Latest CVE Feed
-
9.8
CRITICALCVE-2021-37594
In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input checks for a FILECONTENTS_SIZE File Contents Request PDU.... Read more
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37580
A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affected Apache ShenYu 2.3.0 and 2.4.0... Read more
Affected Products : shenyu- Published: Nov. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37544
In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization.... Read more
Affected Products : teamcity- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37538
Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to execute arbitrary SQL commands via the day, month, or year parameter to the controllers/front/archive.php archive contr... Read more
Affected Products : smartblog- Published: Aug. 24, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37539
Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.... Read more
Affected Products : manageengine_admanager_plus- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37578
Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provides an alternate transport for accessing UDDI services. RMI uses the default Java serialization mechanism to pass parameters in RMI inv... Read more
Affected Products : juddi- Published: Jul. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37522
SQL injection vulnerability in HKing2802 Locke-Bot 2.0.2 allows remote attackers to run arbitrary SQL commands via crafted string to /src/db.js, /commands/mute.js, /modules/event/messageDelete.js.... Read more
Affected Products : locke-bot- Published: Jul. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37475
In NavigateCMS version 2.9.4 and below, function in `templates.php` is vulnerable to sql injection on parameter `template-properties-order`, which results in arbitrary sql query execution in the backend database.... Read more
- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37473
In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `products-order` through a post request, which results in arbitrary sql query execution in the backend database.... Read more
- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37477
In NavigateCMS version 2.9.4 and below, function in `structure.php` is vulnerable to sql injection on parameter `children_order`, which results in arbitrary sql query execution in the backend database.... Read more
- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37415
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.... Read more
Affected Products : manageengine_servicedesk_plus- Actively Exploited
- Published: Sep. 01, 2021
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2021-37401
An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the PLC user program may be uploaded, altered, and/or downloaded.... Read more
- Published: Dec. 28, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37476
In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `id` through a post request, which results in arbitrary sql query execution in the backend database.... Read more
- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37371
Online Student Admission System 1.0 is affected by an unauthenticated SQL injection bypass vulnerability in /admin/login.php.... Read more
Affected Products : online_student_admission_system- Published: Oct. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37384
RCE (Remote Code Execution) vulnerability was found in some Furukawa ONU models, this vulnerability allows remote unauthenticated users to send arbitrary commands to the device via web interface.... Read more
- Published: Jul. 17, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-21896
The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user. If the path is to be treated as a Buffer, the implementation uses Buffer.from() to obtain a Buffer from the result of path.resolv... Read more
Affected Products : node.js- Published: Feb. 20, 2024
- Modified: Apr. 02, 2025
-
9.8
CRITICALCVE-2021-37388
A buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an attacker to crash the webserver and might even gain remote code execution.... Read more
- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37358
SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checkrepeat&v_name=".... Read more
Affected Products : seacms- Published: Aug. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37222
Parsers in the open source project RCDCAP before 1.0.5 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via specially crafted packets.... Read more
Affected Products : rcdcap- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37354
Xerox Phaser 4622 v35.013.01.000 was discovered to contain a buffer overflow in the function sub_3226AC via the TIMEZONE variable. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.... Read more
- Published: Feb. 15, 2022
- Modified: Nov. 21, 2024