CVE Database

CVE-2018-25016CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection.

CVE-2021-0516CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

In p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-181660448

CVE-2021-26461CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.

CVE-2020-19510CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.

CVE-2021-24361CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then used in a SQL statement, leading to unauthenticated SQL Injection issues.

CVE-2021-24376CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archive via the "Import Settings" feature, after its extraction. However, the extracted folders are not checked and it is possible to upload a zip which contained a directory with PHP file in it and then it is not removed from the disk. It is a bypass of CVE-2020-24948 which allows sending a PHP file via the "Import Settings" functionality to achieve Remote Code Execution.

CVE-2021-35066CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-611

An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.

CVE-2010-1433CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Joomla! Core is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.15 are vulnerable.

CVE-2010-1435CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-863

Joomla! Core is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently retrieve password reset tokens from the database through an already existing SQL injection vector. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.15 are vulnerable.

CVE-2021-3044CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-285

An improper authorization vulnerability in Palo Alto Networks Cortex XSOAR enables a remote unauthenticated attacker with network access to the Cortex XSOAR server to perform unauthorized actions through the REST API. This issue impacts: Cortex XSOAR 6.1.0 builds later than 1016923 and earlier than 1271064; Cortex XSOAR 6.2.0 builds earlier than 1271065. This issue does not impact Cortex XSOAR 5.5.0, Cortex XSOAR 6.0.0, Cortex XSOAR 6.0.1, or Cortex XSOAR 6.0.2 versions. All Cortex XSOAR instances hosted by Palo Alto Networks are upgraded to resolve this vulnerability. No additional action is required for these instances.

CVE-2021-27649CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2021-21998CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass. A malicious actor with network access to the VMware Carbon Black App Control management server might be able to obtain administrative access to the product without the need to authenticate.

CVE-2020-20392CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php.

CVE-2021-28800CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

A command injection vulnerability has been reported to affect QNAP NAS running legacy versions of QTS. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.3.6.1663 Build 20210504; versions prior to 4.3.3.1624 Build 20210416. This issue does not affect: QNAP Systems Inc. QTS 4.5.3. QNAP Systems Inc. QuTS hero h4.5.3. QNAP Systems Inc. QuTScloud c4.5.5.

CVE-2021-29954CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-312

Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, including the metadata service. This vulnerability affects Hubs Cloud < mozillareality/reticulum/1.0.1/20210428201255.

CVE-2020-21787CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.

CVE-2020-21784CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.

CVE-2020-21786CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

In IBOS 4.5.4 Open, Arbitrary File Inclusion causes getshell via /system/modules/dashboard/controllers/CronController.php.

CVE-2021-31649CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerable to remote code execute

CVE-2021-33346CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

There is an arbitrary password modification vulnerability in a D-LINK DSL-2888A router product. An attacker can use this vulnerability to modify the password of the admin user without authorization.

CVE-2020-18667CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection vulnerability in WebPort <=1.19.1 via the new connection, parameter name in type-conn.

CVE-2021-35971CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Veeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserialization during Microsoft .NET remoting.

CVE-2020-17752CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

Integer overflow vulnerability in payable function of a smart contract implementation for an Ethereum token, as demonstrated by the smart contract implemented at address 0xB49E984A83d7A638E7F2889fc8328952BA951AbE, an implementation for MillionCoin (MON).

CVE-2021-28958CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.

CVE-2021-35048CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interface. The vulnerability could lead to exposure of authentication tokens in some versions of Fidelis software. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.7 and in version 9.4. Patches and updates are available to address this vulnerability.

CVE-2021-34074CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a relative path is used in the requests.

CVE-2021-34184CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

Miniaudio 0.10.35 has a Double free vulnerability that could cause a buffer overflow in ma_default_vfs_close__stdio in miniaudio.h.

CVE-2021-35502CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data related to generic-template:index.

CVE-2021-23399CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

This affects all versions of package wincred. If attacker-controlled user input is given to the getCredential function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

CVE-2021-35514CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

Narou (aka Narou.rb) before 3.8.0 allows Ruby Code Injection via the title name or author name of a novel.

CVE-2021-31337CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

The Telnet service of the SIMATIC HMI Comfort Panels system component in affected products does not require authentication, which may allow a remote attacker to gain access to the device if the service is enabled. Telnet is disabled by default on the SINAMICS Medium Voltage Products (SINAMICS SL150: All versions, SINAMICS SM150: All versions, SINAMICS SM150i: All versions).

CVE-2021-35456CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Pet Shop We App 1.0 is vulnerable to remote SQL injection and shell upload

CVE-2020-23711CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection vulnerability in NavigateCMS 2.9 via the URL encoded GET input category in navigate.php.

CVE-2017-6361CRITICALpoc
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.

CVE-2020-7868CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-141

A remote code execution vulnerability exists in helpUS(remote administration tool) due to improper validation of parameter of ShellExecutionExA function used for login.

CVE-2020-7871CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

A vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficient validation of the parameter. This issue affects: Cnesty Helpcom 10.0 versions prior to.

CVE-2021-31531CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-918

Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF).

CVE-2021-32988CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

FATEK Automation WinProladder Versions 3.30 and prior are vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code.

CVE-2021-32990CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

FATEK Automation WinProladder Versions 3.30 and prior are vulnerable to an out-of-bounds read, which may allow an attacker to execute arbitrary code.

CVE-2021-32992CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

FATEK Automation WinProladder Versions 3.30 and prior do not properly restrict operations within the bounds of a memory buffer, which may allow an attacker to execute arbitrary code.

CVE-2019-18906CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5, SUSE Manager Server 4.0 allows attackers with access to the hashed password to use it without having to crack it. This issue affects: SUSE Linux Enterprise Server for SAP 12-SP5 cryptctl versions prior to 2.4. SUSE Manager Server 4.0 cryptctl versions prior to 2.4.

CVE-2021-35474CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

CVE-2021-30648CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypass vulnerability. An unauthenticated attacker can execute arbitrary CLI commands, view/modify the appliance configuration and policy, and shutdown/restart the appliance.

CVE-2021-27903CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-862

An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).

CVE-2021-22375CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

There is a Key Management Errors Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality,availability and integrity.

CVE-2021-22323CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

There is an Integer Overflow Vulnerability in Huawei Smartphone. Successful exploitation of these vulnerabilities may escalate the permission to that of the root user.

CVE-2021-35973CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-697

NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthenticated attacker to invoke any action by adding the &currentsetting.htm substring to the HTTP query, a related issue to CVE-2020-27866. This directly allows the attacker to change the web UI password, and eventually to enable debug mode (telnetd) and gain a shell on the device as the admin limited-user account (however, escalation to root is simple because of weak permissions on the /etc/ directory).

CVE-2021-22367CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

There is a Key Management Errors Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may lead to authentication bypass.

CVE-2021-22348CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause code to execute.

CVE-2021-22345CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

There is an Input Verification Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause out-of-bounds memory write.

← PreviousPage 402 / 7034Next →