Export limit exceeded: 403983 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 15547 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 23384 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (23384 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-37721 | 1 Tenda | 10 4g300, 4g300 Firmware, F1202 and 7 more | 2024-11-21 | 9.8 Critical |
| Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromSafeMacFilter. | ||||
| CVE-2023-37719 | 1 Tenda | 8 F1202, F1202 Firmware, Fh1202 and 5 more | 2024-11-21 | 9.8 Critical |
| Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromP2pListFilter. | ||||
| CVE-2023-37718 | 1 Tenda | 6 4g300, 4g300 Firmware, F1202 and 3 more | 2024-11-21 | 9.8 Critical |
| Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromSafeClientFilter. | ||||
| CVE-2023-37717 | 1 Tenda | 14 Ac10, Ac10 Firmware, Ac1206 and 11 more | 2024-11-21 | 9.8 Critical |
| Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were discovered to contain a stack overflow in the page parameter in the function fromDhcpListClient. | ||||
| CVE-2023-37716 | 1 Tenda | 14 Ac10, Ac10 Firmware, Ac1206 and 11 more | 2024-11-21 | 9.8 Critical |
| Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were discovered to contain a stack overflow in the page parameter in the function fromNatStaticSetting. | ||||
| CVE-2023-37715 | 1 Tenda | 4 F1202, F1202 Firmware, Fh1202 and 1 more | 2024-11-21 | 9.8 Critical |
| Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function frmL7ProtForm. | ||||
| CVE-2023-37714 | 1 Tenda | 8 Ac7, Ac7 Firmware, F1202 and 5 more | 2024-11-21 | 9.8 Critical |
| Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromRouteStatic. | ||||
| CVE-2023-37711 | 1 Tenda | 4 Ac10, Ac10 Firmware, Ac1206 and 1 more | 2024-11-21 | 9.8 Critical |
| Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the deviceId parameter in the saveParentControlInfo function. | ||||
| CVE-2023-37710 | 1 Tenda | 4 Ac10, Ac10 Firmware, Ac1206 and 1 more | 2024-11-21 | 9.8 Critical |
| Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the wpapsk_crypto parameter in the fromSetWirelessRepeat function. | ||||
| CVE-2023-37707 | 1 Tenda | 2 Fh1203, Fh1203 Firmware | 2024-11-21 | 9.8 Critical |
| Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function. | ||||
| CVE-2023-37706 | 1 Tenda | 2 Fh1203, Fh1203 Firmware | 2024-11-21 | 9.8 Critical |
| Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the entrys parameter in the fromAddressNat function. | ||||
| CVE-2023-37705 | 1 Tenda | 2 Fh1203, Fh1203 Firmware | 2024-11-21 | 9.8 Critical |
| Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromAddressNat function. | ||||
| CVE-2023-37704 | 1 Tenda | 2 Fh1203, Fh1203 Firmware | 2024-11-21 | 9.8 Critical |
| Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the formSetClientState function. | ||||
| CVE-2023-37703 | 1 Tenda | 2 Fh1203, Fh1203 Firmware | 2024-11-21 | 9.8 Critical |
| Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function. | ||||
| CVE-2023-37702 | 1 Tenda | 2 Fh1203, Fh1203 Firmware | 2024-11-21 | 9.8 Critical |
| Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the formSetDeviceName function. | ||||
| CVE-2023-37701 | 1 Tenda | 2 Fh1203, Fh1203 Firmware | 2024-11-21 | 9.8 Critical |
| Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function. | ||||
| CVE-2023-37700 | 1 Tenda | 2 Fh1203, Fh1203 Firmware | 2024-11-21 | 9.8 Critical |
| Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function. | ||||
| CVE-2023-37564 | 1 Elecom | 10 Wrc-1167febk-a, Wrc-1167febk-a Firmware, Wrc-1167febk-s and 7 more | 2024-11-21 | 8.0 High |
| OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent authenticated attacker to execute an arbitrary OS command with a root privilege by sending a specially crafted request. Affected products and versions are as follows: WRC-1167GHBK-S v1.03 and earlier, WRC-1167GEBK-S v1.03 and earlier, WRC-1167FEBK-S v1.04 and earlier, WRC-1167GHBK3-A v1.24 and earlier, and WRC-1167FEBK-A v1.18 and earlier. | ||||
| CVE-2023-37557 | 1 Codesys | 16 Control For Beaglebone Sl, Control For Empc-a\/imx6 Sl, Control For Iot2000 Sl and 13 more | 2024-11-21 | 6.5 Medium |
| After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted remote communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can lead to a denial-of-service condition. | ||||
| CVE-2023-37477 | 1 Fit2cloud | 1 1panel | 2024-11-21 | 7.2 High |
| 1Panel is an open source Linux server operation and maintenance management panel. An OS command injection vulnerability exists in 1Panel firewall functionality. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. 1Panel firewall functionality `/hosts/firewall/ip` endpoint read user input without validation, the attacker extends the default functionality of the application, which execute system commands. An attacker can execute arbitrary code on the target system, which can lead to a complete compromise of the system. This issue has been addressed in commit `e17b80cff49` which is included in release version `1.4.3`. Users are advised to upgrade. There are no known workarounds for this vulnerability. | ||||
