CVE Database

CVE-2021-40940CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.

CVE-2022-32101CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

kkcms v1.3.7 was discovered to contain a SQL injection vulnerability via the cid parameter at /template/wapian/vlist.php.

CVE-2022-32301CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the IdList parameter at /App/Lib/Action/Home/ApiAction.class.php.

CVE-2022-20733CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sensitive Security Assertion Markup Language (SAML) metadata. An attacker could exploit this vulnerability by using the exposed SAML metadata to bypass authentication to the user portal. A successful exploit could allow the attacker to access all roles without any restrictions.

CVE-2022-20798CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

A vulnerability in the external authentication functionality of Cisco Secure Email and Web Manager, formerly known as Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass authentication and log in to the web management interface of an affected device. This vulnerability is due to improper authentication checks when an affected device uses Lightweight Directory Access Protocol (LDAP) for external authentication. An attacker could exploit this vulnerability by entering a specific input on the login page of the affected device. A successful exploit could allow the attacker to gain unauthorized access to the web-based management interface of the affected device.

CVE-2022-20825CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient user input validation of incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device using root-level privileges. Cisco has not released software updates that address this vulnerability.

CVE-2021-41418CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

AriaNg v0.1.0~v1.2.2 is affected by an incorrect access control vulnerability through not authenticating visitors' access rights.

CVE-2022-33750CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

CA Automic Automation 12.2 and 12.3 contain an authentication error vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary commands.

CVE-2021-41411CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-611

drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.

CVE-2022-2098CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-521

Weak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1.

CVE-2021-41654CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php

CVE-2022-30329CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. An OS injection vulnerability exists within the web interface, allowing an attacker with valid credentials to execute arbitrary shell commands.

CVE-2022-31296CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/posts/view_post.php.

CVE-2022-31784CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

A vulnerability in the management interface of MiVoice Business through 9.3 PR1 and MiVoice Business Express through 8.0 SP3 PR3 could allow an unauthenticated attacker (that has network access to the management interface) to conduct a buffer overflow attack due to insufficient validation of URL parameters. A successful exploit could allow arbitrary code execution.

CVE-2021-40903CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a predefined secret string, which would be randomly generated, however it is static.

CVE-2022-31355CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category&search=.

CVE-2022-31356CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.php?view=edit&id=.

CVE-2022-31357CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/index.php?view=edit&id=.

CVE-2022-29496CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

A stack-based buffer overflow vulnerability exists in the BlynkConsole.h runCommand functionality of Blynk -Library v1.0.1. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.

CVE-2022-22485CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this vulnerability using brute force techniques to gain unauthorized administrative access to the IBM Spectrum Protect Server. IBM X-Force ID: 226325.

CVE-2022-30422CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Proietti Tech srl Planet Time Enterprise 4.2.0.1,4.2.0.0,4.1.0.0,4.0.0.0,3.3.1.0,3.3.0.0 is vulnerable to Remote code execution via the Viewstate parameter.

CVE-2022-21806CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-368

A use-after-free vulnerability exists in the mips_collector appsrv_server functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted set of network packets can lead to remote code execution. The device is exposed to attacks from the network.

CVE-2022-31941CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via \rdms\admin?page=user\manage_user&id=.

CVE-2022-31874CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

ASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface.

CVE-2022-34005CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. There is Remote Code Execution due to a hardcoded password for the sa account on the Microsoft SQL Express 2019 instance installed by default during TitanFTP NextGen installation, aka NX-I674 (sub-issue 1). NOTE: as of 2022-06-21, the 1.2.1050 release corrects this vulnerability in a new installation, but not in an upgrade installation.

CVE-2022-2023CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-648

Incorrect Use of Privileged APIs in GitHub repository polonel/trudesk prior to 1.2.4.

CVE-2022-31794CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the requestTempFile function in hw_view.php. An attacker is able to influence the unitName POST parameter and inject special characters such as semicolons, backticks, or command-substitution sequences in order to force the application to execute arbitrary commands.

CVE-2022-2128CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.4.

CVE-2022-31795CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the grel_finfo function in grel.php. An attacker is able to influence the username (user), password (pw), and file-name (file) parameters and inject special characters such as semicolons, backticks, or command-substitution sequences in order to force the application to execute arbitrary commands.

CVE-2022-22317CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-613

IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281.

CVE-2022-22318CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-613

IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

CVE-2017-20067CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in Hindu Matrimonial Script. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/. The manipulation of the argument username/password with the input 'or''=' leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-31800CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-345

An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.

CVE-2022-31801CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-345

An unauthenticated, remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.

CVE-2022-33139CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-603

A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All versions), SIMATIC WinCC OA V3.16 (All versions in default configuration), SIMATIC WinCC OA V3.17 (All versions in non-default configuration), SIMATIC WinCC OA V3.18 (All versions in non-default configuration). Affected applications use client-side only authentication, when neither server-side authentication (SSA) nor Kerberos authentication is enabled. In this configuration, attackers could impersonate other users or exploit the client-server protocol without being authenticated.

CVE-2022-29774CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

iSpy v7.2.2.0 is vulnerable to remote command execution via path traversal.

CVE-2022-26147CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection.

CVE-2021-26637CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized users can remotely control the device.

CVE-2021-26638CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Improper Authentication vulnerability in S&D smarthome(smartcare) application can cause authentication bypass and information exposure. Remote attackers can use this vulerability to take control of the home environment including indoor control.

CVE-2021-40954CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Laiketui 3.5.0 is affected by an arbitrary file upload vulnerability that can allow an attacker to execute arbitrary code.

CVE-2022-22980CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-917

A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.

CVE-2022-31361CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Docebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2022-31787CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

IdeaTMS 2022 is vulnerable to SQL Injection via the PATH_INFO

CVE-2022-32554CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade products running Purity//FB 3.3.0, 3.2.0 - 3.2.4, 3.1.0 - 3.1.12, 3.0.x and prior Purity//FB releases are vulnerable to possibly exposed credentials for accessing the product’s management interface. The password may be known outside Pure Storage and could be used on an affected system, if reachable, to execute arbitrary instructions with root privileges. No other Pure Storage products or services are affected. Remediation is available from Pure Storage via a self-serve “opt-in” patch, manual patch application or a software upgrade to an unaffected version of Purity software.

CVE-2022-33127CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

The function that calls the diff tool in Diffy 3.4.1 does not properly handle double quotes in a filename when run in a windows environment. This allows attackers to execute arbitrary commands via a crafted string.

CVE-2017-20095CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

A vulnerability classified as critical was found in Simple Ads Manager Plugin. This vulnerability affects unknown code. The manipulation leads to code injection. The attack can be initiated remotely.

CVE-2022-31802CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-187

In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perform authentication by specifying a small password that matches the corresponding part of the longer real CODESYS Gateway password.

CVE-2022-31806CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1188

In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password is set at the controller.

CVE-2022-1517CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-250

LRM utilizes elevated privileges. An unauthenticated malicious actor can upload and execute code remotely at the operating system level, which can allow an attacker to change settings, configurations, software, or access sensitive data on the affected produc. An attacker could also exploit this vulnerability to access APIs not intended for general use and interact through the network.

CVE-2022-1519CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

LRM does not restrict the types of files that can be uploaded to the affected product. A malicious actor can upload any file type, including executable code that allows for a remote code exploit.

← PreviousPage 434 / 7034Next →