Latest CVE Feed
-
9.8
CRITICALCVE-2021-42888
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setLanguageCfg of the file global.so which can control langType to attack.... Read more
- Published: Jun. 03, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42785
Buffer Overflow vulnerability in tvnviewer.exe of TightVNC Viewer allows a remote attacker to execute arbitrary instructions via a crafted FramebufferUpdate packet from a VNC server.... Read more
Affected Products : tightvnc- Published: Nov. 23, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43217
Windows Encrypting File System (EFS) Remote Code Execution Vulnerability... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_server windows_10_1607 +14 more products- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42772
Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, have a buffer overflow vulnerability in the remote GetDumpFile command that could allow a user to attempt vario... Read more
- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42796
An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticated arbitrary commands to be executed.... Read more
- Published: Dec. 16, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42740
The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex designed to support Windows drive letters. If the output of this package is passed to a real shell as a quoted... Read more
Affected Products : shell-quote- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42761
A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 through 6.0.7, 5.9.0 through 5.9.1 may allow a remote, unauthen... Read more
Affected Products : fortiweb- Published: Feb. 16, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42863
A buffer overflow in ecma_builtin_typedarray_prototype_filter() in JerryScript version fe3a5c0 allows an attacker to construct a fake object or a fake arraybuffer with unlimited size.... Read more
Affected Products : jerryscript- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42575
The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.... Read more
- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42911
A Format String vulnerability exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor 300B <= 1.5.1.3 in the mainfunction.cgi file via a crafted HTTP message containing malformed QUERY STRING, which could let a remote mal... Read more
Affected Products : vigor2960_firmware vigor300b_firmware vigor3900_firmware vigor2960 vigor300b vigor3900- Published: Mar. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42627
The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page.... Read more
- Published: Aug. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42756
Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve ... Read more
Affected Products : fortiweb- Published: Feb. 16, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42371
lpar2rrd is a hardcoded system account in XoruX LPAR2RRD and STOR2RRD before 7.30.... Read more
- Published: Nov. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42342
An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix. This permits tunneling untrusted environment variables into vulnerable CGI... Read more
Affected Products : goahead- Published: Oct. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42544
Missing Rate Limiting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on the Login Form allows an unauthenticated remote attacker to perform multiple login attempts, which facilitates gaining privileges.... Read more
- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42242
A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor.... Read more
Affected Products : jfinal_cms- Published: May. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42185
wdja v2.1 is affected by a SQL injection vulnerability in the foreground search function.... Read more
Affected Products : wdja- Published: May. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42258
BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) pa... Read more
Affected Products : billquick_web_suite- Actively Exploited
- Published: Oct. 22, 2021
- Modified: Mar. 19, 2025
-
9.8
CRITICALCVE-2021-42127
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via Data Repository Service.... Read more
Affected Products : avalanche- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42377
An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare... Read more
Affected Products : fedora cloud_backup hci_management_node solidfire h300s_firmware h500s_firmware h700s_firmware h410s_firmware busybox h300s +9 more products- Published: Nov. 15, 2021
- Modified: Nov. 21, 2024