CVE Database

CVE-2021-38574CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.

CVE-2021-37222CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Parsers in the open source project RCDCAP before 1.0.5 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via specially crafted packets.

CVE-2020-28165CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload arbitrary webshell to the server by using the downloadZipPackage() function.

CVE-2020-20975CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

In \lib\admin\action\dataaction.class.php in Gxlcms v1.1, SQL Injection exists via the $filename parameter.

CVE-2020-20979CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

An arbitrary file upload vulnerability in the move_uploaded_file() function of LJCMS v4.3 allows attackers to execute arbitrary code.

CVE-2021-20314CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code execution via malicious crafted SPF explanation messages.

CVE-2020-21726CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

OpenSNS v6.1.0 contains a blind SQL injection vulnerability in /Controller/ChinaCityController.class.php via the cid parameter.

CVE-2021-20509CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 198243.

CVE-2021-38606CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-330

reNgine through 0.5 relies on a predictable directory name.

CVE-2021-26432CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability

CVE-2021-33199CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

In Expression Engine before 6.0.3, addonIcon in Addons/file/mod.file.php relies on the untrusted input value of input->get('file') instead of the fixed file names of icon.png and icon.svg.

CVE-2021-37599CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The exporter/Login.aspx login form in the Exporter in Nuance Winscribe Dictation 4.1.0.99 is vulnerable to SQL injection that allows a remote, unauthenticated attacker to read the database (and execute code in some situations) via the txtPassword parameter.

CVE-2021-29377CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Pear Admin Think through 2.1.2 has an arbitrary file upload vulnerability that allows attackers to execute arbitrary code remotely. A .php file can be uploaded via admin.php/index/upload because app/common/service/UploadService.php mishandles fileExt.

CVE-2021-31556CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1284

An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. MWOAuthConsumerSubmitControl.php does not ensure that the length of an RSA key will fit in a MySQL blob.

CVE-2021-31698CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Quectel EG25-G devices through 202006130814 allow executing arbitrary code remotely by using an AT command to place shell metacharacters in quectel_handle_fumo_cfg input in atfwd_daemon.

CVE-2020-36363CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-327

Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entities consider to be weak ciphers.

CVE-2021-28121CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Virtual Robots.txt before 1.10 does not block HTML tags in the robots.txt field.

CVE-2021-28890CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

J2eeFAST 2.2.1 allows remote attackers to perform SQL injection via the (1) compId parameter to fast/sys/user/list, (2) deptId parameter to fast/sys/role/list, or (3) roleId parameter to fast/sys/role/authUser/list, related to the use of ${} to join SQL statements.

CVE-2021-37350CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper input sanitisation.

CVE-2020-18758CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to execute arbitrary code.

CVE-2021-37353CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-918

Nagios XI Docker Wizard before version 1.1.3 is vulnerable to SSRF due to improper sanitation in table_population.php.

CVE-2021-37344CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS Command (OS Command injection).

CVE-2021-37346CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation of special elements used in an OS Command (OS Command injection).

CVE-2021-46093CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-276

eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php.

CVE-2021-1104CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-908

The RISC-V Instruction Set Manual contains a documented ambiguity for the Machine Trap Vector Base Address (MTVEC) register that may lead to a vulnerability due to the initial state of the register not being defined, potentially leading to information disclosure, data tampering and denial of service.

CVE-2021-32071CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The MiCollab Client service in Mitel MiCollab before 9.3 could allow an unauthenticated user to gain system access due to improper access control. A successful exploit could allow an attacker to view and modify application data, and cause a denial of service for users.

CVE-2020-18753CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-862

An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to gain access to the system and escalate privileges via a crafted packet.

CVE-2021-36789CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection.

CVE-2021-38302CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The Newsletter extension through 4.0.0 for TYPO3 allows SQL Injection.

CVE-2021-21829CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&T Labs’ Xmill 0.7. A specially crafted XMI file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-21830CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&T Labs’ Xmill 0.7. A specially crafted XMI file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-38753CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

An unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain unauthorized access to the server hosting the web app.

CVE-2021-38754CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection vulnerability in Hospital Management System due to lack of input validation in messearch.php.

CVE-2021-35393CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The binary is usually named wscd or mini_upnpd and is the successor to miniigd. The server is vulnerable to a stack buffer overflow vulnerability that is present due to unsafe parsing of the UPnP SUBSCRIBE/UNSUBSCRIBE Callback header. Successful exploitation of this vulnerability allows remote unauthenticated attackers to gain arbitrary code execution on the affected device.

CVE-2020-18698CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/cms/user.py'.

CVE-2020-18701CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-863

Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the application not invalidating a user's authentication token upon logout, which allows for replaying packets.

CVE-2020-18703CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-611

XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/utils/atom.py'.

CVE-2020-18704CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Unrestricted Upload of File with Dangerous Type in Django-Widgy v0.8.4 allows remote attackers to execute arbitrary code via the 'image' widget in the component 'Change Widgy Page'.

CVE-2020-18705CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-611

XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/core/content/views.py'.

CVE-2021-22931CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-170

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.

CVE-2021-37708CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in mail agent settings. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.

CVE-2021-3616CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-285

A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter firmware content and device configuration. This vulnerability is the same as CNVD-2020-68651.

CVE-2020-22937CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file.

CVE-2021-22156CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

An integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® QNX Software Development Platform (SDP) version(s) 6.5.0SP1 and earlier, QNX OS for Medical 1.1 and earlier, and QNX OS for Safety 1.0.1 and earlier that could allow an attacker to potentially perform a denial of service or execute arbitrary code.

CVE-2020-18164CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection vulnerability exists in tp-shop 2.x-3.x via the /index.php/home/api/shop fBill parameter.

CVE-2021-21810CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-21832CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-680

A memory corruption vulnerability exists in the ISO Parsing functionality of Disc Soft Ltd Deamon Tools Pro 8.3.0.0767. A specially crafted malformed file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-21825CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

A heap-based buffer overflow vulnerability exists in the XML Decompression PlainTextUncompressor::UncompressItem functionality of AT&T Labs’ Xmill 0.7. A specially crafted XMI file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-37358CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checkrepeat&v_name=".

CVE-2020-25928CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: DNS response processing functions: dns_upcall(), getoffset(), dnc_set_answer(). The attack vector is: a specific DNS response packet. The code does not check the "response data length" field of individual DNS answers, which may cause out-of-bounds read/write operations, leading to Information leak, Denial-or-Service, or Remote Code Execution, depending on the context.

← PreviousPage 408 / 7034Next →