CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Securview_wireless_internet_camera, Securview_wireless_internet_camera_activex_control, Teg-30102ws, Teg-30102ws_firmware, Tew-632brp, Tew-632brp_firmware, Tew-651br, Tew-651br_firmware, Tew-652br, Tew-652br_firmware
2022-06-28
N/A
6.1 MEDIUM
Trendnet IP-110wn camera fw_tv-ip110wn_v2(1.2.2.68) has an xss vulnerability via the proname parameter in /admin/scheprofile.cgi
Hg100_firmware, Hg100, Zenfone_4_selfie_firmware, Zenfone_4_selfie, Zenfone_live_(l1)_firmware, Zenfone_live_(l1), Zenfone_5_selfie_firmware, Zenfone_5_selfie, Zenfone_3s_max_firmware, Zenfone_3s_max
2022-06-28
N/A
9.8 CRITICAL
ASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface.
Securview_wireless_internet_camera, Securview_wireless_internet_camera_activex_control, Teg-30102ws, Teg-30102ws_firmware, Tew-632brp, Tew-632brp_firmware, Tew-651br, Tew-651br_firmware, Tew-652br, Tew-652br_firmware
2022-06-28
N/A
6.1 MEDIUM
Trendnet IP-110wn camera fw_tv-ip110wn_v2(1.2.2.68) has an XSS vulnerability via the prefix parameter in /admin/general.cgi.
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection is established with the database. However, these PHP pages do not verify the validity of a user. Attackers could leverage this lack of verification to read the state of outlets.
Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs.
An issue was discovered in OpenRemote through 1.0.4 allows attackers to execute arbitrary code via a crafted Groovy rule.
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an attacker to access the device’s main management page from the cloud. This feature enables users to remotely connect devices, however, the current implementation permits users to access other device's information.
Newsletter Module v3.x was discovered to contain a SQL injection vulnerability via the zemez_newsletter_email parameter at /index.php.
Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel.
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product exposes sensitive data concerning the device.
