CVE Database

CVE-2019-20082CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

ASUS RT-N53 3.0.0.4.376.3754 devices have a buffer overflow via a long lan_dns1_x or lan_dns2_x parameter to Advanced_LAN_Content.asp.

CVE-2021-37400CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-522

An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PLC user program may be uploaded, altered, and/or downloaded.

CVE-2021-37401CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-522

An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the PLC user program may be uploaded, altered, and/or downloaded.

CVE-2020-7878CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-353

An arbitrary file download and execution vulnerability was found in the VideoOffice X2.9 and earlier versions (CVE-2020-7878). This issue is due to missing support for integrity check.

CVE-2021-38687CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of Surveillance Station: QTS 5.0.0 (64 bit): Surveillance Station 5.2.0.4.2 ( 2021/10/26 ) and later QTS 5.0.0 (32 bit): Surveillance Station 5.2.0.3.2 ( 2021/10/26 ) and later QTS 4.3.6 (64 bit): Surveillance Station 5.1.5.4.6 ( 2021/10/26 ) and later QTS 4.3.6 (32 bit): Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later QTS 4.3.3: Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later

CVE-2021-36722CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dumping the whole database to full RCE on the affected endpoints. The SQLi caused by CWE-209: Generation of Error Message Containig Sensetive Information, showing parts of the aspx code and the webroot location , information an attacker can leverage to further compromise the host.

CVE-2021-45427CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal. An attacker can browse and delete files without any authentication due to incorrect access control and directory traversal.

CVE-2021-20149CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-863

Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient access controls for the WAN interface. The default iptables ruleset for governing access to services on the device only apply to IPv4. All services running on the devices are accessible via the WAN interface via IPv6 by default.

CVE-2021-20155CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Trendnet AC2600 TEW-827DRU version 2.08B01 makes use of hardcoded credentials. It is possible to backup and restore device configurations via the management web interface. These devices are encrypted using a hardcoded password of "12345678".

CVE-2021-20158CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauthenticated, malicous actor to force the change of the admin password due to a hidden administrative command.

CVE-2021-45951CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Dnsmasq 2.86 has a heap-based buffer overflow in check_bad_address (called from check_for_bogus_wildcard and FuzzCheckForBogusWildcard). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.

CVE-2021-45952CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Dnsmasq 2.86 has a heap-based buffer overflow in dhcp_reply (called from dhcp_packet and FuzzDhcp). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.

CVE-2021-45953CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Dnsmasq 2.86 has a heap-based buffer overflow in extract_name (called from hash_questions and fuzz_util.c). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.

CVE-2021-45954CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Dnsmasq 2.86 has a heap-based buffer overflow in extract_name (called from answer_auth and FuzzAuth). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.

CVE-2021-45955CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Dnsmasq 2.86 has a heap-based buffer overflow in resize_packet (called from FuzzResizePacket and fuzz_rfc1035.c) because of the lack of a proper bounds check upon pseudo header re-insertion. NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge." However, a contributor states that a security patch (mentioned in 016162.html) is needed

CVE-2021-45956CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Dnsmasq 2.86 has a heap-based buffer overflow in print_mac (called from log_packet and dhcp_reply). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.

CVE-2021-45957CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Dnsmasq 2.86 has a heap-based buffer overflow in answer_request (called from FuzzAnswerTheRequest and fuzz_rfc1035.c). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.

CVE-2022-0080CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

mruby is vulnerable to Heap-based Buffer Overflow

CVE-2021-25981CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-613

In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerable to Insufficient Session Expiration. This may allow an attacker to reuse the admin’s still-valid session token even when logged-out, to gain admin privileges, given the attacker is able to obtain that token (via other, hypothetical attacks)

CVE-2021-30351CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

An out of bound memory access can occur due to improper validation of number of frames being passed during music playback in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

CVE-2021-37120CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

There is a Double free vulnerability in Smartphone.Successful exploitation of this vulnerability may cause a kernel crash or privilege escalation.

CVE-2021-37121CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

There is a Configuration defects in Smartphone.Successful exploitation of this vulnerability may elevate the MEID (IMEI) permission.

CVE-2021-37128CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

HwPCAssistant has a Path Traversal vulnerability .Successful exploitation of this vulnerability may write any file.

CVE-2021-39979CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

HHEE system has a Code Injection vulnerability.Successful exploitation of this vulnerability may affect HHEE system integrity.

CVE-2021-39990CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

The screen lock module has a Stack-based Buffer Overflow vulnerability.Successful exploitation of this vulnerability may affect user experience.

CVE-2021-45389CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

A flaw was found with the JWT token. A self-signed JWT token could be injected into the update manager and bypass the authentication process, thus could escalate privileges. This affects StarWind SAN and NAS build 1578 and StarWind Command Center build 6864.

CVE-2022-22704CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-909

The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that systemd would (in effect) determine part of the configuration.

CVE-2022-0086CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-918

uppy is vulnerable to Server-Side Request Forgery (SSRF)

CVE-2021-24042CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.21.230, WhatsApp Business for iOS prior to v2.21.230, WhatsApp for KaiOS prior to v2.2143, WhatsApp Desktop prior to v2.2146 could have allowed an out-of-bounds write if a user makes a 1:1 call to a malicious actor.

CVE-2021-43832CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

Spinnaker is an open source, multi-cloud continuous delivery platform. Spinnaker has improper permissions allowing pipeline creation & execution. This lets an arbitrary user with access to the gate endpoint to create a pipeline and execute it without authentication. If users haven't setup Role-based access control (RBAC) with-in spinnaker, this enables remote execution and access to deploy almost any resources on any account. Patches are available on the latest releases of the supported branches and users are advised to upgrade as soon as possible. Users unable to upgrade should enable RBAC on ALL accounts and applications. This mitigates the ability of a pipeline to affect any accounts. Block application access unless permission are enabled. Users should make sure ALL application creation is restricted via appropriate wildcards.

CVE-2022-21643CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via register.php. In particular usernames, email addresses, and passwords provided by the user were not sanitized and were used directly to construct a sql statement. Users are advised to upgrade as soon as possible. There are not workarounds for this issue.

CVE-2022-21647CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

CodeIgniter is an open source PHP full-stack web framework. Deserialization of Untrusted Data was found in the `old()` function in CodeIgniter4. Remote attackers may inject auto-loadable arbitrary objects with this vulnerability, and possibly execute existing PHP code on the server. We are aware of a working exploit, which can lead to SQL injection. Users are advised to upgrade to v4.1.6 or later. Users unable to upgrade as advised to not use the `old()` function and form_helper nor `RedirectResponse::withInput()` and `redirect()->withInput()`.

CVE-2021-41842CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue was discovered in AtaLegacySmm in the kernel 5.0 before 05.08.46, 5.1 before 05.16.46, 5.2 before 05.26.46, 5.3 before 05.35.46, 5.4 before 05.43.46, and 5.5 before 05.51.45 in Insyde InsydeH2O. Code execution can occur because the SMI handler lacks a CommBuffer check.

CVE-2021-31522CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-470

Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions.

CVE-2021-45456CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch between what is being checked and what is being used as the shell command argument in DiagnosisService. This may cause an illegal project name to pass the check and perform the following steps, resulting in a command injection vulnerability. This issue affects Apache Kylin 4.0.0.

CVE-2021-46067CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

CVE-2021-23543CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.

CVE-2021-23568CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

The package extend2 before 1.0.1 are vulnerable to Prototype Pollution via the extend function due to unsafe recursive merge.

CVE-2021-39993CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

There is an Integer overflow vulnerability with ACPU in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.

CVE-2021-39996CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

There is a Heap-based buffer overflow vulnerability with the NFC module in smartphones. Successful exploitation of this vulnerability may cause memory overflow.

CVE-2021-40010CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

The bone voice ID TA has a heap overflow vulnerability.Successful exploitation of this vulnerability may result in malicious code execution.

CVE-2021-45003CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-276

Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.php through the "image" parameter that can execute a webshell payload.

CVE-2021-42392CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution.

CVE-2021-45334CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Sourcecodester Online Thesis Archiving System 1.0 is vulnerable to SQL Injection. An attacker can bypass admin authentication and gain access to admin panel using SQL Injection

CVE-2022-22847CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Formpipe Lasernet before 9.13.3 allows file inclusion in Client Web Services (either by an authenticated attacker, or in a configuration that does not require authentication).

CVE-2022-22817CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used.

CVE-2022-22822CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

CVE-2022-22823CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

CVE-2022-22824CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

CVE-2022-22845CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key across different customers' installations.

← PreviousPage 425 / 7034Next →