Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

CVE-2023-26978: ttt/28 at main · Am1ngl/ttt

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pppoeAcName parameter at /setting/setWanIeCfg.

CVE
#vulnerability#web#windows#apple#chrome#webkit
CVE-2023-26848: ttt/23 at main · Am1ngl/ttt

TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the org parameter at setting/delStaticDhcpRules.

Universal Media Server 13.2.1 Cross Site Scripting

Universal Media Server version 13.2.1 suffers from a cross site scripting vulnerability.

BulletProof FTP Server 2019.0.0.51 Denial Of Service

BulletProof FTP Server version 2019.0.0.51 suffers from a denial of service vulnerability.

flatnux 2021-03.25 Remote Code Execution

flatnux version 2021-03.25 suffers from a remote code execution vulnerability.

Auto Dealer Management System 1.0 Broken Access Control

Auto Dealer Management System version 1.0 suffers from a broken access control vulnerability

Intern Record System 1.0 SQL Injection

Intern Record System version 1.0 suffers from a remote SQL injection vulnerability.

CVE-2023-1908: bug_report/SQLi-1.md at main · Kerkong/bug_report

A vulnerability was found in SourceCodester Simple Mobile Comparison Website 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/categories/view_category.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-225150 is the identifier assigned to this vulnerability.