Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In July 2023
Certain HP LaserJet Pro print products are potentially vulnerable to an Elevation of Privilege and/or Information Disclosure related to a lack of authentication with certain endpoints.
CVSS Score
9.8
EPSS Score
0.008
Published
2023-07-21
A sensitive information leak issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows access to titles of private issue and MR.
CVSS Score
5.3
EPSS Score
0.006
Published
2023-07-21
WebBoss.io CMS before v3.7.0.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability.
CVSS Score
6.1
EPSS Score
0.005
Published
2023-07-21
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.
CVSS Score
9.8
EPSS Score
0.987
Published
2023-07-21
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pimcore/pimcore prior to 10.6.4.
CVSS Score
7.6
EPSS Score
0.007
Published
2023-07-21
SQL Injection in GitHub repository pimcore/pimcore prior to 10.6.4.
CVSS Score
7.2
EPSS Score
0.012
Published
2023-07-21
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.6.4.
CVSS Score
6.1
EPSS Score
0.006
Published
2023-07-21
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.4.
CVSS Score
6.0
EPSS Score
0.005
Published
2023-07-21
An issue has been discovered in GitLab EE affecting all versions starting from 12.8 before 15.11.11, all versions starting from 16.0 before 16.0.7, all versions starting from 16.1 before 16.1.2. An attacker could change the name or path of a public top-level group in certain situations.
CVSS Score
8.0
EPSS Score
0.006
Published
2023-07-21
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by lacking validation for a specific value when calling cm_processChangedConfigMsg in ccm_processREQ_CHANGED_CONFIG function in AiMesh system. An unauthenticated remote attacker can exploit this vulnerability without privilege to perform remote arbitrary code execution, arbitrary system operation or disrupt service. This issue affects RT-AX56U V2: 3.0.0.4.386_50460; RT-AC86U: 3.0.0.4_386_51529.
CVSS Score
9.8
EPSS Score
0.011
Published
2023-07-21


Contact Us

Shodan ® - All rights reserved