CVE Database

CVE-2020-15744CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

Stack-based Buffer Overflow vulnerability in the ONVIF server component of Victure PC420 smart camera allows an attacker to execute remote code on the target device. This issue affects: Victure PC420 firmware version 1.2.2 and prior versions.

CVE-2021-21741CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

There is a command execution vulnerability in a ZTE conference management system. As some services are enabled by default, the attacker could exploit this vulnerability to execute arbitrary commands by sending specific serialization command.

CVE-2021-27663CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-285

A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system without adequate authorization. This issue affects: Johnson Controls CEM Systems AC2000 10.1; 10.2; 10.3; 10.4; 10.5.

CVE-2021-32955CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to remotely execute code.

CVE-2021-32967CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-288

Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without being authenticated or authorized, which may allow the attacker to log in and use the device with administrative privileges.

CVE-2021-32983CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter keyword before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.

CVE-2021-38390CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter egyid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.

CVE-2021-38391CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter type before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.

CVE-2021-38393CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter agid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.

CVE-2021-33055CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions.

CVE-2021-34066CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

An issue was discovered in EdgeGallery/developer before v1.0. There is a "Deserialization of yaml file" vulnerability that can allow attackers to execute system command through uploading the malicious constructed YAML file.

CVE-2021-37421CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-345

Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.

CVE-2020-22848CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

A remote code execution (RCE) vulnerability in the \Playsong.php component of cscms v4.1 allows attackers to execute arbitrary commands.

CVE-2021-39177CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Versions of Geyser prior to 1.4.2-SNAPSHOT allow anyone that can connect to the server to forge a LoginPacket with manipulated JWT token allowing impersonation as any user. Version 1.4.2-SNAPSHOT contains a patch for the issue. There are no known workarounds aside from upgrading.

CVE-2021-38145CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in Form Tools through 3.0.20. SQL Injection can occur via the export_group_id field when a low-privileged user (client) tries to export a form with data, e.g., manipulation of modules/export_manager/export.php?export_group_id=1&export_group_1_results=all&export_type_id=1.

CVE-2021-34565CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials.

CVE-2021-21811CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-191

A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-39379CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the ResetUserInfo.php password_stn_id parameter.

CVE-2021-22002CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443 could tamper with host headers to facilitate access to the /cfg web app, in addition a malicious actor could access /cfg diagnostic endpoints without authentication.

CVE-2021-40353CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the index.php USERNAME parameter. NOTE: this issue may exist because of an incomplete fix for CVE-2020-6637.

CVE-2021-39377CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the index.php username parameter.

CVE-2021-39378CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the NamesList.php str parameter.

CVE-2022-24219CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php.

CVE-2021-23427CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

This affects all versions of package elFinder.NetCore. The ExtractAsync function within the FileSystem is vulnerable to arbitrary extraction due to insufficient validation.

CVE-2021-23428CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

This affects all versions of package elFinder.NetCore. The Path.Combine(...) method is used to create an absolute file path. Due to missing sanitation of the user input and a missing check of the generated path its possible to escape the Files directory via path traversal

CVE-2021-36020CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-91

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the 'City' field. An unauthenticated attacker can trigger a specially crafted script to achieve remote code execution.

CVE-2022-24220CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php.

CVE-2021-40350CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

webctrl.cgi.elf on Christie Digital DWU850-GS V06.46 devices allows attackers to perform any desired action via a crafted query containing an unspecified Cookie header. Authentication bypass can be achieved by including an administrative cookie that the device does not validate.

CVE-2021-23436CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-843

This affects the package immer before 9.0.6. A type confusion vulnerability can lead to a bypass of CVE-2020-28477 when the user-provided keys used in the path parameter are arrays. In particular, this bypass is possible because the condition (p === "__proto__" || p === "constructor") in applyPatches_ returns false if p is ['__proto__'] (or ['constructor']). The === operator (strict equality operator) returns false if the operands have different type.

CVE-2021-23438CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-843

This affects the package mpath before 0.8.4. A type confusion vulnerability can lead to a bypass of CVE-2018-16490. In particular, the condition ignoreProperties.indexOf(parts[i]) !== -1 returns -1 if parts[i] is ['__proto__']. This is because the method that has been called if the input is an array is Array.prototype.indexOf() and not String.prototype.indexOf(). They behave differently depending on the type of the input.

CVE-2021-34746CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-289

A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and log in to an affected device as an administrator. This vulnerability is due to incomplete validation of user-supplied input that is passed to an authentication script. An attacker could exploit this vulnerability by injecting parameters into an authentication request. A successful exploit could allow the attacker to bypass authentication and log in as an administrator to the affected device.

CVE-2021-3757CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

immer is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CVE-2019-10095CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.

CVE-2020-18048CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

An issue in craigms/main.php of CraigMS 1.0 allows attackers to execute arbitrary commands via a crafted input entered into the DB Name field.

CVE-2021-34436CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. This extension uses lsp4xml (recently renamed to LemMinX) in order to provide language support for XML. This is installed by default.

CVE-2021-40494CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

A Hardcoded JWT Secret Key in metadata.py in AdaptiveScale LXDUI through 2.1.3 allows attackers to gain admin access to the host system.

CVE-2021-3766CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

objection.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CVE-2021-40531CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opened, without the com.apple.quarantine extended attribute. This results in remote code execution, as demonstrated by CommandString in a terminal profile to Terminal.app.

CVE-2021-40532CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Telegram Web K Alpha before 0.7.2 mishandles the characters in a document extension.

CVE-2021-40540CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

ulfius_uri_logger in Ulfius HTTP Framework before 2.7.4 omits con_info initialization and a con_info->request NULL check for certain malformed HTTP requests.

CVE-2021-38840CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection can occur in Simple Water Refilling Station Management System 1.0 via the water_refilling/classes/Login.php username parameter.

CVE-2021-36163CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST request directly to a HessianSkeleton: New HessianSkeleton are created without any configuration of the serialization factory and therefore without applying the dubbo properties for applying allowed or blocked type lists. In addition, the generic service is always exposed and therefore attackers do not need to figure out a valid service/method name pair. This is fixed in 2.7.13, 2.6.10.1

CVE-2021-37716CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

A remote buffer overflow vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.15. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.

CVE-2020-7832CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

A vulnerability (improper input validation) in the DEXT5 Upload solution allows an unauthenticated attacker to download and execute an arbitrary file via AddUploadFile, SetSelectItem, DoOpenFile function.(CVE-2020-7832)

CVE-2020-7865CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

A vulnerability(improper input validation) in the ExECM CoreB2B solution allows an unauthenticated attacker to download and execute an arbitrary file via httpDownload function. A successful exploit could allow the attacker to hijack vulnerable system.

CVE-2021-35946CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-269

A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore elevate their own permissions.

CVE-2021-39497CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-918

eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.

CVE-2021-32802CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-829

Nextcloud server is an open source, self hosted personal cloud. Nextcloud supports rendering image previews for user provided file content. For some image types, the Nextcloud server was invoking a third-party library that wasn't suited for untrusted user-supplied content. There are several security concerns with passing user-generated content to this library, such as Server-Side-Request-Forgery, file disclosure or potentially executing code on the system. The risk depends on your system configuration and the installed library version. It is recommended that the Nextcloud Server is upgraded to 20.0.12, 21.0.4 or 22.1.0. These versions do not use this library anymore. As a workaround users may disable previews by setting `enable_previews` to `false` in `config.php`.

CVE-2020-19853CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

BlueCMS v1.6 contains a SQL injection vulnerability via /ad_js.php.

CVE-2020-11264CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injection in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

← PreviousPage 410 / 7034Next →