Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In March 2023
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in As Koc Energy Web Report System allows SQL Injection.This issue affects Web Report System: before 23.03.10.
CVSS Score
9.8
EPSS Score
0.003
Published
2023-03-23
Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network.
CVSS Score
9.8
EPSS Score
0.003
Published
2023-03-23
Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance.
CVSS Score
8.2
EPSS Score
0.002
Published
2023-03-23
An issue was discovered in Veritas NetBackup before 10.0 on Windows. A vulnerability in the way the client validates the path to a DLL prior to loading may allow a lower-level user to elevate privileges and compromise the system.
CVSS Score
7.8
EPSS Score
0.001
Published
2023-03-23
An issue was discovered in Veritas NetBackup before 8.3.0.2. BPCD allows an unprivileged user to specify a log file path when executing a NetBackup command. This can be used to overwrite existing NetBackup log files.
CVSS Score
7.1
EPSS Score
0.001
Published
2023-03-23
XunRuiCMS v4.3.3 to v4.5.1 vulnerable to PHP file write and CMS PHP file inclusion, allows attackers to execute arbitrary php code, via the add function in cron.php.
CVSS Score
7.2
EPSS Score
0.005
Published
2023-03-23
IS Decisions UserLock MFA 11.01 is vulnerable to authentication bypass using scheduled task.
CVSS Score
7.2
EPSS Score
0.12
Published
2023-03-23
An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T5124. Memory corruption can occur due to improper checking of the parameter length while parsing the fmtp attribute in the SDP (Session Description Protocol) module.
CVSS Score
8.6
EPSS Score
0.052
Published
2023-03-23
swfdump v0.9.2 was discovered to contain a heap buffer overflow in the function swf_GetPlaceObject at swfobject.c.
CVSS Score
5.5
EPSS Score
0.002
Published
2023-03-23
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Profile Update function.
CVSS Score
9.8
EPSS Score
0.002
Published
2023-03-23


Contact Us

Shodan ® - All rights reserved