Show filters
895 Total Results
Displaying 191-200 of 895
Sort by:
Attacker Value
Unknown

CVE-2023-37565

Disclosure Date: July 13, 2023 (last updated February 25, 2025)
Code injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent authenticated attacker to execute arbitrary code by sending a specially crafted request. Affected products and versions are as follows: WRC-1167GHBK-S v1.03 and earlier, WRC-1167GEBK-S v1.03 and earlier, WRC-1167FEBK-S v1.04 and earlier, WRC-1167GHBK3-A v1.24 and earlier, and WRC-1167FEBK-A v1.18 and earlier.
Attacker Value
Unknown

CVE-2023-38198

Disclosure Date: July 13, 2023 (last updated February 25, 2025)
acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.
Attacker Value
Unknown

CVE-2023-37582

Disclosure Date: July 12, 2023 (last updated February 25, 2025)
The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1. When NameServer address are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function on the NameServer component to execute commands as the system users that RocketMQ is running as. It is recommended for users to upgrade their NameServer version to 5.1.2 or above for RocketMQ 5.x or 4.9.7 or above for RocketMQ 4.x to prevent these attacks.
Attacker Value
Unknown

CVE-2023-37199

Disclosure Date: July 12, 2023 (last updated February 25, 2025)
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE tampers with backups which are then manually restored.
Attacker Value
Unknown

CVE-2023-37198

Disclosure Date: July 12, 2023 (last updated February 25, 2025)
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE uploads or tampers with install packages.
Attacker Value
Unknown

CVE-2023-24492

Disclosure Date: July 11, 2023 (last updated February 25, 2025)
A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute code if a victim user opens an attacker-crafted link and accepts further prompts.
Attacker Value
Unknown

CVE-2023-35333

Disclosure Date: July 11, 2023 (last updated February 25, 2025)
MediaWiki PandocUpload Extension Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2023-37659

Disclosure Date: July 11, 2023 (last updated February 25, 2025)
xalpha v0.11.4 is vulnerable to Remote Command Execution (RCE).
Attacker Value
Unknown

CVE-2023-27869

Disclosure Date: July 10, 2023 (last updated February 25, 2025)
IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked logger injection. By sending a specially crafted request using the named traceFile property, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 249517.
Attacker Value
Unknown

CVE-2023-27868

Disclosure Date: July 10, 2023 (last updated February 25, 2025)
IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked class instantiation when providing plugin classes. By sending a specially crafted request using the named pluginClassName class, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 249516.