Latest CVE Feed
-
9.8
CRITICALCVE-2021-25914
Prototype pollution vulnerability in 'object-collider' versions 1.0.0 through 1.0.3 allows attacker to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : object-collider- EPSS Score: %3.23
- Published: Mar. 01, 2021
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2021-25949
Prototype pollution vulnerability in 'set-getter' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : set-getter- EPSS Score: %0.85
- Published: Jun. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-3199
Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.... Read more
Affected Products : document_server- EPSS Score: %6.76
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26918
The ProBot bot through 2021-02-08 for Discord might allow attackers to interfere with the intended purpose of the "Send an image when a user joins the server" feature (or possibly have unspecified other impact) because the uploader web service allows doub... Read more
Affected Products : bot- EPSS Score: %0.78
- Published: Feb. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-20861
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnera... Read more
Affected Products : nexus_dashboard- EPSS Score: %0.38
- Published: Jul. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26987
Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploited could lead to Remote Code Execution. All versions of Element Plug-in fo... Read more
- EPSS Score: %1.87
- Published: Mar. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27007
NetApp Virtual Desktop Service (VDS) when used with an HTML5 gateway is susceptible to a vulnerability which when successfully exploited could allow an unauthenticated attacker to takeover a Remote Desktop Session.... Read more
Affected Products : virtual_desktop_service- EPSS Score: %0.71
- Published: Dec. 23, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27193
Incorrect default permissions vulnerability in the API of Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to read and write files on the remote machine with system privileges resulting in a privilege escalation.... Read more
- EPSS Score: %1.18
- Published: Mar. 25, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-33180
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in cgi component in Synology Media Server before 1.8.1-2876 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : media_server- EPSS Score: %0.34
- Published: Jun. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-33346
There is an arbitrary password modification vulnerability in a D-LINK DSL-2888A router product. An attacker can use this vulnerability to modify the password of the admin user without authorization.... Read more
- EPSS Score: %0.58
- Published: Jun. 24, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-33816
The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked.... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %2.57
- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-28294
Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE).... Read more
Affected Products : online_ordering_system- EPSS Score: %2.61
- Published: Mar. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-28671
Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), WorkCentre 6515 before 65.65.51 and 65.59.11 (Bridge), VersaLink B400 before 37.65.51 and 37.59.01 (Bridge), B405 before 38.65.51 and 38.59.01 (Bridge), B600/B610 before 32.65.51 and 32.59.01 (Bridg... Read more
- EPSS Score: %1.58
- Published: Mar. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-28940
Because of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to add a extra command to the curl binary. This creates an issue on the /scripts/magpie_debug.php and /scripts/magpie_simple.php page tha... Read more
Affected Products : magpierss- EPSS Score: %1.49
- Published: Apr. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-22096
Memory corruption in Bluetooth HOST due to stack-based buffer overflow when when extracting data using command length parameter in Snapdragon Connectivity, Snapdragon Mobile... Read more
Affected Products : aqt1000_firmware qca6390_firmware qca6391_firmware sd_8_gen1_5g_firmware sd855_firmware sd865_5g_firmware sd870_firmware sd888_5g_firmware sdx55m_firmware wcd9341_firmware +103 more products- EPSS Score: %0.21
- Published: Sep. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-29417
gitjacker before 0.1.0 allows remote attackers to execute arbitrary code via a crafted .git directory because of directory traversal.... Read more
Affected Products : gitjacker- EPSS Score: %5.34
- Published: Mar. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-29476
Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been patched and users of `Requests` 1.6.0, 1.6.1 and 1.7.0 should update to version 1.8.0.... Read more
Affected Products : requests- EPSS Score: %2.22
- Published: Apr. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17036
An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain parameter to install/index.php, as demonstrated by injecting a phpinfo() call into /inc/config.php.... Read more
Affected Products : ucms- EPSS Score: %0.51
- Published: Sep. 14, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11542
A Remote Command Execution (RCE) vulnerability in the Sonus SBC 1000 / SBC 2000 / SBC SWe Lite web interface allows for the execution of arbitrary commands via an unspecified vector. It affects the 1000 and 2000 devices 6.0.x up to Build 446, 6.1.x up to ... Read more
- EPSS Score: %2.14
- Published: Jul. 09, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17111
The onlyOwner modifier of a smart contract implementation for Coinlancer (CL), an Ethereum ERC20 token, has a potential access control vulnerability. All contract users can access functions that use this onlyOwner modifier, because the comparison between ... Read more
Affected Products : coinlancer- EPSS Score: %0.43
- Published: Sep. 18, 2018
- Modified: Nov. 21, 2024