Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In February 2023
D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.
CVSS Score
8.8
EPSS Score
0.212
Published
2023-02-02
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP file, leading to arbitrary code execution.
CVSS Score
8.8
EPSS Score
0.311
Published
2023-02-02
PrestaShop module, totadministrativemandate before v1.7.1 was discovered to contain a SQL injection vulnerability.
CVSS Score
8.1
EPSS Score
0.001
Published
2023-02-02
Cross-Site Request Forgery (CSRF) in GitHub repository squidex/squidex prior to 7.4.0.
CVSS Score
6.8
EPSS Score
0.002
Published
2023-02-02
Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.
CVSS Score
5.4
EPSS Score
0.003
Published
2023-02-02
An issue in mRemoteNG v1.76.20 allows attackers to escalate privileges via a crafted executable file. NOTE: third parties were unable to reproduce any scenario in which the claimed access of BUILTIN\Users:(M) is present.
CVSS Score
7.8
EPSS Score
0.0
Published
2023-02-02
A denial of service vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.8.645. A specially-crafted PE file can lead to killing target process. An attacker can provide a malicious file to trigger this vulnerability.
CVSS Score
5.0
EPSS Score
0.0
Published
2023-02-02
The All-in-One WP Migration WordPress plugin before 7.63 uses the wrong content type, and does not properly escape the response from the ai1wm_export AJAX action, allowing an attacker to craft a request that when submitted by any visitor will inject arbitrary html or javascript into the response that will be executed in the victims session. Note: This requires knowledge of a static secret key
CVSS Score
4.7
EPSS Score
0.532
Published
2023-02-02
The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP controls when uploading sensitive data from a mapped drive into a web email client. Loading from a local driver was correctly prevented. Versions prior to 11.9 correctly detected and blocked the attempted upload of sensitive data.
CVSS Score
5.9
EPSS Score
0.001
Published
2023-02-02
A vulnerability, which was classified as critical, was found in TRENDnet TEW-811DRU 1.0.10.0. This affects an unknown part of the file wan.asp of the component Web Management Interface. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-220017 was assigned to this vulnerability.
CVSS Score
6.5
EPSS Score
0.001
Published
2023-02-02


Contact Us

Shodan ® - All rights reserved