Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2023-24806PUBLISHED: 2023-02-04** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage.
CVE-2013-10017PUBLISHED: 2023-02-04
A vulnerability was found in fanzila WebFinance 0.5. It has been classified as critical. Affected is an unknown function of the file htdocs/admin/save_roles.php. The manipulation of the argument id leads to sql injection. The name of the patch is 6cfeb2f6b35c1b3a7320add07cd0493e4f752af3. It is recom...
CVE-2013-10018PUBLISHED: 2023-02-04
A vulnerability was found in fanzila WebFinance 0.5. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file htdocs/prospection/save_contact.php. The manipulation of the argument nom/prenom/email/tel/mobile/client/fonction/note leads to sql injection....
CVE-2023-23082PUBLISHED: 2023-02-03A heap buffer overflow vulnerability in Kodi Home Theater Software up to 19.5 allows attackers to cause a denial of service due to an improper length of the value passed to the offset argument.
CVE-2023-23615PUBLISHED: 2023-02-03
Discourse is an open source discussion platform. The embeddable comments can be exploited to create new topics as any user but without any clear title or content. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. As a workaround, disable embeddable comments by ...
User Rank: Apprentice
1/13/2020 | 9:25:26 AM
This is aligned with the trend- the proliferating IoT scene is where hackers are finding the blind spot of the enterprise and consumer.
Some hacks here are "for shows" but some clearly indicate the risk of product security- it provides access into the data center and it can impact life and business continuity