Latest CVE Feed
-
9.8
CRITICALCVE-2021-45507
Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBW30 before 2.6.2.2, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 befo... Read more
Affected Products : rbs40v_firmware rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware cbr40_firmware rbw30_firmware cbr750_firmware +10 more products- EPSS Score: %1.37
- Published: Dec. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19398
M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability. Due to the input validation logic is incorrect, an attacker can exploit this vulnerability to modify the memory of the device by doing a series of operations. ... Read more
- EPSS Score: %0.38
- Published: Dec. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15447
A vulnerability in the web framework code of Cisco Integrated Management Controller (IMC) Supervisor could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of user-supplied... Read more
Affected Products : integrated_management_controller- EPSS Score: %1.31
- Published: Nov. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19518
CA Automic Sysload 5.6.0 through 6.1.2 contains a vulnerability, related to a lack of authentication on the File Server port, that potentially allows remote attackers to execute arbitrary commands.... Read more
Affected Products : ca_automic_sysload- EPSS Score: %1.29
- Published: Jan. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-46451
An SQL Injection vulnerabilty exists in Sourcecodester Online Project Time Management System 1.0 via the pid parameter in the load_file function.... Read more
Affected Products : online_project_time_management_system- EPSS Score: %0.31
- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-46446
H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=admin_access_group_edit&aagID.... Read more
Affected Products : multistore- EPSS Score: %0.77
- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26471
In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1, the http API located at /sgwebservice_o.php accepts a command argument. Using this command argument an unauthenticated attacker can execute arbitrary shell commands.... Read more
- EPSS Score: %7.30
- Published: Jun. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26956
An issue was discovered in the xcb crate through 2021-02-04 for Rust. It has a soundness violation because bytes from an X server can be interpreted as any data type returned by xcb::xproto::GetPropertyReply::value.... Read more
Affected Products : xcb- EPSS Score: %0.50
- Published: Feb. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27141
An issue was discovered on FiberHome HG6245D devices through RP2613. Credentials in /fhconf/umconfig.txt are obfuscated via XOR with the hardcoded *j7a(L#yZ98sSd5HfSgGjMj8;Ss;d)(*&^#@$a2s0i3g key. (The webs binary has details on how XOR is used.)... Read more
- EPSS Score: %0.23
- Published: Feb. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27150
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded gestiontelebucaramanga / t3l3buc4r4m4ng42013 credentials for an ISP.... Read more
- EPSS Score: %0.70
- Published: Feb. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27162
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / tattoo@home credentials for an ISP.... Read more
- EPSS Score: %0.28
- Published: Feb. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19636
An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_encode_body at tosixel.c.... Read more
Affected Products : libsixel- EPSS Score: %0.42
- Published: Dec. 08, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15680
An issue was discovered in BTITeam XBTIT 2.5.4. The hashed passwords stored in the xbtit_users table are stored as unsalted MD5 hashes, which makes it easier for context-dependent attackers to obtain cleartext values via a brute-force attack.... Read more
Affected Products : xbtit- EPSS Score: %0.17
- Published: Sep. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27730
Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. The fixed version is FTA_9_12_444 and later.... Read more
Affected Products : fta- EPSS Score: %0.42
- Published: Mar. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21776
An out-of-bounds write vulnerability exists in the SGI Format Buffer Size Processing functionality of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulne... Read more
Affected Products : imagegear- EPSS Score: %0.40
- Published: Mar. 31, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21946
Two heap-based buffer overflow vulnerabilities exists in the JPEG-JFIF lossless Huffman image parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigge... Read more
Affected Products : imagegear- EPSS Score: %0.30
- Published: Apr. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22289
Improper Input Validation vulnerability in the project upload mechanism in B&R Automation Studio version >=4.0 may allow an unauthenticated network attacker to execute code.... Read more
Affected Products : studio- EPSS Score: %0.72
- Published: Aug. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-28925
SQL injection vulnerability in Nagios Network Analyzer before 2.4.3 via the o[col] parameter to api/checks/read/.... Read more
Affected Products : network_analyzer- EPSS Score: %74.24
- Published: Apr. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-29003
Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacters to sys_config_valid.xgi, as demonstrated by the sys_config_valid.xgi?exeshell=%60telnetd%20%26%60 URI.... Read more
- EPSS Score: %36.44
- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-3599
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, while notifying a DCI client, a Use After Free condition can occur.... Read more
Affected Products : android- EPSS Score: %0.17
- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024