Latest CVE Feed
-
9.8
CRITICALCVE-2021-43451
SQL Injection vulnerability exists in PHPGURUKUL Employee Record Management System 1.2 via the Email POST parameter in /forgetpassword.php.... Read more
Affected Products : employee_record_management_system- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43636
Two Buffer Overflow vulnerabilities exists in T10 V2_Firmware V4.1.8cu.5207_B20210320 in the http_request_parse function when processing host data in the HTTP request process.... Read more
- Published: Mar. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24175
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any user (including admin) by just providing the related use... Read more
Affected Products : the_plus_addons_for_elementor- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43987
An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web interface, which cannot be deleted or changed through the regular web interface.... Read more
Affected Products : mypro- Published: Dec. 23, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42668
A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter in the my_classmates.php web page.. As a result, an attacker can extract sensitive data from the web server and in some cases can use this vulnerabi... Read more
Affected Products : engineers_online_portal- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44524
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0).... Read more
- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44679
An issue (3 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP serv... Read more
Affected Products : enterprise_vault- Published: Dec. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19502
Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP code.... Read more
Affected Products : image_uploader_and_browser_for_ckeditor- Published: Dec. 02, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-46321
Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the wifiBasicCfg module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.... Read more
- Published: Feb. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-46377
There is a front-end sql injection vulnerability in cszcms 1.2.9 via cszcms/controllers/Member.php#viewUser... Read more
- Published: Jan. 27, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-46453
D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetStaticRouteSettings. This vulnerability allows attackers to execute arbitrary commands via the staticroute_list parameter.... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26608
An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware ActiveX module. This issue is due to missing support for integrity check of download URL or downloaded file hash.... Read more
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26740
Arbitrary file upload vulnerability sysupload.php in millken doyocms 2.3 allows attackers to execute arbitrary code.... Read more
- Published: Nov. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27177
An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to bypass authentication by sending the decoded value of the GgpoZWxwCmxpc3QKd2hvCg== string to the telnet server.... Read more
- Published: Feb. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19649
Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function.... Read more
Affected Products : manageengine_applications_manager- Published: Dec. 11, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27480
Delta Industrial Automation COMMGR Versions 1.12 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute remote code.... Read more
Affected Products : industrial_automation_commgr- Published: Apr. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21827
A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. Within `DecodeTreeBlock` which is called during the decompression of an XMI file, a UINT32 is loaded from the file and used as... Read more
Affected Products : xmill- Published: Aug. 20, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-28024
Unauthorized system access in the login form in ServiceTonic Helpdesk software version < 9.0.35937 allows attacker to login without using a password.... Read more
Affected Products : servicetonic- Published: Nov. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-28119
Twinkle Tray (aka twinkle-tray) through 1.13.3 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal API.... Read more
Affected Products : twinkle_tray- Published: Mar. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-28132
LUCY Security Awareness Software through 4.7.x allows unauthenticated remote code execution because the Migration Tool (in the Support section) allows upload of .php files within a system.tar.gz file. The .php file becomes accessible with a public/system/... Read more
Affected Products : security_awareness- Published: Mar. 11, 2021
- Modified: Nov. 21, 2024