CVE Vulnerability Database

Search and browse 99 known security vulnerabilities. Filter by severity, vendor, product, and year.

99 vulnerabilities found
CVE-2023-2713
9.8 critical

Authorization Bypass Through User-Controlled Key vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Authentication Abuse, Authentication Bypass.This issue affects Rental Module: before 23.05.15.

Rental Module Project Rental Module May 20, 2023
CVE-2023-2712
9.8 critical

Unrestricted Upload of File with Dangerous Type vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Command Injection, Using Malicious Files, Upload a Web Shell to a Web Server.This issue affects Rental Module: before 23.05.15.

Rental Module Project Rental Module May 20, 2023
CVE-2023-1873
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Faturamatik Bircard allows SQL Injection.This issue affects Bircard: before 23.04.05.

Faturamatik Bircard Apr 17, 2023
CVE-2023-1723
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veragroup Mobile Assistant allows SQL Injection.This issue affects Mobile Assistant: before 21.S.2343.

Vegayazilim Mobile Assistant Apr 17, 2023
CVE-2023-1833
9.8 critical

Authentication Bypass by Primary Weakness vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass.This issue affects Redline Router: before 7.17.

Redline Router Firmware Apr 14, 2023
CVE-2023-1803
9.8 critical

Authentication Bypass by Alternate Name vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass.This issue affects Redline Router: before 7.17.

Redline Router Firmware Apr 14, 2023
CVE-2023-1863
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eskom Water Metering Software allows Command Line Execution through SQL Injection.This issue affects Water Metering Software: before 23.04.06.

Eskom El Terminali \(Su Okuma\) Uygulamalarimiz Apr 14, 2023
CVE-2023-1728
9.8 critical

Unrestricted Upload of File with Dangerous Type vulnerability in Fernus Informatics LMS allows OS Command Injection, Server Side Include (SSI) Injection.This issue affects LMS: before 23.04.03.

Fernus Learning Management Systems Apr 4, 2023
CVE-2023-1765
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Akbim Computer Panon allows SQL Injection.This issue affects Panon: before 1.0.2.

Akbim Panon Apr 3, 2023
CVE-2023-1725
9.8 critical

Server-Side Request Forgery (SSRF) vulnerability in Infoline Project Management System allows Server Side Request Forgery.This issue affects Project Management System: before 4.09.31.125.

Infoline-Tr Project Management System Mar 30, 2023
CVE-2023-1050
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in As Koc Energy Web Report System allows SQL Injection. This issue affects Web Report System: before 23.03.10.

Askoc Web Report System Mar 23, 2023
CVE-2023-1153
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pacsrapor allows SQL Injection, Command Line Execution through SQL Injection. This issue affects Pacsrapor: before 1.22.

Pacsrapor Pacsrapor Mar 21, 2023
CVE-2023-1152
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information Technologies Persolus allows SQL Injection. This issue affects Persolus: before 2.03.93.

Utarit Persolus Mar 17, 2023
CVE-2023-28531
9.8 critical

ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.

Openbsd Openssh Mar 17, 2023
CVE-2023-1198
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saysis Starcities allows SQL Injection. This issue affects Starcities: through 1.3.

Saysis Starcities Mar 10, 2023
CVE-2023-1091
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alpata Licensed Warehousing Automation System allows Command Line Execution through SQL Injection. This issue affects Licensed Warehousing Automation System: through 2023.1.01.

Alpatateknoloji Licensed Warehousing Automation System Mar 10, 2023
CVE-2023-1251
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Akinsoft Wolvox. This issue affects Wolvox: before 8.02.03.

Akinsoft Wolvox Mar 9, 2023
CVE-2023-1267
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ulkem Company PtteM Kart. This issue affects PtteM Kart: before 2.1.

Pttemkart Pttem Kart Mar 8, 2023
CVE-2022-3760
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mia Technology Mia-Med. This issue affects Mia-Med: before 1.0.0.58.

Miateknoloji Mia-Med Mar 7, 2023
CVE-2023-0979
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData MedDataPACS allows SQL Injection. This issue affects MedDataPACS : before 2023-03-03.

Meddatapacs Meddatapacs Mar 6, 2023
CVE-2023-0839
9.8 critical

Improper Protection for Outbound Error Messages and Alert Signals vulnerability in ProMIS Process Co. InSCADA allows Account Footprinting. This issue affects inSCADA: before 20230115-1.

Inscada Project Inscada Mar 6, 2023
CVE-2023-1114
9.8 critical

Missing Authorization vulnerability in Eskom e-Belediye allows Information Elicitation. This issue affects e-Belediye: from 1.0.0.95 before 1.0.0.100.

Eskom E-Belediye Mar 1, 2023
CVE-2023-1064
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Uzay Baskul Weighbridge Automation Software allows SQL Injection. This issue affects Weighbridge Automation Software: before 1.1.

Uzaybaskul Weighbridge Automation Software Mar 1, 2023
CVE-2022-2504
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SDD Computer Software SDD-Baro allows SQL Injection. This issue affects SDD-Baro: before 2.8.432.

Sdd-Baro Project Sdd-Baro Feb 23, 2023