CVE Database

CVE-2019-6288CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Edgecore ECS2020 Firmware 1.0.0.0 devices allow Unauthenticated Command Injection via the command1 HTTP header to the /EXCU_SHELL URI.

CVE-2024-9234KEVCRITICALin_the_wild
CVSS 9.8
EPSS
Priority 0

The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the install_and_activate_plugin_from_external() function (install-active-plugin REST API endpoint) in all versions up to, and including, 2.1.0. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins, or utilize the functionality to upload arbitrary files spoofed like plugins.

CVE-2021-34727CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when an affected device processes traffic. An attacker could exploit this vulnerability by sending crafted traffic to the device. A successful exploit could allow the attacker to cause a buffer overflow and possibly execute arbitrary commands with root-level privileges, or cause the device to reload, which could result in a denial of service condition.

CVE-2021-34770CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to execute arbitrary code with administrative privileges or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a logic error that occurs during the validation of CAPWAP packets. An attacker could exploit this vulnerability by sending a crafted CAPWAP packet to an affected device. A successful exploit could allow the attacker to execute arbitrary code with administrative privileges or cause the affected device to crash and reload, resulting in a DoS condition.

CVE-2021-32959CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

Heap-based buffer overflow in SuiteLink server while processing commands 0x05/0x06

CVE-2021-21913CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

An information disclosure vulnerability exists in the WiFi Smart Mesh functionality of D-LINK DIR-3040 1.13B03. A specially-crafted network request can lead to command execution. An attacker can connect to the MQTT service to trigger this vulnerability.

CVE-2020-4690CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 186697.

CVE-2021-26794CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php file.

CVE-2021-22869CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-668

An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not have had access to. This affects customers using self-hosted runner groups for access control. A repository with access to one enterprise runner group could access all of the enterprise runner groups within the organization because of improper authentication checks during the request. This could cause code to be run unintentionally by the incorrect runner group. This vulnerability affected GitHub Enterprise Server versions from 3.0.0 to 3.0.15 and 3.1.0 to 3.1.7 and was fixed in 3.0.16 and 3.1.8 releases.

CVE-2020-28425CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

This affects all versions of package curljs.

CVE-2021-34348CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210803 and later

CVE-2021-34351CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210803 and later

CVE-2021-38299CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to login to a vulnerable service using an attached FIDO2 authenticator without passing a check of the user presence.

CVE-2021-40098CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

An issue was discovered in Concrete CMS through 8.5.5. Path Traversal leading to RCE via external form by adding a regular expression.

CVE-2021-33907CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-295

The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files when performing an update of the client. This could lead to remote code execution in an elevated privileged context.

CVE-2021-34416CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.20210325, Zoom on-premise Meeting Connector MMR before version 4.6.360.20210325, Zoom on-premise Recording Connector before version 3.8.44.20210326, Zoom on-premise Virtual Room Connector before version 4.4.6752.20210326, and Zoom on-premise Virtual Room Connector Load Balancer before version 2.5.5495.20210326 fails to validate input sent in requests to update the network configuration, which could lead to remote command injection on the on-premise image by the web portal administrators.

CVE-2021-36219CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-824

An issue was discovered in SKALE sgxwallet 1.58.3. The provided input for ECALL 14 triggers a branch in trustedEcdsaSign that frees a non-initialized pointer from the stack. An attacker can chain multiple enclave calls to prepare a stack that contains a valid address. This address is then freed, resulting in compromised integrity of the enclave. This was resolved after v1.58.3 and not reproducible in sgxwallet v1.77.0.

CVE-2021-37539CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.

CVE-2021-36879CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-264

Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPress configuration allows user registration.

CVE-2021-36880CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable parameter: custom.

CVE-2021-37761CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution.

CVE-2021-40329CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management.

CVE-2021-41558CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

The set_user extension module before 3.0.0 for PostgreSQL allows ProcessUtility_hook bypass via set_config.

CVE-2021-37270CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-862

There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0. Attackers can use this vulnerability to directly access the specified background path without logging in to the background to obtain the background administrator authority.

CVE-2021-38124CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Remote Code Execution vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, affecting versions 7.0.2 through 7.5. The vulnerability could be exploited resulting in remote code execution.

CVE-2021-36363CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-276

Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.

CVE-2021-36364CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Nagios XI before 5.8.5 incorrectly allows backup_xi.sh wildcards.

CVE-2021-36365CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-276

Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.

CVE-2021-36366CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Nagios XI before 5.8.5 incorrectly allows manage_services.sh wildcards.

CVE-2021-38303CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A SQL injection vulnerability exists in Sureline SUREedge Migrator 7.0.7.29360.

CVE-2020-20120CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

ThinkPHP v3.2.3 and below contains a SQL injection vulnerability which is triggered when the array is not passed to the "where" and "query" methods.

CVE-2020-20122CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Wuzhi CMS v4.1 contains a SQL injection vulnerability in the checktitle() function in /coreframe/app/content/admin/content.php.

CVE-2021-33924CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-862

Confluent Ansible (cp-ansible) version 5.5.0, 5.5.1, 5.5.2 and 6.0.0 is vulnerable to Incorrect Access Control via its auxiliary component that allows remote attackers to access sensitive information.

CVE-2021-36745CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-425

A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers 5.8, and ServerProtect for Microsoft Windows / Novell Netware 5.8 could allow a remote attacker to bypass authentication on affected installations.

CVE-2021-35943CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password, per RFC4513.

CVE-2020-18685CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of unchecked prerequisites related to TCP or UDP ports, or group or table IDs.

CVE-2021-41616CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINARY, LONGVARBINARY, or BLOB between databases using the ddlutils features. The BinaryObjectsHelper class was insecure and used ObjectInputStream.readObject without validating that the input data was safe to deserialize. Please note that DdlUtils is no longer being actively developed. To address the insecurity of the BinaryObjectHelper class, the following changes to DdlUtils have been made: (1) BinaryObjectsHelper.java has been deleted from the DdlUtils source repository and the DdlUtils feature of propagating data of SQL binary types is therefore no longer present in DdlUtils; (2) The ddlutils-1.0 release has been removed from the Apache Release Distribution Infrastructure; (3) The DdlUtils web site has been updated to indicate that DdlUtils is now available only as source code, not as a packaged release.

CVE-2021-41290CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can remotely set arbitrary values for location and content type and gain the possibility to execute arbitrary code on the affected device.

CVE-2021-41296CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-521

ECOA BAS controller uses weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system.

CVE-2021-41299CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

ECOA BAS controller is vulnerable to hard-coded credentials within its Linux distribution image, thus remote attackers can obtain administrator’s privilege without logging in.

CVE-2021-41300CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-522

ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain privilege with full functionality.

CVE-2021-41301CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-200

ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. This will enable the unauthenticated attacker to remotely disclose sensitive information and help her in authentication bypass, privilege escalation and full system access.

CVE-2021-20578CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized actions due to improper or missing authentication controls. IBM X-Force ID: 199282.

CVE-2021-41288CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.

CVE-2021-33583CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

REINER timeCard 6.05.07 installs a Microsoft SQL Server with an sa password that is hardcoded in the TCServer.jar file.

CVE-2020-20796CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

FlameCMS 3.3.5 contains a SQL injection vulnerability in /master/article.php via the "Id" parameter.

CVE-2020-20797CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

FlameCMS 3.3.5 contains a time-based blind SQL injection vulnerability in /account/register.php.

CVE-2021-34352CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210902 and later

CVE-2021-41110CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

cwlviewer is a web application to view and share Common Workflow Language workflows. Versions prior to 1.3.1 contain a Deserialization of Untrusted Data vulnerability. Commit number f6066f09edb70033a2ce80200e9fa9e70a5c29de (dated 2021-09-30) contains a patch. There are no available workarounds aside from installing the patch. The SnakeYaml constructor, by default, allows any data to be parsed. To fix the issue the object needs to be created with a `SafeConstructor` object, as seen in the patch.

CVE-2021-40960CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Galera WebTemplate 1.0 is affected by a directory traversal vulnerability that could reveal information from /etc/passwd and /etc/shadow.

← PreviousPage 413 / 7034Next →