CVE Database

CVE-2021-45014CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

There is an upload sql injection vulnerability in the background of taocms 3.0.2 in parameter id:action=cms&ctrl=update&id=26

CVE-2021-44524CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-668

A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0). Affected applications insufficiently limit the access to the internal user authentication service. This could allow an unauthenticated remote attacker to trigger several actions on behalf of valid user accounts.

CVE-2021-44538CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of the channel. Attackers can construct a crafted sequence of messages to manipulate the state of the receiver's session in such a way that, for some buffer sizes, a buffer overflow happens on a call to olm_session_describe. Furthermore, safe buffer sizes were undocumented. The overflow content is partially controllable by the attacker and limited to ASCII spaces and digits. The known affected products are Element Web And SchildiChat Web.

CVE-2021-42064CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized "in" clause, SAP Commerce - versions 1905, 2005, 2105, 2011, allows attacker to execute crafted database queries, exposing backend database. The vulnerability is present if the parameterized "in" clause accepts more than 1000 values.

CVE-2021-44231CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.

CVE-2021-44041CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-610

UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI handler for uipath-assistant://. This allows an attacker to execute code on a victim's machine or capture NTLM credentials by supplying a networked or WebDAV file path.

CVE-2021-44042CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-116

An issue was discovered in UiPath Assistant 21.4.4. User-controlled data supplied to the --process-start argument of the URI handler for uipath-assistant:// is not correctly encoded, resulting in attacker-controlled content being injected into the error message displayed (when the injected content does not match an existing process). A determined attacker could leverage this to execute JavaScript in the context of the Electron application.

CVE-2021-40883CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins.

CVE-2021-43214CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Web Media Extensions Remote Code Execution Vulnerability

CVE-2021-41560CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php.

CVE-2021-41844CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Crocoblock JetEngine before 2.9.1 does not properly validate and sanitize form data.

CVE-2021-43113CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.

CVE-2021-42310CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Microsoft Defender for IoT Remote Code Execution Vulnerability

CVE-2021-43215CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution

CVE-2021-43217CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Windows Encrypting File System (EFS) Remote Code Execution Vulnerability

CVE-2021-43225CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Bot Framework SDK Remote Code Execution Vulnerability

CVE-2021-43882CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-295

Microsoft Defender for IoT Remote Code Execution Vulnerability

CVE-2021-43899CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability

CVE-2021-43907CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Visual Studio Code WSL Extension Remote Code Execution Vulnerability

CVE-2021-42216CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-326

A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.

CVE-2021-0889CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-8.1 Android-9Android ID: A-180745296

CVE-2021-0956CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

In NfcTag::discoverTechnologies (activation) of NfcTag.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additionalSystem execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-189942532

CVE-2021-39641CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Product: AndroidVersions: Android kernelAndroid ID: A-126949257References: N/A

CVE-2021-40850CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx.

CVE-2021-39644CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Product: AndroidVersions: Android kernelAndroid ID: A-199809304References: N/A

CVE-2021-39645CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Product: AndroidVersions: Android kernelAndroid ID: A-199805112References: N/A

CVE-2021-39655CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Product: AndroidVersions: Android kernelAndroid ID: A-192641593References: N/A

CVE-2021-43935CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-288

The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any active directory (AD) account provisioned in the application without supplying a password, resulting in access to the application as the supplied AD account, with all associated privileges.

CVE-2021-4119CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-284

bookstack is vulnerable to Improper Access Control

CVE-2021-44350CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php.

CVE-2021-43834CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows an attacker to authenticate as an existing user, if that user was created using a single sign-on authentication option such as LDAP or SAML. It impacts instances where LDAP or SAML is used for authentication instead of the (default) local password mechanism. Users should upgrade to at least version 4.2.0.

CVE-2020-18078CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password.

CVE-2021-23450CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.

CVE-2021-23797CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

All versions of package http-server-node are vulnerable to Directory Traversal via use of --path-as-is.

CVE-2021-23803CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-863

This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the security of the application. When the template is set to allow/disallow the use of certain functions, adding control characters (x00-x08) after the function will bypass these restrictions.

CVE-2021-44732CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.

CVE-2021-44159CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files without authentication and execute arbitrary code in order to perform arbitrary system operations or deny of service attack.

CVE-2021-44164CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pass file type validation, upload malicious script and execute arbitrary code without authentication, in order to take control of the system or terminate service.

CVE-2021-44675CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which authentication is not required.

CVE-2021-44676CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects of the application state.

CVE-2021-44525CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authentication is not required.

CVE-2021-43439CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-79

RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely

CVE-2021-24849CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

CVE-2021-45090CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Stormshield Endpoint Security before 2.1.2 allows remote code execution.

CVE-2021-45252CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be retrieving all information from the database of this system by using this vulnerability.

CVE-2021-45253CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The application interacted with that domain, indicating that the injected SQL query was executed.

CVE-2021-45255CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The email parameter from ajax.php of Video Sharing Website 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The application interacted with that domain, indicating that the injected SQL query was executed.

CVE-2021-36336CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticated attacker to execute code on the affected system.

CVE-2021-27451CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Mesa Labs AmegaView Versions 3.0 and prior’s passcode is generated by an easily reversible algorithm, which may allow an attacker to gain access to the device.

CVE-2021-27453CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-288

Mesa Labs AmegaView Versions 3.0 uses default cookies that could be set to bypass authentication to the web application, which may allow an attacker to gain access.

← PreviousPage 422 / 7034Next →