CVE Database

CVE-2022-24300CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection.

CVE-2021-39070CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to authenticate as any user on the system. IBM X-Force ID: 215353.

CVE-2021-45742CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

CVE-2022-21724CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-665

pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties. However, the driver did not verify if the class implements the expected interface before instantiating the class. This can lead to code execution loaded via arbitrary classes. Users using plugins are advised to upgrade. There are no known workarounds for this issue.

CVE-2021-42637CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-918

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) vulnerability.

CVE-2022-24144CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function WanParameterSetting. This vulnerability allows attackers to execute arbitrary commands via the gateway, dns1, and dns2 parameters.

CVE-2021-45740CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the setWiFiWpsStart function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the pin parameter.

CVE-2022-24307CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-863

Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities. (JSON-LD signing has been supported since version 1.6.0.)

CVE-2021-44247CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg. This vulnerability allows attackers to execute arbitrary commands via the IpFrom parameter.

CVE-2021-44880CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

CVE-2021-44881CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

CVE-2021-44882CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

D-Link device DIR_878_FW1.30B08_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

CVE-2021-45733CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function NTPSyncWithHost. This vulnerability allows attackers to execute arbitrary commands via the parameter host_time.

CVE-2021-45738CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function UploadFirmwareFile. This vulnerability allows attackers to execute arbitrary commands via the parameter FileName.

CVE-2021-45986CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetUSBShareInfo. This vulnerability allows attackers to execute arbitrary commands via the usbOrdinaryUserName parameter.

CVE-2021-45987CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetNetCheckTools. This vulnerability allows attackers to execute arbitrary commands via the hostName parameter.

CVE-2021-45990CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function uploadPicture. This vulnerability allows attackers to execute arbitrary commands via the pic_name parameter.

CVE-2021-45998CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the LocalIPAddress parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

CVE-2021-46226CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function wget_test.asp. This vulnerability allows attackers to execute arbitrary commands via the url parameter.

CVE-2021-46227CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function proxy_client.asp. This vulnerability allows attackers to execute arbitrary commands via the proxy_srv, proxy_srvport, proxy_lanip, proxy_lanport parameters.

CVE-2021-46228CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function httpd_debug.asp. This vulnerability allows attackers to execute arbitrary commands via the time parameter.

CVE-2021-46230CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function upgrade_filter. This vulnerability allows attackers to execute arbitrary commands via the path and time parameters.

CVE-2021-46231CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function urlrd_opt.asp. This vulnerability allows attackers to execute arbitrary commands via the url_en parameter.

CVE-2021-46232CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function version_upgrade.asp. This vulnerability allows attackers to execute arbitrary commands via the path parameter.

CVE-2021-46233CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function msp_info.htm. This vulnerability allows attackers to execute arbitrary commands via the cmd parameter.

CVE-2021-46452CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via the tomography_ping_address, tomography_ping_number, tomography_ping_size, tomography_ping_timeout, and tomography_ping_ttl parameters.

CVE-2021-46453CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetStaticRouteSettings. This vulnerability allows attackers to execute arbitrary commands via the staticroute_list parameter.

CVE-2021-46454CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetWLanApcliSettings. This vulnerability allows attackers to execute arbitrary commands via the ApCliKeyStr parameter.

CVE-2021-46455CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetStationSettings. This vulnerability allows attackers to execute arbitrary commands via the station_access_enable parameter.

CVE-2021-46456CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetWLanACLSettings. This vulnerability allows attackers to execute arbitrary commands via the wl(0).(0)_maclist parameter.

CVE-2021-46457CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function ChgSambaUserSettings. This vulnerability allows attackers to execute arbitrary commands via the samba_name parameter.

CVE-2022-24148CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function mDMZSetCfg. This vulnerability allows attackers to execute arbitrary commands via the dmzIp parameter.

CVE-2022-24150CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function formSetSafeWanWebMan. This vulnerability allows attackers to execute arbitrary commands via the remoteIp parameter.

CVE-2022-24165CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetQvlanList. This vulnerability allows attackers to execute arbitrary commands via the qvlanIP parameter.

CVE-2022-24167CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetDMZ. This vulnerability allows attackers to execute arbitrary commands via the dmzHost1 parameter.

CVE-2022-24168CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetIpGroup. This vulnerability allows attackers to execute arbitrary commands via the IPGroupStartIP and IPGroupEndIP parameters.

CVE-2022-24170CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetIpSecTunnel. This vulnerability allows attackers to execute arbitrary commands via the IPsecLocalNet and IPsecRemoteNet parameters.

CVE-2022-24171CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetPppoeServer. This vulnerability allows attackers to execute arbitrary commands via the pppoeServerIP, pppoeServerStartIP, and pppoeServerEndIP parameters.

CVE-2021-44978CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution.

CVE-2022-24259CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a crafted request.

CVE-2021-29393CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to inject and execute arbitrary system commands via the unsanitized user-controlled "command" and "commandvalues" parameters.

CVE-2021-29396CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-732

Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to use various functionalities without authentication.

CVE-2021-23470CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

This affects the package putil-merge before 3.8.0. The merge() function does not check the values passed into the argument. An attacker can supply a malicious value by adjusting the value to include the constructor property. Note: This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-PUTILMERGE-1317077

CVE-2021-23497CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

This affects the package @strikeentco/set before 1.0.2. It allows an attacker to cause a denial of service and may lead to remote code execution. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-STRIKEENTCOSET-1038821

CVE-2021-23507CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

The package object-path-set before 1.0.2 are vulnerable to Prototype Pollution via the setPath method, as it allows an attacker to merge object prototypes into it. *Note:* This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-OBJECTPATHSET-607908

CVE-2022-23329CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via uploading malicious files.

CVE-2021-28503CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-305

The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.

CVE-2021-36152CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Apache Gobblin trusts all certificates used for LDAP connections in Gobblin-as-a-Service. This affects versions <= 0.15.0. Users should update to version 0.16.0 which addresses this issue.

CVE-2021-44779CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Unauthenticated SQL Injection (SQLi) vulnerability discovered in [GWA] AutoResponder WordPress plugin (versions <= 2.3), vulnerable at (&listid). No patched version available, plugin closed.

CVE-2022-0365CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

The affected product is vulnerable to an authenticated OS command injection, which may allow an attacker to inject and execute arbitrary shell commands as the Admin (root) user.

← PreviousPage 429 / 7034Next →