CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Apq8009_firmware, Apq8009, Apq8017_firmware, Apq8017, Apq8053_firmware, Apq8053, Apq8096au_firmware, Apq8096au, Apq8098_firmware, Apq8098
2023-02-21
N/A
9.8 CRITICAL
Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in reassoc response frame.
Apq8009_firmware, Apq8009, Apq8017_firmware, Apq8017, Apq8053_firmware, Apq8053, Apq8096au_firmware, Apq8096au, Apq8098_firmware, Apq8098
2023-02-21
N/A
7.5 HIGH
Transient DOS due to uncontrolled resource consumption in WLAN firmware when peer is freed in non qos state.
Apq8009_firmware, Apq8009, Apq8017_firmware, Apq8017, Apq8053_firmware, Apq8053, Apq8096au_firmware, Apq8096au, Apq8098_firmware, Apq8098
2023-02-21
N/A
7.5 HIGH
Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon.
A vulnerability has been found in Hostel Searching Project and classified as critical. This vulnerability affects unknown code of the file view-property.php. The manipulation of the argument property_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-213844.
Apq8009_firmware, Apq8009, Apq8017_firmware, Apq8017, Apq8053_firmware, Apq8053, Apq8096au_firmware, Apq8096au, Apq8098_firmware, Apq8098
2023-02-21
N/A
7.5 HIGH
Transient DOS due to improper input validation in WLAN Host.
The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users
Wazuh v3.6.1 - v3.13.5, v4.0.0 - v4.2.7, and v4.3.0 - v4.3.7 were discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Response endpoint.
NPS before v0.26.10 was discovered to contain an authentication bypass vulnerability via constantly generating and sending the Auth key and Timestamp parameters.
The WP User WordPress plugin through 7.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
ThinkCMF version 6.0.7 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows a Super Administrator user to be injected into administrative users.
