Common Vulnerabilities and Exposures (CVE)

CVE-2023-4103

Sep 19, 2024 20:22:31 UTC

QSige statistics are affected by a remote SQLi vulnerability. It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prerequisite, it is neces...

CVE-2023-37935

Sep 19, 2024 20:22:22 UTC

A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able...

CVE-2023-36547

Sep 19, 2024 20:21:28 UTC

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically ...

CVE-2023-5350

Sep 19, 2024 20:17:01 UTC

SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1.

CVE-2023-5351

Sep 19, 2024 20:16:27 UTC

Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1.

CVE-2023-0506

Sep 19, 2024 20:15:43 UTC

The web service of ByDemes Group Airspace CCTV Web Service in its 2.616.BY00.11 version, contains a privilege escalation vulnerability, detected in the Camera Control Panel, whose exploitation could allow a low-privileged attacker to gain a...

CVE-2024-9001

Sep 19, 2024 20:11:23 UTC

A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. This vulnerability affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument command leads to os comman...

CVE-2023-4097

Sep 19, 2024 20:02:40 UTC

The file upload functionality is not implemented correctly and allows uploading of any type of file. As a prerequisite, it is necessary for the attacker to log into the application with a valid username.

CVE-2023-4577

Sep 19, 2024 20:02:40 UTC

When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbage collected prior to entering the function, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 1...

CVE-2023-4578

Sep 19, 2024 20:02:19 UTC

When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErrorAndClear`. A path in the function could attempt to allocate memory when none is available which would have caused a new...

CVE-2023-4580

Sep 19, 2024 20:01:56 UTC

Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.

CVE-2024-45620

Sep 19, 2024 20:00:52 UTC

A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, i...

CVE-2023-4582

Sep 19, 2024 20:00:33 UTC

Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could have occured when allocating too much private shader memory on mac OS. *This bug only affects Firefox on macOS. Other operating systems are ...

CVE-2023-4583

Sep 19, 2024 19:57:57 UTC

When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already been discarded which was not always the case for private channels after the private sessi...

CVE-2023-4882

Sep 19, 2024 19:57:12 UTC

DOS vulnerability that could allow an attacker to register a new VNF (Virtual Network Function) value. This action could trigger the args_assets() function defined in the arg-log.php file, which would then execute the args-abort.c file, cau...