CVE Database

CVE-2020-24914KEVCRITICALin_the_wild
CVSS 9.8
EPSS 37.72%
Priority 0

A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileData" and allows an unauthenticated attacker to execute code via a crafted POST request.

CVE-2021-23344CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set.

CVE-2023-27853CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a format string vulnerability in a SOAP service that could allow an attacker to execute arbitrary code on the device.

CVE-2020-28636CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-129

A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh->twin() An attacker can provide malicious input to trigger this vulnerability.

CVE-2020-35628CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-129

A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh->incident_sface. An attacker can provide malicious input to trigger this vulnerability.

CVE-2020-35636CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-129

A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sface() sfh->volume() OOB read. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger this vulnerability.

CVE-2020-8298CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

fs-path node module before 0.0.25 is vulnerable to command injection by way of user-supplied inputs via the `copy`, `copySync`, `remove`, and `removeSync` methods.

CVE-2021-26293CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

An issue was discovered in AfterLogic Aurora through 8.5.3 and WebMail Pro through 8.5.3, when DAV is enabled. They allow directory traversal to create new files (such as an executable file under the web root). This is related to DAVServer.php in 8.x and DAV/Server.php in 7.x.

CVE-2021-25346CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A possible arbitrary memory overwrite vulnerabilities in quram library version prior to SMR Jan-2021 Release 1 allow arbitrary code execution.

CVE-2021-27965CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

The MsIo64.sys driver before 1.1.19.1016 in MSI Dragon Center before 2.0.98.0 has a buffer overflow that allows privilege escalation via a crafted 0x80102040, 0x80102044, 0x80102050, or 0x80102054 IOCTL request.

CVE-2021-28033CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-908

An issue was discovered in the byte_struct crate before 0.6.1 for Rust. There can be a drop of uninitialized memory if a certain deserialization method panics.

CVE-2020-29658CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Zoho ManageEngine Application Control Plus before 100523 has an insecure SSL configuration setting for Nginx, leading to Privilege Escalation.

CVE-2021-28027CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-191

An issue was discovered in the bam crate before 0.1.3 for Rust. There is an integer underflow and out-of-bounds write during the loading of a bgzip block.

CVE-2021-28028CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

An issue was discovered in the toodee crate before 0.3.0 for Rust. Row insertion can cause a double free upon an iterator panic.

CVE-2021-28031CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

An issue was discovered in the scratchpad crate before 1.3.1 for Rust. The move_elements function can have a double-free upon a panic in a user-provided f function.

CVE-2021-28037CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue was discovered in the internment crate before 0.4.2 for Rust. There is a data race that can cause memory corruption because of the unconditional implementation of Sync for Intern<T>.

CVE-2021-34601CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-259

In Bender/ebee Charge Controllers in multiple versions are prone to Hardcoded Credentials. Bender charge controller CC612 in version 5.20.1 and below is prone to hardcoded ssh credentials. An attacker may use the password to gain administrative access to the web-UI.

CVE-2021-38869CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-384

IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 208341.

CVE-2021-3420CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

A flaw was found in newlib in versions prior to 4.0.0. Improper overflow validation in the memory allocation functions mEMALIGn, pvALLOc, nano_memalign, nano_valloc, nano_pvalloc could case an integer overflow, leading to an allocation of a small buffer and then to a heap-based buffer overflow.

CVE-2021-27581CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The Blog module in Kentico CMS 5.5 R2 build 5.5.3996 allows SQL injection via the tagname parameter.

CVE-2022-27336CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php.

CVE-2021-21335CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

In the SPNEGO HTTP Authentication Module for nginx (spnego-http-auth-nginx-module) before version 1.1.1 basic Authentication can be bypassed using a malformed username. This affects users of spnego-http-auth-nginx-module that have enabled basic authentication. This is fixed in version 1.1.1 of spnego-http-auth-nginx-module. As a workaround, one may disable basic authentication.

CVE-2021-21484CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-863

LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured to enable unauthenticated bind.

CVE-2022-29859CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

component/common/network/dhcp/dhcps.c in ambiot amb1_sdk (aka SDK for Ameba1) before 2022-03-11 mishandles data structures for DHCP packet data.

CVE-2022-28719CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the system configuration to upload a crafted configuration file to the managing server, which may result in the managed clients to execute arbitrary code with the administrative privilege.

CVE-2021-41921CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution.

CVE-2021-43934CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate upload requests, enabling a malicious user to potentially upload arbitrary files.

CVE-2021-28119CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Twinkle Tray (aka twinkle-tray) through 1.13.3 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal API.

CVE-2022-29411CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection (SQLi) vulnerability in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allows attackers to execute SQLi attack via (&id).

CVE-2020-1916CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

An incorrect size calculation in ldap_escape may lead to an integer overflow when overly long input is passed in, resulting in an out-of-bounds write. This issue affects HHVM prior to 4.56.2, all versions between 4.57.0 and 4.78.0, 4.79.0, 4.80.0, 4.81.0, 4.82.0, 4.83.0.

CVE-2022-29556CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-918

The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several SSRF primitives that can execute cross-tenant actions via internal API endpoints.

CVE-2022-24449CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-611

Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML document.

CVE-2021-0396CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

In Builtins::Generate_ArgumentsAdaptorTrampoline of builtins-arm.cc and related files, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-160610106

CVE-2021-0397CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

In sdp_copy_raw_data of sdp_discovery.cc, there is a possible system compromise due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-174052148

CVE-2022-29904CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain '-' and '_' constraints.

CVE-2021-24030CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-88

The fbgames protocol handler registered as part of Facebook Gameroom does not properly quote arguments passed to the executable. That allows a malicious URL to cause code execution. This issue affects versions prior to v1.26.0.

CVE-2022-29906CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-862

The admin API module in the QuizGame extension for MediaWiki through 1.37.2 (before 665e33a68f6fa1167df99c0aa18ed0157cdf9f66) omits a check for the quizadmin user.

CVE-2022-1531CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in ARAX-UI Synonym Lookup functionality in GitHub repository rtxteam/rtx prior to checkpoint_2022-04-20 . This vulnerability is critical as it can lead to remote code execution and thus complete server takeover.

CVE-2022-28452CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.

CVE-2021-43938CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-200

Elcomplus SmartPTT SCADA Server is vulnerable to an unauthenticated user can request various files from the server without any authentication or authorization.

CVE-2020-1900CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

When unserializing an object with dynamic properties HHVM needs to pre-reserve the full size of the dynamic property array before inserting anything into it. Otherwise the array might resize, invalidating previously stored references. This pre-reservation was not occurring in HHVM prior to v4.32.3, between versions 4.33.0 and 4.56.0, 4.57.0, 4.58.0, 4.58.1, 4.59.0, 4.60.0, 4.61.0, 4.62.0.

CVE-2022-28480CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

ALLMediaServer 1.6 is vulnerable to Buffer Overflow via MediaServer.exe.

CVE-2022-28994CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Small HTTP Server version 3.06 suffers from a remote buffer overflow vulnerability via long GET request.

CVE-2021-26877CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Windows DNS Server Remote Code Execution Vulnerability

CVE-2021-26893CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Windows DNS Server Remote Code Execution Vulnerability

CVE-2021-26894CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Windows DNS Server Remote Code Execution Vulnerability

CVE-2020-29045CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php.

CVE-2021-22714CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION7400, PM8000 and ION9000 (All versions prior to V3.0.0), which could cause the meter to reboot or allow for remote code execution.

CVE-2022-28481CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1236

CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection.

CVE-2020-36282CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

JMS Client for RabbitMQ 1.x before 1.15.2 and 2.x before 2.2.0 is vulnerable to unsafe deserialization that can result in code execution via crafted StreamMessage data.

← PreviousPage 385 / 7034Next →