Security
Headlines
HeadlinesLatestCVEs

Source

CVE

CVE-2023-33273: CVE-Disclosures/CVE-2023-33273.md at main · l4rRyxz/CVE-Disclosures

An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the WGET check function is vulnerable to OS command injection (blind).

CVE
#vulnerability#git
CVE-2023-33272: CVE-Disclosures/CVE-2023-33272.md at main · l4rRyxz/CVE-Disclosures

An issue was discovered in DTS Monitoring 3.57.0. The parameter ip within the Ping check function is vulnerable to OS command injection (blind).

CVE-2023-43952: Security-Advisories/CVE-2023-43952 at main · M19O/Security-Advisories

SSCMS 7.2.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Material Management component.

CVE-2023-43953: Security-Advisories/CVE-2023-43953 at main · M19O/Security-Advisories

SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component.

CVE-2023-43951: Security-Advisories/CVE-2023-43951 at main · M19O/Security-Advisories

SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Column Management component.

CVE-2023-33268: CVE-Disclosures/CVE-2023-33268.md at main · l4rRyxz/CVE-Disclosures

An issue was discovered in DTS Monitoring 3.57.0. The parameter port within the SSL Certificate check function is vulnerable to OS command injection (blind).

CVE-2023-33269: CVE-Disclosures/CVE-2023-33269.md at main · l4rRyxz/CVE-Disclosures

An issue was discovered in DTS Monitoring 3.57.0. The parameter options within the WGET check function is vulnerable to OS command injection (blind).

CVE-2023-33270: CVE-Disclosures/CVE-2023-33270.md at main · l4rRyxz/CVE-Disclosures

An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the Curl check function is vulnerable to OS command injection (blind).

CVE-2023-40830

Tenda AC6 v15.03.05.19 is vulnerable to Buffer Overflow as the Index parameter does not verify the length.

CVE-2023-43976: 2023-43976 - CatoNetworks macOS LPE

An issue in CatoNetworks CatoClient before v.5.4.0 allows attackers to escalate privileges and winning the race condition (TOCTOU) via the PrivilegedHelperTool component.