Latest CVE Feed
-
9.8
CRITICALCVE-2021-45658
Certain NETGEAR devices are affected by server-side injection. This affects D7800 before 1.0.1.58, DM200 before 1.0.0.66, EX2700 before 1.0.1.56, EX6150v2 before 1.0.1.86, EX6100v2 before 1.0.1.86, EX6200v2 before 1.0.1.78, EX6250 before 1.0.0.110, EX6410... Read more
Affected Products : r7800_firmware r8900_firmware r9000_firmware xr500_firmware d7800_firmware rax120_firmware rbk20_firmware rbr20_firmware rbs20_firmware rbk40_firmware +54 more products- Published: Dec. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45611
Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects DC112A before 1.0.0.52, R6400 before 1.0.1.68, RAX200 before 1.0.3.106, WNDR3400v3 before 1.0.1.38, XR300 before 1.0.3.68, R8500 before 1.0.2.144, RAX75... Read more
Affected Products : r6400_firmware rax200_firmware rax75_firmware rax80_firmware xr300_firmware dc112a_firmware r8300_firmware r8500_firmware wndr3400v3_firmware r6400 +8 more products- Published: Dec. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45707
An issue was discovered in the nix crate 0.16.0 and later before 0.20.2, 0.21.x before 0.21.2, and 0.22.x before 0.22.2 for Rust. unistd::getgrouplist has an out-of-bounds write if a user is in more than 16 /etc/groups groups.... Read more
Affected Products : nix- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45790
An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to arbitrary directory, where attackers can write a cron job to execute commands.... Read more
Affected Products : metersphere- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45527
Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D6220 before 1.0.0.68, D6400 before 1.0.0.102, D7000v2 before 1.0.0.66, D8500 before 1.0.3.58, DC112A before 1.0.0.54, EX7000 before 1.0.1.94, EX7500 before 1... Read more
Affected Products : ex7000_firmware r6900p_firmware r7000_firmware r7000p_firmware rbs40v_firmware rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware +62 more products- Published: Dec. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45435
An SQL Injection vulnerability exists in Sourcecodester Simple Cold Storage Management System using PHP/OOP 1.0 via the username field in login.php.... Read more
- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45414
A Remote Code Execution (RCE) vulnerability exists in DataRobot through 2021-10-28 because it allows submission of a Docker environment or Java driver.... Read more
Affected Products : datarobot- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45467
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&scripts= .%00./.%00./api/account_ne... Read more
Affected Products : webpanel- Published: Dec. 26, 2022
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2021-45331
An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for the 2FA can be submitted correctly more than once.... Read more
Affected Products : gitea- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45092
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.... Read more
Affected Products : thinfinity_virtualui- Published: Dec. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45330
An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse.... Read more
Affected Products : gitea- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45327
Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. which could let a remote malisious user execute arbitrary code.... Read more
Affected Products : gitea- Published: Feb. 08, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45005
Artifex MuJS v1.1.3 was discovered to contain a heap buffer overflow which is caused by conflicting JumpList of nested try/finally statements.... Read more
Affected Products : mujs- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44908
SailsJS Sails.js <=1.4.0 is vulnerable to Prototype Pollution via controller/load-action-modules.js, function loadActionModules().... Read more
Affected Products : sails- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44949
glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php.... Read more
Affected Products : glfusion- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45039
Multiple models of the Uniview IP Camera (e.g., IPC_G6103 B6103.16.10.B25.201218, IPC_G61, IPC21, IPC23, IPC32, IPC36, IPC62, and IPC_HCMN) offer an undocumented UDP service on port 7788 that allows a remote unauthenticated attacker to overflow an interna... Read more
Affected Products : camera_firmware- Published: May. 31, 2023
- Modified: Jan. 10, 2025
-
9.8
CRITICALCVE-2021-44681
An issue (5 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP serv... Read more
Affected Products : enterprise_vault- Published: Dec. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44790
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issu... Read more
Affected Products : fedora zfs_storage_appliance_kit debian_linux cloud_backup macos http_server mac_os_x http_server communications_session_report_manager communications_session_route_manager +4 more products- Published: Dec. 20, 2021
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2021-44610
Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) default_group, and (8) page group parameters in the settings mode in admin/index.... Read more
Affected Products : bloofoxcms- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44685
Git-it through 4.4.0 allows OS command injection at the Branches Aren't Just For Birds challenge step. During the verification process, it attempts to run the reflog command followed by the current branch name (which is not sanitized for execution).... Read more
Affected Products : git-it- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024