CVE Database

CVE-2020-17383CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

A directory traversal vulnerability on Telos Z/IP One devices through 4.0.0r grants an unauthenticated individual root level access to the device's file system. This can be used to identify configuration settings, password hashes for built-in accounts, and the cleartext password for remote configuration of the device through the WebUI.

CVE-2021-46451CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An SQL Injection vulnerabilty exists in Sourcecodester Online Project Time Management System 1.0 via the pid parameter in the load_file function.

CVE-2021-43394CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Unisys OS 2200 Messaging Integration Services (NTSI) 7R3B IC3 and IC4, 7R3C, and 7R3D has an Incorrect Implementation of an Authentication Algorithm. An LDAP password is not properly validated.

CVE-2021-45029CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

CVE-2021-45802CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter values are added to the SQL query without any verification at the time of membership registration.

CVE-2021-46033CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

In ForestBlog, as of 2021-12-28, File upload can bypass verification.

CVE-2021-46089CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

In JeecgBoot 3.0, there is a SQL injection vulnerability that can operate the database with root privileges.

CVE-2021-43298CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-208

The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting. This means that an unauthenticated network attacker can brute-force the HTTP basic password, byte-by-byte, by recording the webserver's response time until the unauthorized (401) response.

CVE-2021-43799CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-338

Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In versions of Zulip Server prior to 4.9, the initial installation (until first reboot, or restart of RabbitMQ) does not successfully limit the default ports which RabbitMQ opens; this includes port 25672, the RabbitMQ distribution port, which is used as a management port. RabbitMQ's default "cookie" which protects this port is generated using a weak PRNG, which limits the entropy of the password to at most 36 bits; in practicality, the seed for the randomizer is biased, resulting in approximately 20 bits of entropy. If other firewalls (at the OS or network level) do not protect port 25672, a remote attacker can brute-force the 20 bits of entropy in the "cookie" and leverage it for arbitrary execution of code as the rabbitmq user. They can also read all data which is sent through RabbitMQ, which includes all message traffic sent by users. Version 4.9 contains a patch for this vulnerability. As a workaround, ensure that firewalls prevent access to ports 5672 and 25672 from outside the Zulip server.

CVE-2021-36294CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-331

Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability. A remote unauthenticated attacker may exploit this vulnerability by forging a cookie to login as any user.

CVE-2022-0362CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection in Packagist showdoc/showdoc prior to 2.10.3.

CVE-2021-46560CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

The firmware on Moxa TN-5900 devices through 3.1 allows command injection that could lead to device damage.

CVE-2021-46386CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload.

CVE-2022-21686CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an attacker is able to inject twig code inside the back office when using the legacy layout. The problem is fixed in version 1.7.8.3. There are no known workarounds.

CVE-2021-32840CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry `../evil.txt` may be extracted in the parent directory of `destFolder`. This leads to arbitrary file write that may lead to code execution. The vulnerability was patched in version 1.3.3.

CVE-2021-46377CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

There is a front-end sql injection vulnerability in cszcms 1.2.9 via cszcms/controllers/Member.php#viewUser

CVE-2021-46427CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Master.php.

CVE-2021-46428CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versions via the bot_avatar parameter in SystemSettings.php.

CVE-2021-44249CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Motorcycle (Bike) Rental System 1.0 is vulnerable to a Blind Time-Based SQL Injection attack within the login portal. This can lead attackers to remotely dump MySQL database credentials.

CVE-2021-45435CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An SQL Injection vulnerability exists in Sourcecodester Simple Cold Storage Management System using PHP/OOP 1.0 via the username field in login.php.

CVE-2020-25905CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An SQL Injection vulnerabilty exists in Sourcecodester Mobile Shop System in PHP MySQL 1.0 via the email parameter in (1) login.php or (2) LoginAsAdmin.php.

CVE-2021-45898CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.

CVE-2021-45899CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.

CVE-2022-22294CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A SQL injection vulnerability exists in ZFAKA<=1.43 which an attacker can use to complete SQL injection in the foreground and add a background administrator account.

CVE-2021-41609CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection in the ID parameter of the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve data from the application's backend database via boolean-based blind and UNION injection.

CVE-2021-44971CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-697

Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticated command injection to implement RCE.

CVE-2022-0339CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-918

Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16.

CVE-2021-22820CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-613

A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized access over a hijacked session to the charger station web server even after the legitimate user account holder has changed his password. Affected Products: EVlink City EVC1S22P4 / EVC1S7P4 (All versions prior to R8 V3.4.0.2 ), EVlink Parking EVW2 / EVF2 / EVP2PE (All versions prior to R8 V3.4.0.2), and EVlink Smart Wallbox EVB1A (All versions prior to R8 V3.4.0.2)

CVE-2022-24677CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Admin.php in HYBBS2 through 2.3.2 allows remote code execution because it writes plugin-related configuration information to conf.php.

CVE-2021-40408CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->username variable, that has the value of the userName parameter provided through the SetDdns API, is not validated properly. This would lead to an OS command injection.

CVE-2021-40409CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->password variable, that has the value of the password parameter provided through the SetDdns API, is not validated properly. This would lead to an OS command injection.

CVE-2022-21217CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-457

An out-of-bounds write vulnerability exists in the device TestEmail functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted network request can lead to an out-of-bounds write. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-22992CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-116

A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the device. The vulnerability was addressed by escaping individual arguments to shell functions coming from user input.

CVE-2022-22994CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-345

A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a NAS device into loading through an unsecured HTTP call. This was a result insufficient verification of calls to the device. The vulnerability was addressed by disabling checks for internet connectivity using HTTP.

CVE-2021-23484CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

The package zip-local before 0.3.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) which can lead to an extraction of a crafted file outside the intended extraction directory.

CVE-2021-23558CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

The package bmoor before 0.10.1 are vulnerable to Prototype Pollution due to missing sanitization in set function. **Note:** This vulnerability derives from an incomplete fix in [CVE-2020-7736](https://security.snyk.io/vuln/SNYK-JS-BMOOR-598664)

CVE-2021-23760CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

The package keyget from 0.0.0 are vulnerable to Prototype Pollution via the methods set, push, and at which could allow an attacker to cause a denial of service and may lead to remote code execution. **Note:** This vulnerability derives from an incomplete fix to [CVE-2020-28272](https://security.snyk.io/vuln/SNYK-JS-KEYGET-1048048)

CVE-2022-28995CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Rengine v1.0.2 was discovered to contain a remote code execution (RCE) vulnerability via the yaml configuration function.

CVE-2021-46444CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=admin_group_edit&agID.

CVE-2021-46445CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/categories.php?box_group_id.

CVE-2021-46446CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=admin_access_group_edit&aagID.

CVE-2021-46448CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/customers.php?page=1&cID.

CVE-2021-46660CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-611

Signiant Manager+Agents before 15.1 allows XML External Entity (XXE) attacks.

CVE-2021-23520CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

The package juce-framework/juce before 6.1.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) via the ZipFile::uncompressEntry function in juce_ZipFile.cpp. This vulnerability is triggered when the archive is extracted upon calling uncompressTo() on a ZipFile object.

CVE-2020-36064CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Online Course Registration v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised.

CVE-2021-31617CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.1 through 4.2.2, mishandling of memory management can lead to remote code execution.

CVE-2022-0320CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data before it them in include statements, which could allow unauthenticated attackers to perform Local File Inclusion attack and read arbitrary files on the server, this could also lead to RCE via user uploaded files or other LFI to RCE techniques.

CVE-2022-0401CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Path Traversal in NPM w-zip prior to 1.0.12.

CVE-2021-43509CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the id parameter in view-service.php.

CVE-2021-43510CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php.

← PreviousPage 428 / 7034Next →