CVE Database

CVE-2022-26674CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-134

ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary memory address and perform remote arbitrary code execution, arbitrary system operation or disrupt service.

CVE-2022-27404CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.

CVE-2021-20658CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspecified vectors.

CVE-2021-22667CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

BB-ESWGP506-2SFP-T versions 1.01.09 and prior is vulnerable due to the use of hard-coded credentials, which may allow an attacker to gain unauthorized access and permit the execution of arbitrary code on the BB-ESWGP506-2SFP-T (versions 1.01.01 and prior).

CVE-2022-1440CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Command Injection vulnerability in git-interface@2.1.1 in GitHub repository yarkeev/git-interface prior to 2.1.2. If both are provided by user input, then the use of a `--upload-pack` command-line argument feature of git is also supported for `git clone`, which would then allow for any operating system command to be spawned by the attacker.

CVE-2022-27341CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management function.

CVE-2022-27342CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Link-Admin v0.0.1 was discovered to contain a SQL injection vulnerability via DictRest.ResponseResult().

CVE-2021-3849CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-288

An authentication bypass vulnerability was discovered in the web interface of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware that could allow an unauthenticated attacker to execute commands on the SMM and FPC2. SMM2 is not affected.

CVE-2021-3897CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-288

An authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware during an that could allow an unauthenticated attacker to execute commands on the SMM and FPC2. SMM2 is not affected.

CVE-2020-23534CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-918

A server-side request forgery (SSRF) vulnerability in Upgrade.php of gopeak masterlab 2.1.5, via the 'source' parameter.

CVE-2021-24074CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Windows TCP/IP Remote Code Execution Vulnerability

CVE-2022-29077CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A heap-based buffer overflow exists in rippled before 1.8.5. The vulnerability allows attackers to cause a crash or execute commands remotely on a rippled node, which may lead to XRPL mainnet DoS or compromise. This exposes all digital assets on the XRPL to a security threat.

CVE-2022-29264CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue was discovered in coreboot 4.13 through 4.16. On APs, arbitrary code execution in SMM may occur.

CVE-2021-45840CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending specifically crafted input to /tos/index.php?app/app_start_stop.

CVE-2019-11684CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

Improper Access Control in the RCP+ server of the Bosch Video Recording Manager (VRM) component allows arbitrary and unauthenticated access to a limited subset of certificates, stored in the underlying Microsoft Windows operating system. The fixed versions implement modified authentication checks. Prior releases of VRM software version 3.70 are considered unaffected. This vulnerability affects VRM v3.70.x, v3.71 < v3.71.0034 and v3.81 < 3.81.0050; DIVAR IP 5000 3.80 < 3.80.0039; BVMS all versions using VRM.

CVE-2022-27311CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-918

Gibbon v3.4.4 and below allows attackers to execute a Server-Side Request Forgery (SSRF) via a crafted URL.

CVE-2022-27429CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-918

Jizhicms v1.9.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via /admin.php/Plugins/update.html.

CVE-2022-28093CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which allow attackers to execute arbitrary code via a crafted PHP file.

CVE-2021-27198CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

An issue was discovered in Visualware MyConnection Server before v11.1a. Unauthenticated Remote Code Execution can occur via Arbitrary File Upload in the web service when using a myspeed/sf?filename= URI. This application is written in Java and is thus cross-platform. The Windows installation runs as SYSTEM, which means that exploitation gives one Administrator privileges on the target system.

CVE-2021-26476CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI.

CVE-2021-3148CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quotes. This is related to salt/utils/thin.py.

CVE-2022-0541CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-284

The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any attacker to initiate a new site install by setting the flo_custom_table_prefix cookie to an arbitrary value.

CVE-2021-3197CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request.

CVE-2021-27132CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.

CVE-2021-25830CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13. An attacker must request the conversion of the crafted file from DOCT into DOCX format. Using the chain of two other bugs related to improper string handling, an attacker can achieve remote code execution on DocumentServer.

CVE-2022-0657CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validate and escape lead ids before using them in a SQL statement via the rrtngg_delete_leads AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue. There is an attempt to sanitise the input, using sanitize_text_field(), however such function is not intended to prevent SQL injections.

CVE-2021-25832CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0. Using this vulnerability, an attacker is able to gain remote code executions on DocumentServer.

CVE-2022-0693CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_meta_condition AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL Injection

CVE-2022-0782CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in a SQL statement via the nd_donations_single_cause_form_validate_fields_php_function AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection

CVE-2021-26703CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-611

EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase URI.

CVE-2021-3342CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/latex2png?latex= URI.

CVE-2023-27852CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a buffer overflow vulnerability in various CGI mechanisms that could allow an attacker to execute arbitrary code on the device.

CVE-2022-25866CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-88

The package czproject/git-php before 4.0.3 are vulnerable to Command Injection via git argument injection. When calling the isRemoteUrlReadable($url, array $refs = NULL) function, both the url and refs parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.

CVE-2021-27730CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. The fixed version is FTA_9_12_444 and later.

CVE-2022-23457CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, the default implementation of `Validator.getValidDirectoryPath(String, String, File, boolean)` may incorrectly treat the tested input string as a child of the specified parent directory. This potentially could allow control-flow bypass checks to be defeated if an attack can specify the entire string representing the 'input' path. This vulnerability is patched in release 2.3.0.0 of ESAPI. As a workaround, it is possible to write one's own implementation of the Validator interface. However, maintainers do not recommend this.

CVE-2022-29806CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contributes to exploitability.

CVE-2020-28657CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

In bPanel 2.0, the administrative ajax endpoints (aka ajax/aj_*.php) are accessible without authentication and allow SQL injections, which could lead to platform compromise.

CVE-2022-27299CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the component room.php.

CVE-2022-27468CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code via a crafted file uploaded to the web server.

CVE-2022-27469CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-918

Monstaftp v2.10.3 was discovered to allow attackers to execute Server-Side Request Forgery (SSRF).

CVE-2022-27984CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.

CVE-2022-27985CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.

CVE-2022-24881CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote code execution through malicious code injection of the template engine. This happens because Velocity and freemarker templates are introduced but input verification is not done. The fault is rectified in version 1.0.0.beta.2.

CVE-2022-24883CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a `SAM` file might be successful for invalid credentials if the server has configured an invalid `SAM` file path. FreeRDP based clients are not affected. RDP server implementations using FreeRDP to authenticate against a `SAM` file are affected. Version 2.7.0 contains a fix for this issue. As a workaround, use custom authentication via `HashCallback` and/or ensure the `SAM` database path configured is valid and the application has file handles left.

CVE-2021-27215CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

An issue was discovered in genua genugate before 9.0 Z p19, 9.1.x through 9.6.x before 9.6 p7, and 10.x before 10.1 p4. The Web Interfaces (Admin, Userweb, Sidechannel) can use different methods to perform the authentication of a user. A specific authentication method during login does not check the provided data (when a certain manipulation occurs) and returns OK for any authentication request. This allows an attacker to login to the admin panel as a user of his choice, e.g., the root user (with highest privileges) or even a non-existing user.

CVE-2020-36539CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in Lógico y Creativo 1.0 and classified as critical. This issue affects some unknown processing. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely.

CVE-2020-36540CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability, which was classified as critical, was found in Neetai Tech. Affected is an unknown function of the file /product.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-28521CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

ZCMS v20170206 was discovered to contain a file inclusion vulnerability via index.php?m=home&c=home&a=sp_set_config.

CVE-2021-27314CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter at login page.

CVE-2022-28524CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php.

← PreviousPage 384 / 7034Next →