Latest CVE Feed
-
8.8
HIGHCVE-2021-26615
ARK library allows attackers to execute remote code via the parameter(path value) of Ark_NormalizeAndDupPAthNameW function because of an integer overflow.... Read more
- EPSS Score: %0.20
- Published: Nov. 26, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-26614
ius_get.cgi in IpTime C200 camera allows remote code execution. A remote attacker may send a crafted parameters to the exposed vulnerable web service interface which invokes the arbitrary shell command.... Read more
- EPSS Score: %3.46
- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-26613
improper input validation vulnerability in nexacro permits copying file to the startup folder using rename method.... Read more
- EPSS Score: %0.31
- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26612
An improper input validation leading to arbitrary file creation was discovered in copy method of Nexacro platform. Remote attackers use copy method to execute arbitrary command after the file creation included malicious code.... Read more
- EPSS Score: %0.92
- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26611
HejHome GKW-IC052 IP Camera contained a hard-coded credentials vulnerability. This issue allows remote attackers to operate the IP Camera.(reboot, factory reset, snapshot etc..)... Read more
- EPSS Score: %0.71
- Published: Nov. 26, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-26610
The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code.... Read more
- EPSS Score: %0.14
- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-26609
A vulnerability was found in Mangboard(WordPress plugin). A SQL-Injection vulnerability was found in order_type parameter. The order_type parameter makes a SQL query using unfiltered data. This vulnerability allows a remote attacker to steal user informat... Read more
Affected Products : mang_board- EPSS Score: %0.65
- Published: Oct. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26608
An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware ActiveX module. This issue is due to missing support for integrity check of download URL or downloaded file hash.... Read more
- EPSS Score: %0.23
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-26607
An Improper input validation in execDefaultBrowser method of NEXACRO17 allows a remote attacker to execute arbitrary command on affected systems.... Read more
- EPSS Score: %0.97
- Published: Oct. 26, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-26606
A vulnerability in PKI Security Solution of Dream Security could allow arbitrary command execution. This vulnerability is due to insufficient validation of the authorization certificate. An attacker could exploit this vulnerability by sending a crafted HT... Read more
- EPSS Score: %0.36
- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26605
An improper input validation vulnerability in the service of ezPDFReader allows attacker to execute arbitrary command. This issue occurred when the ezPDF launcher received and executed crafted input values through JSON-RPC communication.... Read more
- EPSS Score: %0.43
- Published: Aug. 05, 2021
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-26603
A heap overflow issue was found in ARK library of bandisoft Co., Ltd when the Ark_DigPathA function parsed a file path. This vulnerability is due to missing support for string length check.... Read more
- EPSS Score: %0.21
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-26601
ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal.... Read more
Affected Products : impresscms- EPSS Score: %14.05
- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26600
ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==).... Read more
Affected Products : impresscms- EPSS Score: %1.38
- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26599
ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.... Read more
Affected Products : impresscms- EPSS Score: %5.64
- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-26598
ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, able to have a security token).... Read more
Affected Products : impresscms- EPSS Score: %59.74
- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-26597
An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the NOKIA NetAct Web Page, can visit the Site Configuration Tool web site section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir ... Read more
Affected Products : netact- EPSS Score: %0.48
- Published: Mar. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-26596
An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is ... Read more
Affected Products : netact- EPSS Score: %0.51
- Published: Mar. 25, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-26595
In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the version of the CMS, the PHP version used by the site, and the name of the DBMS, simply by view the result of the api-aa, called automatically upon a connection. NOTE: T... Read more
- EPSS Score: %0.11
- Published: Feb. 23, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-26594
In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any control by the back end. NOTE: This vulnerability only affects products that are no longer supported by the maintainer... Read more
- EPSS Score: %0.31
- Published: Feb. 23, 2021
- Modified: Nov. 21, 2024