CVE Database

CVE-2021-32588CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

A use of hard-coded credentials (CWE-798) vulnerability in FortiPortal versions 5.2.5 and below, 5.3.5 and below, 6.0.4 and below, versions 5.1.x and 5.0.x may allow a remote and unauthenticated attacker to execute unauthorized commands as root by uploading and deploying malicious web application archive files using the default hard-coded Tomcat Manager username and password.

CVE-2021-31226CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered in HCC embedded InterNiche 4.0.1. A potential heap buffer overflow exists in the code that parses the HTTP POST request, due to lack of size validation. This vulnerability requires the attacker to send a crafted HTTP POST request with a URI longer than 50 bytes. This leads to a heap overflow in wbs_post() via an strcpy() call.

CVE-2021-39274CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-276

In XeroSecurity Sn1per 9.0 (free version), insecure directory permissions (0777) are set during installation, allowing an unprivileged user to modify the main application and the application configuration file. This results in arbitrary code execution with root privileges.

CVE-2021-39302CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value.

CVE-2021-37597CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation.

CVE-2020-18879CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bl-kereln/ajax/upload-logo.php'.

CVE-2020-36474CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

SafeCurl before 0.9.2 has a DNS rebinding vulnerability.

CVE-2021-21826CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. Within `DecodeTreeBlock` which is called during the decompression of an XMI file, a UINT32 is loaded from the file and used as trusted input as the length of a buffer. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-21827CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. Within `DecodeTreeBlock` which is called during the decompression of an XMI file, a UINT32 is loaded from the file and used as trusted input as the length of a buffer. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2020-18683CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of undefined fields mishandling.

CVE-2021-21828CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. In the default case of DecodeTreeBlock a label is created via CurPath::AddLabel in order to track the label for later reference. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-38171CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-252

adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the init_get_bits return value, which is a necessary step because the second argument to init_get_bits can be crafted.

CVE-2020-18684CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

Floodlight through 1.2 has an integer overflow in checkFlow in StaticFlowEntryPusherResource.java via priority or port number.

CVE-2021-39290CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-384

Certain NetModule devices allow Limited Session Fixation via PHPSESSID. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, NB3701, NB3710, NB3711, NB3720, and NB3800.

CVE-2021-24551CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The Edit Comments WordPress plugin through 0.3 does not sanitise, validate or escape the jal_edit_comments GET parameter before using it in a SQL statement, leading to a SQL injection issue

CVE-2021-39613CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

D-Link DVG-3104MS version 1.0.2.0.3, 1.0.2.0.4, and 1.0.2.0.4E contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file. As weak passwords have been used, the plaintext passwords can be recovered from the hash values. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2021-39614CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

D-Link DVX-2000MS contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file. As weak passwords have been used, the plaintext passwords can be recovered from the hash values.

CVE-2021-39615CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

D-Link DSR-500N version 1.02 contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file.If an attacker succeeds in recovering the cleartext password of the identified hash value, he will be able to log in via SSH or Telnet and thus gain access to the underlying embedded Linux operating system on the device. Fixed in version 2.12/2. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2021-23406CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

This affects the package pac-resolver before 5.0.0. This can occur when used with untrusted input, due to unsafe PAC file handling. **NOTE:** The fix for this vulnerability is applied in the node-degenerator library, a dependency written by the same maintainer.

CVE-2021-23432CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge()

CVE-2021-33191CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to patch the application binary. This "patching" command defaults to calling a trusted binary, but might be modified to an arbitrary value through a "c2-update" command. Said command is then executed using the same privileges as the application binary. This was addressed in version 0.10.0

CVE-2021-36385CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A SQL Injection vulnerability in Cerner Mobile Care 5.0.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via a Fullwidth Apostrophe (aka U+FF07) in the default.aspx User ID field. Arbitrary system commands can be executed through the use of xp_cmdshell.

CVE-2021-38611CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

A command-injection vulnerability in the Image Upload function of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to execute arbitrary commands, as root, via shell metacharacters in the filename parameter to assets/index.php.

CVE-2021-38613CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

The assets/index.php Image Upload feature of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to upload any code to the target system and achieve remote code execution.

CVE-2021-38306CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Network Attached Storage on LG N1T1*** 10124 devices allows an unauthenticated attacker to gain root access via OS command injection in the en/ajp/plugins/access.ssh/checkInstall.php destServer parameter.

CVE-2021-3711CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the decrypted plaintext. The application can then allocate a sufficiently sized buffer and call EVP_PKEY_decrypt() again, but this time passing a non-NULL value for the "out" parameter. A bug in the implementation of the SM2 decryption code means that the calculation of the buffer size required to hold the plaintext returned by the first call to EVP_PKEY_decrypt() can be smaller than the actual size required by the second call. This can lead to a buffer overflow when EVP_PKEY_decrypt() is called by the application a second time with a buffer that is too small. A malicious attacker who is able present SM2 content for decryption to an application could cause attacker chosen data to overflow the buffer by up to a maximum of 62 bytes altering the contents of other data held after the buffer, possibly changing application behaviour or causing the application to crash. The location of the buffer is application dependent but is typically heap allocated. Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k).

CVE-2021-31009CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Multiple issues were addressed by removing HDF5. This issue is fixed in iOS 15.2 and iPadOS 15.2, macOS Monterey 12.1. Multiple issues in HDF5.

CVE-2021-38408CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper validation of the length of user-supplied data may allow remote code execution.

CVE-2020-19267CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

An issue in index.php/Dswjcms/Basis/resources of Dswjcms 1.6.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.

CVE-2021-39510CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

An issue was discovered in D-Link DIR816_A1_FW101CNB04 750m11ac wireless router, The HTTP request parameter is used in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function. This can lead to command injection through shell metacharacters.

CVE-2021-40084CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

opensysusers through 0.6 does not safely use eval on files in sysusers.d that may contain shell metacharacters. For example, it allows command execution via a crafted GECOS field whereas systemd-sysusers (a program with the same specification) does not do that.

CVE-2021-33885CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-347

An Insufficient Verification of Data Authenticity vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote unauthenticated attacker to send the device malicious data that will be used in place of the correct data. This results in full system command access and execution because of the lack of cryptographic signatures on critical data sets.

CVE-2021-37153CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue.

CVE-2021-43200CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

In JetBrains TeamCity before 2021.1.2, permission checks in the Agent Push functionality were insufficient.

CVE-2021-37154CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-91

In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.

CVE-2021-39159CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

BinderHub is a kubernetes-based cloud service that allows users to share reproducible interactive computing environments from code repositories. In affected versions a remote code execution vulnerability has been identified in BinderHub, where providing BinderHub with maliciously crafted input could execute code in the BinderHub context, with the potential to egress credentials of the BinderHub deployment, including JupyterHub API tokens, kubernetes service accounts, and docker registry credentials. This may provide the ability to manipulate images and other user created pods in the deployment, with the potential to escalate to the host depending on the underlying kubernetes configuration. Users are advised to update to version 0.2.0-n653. If users are unable to update they may disable the git repo provider by specifying the `BinderHub.repo_providers` as a workaround.

CVE-2021-37334CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Umbraco Forms version 4.0.0 up to and including 8.7.5 and below are vulnerable to a security flaw that could lead to a remote code execution attack and/or arbitrary file deletion. A vulnerability occurs because validation of the file extension is performed after the file has been stored in a temporary directory. By default, files are stored within the application directory structure at %BASEDIR%/APP_DATA/TEMP/FileUploads/. Whilst access to this directory is restricted by the root web.config file, it is possible to override this restriction by uploading another specially crafted web.config file to the temporary directory. It is possible to exploit this flaw to upload a malicious script file to execute arbitrary code and system commands on the server.

CVE-2021-27944CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Several high privileged APIs on the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs do not enforce access controls, allowing an unauthenticated threat actor to access privileged functionality, leading to OS command execution. The specific attack methodology is a file upload.

CVE-2020-19705CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

thinkphp-zcms as of 20190715 allows SQL injection via index.php?m=home&c=message&a=add.

CVE-2021-40147CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

EmTec ZOC before 8.02.2 allows \e[201~ pastes, a different vulnerability than CVE-2021-32198.

CVE-2021-29772CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsanitized user input. IBM X-Force ID: 202774.

CVE-2020-20675CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Nuishop v2.3 contains a SQL injection vulnerability in /goods/getGoodsListByConditions/.

CVE-2021-39167CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-269

OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executor role to escalate privileges. Further details about the vulnerability will be disclosed at a later date. As a workaround revoke the executor role from accounts not strictly under the team's control. We recommend revoking all executors that are not also proposers. When applying this mitigation, ensure there is at least one proposer and executor remaining.

CVE-2021-39168CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-269

OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executor role to escalate privileges. Further details about the vulnerability will be disclosed at a later date. As a workaround revoke the executor role from accounts not strictly under the team's control. We recommend revoking all executors that are not also proposers. When applying this mitigation, ensure there is at least one proposer and executor remaining.

CVE-2020-19001CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Command Injection in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary system commands via line 64 of the component 'simiki/blob/master/simiki/config.py'.

CVE-2020-18106CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The GET parameter "id" in WMS v1.0 is passed without filtering, which allows attackers to perform SQL injection.

CVE-2021-40177CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Zoho ManageEngine Log360 before Build 5225 allows remote code execution via BCP file overwrite.

CVE-2021-40175CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution.

CVE-2021-37749CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

MapService.svc in Hexagon GeoMedia WebMap 2020 before Update 2 (aka 16.6.2.66) allows blind SQL Injection via the Id (within sourceItems) parameter to the GetMap method.

CVE-2021-37417CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation.

← PreviousPage 409 / 7034Next →