icms
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.
The CVSS severity warrants an early asset and exposure review.Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.
NVD data is used under its public data terms. This service is not endorsed or certified by NVD.iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.
The CVSS severity warrants an early asset and exposure review.iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.
The CVSS severity warrants an early asset and exposure review.In instances where the screen is visible and remote mouse connection is enabled, KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 can be exploited to achieve local code execution at the root level.
The CVSS severity warrants an early asset and exposure review.KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device. This vulnerability involves extracting the connection confirmation code remotely, bypassing the need to obtain it directly from the physical screen.
The CVSS severity warrants an early asset and exposure review.Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which could lead to privilege escalation.
The CVSS severity warrants an early asset and exposure review.OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions in the directory /tmp.
The CVSS severity warrants an early asset and exposure review.ASUS RT-AC66U B1 3.0.0.4.286_51665 was discovered to transmit sensitive information in cleartext.
The CVSS severity warrants an early asset and exposure review.CVE-2023-38180 affects Microsoft .NET Core and Visual Studio. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.
CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.An issue in the CAB file extraction function of Bitberry File Opener v23.0 allows attackers to execute a directory traversal.
The CVSS severity warrants an early asset and exposure review.Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the View Request of Nurse Page in the Admin portal.
The CVSS severity warrants an early asset and exposure review.An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affected functions include from_math_prompt and from_colored_object_prompt.
The CVSS severity warrants an early asset and exposure review.Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due to the fact that session ids are not validated for the type of user accessing the application by default. Privilege restrictions between non-admin and admin users are not enforced and any authenticated user can leverage admin functions without restriction by making direct requests to administrative endpoints.
The CVSS severity warrants an early asset and exposure review.ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server via crafted requests to /base/sftpsetting/ endpoints that abuse a path traversal issue in the Username field and a lack of input sanitization on the SSH Key field. Overwriting specific files may lead to arbitrary code execution as NT AUTHORITY\SYSTEM.
The CVSS severity warrants an early asset and exposure review.A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.
CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrator password via a crafted web request.
The CVSS severity warrants an early asset and exposure review.