | https://seclists.org/fulldisclosure/2023/Jul/36 | CVE-2023-3789 | https://nvd.nist.gov/vuln/detail/CVE-2023-3789 | 2023-07-28 15:57:00 | A vulnerability, which was classified as problematic, was found in PaulPrinting CMS 2018. Affected is an unknown function of the file /account/delivery of the component Search. The manipulation of the argument s leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235056. | Exploits_InTheWild,Exploits_NVD |
62dfd5fd-8bee-4361-8066-feb1b216d03c | https://www.vulnerability-lab.com/get_content.php?id=2286 | CVE-2023-3789 | https://nvd.nist.gov/vuln/detail/CVE-2023-3789 | 2023-07-28 15:57:00 | A vulnerability, which was classified as problematic, was found in PaulPrinting CMS 2018. Affected is an unknown function of the file /account/delivery of the component Search. The manipulation of the argument s leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235056. | Exploits_InTheWild,Exploits_NVD |
0dbf1212-de24-47b6-9d2f-2b7e9cd03902 | https://seclists.org/fulldisclosure/2023/Jul/35 | CVE-2023-3787 | https://nvd.nist.gov/vuln/detail/CVE-2023-3787 | 2023-07-28 15:56:00 | A vulnerability classified as problematic was found in Codecanyon Tiva Events Calender 1.4. This vulnerability affects unknown code. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235054 is the identifier assigned to this vulnerability. | Exploits_InTheWild,Exploits_NVD |
d74a82bb-bdf6-4c48-b6c8-dd53848b02ea | https://www.vulnerability-lab.com/get_content.php?id=2276 | CVE-2023-3787 | https://nvd.nist.gov/vuln/detail/CVE-2023-3787 | 2023-07-28 15:56:00 | A vulnerability classified as problematic was found in Codecanyon Tiva Events Calender 1.4. This vulnerability affects unknown code. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235054 is the identifier assigned to this vulnerability. | Exploits_InTheWild,Exploits_NVD |
bcbf9393-333b-4f66-9e61-aff360b11221 | https://github.com/feathersjs/feathers/security/advisories/GHSA-hhr9-rh25-hvf9 | CVE-2023-37899 | https://nvd.nist.gov/vuln/detail/CVE-2023-37899 | 2023-07-28 15:55:00 | Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Feathers socket handler did not catch invalid string conversion errors like `const message = ${{ toString: '' }}` which would cause the NodeJS process to crash when sending an unexpected Socket.io message like `socket.emit('find', { toString: '' })`. A fix has been released in versions 5.0.8 and 4.5.18. Users are advised to upgrade. There is no known workaround for this vulnerability. | Exploits_InTheWild,Exploits_NVD |
e86e2634-c54c-4f0d-82e6-d0bb54dfb502 | https://github.com/aio-libs/aiohttp/security/advisories/GHSA-45c4-8wx5-qw6w | CVE-2023-37276 | https://nvd.nist.gov/vuln/detail/CVE-2023-37276 | 2023-07-28 15:55:00 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. aiohttp v3.8.4 and earlier are bundled with llhttp v6.0.6. Vulnerable code is used by aiohttp for its HTTP request parser when available which is the default case when installing from a wheel. This vulnerability only affects users of aiohttp as an HTTP server (ie `aiohttp.Application`), you are not affected by this vulnerability if you are using aiohttp as an HTTP client library (ie `aiohttp.ClientSession`). Sending a crafted HTTP request will cause the server to misinterpret one of the HTTP header values leading to HTTP request smuggling. This issue has been addressed in version 3.8.5. Users are advised to upgrade. Users unable to upgrade can reinstall aiohttp using `AIOHTTP_NO_EXTENSIONS=1` as an environment variable to disable the llhttp HTTP request parser implementation. The pure Python implementation isn't vulnerable. | Exploits_InTheWild,Exploits_NVD |
390cacb0-2c0d-49c5-880c-a5414652552c | https://hackerone.com/reports/2001873 | CVE-2023-30589 | https://nvd.nist.gov/vuln/detail/CVE-2023-30589 | 2023-07-11 17:21:00 | The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).
The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence should delimit each header-field. This impacts all Node.js active versions: v16, v18, and, v20 | Exploits_InTheWild,Exploits_NVD |
2a1c358e-16c3-44f8-baa6-7213817d9453 | https://www.vulnerability-lab.com/get_content.php?id=2317 | CVE-2023-3784 | https://nvd.nist.gov/vuln/detail/CVE-2023-3784 | 2023-07-28 15:52:00 | A vulnerability was found in Dooblou WiFi File Explorer 1.13.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument search/order/download/mode leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235051. | Exploits_InTheWild,Exploits_NVD |
61e54df6-3c5f-4b22-9b62-5964170f99a2 | https://seclists.org/fulldisclosure/2023/Jul/37 | CVE-2023-3784 | https://nvd.nist.gov/vuln/detail/CVE-2023-3784 | 2023-07-28 15:52:00 | A vulnerability was found in Dooblou WiFi File Explorer 1.13.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument search/order/download/mode leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235051. | Exploits_InTheWild,Exploits_NVD |
cc27125d-5289-4800-bf18-0c300319b845 | https://www.vulnerability-lab.com/get_content.php?id=2321 | CVE-2023-3783 | https://nvd.nist.gov/vuln/detail/CVE-2023-3783 | 2023-07-28 15:52:00 | A vulnerability was found in Webile 1.0.1. It has been classified as problematic. Affected is an unknown function of the component HTTP POST Request Handler. The manipulation of the argument new_file_name/c leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-235050 is the identifier assigned to this vulnerability. | Exploits_InTheWild,Exploits_NVD |
6317dc3f-9e1f-4457-ad80-aa2d95fca291 | https://seclists.org/fulldisclosure/2023/Jul/38 | CVE-2023-3783 | https://nvd.nist.gov/vuln/detail/CVE-2023-3783 | 2023-07-28 15:52:00 | A vulnerability was found in Webile 1.0.1. It has been classified as problematic. Affected is an unknown function of the component HTTP POST Request Handler. The manipulation of the argument new_file_name/c leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-235050 is the identifier assigned to this vulnerability. | Exploits_InTheWild,Exploits_NVD |
23b35b70-3fae-44b9-9309-7f34704f63c1 | https://www.vulnerability-lab.com/get_content.php?id=2285 | CVE-2023-3785 | https://nvd.nist.gov/vuln/detail/CVE-2023-3785 | 2023-07-28 15:41:00 | A vulnerability was found in PaulPrinting CMS 2018. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument firstname/lastname/address/city/state leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235052. | Exploits_InTheWild,Exploits_NVD |
f557e012-6238-44a6-bf14-be63d9c8f50b | https://seclists.org/fulldisclosure/2023/Jul/39 | CVE-2023-3785 | https://nvd.nist.gov/vuln/detail/CVE-2023-3785 | 2023-07-28 15:41:00 | A vulnerability was found in PaulPrinting CMS 2018. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument firstname/lastname/address/city/state leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235052. | Exploits_InTheWild,Exploits_NVD |
70b52634-77a9-4e72-abf2-ee0d3a14d355 | https://research.jfrog.com/vulnerabilities/okhttp-client-brotli-dos/ | CVE-2023-3782 | https://nvd.nist.gov/vuln/detail/CVE-2023-3782 | 2023-07-28 14:57:00 | DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb into an HTTP response
| Exploits_InTheWild,Exploits_NVD |
bdd0cb92-9193-48f6-96f8-75de58338122 | https://github.com/miniupnp/ngiflib/issues/25 | CVE-2023-37748 | https://nvd.nist.gov/vuln/detail/CVE-2023-37748 | 2023-07-28 14:55:00 | ngiflib commit 5e7292 was discovered to contain an infinite loop via the function DecodeGifImg at ngiflib.c. | Exploits_InTheWild,Exploits_NVD |
2e4da850-cfbe-49f5-a690-6014f22749b7 | https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1927070 | CVE-2021-32256 | https://nvd.nist.gov/vuln/detail/CVE-2021-32256 | 2023-07-28 14:08:00 | An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c. | Exploits_InTheWild,Exploits_NVD |
197d6c11-d809-45a1-8d2a-4915c032d6e1 | https://cacharros-inthewild.blogspot.com/2023/07/the-3080ipx-is-integrated-multicast.html | CVE-2020-22159 | https://nvd.nist.gov/vuln/detail/CVE-2020-22159 | 2023-07-28 13:52:00 | EVERTZ devices 3080IPX exe-guest-v1.2-r26125, 7801FC 1.3 Build 27, and 7890IXG V494 are vulnerable to Arbitrary File Upload, allowing an authenticated attacker to upload a webshell or overwrite any critical system files. | Exploits_InTheWild,Exploits_NVD |
a895592e-9f6b-4061-a4e4-5bafcc4969b3 | https://github.com/segonse/cve/blob/main/sichuang/sichuang.md | CVE-2023-3797 | https://nvd.nist.gov/vuln/detail/CVE-2023-3797 | 2023-07-28 13:43:00 | A vulnerability, which was classified as critical, was found in Gen Technology Four Mountain Torrent Disaster Prevention and Control of Monitoring and Early Warning System up to 20230712. This affects an unknown part of the file /Duty/AjaxHandle/UploadFloodPlanFileUpdate.ashx. The manipulation of the argument Filedata leads to unrestricted upload. The exploit has been disclosed to the public and may be used. The identifier VDB-235065 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | Exploits_InTheWild,Exploits_NVD |
5bca1692-689f-4a9d-81c8-f8f75b735a98 | https://github.com/RCEraser/cve/blob/main/wanjiang.md | CVE-2023-3798 | https://nvd.nist.gov/vuln/detail/CVE-2023-3798 | 2023-07-28 13:42:00 | A vulnerability has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0 and classified as critical. This vulnerability affects unknown code of the file /App_Resource/UEditor/server/upload.aspx. The manipulation of the argument file leads to unrestricted upload. The exploit has been disclosed to the public and may be used. VDB-235066 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | Exploits_InTheWild,Exploits_NVD |
efa0772a-cf10-4b48-9d31-543a31c4a75b | https://fluidattacks.com/advisories/indio/ | CVE-2023-30791 | https://nvd.nist.gov/vuln/detail/CVE-2023-30791 | 2023-07-28 13:31:00 | Plane version 0.7.1-dev allows an attacker to change the avatar of his profile, which allows uploading files with HTML extension that interprets both HTML and JavaScript.
| Exploits_InTheWild,Exploits_NVD |
aeb088a4-2dcb-4485-8cdd-db997cf7d500 | https://github.com/emqx/emqx/issues/10419 | CVE-2023-37781 | https://nvd.nist.gov/vuln/detail/CVE-2023-37781 | 2023-07-28 13:26:00 | An issue in the emqx_sn plugin of EMQX v4.3.8 allows attackers to execute a directory traversal via uploading a crafted .txt file. | Exploits_InTheWild,Exploits_NVD |
80883f3b-f9e5-4c63-8a96-0c0869873441 | https://wpscan.com/vulnerability/545007fc-3173-47b1-82c4-ed3fd1247b9c | CVE-2023-3186 | https://nvd.nist.gov/vuln/detail/CVE-2023-3186 | 2023-07-28 13:24:00 | The Popup by Supsystic WordPress plugin before 1.10.19 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties into Object.prototype. | Exploits_InTheWild,Exploits_NVD |
ca46cc42-c461-463a-a397-7e04c1212996 | https://gitlab.freedesktop.org/pixman/pixman/-/issues/76 | CVE-2023-37769 | https://nvd.nist.gov/vuln/detail/CVE-2023-37769 | 2023-07-28 13:22:00 | stress-test master commit e4c878 was discovered to contain a FPE vulnerability via the component combine_inner at /pixman-combine-float.c. | Exploits_InTheWild,Exploits_NVD |
a08916a1-0feb-46dc-b8a4-d0afac9ccc12 | https://wpscan.com/vulnerability/f9f8ae7e-6621-4e29-9257-b8306dbe8811 | CVE-2023-3245 | https://nvd.nist.gov/vuln/detail/CVE-2023-3245 | 2023-07-28 13:22:00 | The Floating Chat Widget WordPress plugin before 3.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | Exploits_InTheWild,Exploits_NVD |
b55d59c1-341b-4d6c-b800-ad6a3ddd4bb0 | https://hackmd.io/@pSgS7xsnS5a4K7Y0yiB43g/rJr8oNn_n | CVE-2023-37758 | https://nvd.nist.gov/vuln/detail/CVE-2023-37758 | 2023-07-28 13:07:00 | D-LINK DIR-815 v1.01 was discovered to contain a buffer overflow via the component /web/captcha.cgi. | Exploits_InTheWild |
bbb8fd69-267e-4c97-813f-ea84252dc6e8 | https://github.com/Pumpkin-Garden/POC_Metabase_CVE-2023-38646 | CVE-2023-38646 | https://nvd.nist.gov/vuln/detail/CVE-2023-38646 | 2023-07-28 11:43:06 | Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2. | Exploits_CVE_Monitor,Exploits_InTheWild,Exploits_PoC_CVE |
e6b5def8-caa0-4871-90c3-ec208ea5c2f1 | https://github.com/GUIqizsq/cve/blob/main/sql.md | CVE-2023-3799 | https://nvd.nist.gov/vuln/detail/CVE-2023-3799 | 2023-07-28 00:20:00 | A vulnerability was found in IBOS OA 4.5.5 and classified as critical. This issue affects some unknown processing of the file ?r=article/category/del of the component Delete Category Handler. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235067. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | Exploits_InTheWild,Exploits_NVD |
0394532f-d72b-44a2-8307-a83114f4c22c | https://github.com/weng-xianhu/eyoucms/issues/50 | CVE-2023-37645 | https://nvd.nist.gov/vuln/detail/CVE-2023-37645 | 2023-07-27 23:49:00 | eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt. | Exploits_InTheWild,Exploits_NVD |
37307ebd-f56c-4fb0-9864-12a8e9f50c25 | https://www.akamai.com/blog/security-research/exploit-steelseries-subapp-privilege-escalation | CVE-2023-31461 | https://nvd.nist.gov/vuln/detail/CVE-2023-31461 | 2023-07-27 23:40:00 | Attackers can exploit an open API listener on SteelSeries GG 36.0.0 to create a sub-application that will be executed automatically from a controlled location, because of a path traversal vulnerability. | Exploits_InTheWild,Exploits_NVD |
62fbe313-6496-47b0-aa54-a5c0c35794bc | https://github.com/khmk2k/CVE-2023-31753/ | CVE-2023-31753 | https://nvd.nist.gov/vuln/detail/CVE-2023-31753 | 2023-07-27 23:37:00 | SQL injection vulnerability in diskusi.php in eNdonesia 8.7, allows an attacker to execute arbitrary SQL commands via the "rid=" parameter. | Exploits_InTheWild,Exploits_NVD |
6e24b967-7518-49b6-a67e-57770e52b830 | https://medium.com/@ayush.engr29/cve-2023-37728-6dfb7586311 | CVE-2023-37728 | https://nvd.nist.gov/vuln/detail/CVE-2023-37728 | 2023-07-27 23:36:00 | IceWarp v10.2.1 was discovered to contain cross-site scripting (XSS) vulnerability via the color parameter. | Exploits_InTheWild |
7ccab381-b577-48cf-9848-51188329add3 | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/wd_mycloud_unauthenticated_cmd_injection.rb | CVE-2018-17153 | https://nvd.nist.gov/vuln/detail/CVE-2018-17153 | 2023-07-27 23:09:50 | It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated attacker can exploit this vulnerability to authenticate as an admin user without needing to provide a password, thereby gaining full control of the device. (Whenever an admin logs into My Cloud, a server-side session is created that is bound to the user's IP address. After the session is created, it is possible to call authenticated CGI modules by sending the cookie username=admin in the HTTP request. The invoked CGI will check if a valid session is present and bound to the user's IP address.) It was found that it is possible for an unauthenticated attacker to create a valid session without a login. The network_mgr.cgi CGI module contains a command called "cgi_get_ipv6" that starts an admin session -- tied to the IP address of the user making the request -- if the additional parameter "flag" with the value "1" is provided. Subsequent invocation of commands that would normally require admin privileges now succeed if an attacker sets the username=admin cookie. | Exploits_InTheWild |
5e73913b-da57-4498-8f5b-3932a0431ecf | https://youtu.be/CtOFB-L1rOg | CVE-2023-3760 | https://nvd.nist.gov/vuln/detail/CVE-2023-3760 | 2023-07-27 23:08:00 | A vulnerability has been found in Intergard SGS 8.7.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Change Password Handler. The manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-234445 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | Exploits_InTheWild,Exploits_NVD |
66c22163-2762-4545-92ff-d23c5d4f6660 | https://huntr.dev/bounties/be6616eb-384d-40d6-b1fd-0ec9e4973f12 | CVE-2023-3692 | https://nvd.nist.gov/vuln/detail/CVE-2023-3692 | 2023-07-27 19:56:00 | Unrestricted Upload of File with Dangerous Type in GitHub repository admidio/admidio prior to 4.2.10. | Exploits_InTheWild,Exploits_NVD |
b7b67cd1-4b05-4500-9b52-422112056e5d | https://huntr.dev/bounties/e8d530db-a6a7-4f79-a95d-b77654cc04f8 | CVE-2023-3700 | https://nvd.nist.gov/vuln/detail/CVE-2023-3700 | 2023-07-27 19:54:00 | Authorization Bypass Through User-Controlled Key in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
| Exploits_InTheWild,Exploits_NVD |
f806ef9e-70a0-4ec9-a78b-39b9a4b939f8 | https://lore.kernel.org/all/CABcoxUayum5oOqFMMqAeWuS8+EzojquSOSyDA3J_2omY=2EeAg@mail.gmail.com/ | CVE-2023-0160 | https://nvd.nist.gov/vuln/detail/CVE-2023-0160 | 2023-07-27 19:48:00 | A deadlock flaw was found in the Linux kernel’s BPF subsystem. This flaw allows a local user to potentially crash the system. | Exploits_InTheWild,Exploits_NVD |
174311a3-9866-4302-a26f-48c5fe49c584 | https://github.com/9001/copyparty/security/advisories/GHSA-pxfv-7rr3-2qjg | CVE-2023-37474 | https://nvd.nist.gov/vuln/detail/CVE-2023-37474 | 2023-07-27 19:47:00 | Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path Traversal attack technique allows an attacker access to files, directories, and commands that reside outside the web document root directory. This issue has been addressed in commit `043e3c7d` which has been included in release 1.8.2. Users are advised to upgrade. There are no known workarounds for this vulnerability. | Exploits_InTheWild,Exploits_NVD |
ba06e59b-a6a4-4197-8a73-24ce4bb059f0 | https://talosintelligence.com/vulnerability_reports/TALOS-2022-1666 | CVE-2022-46291 | https://nvd.nist.gov/vuln/detail/CVE-2022-46291 | 2023-07-27 18:31:00 | Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability affects the MSI file format | Exploits_InTheWild,Exploits_NVD |
9954d332-cb40-482f-907f-1561e8e94111 | https://talosintelligence.com/vulnerability_reports/TALOS-2022-1665 | CVE-2022-46289 | https://nvd.nist.gov/vuln/detail/CVE-2022-46289 | 2023-07-27 18:22:00 | Multiple out-of-bounds write vulnerabilities exist in the ORCA format nAtoms functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.nAtoms calculation wrap-around, leading to a small buffer allocation | Exploits_InTheWild,Exploits_NVD |
f6202b42-c88e-430d-b31f-1313fde99ec1 | https://talosintelligence.com/vulnerability_reports/TALOS-2022-1670 | CVE-2022-46280 | https://nvd.nist.gov/vuln/detail/CVE-2022-46280 | 2023-07-27 18:21:00 | A use of uninitialized pointer vulnerability exists in the PQS format pFormat functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | Exploits_InTheWild,Exploits_NVD |
b8715061-6d66-4a75-8d3f-4633e92f167b | https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-p9xf-74xh-mhw5 | CVE-2023-37477 | https://nvd.nist.gov/vuln/detail/CVE-2023-37477 | 2023-07-27 18:20:00 | 1Panel is an open source Linux server operation and maintenance management panel. An OS command injection vulnerability exists in 1Panel firewall functionality. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. 1Panel firewall functionality `/hosts/firewall/ip` endpoint read user input without validation, the attacker extends the default functionality of the application, which execute system commands. An attacker can execute arbitrary code on the target system, which can lead to a complete compromise of the system. This issue has been addressed in commit `e17b80cff49` which is included in release version `1.4.3`. Users are advised to upgrade. There are no known workarounds for this vulnerability.
| Exploits_InTheWild,Exploits_NVD |
b6ad7184-52c8-4c04-b0c5-feeb28b3ac04 | https://talosintelligence.com/vulnerability_reports/TALOS-2022-1664 | CVE-2022-43607 | https://nvd.nist.gov/vuln/detail/CVE-2022-43607 | 2023-07-27 18:10:00 | An out-of-bounds write vulnerability exists in the MOL2 format attribute and value functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | Exploits_InTheWild,Exploits_NVD |
1684e458-f149-4f3d-a134-b03ec3fe4bd1 | https://talosintelligence.com/vulnerability_reports/TALOS-2022-1669 | CVE-2022-44451 | https://nvd.nist.gov/vuln/detail/CVE-2022-44451 | 2023-07-27 18:09:00 | A use of uninitialized pointer vulnerability exists in the MSI format atom functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | Exploits_InTheWild,Exploits_NVD |
cbeb7c91-e945-48ed-aeec-5521120f6bf3 | https://talosintelligence.com/vulnerability_reports/TALOS-2022-1671 | CVE-2022-43467 | https://nvd.nist.gov/vuln/detail/CVE-2022-43467 | 2023-07-27 18:09:00 | An out-of-bounds write vulnerability exists in the PQS format coord_file functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | Exploits_InTheWild,Exploits_NVD |
f8e36850-e97d-44f6-95c5-5d40e110fb24 | https://talosintelligence.com/vulnerability_reports/TALOS-2022-1672 | CVE-2022-37331 | https://nvd.nist.gov/vuln/detail/CVE-2022-37331 | 2023-07-27 18:06:00 | An out-of-bounds write vulnerability exists in the Gaussian format orientation functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | Exploits_InTheWild,Exploits_NVD |
c3a33ba9-a59a-4833-8b2f-a3d0bd5b074e | https://talosintelligence.com/vulnerability_reports/TALOS-2022-1667 | CVE-2022-41793 | https://nvd.nist.gov/vuln/detail/CVE-2022-41793 | 2023-07-27 18:05:00 | An out-of-bounds write vulnerability exists in the CSR format title functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | Exploits_InTheWild,Exploits_NVD |
4c559ae1-f042-4856-a0a3-724b02505480 | https://talosintelligence.com/vulnerability_reports/TALOS-2022-1668 | CVE-2022-42885 | https://nvd.nist.gov/vuln/detail/CVE-2022-42885 | 2023-07-27 18:04:00 | A use of uninitialized pointer vulnerability exists in the GRO format res functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | Exploits_InTheWild,Exploits_NVD |
38b99267-00e8-4442-806c-a8a628275f8d | https://github.com/naihsin/IoT/tree/main/D-Link/DIR-619L/overflow | CVE-2023-37791 | https://nvd.nist.gov/vuln/detail/CVE-2023-37791 | 2023-07-27 16:11:00 | D-Link DIR-619L v2.04(TW) was discovered to contain a stack overflow via the curTime parameter at /goform/formLogin. | Exploits_InTheWild,Exploits_NVD |
3b893e34-ac58-42bd-844d-8cab948f47cd | https://github.com/michaelrsweet/htmldoc/issues/433 | CVE-2021-34121 | https://nvd.nist.gov/vuln/detail/CVE-2021-34121 | 2023-07-27 15:19:00 | An Out of Bounds flaw was discovered in htmodoc 1.9.12 in function parse_tree() in toc.cxx, this possibly leads to memory layout information leaking in the data. This might be used in a chain of vulnerability in order to reach code execution. | Exploits_InTheWild,Exploits_NVD |
f4c5e871-df53-44ff-8152-62d6264d6793 | https://github.com/michaelrsweet/htmldoc/issues/431 | CVE-2021-34119 | https://nvd.nist.gov/vuln/detail/CVE-2021-34119 | 2023-07-27 15:19:00 | A flaw was discovered in htmodoc 1.9.12 in function parse_paragraph in ps-pdf.cxx ,this flaw possibly allows possible code execution and a denial of service via a crafted file. | Exploits_InTheWild,Exploits_NVD |
85a45334-1d58-4f37-8714-379baae1e0bf | https://sourceware.org/bugzilla/show_bug.cgi?id=27501 | CVE-2021-33294 | https://nvd.nist.gov/vuln/detail/CVE-2021-33294 | 2023-07-27 15:19:00 | In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) via crafted file. | Exploits_InTheWild,Exploits_NVD |
0e75da41-aa2c-4eb1-906e-77dfb72f13fd | https://github.com/libsndfile/libsndfile/issues/832 | CVE-2022-33064 | https://nvd.nist.gov/vuln/detail/CVE-2022-33064 | 2023-07-27 15:14:00 | An off-by-one error in function wav_read_header in src/wav.c in Libsndfile 1.1.0, results in a write out of bound, which allows an attacker to execute arbitrary code, Denial of Service or other unspecified impacts. | Exploits_InTheWild,Exploits_NVD |
3a1ff867-f48f-42c7-8a25-4789411d27cf | https://lana.codes/lanavdb/071fa6eb-2e54-43a1-b37f-1e562988b7d4?_s_id=cve | CVE-2022-34155 | https://nvd.nist.gov/vuln/detail/CVE-2022-34155 | 2023-07-27 15:12:00 | Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 6.23.3.
| Exploits_InTheWild,Exploits_NVD |
7f481b7d-ae65-43fb-8447-31451e83f74c | https://github.com/libsndfile/libsndfile/issues/833 | CVE-2022-33065 | https://nvd.nist.gov/vuln/detail/CVE-2022-33065 | 2023-07-27 15:11:00 | Multiple signed integers overflow in function au_read_header in src/au.c and in functions mat4_open and mat4_read_header in src/mat4.c in Libsndfile, allows an attacker to cause Denial of Service or other unspecified impacts. | Exploits_InTheWild,Exploits_NVD |
2a46947e-3aba-4271-be4a-14287ff05092 | https://doc.rust-lang.org/std/macro.eprintln.html | CVE-2022-47085 | https://nvd.nist.gov/vuln/detail/CVE-2022-47085 | 2023-07-27 15:08:00 | An issue was discovered in ostree before 2022.7 allows attackers to cause a denial of service or other unspecified impacts via the print_panic function in repo_checkout_filter.rs. | Exploits_InTheWild,Exploits_NVD |
1720569b-5187-47ca-9ca6-33b010c97540 | https://github.com/NCI-Agency/anet/issues/4408 | CVE-2023-31441 | https://nvd.nist.gov/vuln/detail/CVE-2023-31441 | 2023-07-27 15:07:00 | In NATO Communications and Information Agency anet (aka Advisor Network) through 3.3.0, an attacker can provide a crafted JSON file to sanitizeJson and cause an exception. This is related to the U+FFFD Unicode replacement character. A for loop does not consider that a data structure is being modified during loop execution. | Exploits_InTheWild,Exploits_NVD |
c77509c9-4378-4168-a121-609eab3ab9af | https://github.com/thorfdbg/libjpeg/issues/87#BUG1 | CVE-2023-37836 | https://nvd.nist.gov/vuln/detail/CVE-2023-37836 | 2023-07-27 15:02:00 | libjpeg commit db33a6e was discovered to contain a reachable assertion via BitMapHook::BitMapHook at bitmaphook.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file. | Exploits_InTheWild,Exploits_NVD |
41e42507-5d7a-40dd-b4d4-624dde48c25b | https://github.com/thorfdbg/libjpeg/issues/87#BUG0 | CVE-2023-37837 | https://nvd.nist.gov/vuln/detail/CVE-2023-37837 | 2023-07-27 15:00:00 | libjpeg commit db33a6e was discovered to contain a heap buffer overflow via LineBitmapRequester::EncodeRegion at linebitmaprequester.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file. | Exploits_InTheWild,Exploits_NVD |
a9d33458-8936-474f-bdc8-c9a10e5d4714 | https://heegong.github.io/posts/Local-privilege-escalation-in-Panda-Dome-VPN-for-Windows-Installer/ | CVE-2023-37849 | https://nvd.nist.gov/vuln/detail/CVE-2023-37849 | 2023-07-27 14:50:00 | A DLL hijacking vulnerability in Panda Security VPN for Windows prior to version v15.14.8 allows attackers to execute arbitrary code via placing a crafted DLL file in the same directory as PANDAVPN.exe. | Exploits_InTheWild,Exploits_NVD |
5c65be17-0fd0-47f3-9875-5c2282dbb9cf | https://github.com/yezere/src/blob/main/Dedecms%20v5.7.109%20Background%20Command%20Execution%20Vulnerability.md | CVE-2023-37839 | https://nvd.nist.gov/vuln/detail/CVE-2023-37839 | 2023-07-27 14:48:00 | An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading a crafted PHP file. | Exploits_InTheWild,Exploits_NVD |
fb8dbc2d-3c92-41b8-a13b-63db85ee682d | https://github.com/sahiloj/CVE-2023-37599 | CVE-2023-37599 | https://nvd.nist.gov/vuln/detail/CVE-2023-37599 | 2023-07-27 14:40:00 | An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory | Exploits_CVE_Monitor,Exploits_InTheWild,Exploits_NVD,Exploits_PoC_CVE |
049d064f-e65b-40c3-84fb-f2278a389177 | https://github.com/rapid7/metasploit-framework/pull/13607 | CVE-2020-7357 | https://nvd.nist.gov/vuln/detail/CVE-2020-7357 | 2023-07-27 13:31:00 | Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue affects several branches and versions of the CMS application, including CME-SE, CMS-60, CMS-40, CMS-20, and CMS version 8.2, 8.0, and 7.5. | Exploits_InTheWild,Exploits_NVD |
a952077c-368d-42ef-8e48-e44a93d58d62 | https://starlabs.sg/advisories/23/23-3514/ | CVE-2023-3514 | https://nvd.nist.gov/vuln/detail/CVE-2023-3514 | 2023-07-27 12:58:00 | Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a malicious actor with local access to gain SYSTEM privilege via communicating with the named pipe as a low-privilege user and calling "AddModule" or "UninstallModules" command to execute arbitrary executable file.
| Exploits_InTheWild,Exploits_NVD |