CVE Database

CVE-2021-44682CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

An issue (6 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited due to deserialization behavior that is inherent to the .NET Remoting service. A malicious attacker can exploit both TCP remoting services and local IPC services on the Enterprise Vault Server. This vulnerability is mitigated by properly configuring the servers and firewall as described in the vendor's security alert for this vulnerability (VTS21-003, ZDI-CAN-14079).

CVE-2021-44684CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

naholyr github-todos 3.1.0 is vulnerable to command injection. The range argument for the _hook subcommand is concatenated without any validation, and is directly used by the exec function.

CVE-2021-44685CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Git-it through 4.4.0 allows OS command injection at the Branches Aren't Just For Birds challenge step. During the verification process, it attempts to run the reflog command followed by the current branch name (which is not sanitized for execution).

CVE-2021-29114CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthenticated attacker to impact the confidentiality, integrity and availability of targeted services via specifically crafted queries.

CVE-2021-37059CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

There is a Weaknesses Introduced During Design

CVE-2021-37084CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to malicious invoking other functions of the Smart Assistant through text messages.

CVE-2021-37095CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to remote denial of service and potential remote code execution.

CVE-2021-43789CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

PrestaShop is an Open Source e-commerce web application. Versions of PrestaShop prior to 1.7.8.2 are vulnerable to blind SQL injection using search filters with `orderBy` and `sortOrder` parameters. The problem is fixed in version 1.7.8.2.

CVE-2021-24041CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

A missing bounds check in image blurring code prior to WhatsApp for Android v2.21.22.7 and WhatsApp Business for Android v2.21.22.7 could have allowed an out-of-bounds write if a user sent a malicious image.

CVE-2021-41716CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function

CVE-2021-42945CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A SQL Injection vulnerability exists in ZZCMS 2021 via the askbigclassid parameter in /admin/ask.php.

CVE-2021-20042CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-441

An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

CVE-2021-20045CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

A buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated attacker to potentially execute code as the 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

CVE-2021-26109CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an unauthenticated attacker to corrupt control data on the heap via specifically crafted requests to SSLVPN, resulting in potentially arbitrary code execution.

CVE-2021-37040CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-88

There is a Parameter injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause privilege escalation of files after CIFS share mounting.

CVE-2021-37045CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

There is an UAF vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the device to restart unexpectedly and the kernel-mode code to be executed.

CVE-2021-37049CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

There is a Heap-based buffer overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may rewrite the memory of adjacent objects.

CVE-2021-3815CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

utils.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CVE-2021-41063CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability was discovered in Aanderaa GeoView Webservice prior to version 2.1.3 that could allow an unauthenticated attackers to execute arbitrary commands.

CVE-2020-27416CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-613

Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to control a users account.

CVE-2021-41025CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-362

Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 thorugh 6.0.7, including an instance of concurrent execution using shared resource with improper synchronization and one of authentication bypass by capture-replay, may allow a remote unauthenticated attacker to circumvent the authentication process and authenticate as a legitimate cluster peer.

CVE-2021-43527CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS < 3.73 and NSS < 3.68.1.

CVE-2021-20146CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-522

An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliated with Gryphon's development and infrastructure. At the time of discovery, the ssh key could be used to login to the development server hosted in Amazon Web Services.

CVE-2021-41694CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-330

An Incorrect Access Control vulnerability exists in Premiumdatingscript 4.2.7.7 via the password change procedure in requests\user.php.

CVE-2021-41695CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An SQL Injection vulnerability exists in Premiumdatingscript 4.2.7.7 via the ip parameter in connect.php. .

CVE-2021-43703CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

An Incorrect Access Control vulnerability exists in zzcms less than or equal to 2019 via admin.php. After disabling JavaScript, you can directly access the administrator console.

CVE-2021-43608CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Doctrine DBAL 3.x before 3.1.4 allows SQL Injection. The escaping of offset and length inputs to the generation of a LIMIT clause was not probably cast to an integer, allowing SQL injection to take place if application developers passed unescaped user input to the DBAL QueryBuilder or any other API that ultimately uses the AbstractPlatform::modifyLimitQuery API.

CVE-2021-44514CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.

CVE-2021-35978CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR. The ZING protocol allows arbitrary remote command execution with SUPER privileges. This allows an attacker (with knowledge of the protocol) to execute arbitrary code on the controller including overwriting firmware, adding/removing users, disabling the internal firewall, etc.

CVE-2021-37934CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

Due to insufficient server-side login-attempt limit enforcement, a vulnerability in /account/login in Huntflow Enterprise before 3.10.14 could allow an unauthenticated, remote user to perform multiple login attempts for brute-force password guessing.

CVE-2021-31746CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal and potentially arbitrary code execution.

CVE-2021-27983CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page.

CVE-2021-23561CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

All versions of package comb are vulnerable to Prototype Pollution via the deepMerge() function.

CVE-2021-23639CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter content, without disabling the JS engine.

CVE-2021-23663CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

All versions of package sey are vulnerable to Prototype Pollution via the deepmerge() function.

CVE-2021-23700CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

All versions of package merge-deep2 are vulnerable to Prototype Pollution via the mergeDeep() function.

CVE-2021-44833CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-276

The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.

CVE-2021-44847CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-682

A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the handling of received network packets) allows remote attackers to crash the process or potentially execute arbitrary code via a network packet.

CVE-2021-27447CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Mesa Labs AmegaView version 3.0 is vulnerable to a command injection, which may allow an attacker to remotely execute arbitrary code.

CVE-2021-44152CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or authorization, an unauthenticated user can change the password of any existing user. This allows an attacker to change the password of any known user, thereby preventing valid users from accessing the system and granting the attacker full access to that user's account.

CVE-2021-24857CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain.

CVE-2021-24863CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots WordPress plugin before 6.67 does not sanitise and escape the User Agent before using it in a SQL statement to save it, leading to a SQL injection

CVE-2021-24951CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in SQL statements when duplicating course/lesson/quiz/question, leading to SQL Injections issues

CVE-2021-43117CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

fastadmin v1.2.1 is affected by a file upload vulnerability which allows arbitrary code execution through shell access.

CVE-2021-44966CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection bypass authentication vulnerability in PHPGURUKUL Employee Record Management System 1.2 via index.php. An attacker can log in as an admin account of this system and can destroy, change or manipulate all sensitive information on the system.

CVE-2021-22279CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

A Missing Authentication vulnerability in RobotWare for the OmniCore robot controller allows an attacker to read and modify files on the robot controller if the attacker has access to the Connected Services Gateway Ethernet port.

CVE-2021-39052CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to access the Spring Boot console without authorization. IBM X-Force ID: 214523.

CVE-2021-39065CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of user-supplied input by the Spectrum Copy Data Management Admin Console login and uploadcertificate function . A remote attacker could inject arbitrary shell commands which would be executed on the affected system. IBM X-Force ID: 214958.

CVE-2021-32024CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1287

A remote code execution vulnerability in the BMP image codec of BlackBerry QNX SDP version(s) 6.4 to 7.1 could allow an attacker to potentially execute code in the context of the affected process.

CVE-2021-24045CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-843

A type confusion vulnerability could be triggered when resolving the "typeof" unary operator in Facebook Hermes prior to v0.10.0. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.

← PreviousPage 421 / 7034Next →