CVE Database

CVE-2020-28490CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For example: git.reset('atouch HACKEDb')

CVE-2020-28499CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

All versions of package merge are vulnerable to Prototype Pollution via _recursiveMerge .

CVE-2021-27335CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

KollectApps before 4.8.16c is affected by insecure Java deserialization, leading to Remote Code Execution via a ysoserial.payloads.CommonsCollections parameter.

CVE-2021-26747CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.

CVE-2021-20587CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3 all versions, FR Configurator2 versions 1.24A and prior, GT Designer3 Version1(GOT1000) versions 1.250L and prior, GT Designer3 Version1(GOT2000) versions 1.250L and prior, GT SoftGOT1000 Version3 versions 3.245F and prior, GT SoftGOT2000 Version1 versions 1.250L and prior, GX Configurator-DP versions 7.14Q and prior, GX Configurator-QP all versions, GX Developer versions 8.506C and prior, GX Explorer all versions, GX IEC Developer all versions, GX LogViewer versions 1.115U and prior, GX RemoteService-I all versions, GX Works2 versions 1.597X and prior, GX Works3 versions 1.070Y and prior, iQ Monozukuri ANDON (Data Transfer) versions 1.003D and prior, iQ Monozukuri Process Remote Monitoring (Data Transfer) versions 1.002C and prior, M_CommDTM-HART all versions, M_CommDTM-IO-Link versions 1.03D and prior, MELFA-Works versions 4.4 and prior, MELSEC WinCPU Setting Utility all versions, MELSOFT EM Software Development Kit (EM Configurator) versions 1.015R and prior, MELSOFT Navigator versions 2.74C and prior, MH11 SettingTool Version2 versions 2.004E and prior, MI Configurator versions 1.004E and prior, MT Works2 versions 1.167Z and prior, MX Component versions 5.001B and prior, Network Interface Board CC IE Control utility versions 1.29F and prior, Network Interface Board CC IE Field Utility versions 1.16S and prior, Network Interface Board CC-Link Ver.2 Utility versions 1.23Z and prior, Network Interface Board MNETH utility versions 34L and prior, PX Developer versions 1.53F and prior, RT ToolBox2 versions 3.73B and prior, RT ToolBox3 versions 1.82L and prior, Setting/monitoring tools for the C Controller module (SW4PVC-CCPU) versions 4.12N and prior, and SLMP Data Collector versions 1.04E and prior) allows a remote unauthenticated attacker to cause a DoS condition on the software products, and possibly to execute a malicious code on the personal computer running the software products although it has not been reproduced, by spoofing MELSEC, GOT or FREQROL and returning crafted reply packets.

CVE-2021-20588CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-130

Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3 all versions, FR Configurator2 versions 1.24A and prior, GT Designer3 Version1(GOT1000) versions 1.250L and prior, GT Designer3 Version1(GOT2000) versions 1.250L and prior, GT SoftGOT1000 Version3 versions 3.245F and prior, GT SoftGOT2000 Version1 versions 1.250L and prior, GX Configurator-DP versions 7.14Q and prior, GX Configurator-QP all versions, GX Developer versions 8.506C and prior, GX Explorer all versions, GX IEC Developer all versions, GX LogViewer versions 1.115U and prior, GX RemoteService-I all versions, GX Works2 versions 1.597X and prior, GX Works3 versions 1.070Y and prior, iQ Monozukuri ANDON (Data Transfer) versions 1.003D and prior, iQ Monozukuri Process Remote Monitoring (Data Transfer) versions 1.002C and prior, M_CommDTM-HART all versions, M_CommDTM-IO-Link versions 1.03D and prior, MELFA-Works versions 4.4 and prior, MELSEC WinCPU Setting Utility all versions, MELSOFT EM Software Development Kit (EM Configurator) versions 1.015R and prior, MELSOFT Navigator versions 2.74C and prior, MH11 SettingTool Version2 versions 2.004E and prior, MI Configurator versions 1.004E and prior, MT Works2 versions 1.167Z and prior, MX Component versions 5.001B and prior, Network Interface Board CC IE Control utility versions 1.29F and prior, Network Interface Board CC IE Field Utility versions 1.16S and prior, Network Interface Board CC-Link Ver.2 Utility versions 1.23Z and prior, Network Interface Board MNETH utility versions 34L and prior, PX Developer versions 1.53F and prior, RT ToolBox2 versions 3.73B and prior, RT ToolBox3 versions 1.82L and prior, Setting/monitoring tools for the C Controller module (SW4PVC-CCPU) versions 4.12N and prior, and SLMP Data Collector versions 1.04E and prior) allows a remote unauthenticated attacker to cause a DoS condition on the software products, and possibly to execute a malicious code on the personal computer running the software products although it has not been reproduced, by spoofing MELSEC, GOT or FREQROL and returning crafted reply packets.

CVE-2021-27514CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication bypass (such as in CVE-2021-27513 exploitation).

CVE-2021-26120CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.

CVE-2022-28021CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Purchase Order Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /purchase_order/admin/?page=user.

CVE-2022-28022CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Purchase Order Management System v1.0 was discovered to contain a SQL injection vulnerability via /purchase_order/classes/Master.php?f=delete_item.

CVE-2020-11163CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-129

Possible buffer overflow while updating ikev2 parameters due to lack of check of input validation for certain parameters received from the ePDG server in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

CVE-2020-11170CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Out of bound memory access while playing music playbacks with crafted vorbis content due to improper checks in header extraction in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

CVE-2022-28023CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Purchase Order Management System v1.0 was discovered to contain a SQL injection vulnerability via /purchase_order/classes/Master.php?f=delete_supplier.

CVE-2022-28024CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=grade.

CVE-2022-28025CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=school_year.

CVE-2022-28026CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=student_p&id=.

CVE-2022-28028CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_amenity.

CVE-2022-28029CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_type.

CVE-2020-11272CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Before enqueuing a frame to the PE queue for further processing, an entry in a hash table can be deleted and using a stale version later can lead to use after free condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2022-28030CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_estate.

CVE-2020-11283CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A buffer overflow can occur when playing an MKV clip due to lack of input validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2022-28410CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Users.php?f=delete_agent.

CVE-2022-28411CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/admin/?page=agents/manage_agent.

CVE-2022-28412CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Car Driving School Managment System v1.0 was discovered to contain a SQL injection vulnerability via /cdsms/classes/Master.php?f=delete_package.

CVE-2022-28413CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Car Driving School Management System v1.0 was discovered to contain a SQL injection vulnerability via /cdsms/classes/Master.php?f=delete_enrollment.

CVE-2020-21224KEVCRITICALin_the_wild
CVSS 9.8
EPSS 92.14%
Priority 0

A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a malicious login packet to the control server

CVE-2022-28414CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_member.

CVE-2022-28415CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_collection.

CVE-2022-28416CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase.

CVE-2022-28417CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase.

CVE-2021-27228CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

An issue was discovered in Shinobi through ocean version 1. lib/auth.js has Incorrect Access Control. Valid API Keys are held in an internal JS Object. Therefore an attacker can use JS Proto Method names (such as constructor or hasOwnProperty) to convince the System that the supplied API Key exists in the underlying JS object, and consequently achieve complete access to User/Admin/Super API functions, as demonstrated by a /super/constructor/accounts/list URI.

CVE-2022-28420CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via BabyCare/admin.php?id=theme&setid=.

CVE-2022-28421CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=posts&action=display&value=1&postid=.

CVE-2022-28422CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/posts.php&action=edit.

CVE-2022-28423CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/posts.php&action=delete.

CVE-2022-28424CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/posts.php&find=.

CVE-2022-28425CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/pagerole.php&action=display&value=1&roleid=.

CVE-2022-28426CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/pagerole.php&action=edit&roleid=.

CVE-2022-28427CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/inbox.php&action=read&msgid=.

CVE-2022-28429CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/inbox.php&action=delete&msgid=.

CVE-2022-28431CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/siteoptions.php&social=remove&sid=2.

CVE-2022-28432CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=siteoptions&social=display&value=0&sid=2.

CVE-2022-28433CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=display&value=Show&userid=.

CVE-2022-28434CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=siteoptions&social=edit&sid=2.

CVE-2022-28435CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/siteoptions.php&action=displaygoal&value=1&roleid=1.

CVE-2022-28436CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=display&value=Hide&userid=.

CVE-2022-28437CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=type&userrole=Admin&userid=3.

CVE-2022-28438CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=type&userrole=User&userid=.

CVE-2022-28439CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&&action=delete&userid=4.

CVE-2022-26672CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

ASUS WebStorage has a hardcoded API Token in the APP source code. An unauthenticated remote attacker can use this token to establish connections with the server and carry out login attempts to general user accounts. A successful login to a general user account allows the attacker to access, modify or delete this user account information.

← PreviousPage 383 / 7034Next →