CVE Database

CVE-2021-44735CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.

CVE-2021-44736CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature.

CVE-2021-44090CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An SQL Injection vulnerability exists in Sourcecodester Online Reviewer System 1.0 via the password parameter.

CVE-2021-44092CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An SQL Injection vulnerability exists in code-projects Pharmacy Management 1.0 via the username parameter in the administer login form.

CVE-2021-44244CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An SQL Injection vulnerabiity exists in Sourcecodester Logistic Hub Parcel's Management System 1.0 via the username parameter in login.php.

CVE-2021-44245CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An SQL Injection vulnerability exists in Courcecodester COVID 19 Testing Management System (CTMS) 1.0 via the (1) username and (2) contactno parameters.

CVE-2021-46061CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An SQL Injection vulnerability exists in Sourcecodester Computer and Mobile Repair Shop Management system (RSMS) 1.0 via the code parameter in /rsms/ node app.

CVE-2022-22928CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.

CVE-2022-22929CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbitrary code via a crafted ZIP file.

CVE-2022-22930CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitrary code via a crafted payload.

CVE-2022-23314CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do.

CVE-2022-23315CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.

CVE-2022-0318CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

Heap-based Buffer Overflow in vim/vim prior to 8.2.

CVE-2021-35003CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer C90 1.0.6 Build 20200114 rel.73164(5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of DNS responses. A crafted DNS message can trigger an overflow of a fixed-length, stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-14655.

CVE-2021-35004CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link TL-WA1201 1.0.1 Build 20200709 rel.66244(5553) wireless access points. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of DNS responses. A crafted DNS message can trigger an overflow of a fixed-length, stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-14656.

CVE-2021-40855CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-295

The EU Technical Specifications for Digital COVID Certificates before 1.1 mishandle certificate governance. A non-production public key certificate could have been used in production.

CVE-2021-46198CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An SQL Injection vulnerability exists in Sourceodester Courier Management System 1.0 via the email parameter in /cms/ajax.php app.

CVE-2021-46200CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php.

CVE-2021-46201CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An SQL Injection vulnerability exists in Sourcecodester Online Resort Management System 1.0 via the id parameterv in /orms/ node.

CVE-2021-46307CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An SQL Injection vulnerability exists in Projectworlds Online Examination System 1.0 via the eid parameter in account.php.

CVE-2021-46308CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An SQL Injection vulnerability exists in Sourcecodester Online Railway Reservation Sysytem 1.0 via the sid parameter.

CVE-2021-46309CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An SQL Injection vulnerability exists in Sourcecodester Employee and Visitor Gate Pass Logging System 1.0 via the username parameter.

CVE-2020-4877CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-863

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Force ID: 190843.

CVE-2020-4879CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of authentication cookies. IBM X-Force ID: 190847.

CVE-2021-23196CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-522

The web application on Agilia Link+ version 3.0 implements authentication and session management mechanisms exclusively on the client-side and does not protect authentication attributes sufficiently.

CVE-2021-23233CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-284

Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information such as the session cookie. An attacker can send requests to sensitive endpoints as an unauthenticated user to perform critical actions or modify critical configuration parameters.

CVE-2021-40247CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username field.

CVE-2021-43355CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-603

Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 allows user input to be validated on the client side without authentication by the server. The server should not rely on the correctness of the data because users might not support or block JavaScript or intentionally bypass the client-side checks. An attacker with knowledge of the service user could circumvent the client-side control and login with service privileges.

CVE-2022-23128CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

Incomplete List of Disallowed Inputs vulnerability in Mitsubishi Electric MC Works64 versions 4.00A (10.95.201.23) to 4.04E (10.95.210.01), ICONICS GENESIS64 versions 10.95.3 to 10.97, ICONICS Hyper Historian versions 10.95.3 to 10.97, ICONICS AnalytiX versions 10.95.3 to 10.97 and ICONICS MobileHMI versions 10.95.3 to 10.97 allows a remote unauthenticated attacker to bypass the authentication of MC Works64, GENESIS64, Hyper Historian, AnalytiX and MobileHMI, and gain unauthorized access to the products, by sending specially crafted WebSocket packets to FrameWorX server, one of the functions of the products.

CVE-2021-23518CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using the origin path as __proto__, the attribute of the object is accessed instead of a path. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-72573

CVE-2021-40595CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in Sourcecodester Online Leave Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter to /leave_system/classes/Login.php.

CVE-2022-22553CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

Dell EMC AppSync versions 3.9 to 4.3 contain an Improper Restriction of Excessive Authentication Attempts Vulnerability that can be exploited from UI and CLI. An adjacent unauthenticated attacker could potentially exploit this vulnerability, leading to password brute-forcing. Account takeover is possible if weak passwords are used by users.

CVE-2022-23363CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via index.php.

CVE-2022-23364CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

HMS v1.0 was discovered to contain a SQL injection vulnerability via adminlogin.php.

CVE-2022-23365CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

HMS v1.0 was discovered to contain a SQL injection vulnerability via doctorlogin.php.

CVE-2021-46024CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the "id" parameter in cart_add.php, No login is required.

CVE-2021-26706CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

An issue was discovered in lib_mem.c in Micrium uC/OS uC/LIB 1.38.x and 1.39.00. The following memory allocation functions do not check for integer overflow when allocating a pool whose size exceeds the address space: Mem_PoolCreate, Mem_DynPoolCreate, and Mem_DynPoolCreateHW. Because these functions use multiplication to calculate the pool sizes, the operation may cause an integer overflow if the arguments are large enough. The resulting memory pool will be smaller than expected and may be exploited by an attacker.

CVE-2021-30636CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

In MediaTek LinkIt SDK before 4.6.1, there is a possible memory corruption due to an integer overflow during mishandled memory allocation by pvPortCalloc and pvPortRealloc.

CVE-2022-23852CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.

CVE-2022-23855CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-640

An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An authentication bypass in ECM/maintenance/forgotpasswordstep1 allows an unauthenticated user to reset passwords and login as any local account.

CVE-2021-41472CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in Sourcecodester Simple Membership System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password parameters.

CVE-2021-40596CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in Login.php in sourcecodester Online Learning System v2 by oretnom23, allows attackers to execute arbitrary SQL commands via the faculty_id parameter.

CVE-2021-40907CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in Sourcecodester Storage Unit Rental Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter to /storage/classes/Login.php.

CVE-2021-40908CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in Login.php in Sourcecodester Purchase Order Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter.

CVE-2021-41471CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in Sourcecodester South Gate Inn Online Reservation System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the email and Password parameters.

CVE-2021-41659CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username or password field.

CVE-2021-41660CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in Sourcecodester Patient Appointment Scheduler System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password fields to login.php.

CVE-2021-41928CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection in Sourcecodester Try My Recipe (Recipe Sharing Website - CMS) 1.0 by oretnom23, allows attackers to execute arbitrary code via the rid parameter to the view_recipe page.

CVE-2021-43420CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in Login.php in Sourcecodester Online Payment Hub v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter.

CVE-2022-23126CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

TeslaMate before 1.25.1 (when using the default Docker configuration) allows attackers to open doors of Tesla vehicles, start Keyless Driving, and interfere with vehicle operation en route. This occurs because an attacker can leverage Grafana login access to obtain a token for Tesla API calls.

← PreviousPage 427 / 7034Next →