CVE Database

CVE-2021-3013CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

ripgrep before 13 on Windows allows attackers to trigger execution of arbitrary programs from the current working directory via the -z/--search-zip or --pre flag.

CVE-2021-25383CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

An improper input validation vulnerability in scmn_mfal_read() in libsapeextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.

CVE-2021-25384CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

An improper input validation vulnerability in sdfffd_parse_chunk_PROP() with Sample Rate Chunk in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.

CVE-2021-25385CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

An improper input validation vulnerability in sdfffd_parse_chunk_PROP() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.

CVE-2021-25386CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

An improper input validation vulnerability in sdfffd_parse_chunk_FVER() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.

CVE-2021-22763CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-640

A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could allow an attacker administrator level access to a device.

CVE-2021-22765CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet

CVE-2021-22767CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet.This CVE ID is unique from CVE-2021-2276

CVE-2021-22768CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet.This CVE ID is unique from CVE-2021-22767

CVE-2021-32930CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

The affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations and execute arbitrary code on the iView (versions prior to v5.7.03.6182).

CVE-2021-22915CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limiting considerations. This could potentially result in an attacker bypassing rate-limit controls such as the Nextcloud brute-force protection.

CVE-2021-0474CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-177611958

CVE-2021-21795CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

A heap-based buffer overflow vulnerability exists in the PSD read_icc_icCurve_data functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to an integer overflow that, in turn, leads to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-21824CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-131

An out-of-bounds write vulnerability exists in the JPG Handle_JPEG420 functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-21833CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

An improper array index validation vulnerability exists in the TIF IP_planar_raster_unpack functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-27410CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

The affected product is vulnerable to an out-of-bounds write, which may result in corruption of data or code execution on the Welch Allyn medical device management tools (Welch Allyn Service Tool: versions prior to v1.10, Welch Allyn Connex Device Integration Suite – Network Connectivity Engine (NCE): versions prior to v5.3, Welch Allyn Software Development Kit (SDK): versions prior to v3.2, Welch Allyn Connex Central Station (CS): versions prior to v1.8.6, Welch Allyn Service Monitor: versions prior to v1.7.0.0, Welch Allyn Connex Vital Signs Monitor (CVSM): versions prior to v2.43.02, Welch Allyn Connex Integrated Wall System (CIWS): versions prior to v2.43.02, Welch Allyn Connex Spot Monitor (CSM): versions prior to v1.52, Welch Allyn Spot Vital Signs 4400 Device (Spot 4400) / Welch Allyn Spot 4400 Vital Signs Extended Care Device: versions prior to v1.11.00).

CVE-2021-27200CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-330

In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day.

CVE-2021-32682CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with minimal configuration. The issues were patched in version 2.1.59. As a workaround, ensure the connector is not exposed without authentication.

CVE-2021-0324CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Product: AndroidVersions: Android SoCAndroid ID: A-175402462

CVE-2020-7864CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Parameter manipulation can bypass authentication to cause file upload and execution. This will execute the remote code. This issue affects: Raonwiz DEXT5Editor versions prior to 3.5.1405747.1100.03.

CVE-2021-27388CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

SINAMICS medium voltage routable products are affected by a vulnerability in the Sm@rtServer component for remote access that could allow an unauthenticated attacker to cause a denial-of-service condition, and/or execution of limited configuration modifications and/or execution of limited control commands on the SINAMICS Medium Voltage Products, Remote Access (SINAMICS SL150: All versions, SINAMICS SM150: All versions, SINAMICS SM150i: All versions).

CVE-2020-29214CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in SourceCodester Alumni Management System 1.0 allows the user to inject SQL payload to bypass the authentication via admin/login.php.

CVE-2021-33622CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-754

Sylabs Singularity 3.5.x and 3.6.x, and SingularityPRO before 3.5-8, has an Incorrect Check of a Function's Return Value.

CVE-2021-34170CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

Bandai Namco FromSoftware Dark Souls III allows remote attackers to execute arbitrary code.

CVE-2021-24037CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

A use after free in hermes, while emitting certain error messages, prior to commit d86e185e485b6330216dee8e854455c694e3a36e allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.

CVE-2021-32685CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-347

tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the browser (hashing, random, encryption, decryption, signatures, conversions), used by TogaTech.org. In versions prior to 7.0.3, the `verifyWithMessage` method of `tEnvoyNaClSigningKey` always returns `true` for any signature that has a SHA-512 hash matching the SHA-512 hash of the message even if the signature was invalid. This issue is patched in version 7.0.3. As a workaround: In `tenvoy.js` under the `verifyWithMessage` method definition within the `tEnvoyNaClSigningKey` class, ensure that the return statement call to `this.verify` ends in `.verified`.

CVE-2020-9493CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution.

CVE-2021-32928CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-459

The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License Manager” that allows incoming connections from private networks using TCP Port 1947. While uninstalling, the uninstaller fails to close Port 1947.

CVE-2021-27610CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about internal and external RFC user in consistent and distinguished format, which could lead to improper authentication and may be exploited by malicious users to obtain illegitimate access to the system.

CVE-2020-22198CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.

CVE-2020-35760CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files).

CVE-2020-22203CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection in phpCMS 2008 sp4 via the genre parameter to yp/job.php.

CVE-2020-22208KEVCRITICALin_the_wild
CVSS 9.8
EPSS 38.37%
Priority 0

SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.

CVE-2020-22209CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php.

CVE-2020-22210CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.

CVE-2020-22211KEVCRITICALin_the_wild
CVSS 9.8
EPSS 35.19%
Priority 0

SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.

CVE-2020-22212CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection in 74cms 3.2.0 via the id parameter to wap/wap-company-show.php.

CVE-2021-34813CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because olm_pk_decrypt has a stack-based buffer overflow. Remote code execution might be possible for some nonstandard build configurations.

CVE-2020-25753CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software. The default admin password is set to the last 6 digits of the serial number. The serial number can be retrieved by an unauthenticated user at /info.xml.

CVE-2021-32691CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-303

Apollos Apps is an open source platform for launching church-related apps. In Apollos Apps versions prior to 2.20.0, new user registrations are able to access anyone's account by only knowing their basic profile information (name, birthday, gender, etc). This includes all app functionality within the app, as well as any authenticated links to Rock-based webpages (such as giving and events). There is a patch in version 2.20.0. As a workaround, one can patch one's server by overriding the `create` data source method on the `People` class.

CVE-2020-25414CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-829

A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitrary PHP code.

CVE-2013-20002CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/themify-ajax.php file.

CVE-2021-23396CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

All versions of package lutils are vulnerable to Prototype Pollution via the main (merge) function.

CVE-2021-21669CRITICALnone
CVSS 9.8
EPSS
Priority 0

Jenkins Generic Webhook Trigger Plugin 1.72 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

CVE-2021-33576CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

An issue was discovered in Cleo LexiCom 5.5.0.0. Within the AS2 message, the sender can specify a filename. This filename can include path-traversal characters, allowing the file to be written to an arbitrary location on disk.

CVE-2021-3604CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Secure 8 (Evalos) does not validate user input data correctly, allowing a remote attacker to perform a Blind SQL Injection. An attacker could exploit this vulnerability in order to extract information of users and administrator accounts stored in the database.

CVE-2021-21282CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Contiki-NG is an open-source, cross-platform operating system for internet of things devices. In versions prior to 4.5, buffer overflow can be triggered by an input packet when using either of Contiki-NG's two RPL implementations in source-routing mode. The problem has been patched in Contiki-NG 4.5. Users can apply the patch for this vulnerability out-of-band as a workaround.

CVE-2021-21280CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Contiki-NG is an open-source, cross-platform operating system for internet of things devices. It is possible to cause an out-of-bounds write in versions of Contiki-NG prior to 4.6 when transmitting a 6LoWPAN packet with a chain of extension headers. Unfortunately, the written header is not checked to be within the available space, thereby making it possible to write outside the buffer. The problem has been patched in Contiki-NG 4.6. Users can apply the patch for this vulnerability out-of-band as a workaround.

CVE-2021-21281CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Contiki-NG is an open-source, cross-platform operating system for internet of things devices. A buffer overflow vulnerability exists in Contiki-NG versions prior to 4.6. After establishing a TCP socket using the tcp-socket library, it is possible for the remote end to send a packet with a data offset that is unvalidated. The problem has been patched in Contiki-NG 4.6. Users can apply the patch for this vulnerability out-of-band as a workaround.

CVE-2021-31272CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

SerenityOS before commit 3844e8569689dd476064a0759d704bc64fb3ca2c contains a directory traversal vulnerability in tar/unzip that may lead to command execution or privilege escalation.

← PreviousPage 401 / 7034Next →