CVE-2023-32615

CVSS v3 Score
8.1
High

Vulnerability Description

A file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary file creation or overwrite. An attacker can send a sequence of requests to trigger this vulnerability.

CVSS:8.1(High)

Advantech R-SeeNet versions 2.4.22 allows low-level users to access and load the content of local files.

CWE-732023
CVSS:8.1(High)

An arbitrary file deletion vulnerability exists in danny-avila/librechat version v0.7.5-rc2, specifically within the /api/files endpoint. This vulnerability arises from improper input validation, allo...

CWE-732024
CVSS:8.1(High)

Windows HTML Platforms Security Feature Bypass Vulnerability

CWE-732024
CVSS:8.1(High)

Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allows attackers with sufficient permissions to configur...

CWE-732024
CVSS:8.1(High)

Windows Distributed Transaction Coordinator Remote Code Execution Vulnerability

CWE-732024
CVSS:8.1(High)

The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to arbitrary file movement and reading due to insufficient file path validation in th...

CWE-732024