Page 478 of 45888 results (0.066 seconds)

CVSS: 8.9EPSS: 0%CPEs: 1EXPL: 0

Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the camera. An attacker could inject malicious into http request packets to execute arbitrary code. • https://www.hanwhavision.com/wp-content/uploads/2024/04/NVR-DVR-Vulnerability-Report-CVE-2023-6116.pdf • CWE-121: Stack-based Buffer Overflow •

CVSS: 8.9EPSS: 0%CPEs: 1EXPL: 0

Vladimir Kononovich, a Security Researcher has found a flaw that allows for a remote code execution on the DVR. An attacker could inject malicious HTTP headers into request packets to execute arbitrary code. • https://www.hanwhavision.com/wp-content/uploads/2024/04/NVR-DVR-Vulnerability-Report-CVE-2023-6095-6096.pdf • CWE-121: Stack-based Buffer Overflow •

CVSS: 7.5EPSS: 0%CPEs: -EXPL: 0

Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Batch-Issue Exam Tickets function. • https://packetstormsecurity.com/files/178251/Relate-Learning-And-Teaching-System-SSTI-Remote-Code-Execution.html • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 9.8EPSS: 0%CPEs: -EXPL: 0

., Ltd Panalog big data analysis platform v. 20240323 and before allows attackers to execute arbitrary code via the exportpdf.php component. • https://github.com/tianqing191/book.io • CWE-616: Incomplete Identification of Uploaded File Variables (PHP) •

CVSS: 8.8EPSS: 0%CPEs: -EXPL: 0

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lexmark CX331adwe printers. ... An attacker can leverage this vulnerability to execute code in the context of root. •