CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2023-46419

    Last Modified: 21 Nov 2024

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415730 function.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46420

    Last Modified: 21 Nov 2024

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41590C function.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46421

    Last Modified: 21 Nov 2024

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411D00 function.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46422

    Last Modified: 21 Nov 2024

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411994 function.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46527

    Last Modified: 21 Nov 2024

    TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin and TL-WDR7660 2.0.30 was discovered to contain a stack overflow via the function bindRequestHandle.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46543

    Last Modified: 21 Nov 2024

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formWlSiteSurvey.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46544

    Last Modified: 21 Nov 2024

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formWirelessTbl.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46546

    Last Modified: 21 Nov 2024

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formStats.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46548

    Last Modified: 21 Nov 2024

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formWlanRedirect.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46549

    Last Modified: 21 Nov 2024

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formSetLg.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46558

    Last Modified: 21 Nov 2024

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMapDelDevice.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46559

    Last Modified: 21 Nov 2024

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIPv6Addr.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46560

    Last Modified: 21 Nov 2024

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formTcpipSetup.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46562

    Last Modified: 21 Nov 2024

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDosCfg.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46563

    Last Modified: 21 Nov 2024

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIpQoS.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46564

    Last Modified: 21 Nov 2024

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDMZ.

    Published: 25 Oct 2023
    6.1
    Medium

    CVE-2023-46583

    Last Modified: 21 Nov 2024

    Cross-Site Scripting (XSS) vulnerability in PHPGurukul Nipah virus (NiV) " Testing Management System v.1.0 allows attackers to execute arbitrary code via a crafted payload injected into the State field.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46584

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in PHPGurukul Nipah virus (NiV) " Testing Management System v.1.0 allows a remote attacker to escalate privileges via a crafted request to the new-user-testing.php endpoint.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46523

    Last Modified: 21 Nov 2024

    TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function upgradeInfoRegister.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46525

    Last Modified: 21 Nov 2024

    TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function loginRegister.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46526

    Last Modified: 21 Nov 2024

    TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function resetCloudPwdRegister.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46541

    Last Modified: 21 Nov 2024

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIpv6Setup.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46542

    Last Modified: 21 Nov 2024

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMeshUploadConfig.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46545

    Last Modified: 21 Nov 2024

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formWsc.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46547

    Last Modified: 21 Nov 2024

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formSysLog.

    Published: 25 Oct 2023
    7.5
    High

    CVE-2023-38849

    Last Modified: 21 Nov 2024

    An issue in tire-sales Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.

    Published: 25 Oct 2023
    7.5
    High

    CVE-2023-38845

    Last Modified: 21 Nov 2024

    An issue in Anglaise Company Anglaise.Company v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.

    Published: 25 Oct 2023
    7.5
    High

    CVE-2023-38846

    Last Modified: 21 Nov 2024

    An issue in Marbre Lapin Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.

    Published: 25 Oct 2023
    7.5
    High

    CVE-2023-38847

    Last Modified: 21 Nov 2024

    An issue in CHRISTINA JAPAN Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.

    Published: 25 Oct 2023
    7.5
    High

    CVE-2023-38848

    Last Modified: 21 Nov 2024

    An issue in rmc R Beauty CLINIC Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-44794

    Last Modified: 21 Nov 2024

    An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL.

    Published: 25 Oct 2023
    7.5
    High

    CVE-2023-43905

    Last Modified: 21 Nov 2024

    Incorrect access control in writercms v1.1.0 allows attackers to directly obtain backend account passwords via unspecified vectors.

    Published: 25 Oct 2023
    6.1
    Medium

    CVE-2023-43906

    Last Modified: 21 Nov 2024

    Xolo CMS v0.11 was discovered to contain a reflected cross-site scripting (XSS) vulnerability.

    Published: 25 Oct 2023
    8.8
    High

    CVE-2023-43961

    Last Modified: 21 Nov 2024

    An issue in Dromara SaToken version 1.3.50RC and before when using Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

    Published: 25 Oct 2023
    7.5
    High

    CVE-2023-46345

    Last Modified: 21 Nov 2024

    Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/xlsparse.c.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46347

    Last Modified: 21 Nov 2024

    In the module "Step by Step products Pack" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform SQL injection. The method `NdkSpack::getPacks()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

    Published: 25 Oct 2023
    5.4
    Medium

    CVE-2023-46396

    Last Modified: 21 Nov 2024

    Audimex 15.0.0 is vulnerable to Cross Site Scripting (XSS) in /audimex/cgi-bin/wal.fcgi via company parameter search filters.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46408

    Last Modified: 21 Nov 2024

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ The 41DD80 function.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46409

    Last Modified: 21 Nov 2024

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ 41CC04 function.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46417

    Last Modified: 21 Nov 2024

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415498 function.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46410

    Last Modified: 21 Nov 2024

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ The 416F60 function.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46411

    Last Modified: 21 Nov 2024

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_415258 function.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46412

    Last Modified: 21 Nov 2024

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_41D998 function.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46413

    Last Modified: 21 Nov 2024

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_4155DC function.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46414

    Last Modified: 21 Nov 2024

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ 41D494 function.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46415

    Last Modified: 21 Nov 2024

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41E588 function.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46416

    Last Modified: 21 Nov 2024

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ The 41A414 function.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46540

    Last Modified: 21 Nov 2024

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formNtp.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46518

    Last Modified: 21 Nov 2024

    Mercury A15 V1.0 20230818_1.0.3 was discovered to contain a command execution vulnerability via the component cloudDeviceTokenSuccCB.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46520

    Last Modified: 21 Nov 2024

    TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function uninstallPluginReqHandle.

    Published: 25 Oct 2023