| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-29464 | — | Cri | 0.93 | 9.8 | 1.00 | KEV | Apr 18, 2022 | Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a… |
| CVE-2022-1020 | Cri | 0.66 | 9.8 | 0.26 | Apr 18, 2022 | The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does not validate the callback… | ||
| CVE-2022-0785 | Cri | 0.64 | 9.8 | 0.09 | Apr 18, 2022 | The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using it in a SQL statement via the get_monthly_timetable AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection | ||
| CVE-2022-25226 | Cri | 0.66 | 10.0 | 0.11 | Apr 18, 2022 | ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?cmd=connect' by obtaining a valid SID without any kind of authentication. It is possible to achieve code execution on the server by sending keyboard or mouse… | ||
| CVE-2020-13567 | Cri | 0.64 | 9.8 | 0.02 | Apr 18, 2022 | Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability. | ||
| CVE-2022-26631 | Cri | 0.64 | 9.8 | 0.01 | Apr 18, 2022 | Automatic Question Paper Generator v1.0 contains a Time-Based Blind SQL injection vulnerability via the id GET parameter. | ||
| CVE-2022-27423 | Cri | 0.64 | 9.8 | 0.01 | Apr 15, 2022 | Chamilo LMS v1.11.13 was discovered to contain a SQL injection vulnerability via the blog_id parameter at /blog/blog.php. | ||
| CVE-2022-26809 | Cri | 0.71 | 9.8 | 0.91 | Apr 15, 2022 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | ||
| CVE-2022-24497 | Cri | 0.66 | 9.8 | 0.35 | Apr 15, 2022 | Windows Network File System Remote Code Execution Vulnerability | ||
| CVE-2022-24491 | Cri | 0.66 | 9.8 | 0.33 | Apr 15, 2022 | Windows Network File System Remote Code Execution Vulnerability | ||
| CVE-2022-27158 | Cri | 0.00 | 9.8 | 0.01 | Apr 15, 2022 | pearweb < 1.32 suffers from Deserialization of Untrusted Data. | ||
| CVE-2022-27157 | Cri | 0.00 | 9.8 | 0.01 | Apr 15, 2022 | pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php. | ||
| CVE-2021-44496 | Cri | 0.64 | 9.8 | 0.02 | Apr 15, 2022 | An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can control the size variable and buffer that is passed to a call to memcpy. An attacker can use this to overwrite key data structures and gain control of… | ||
| CVE-2021-44488 | Cri | 0.59 | 9.1 | 0.01 | Apr 15, 2022 | An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can control the size and input to calls to memcpy in op_fnfnumber in sr_port/op_fnfnumber.c in order to corrupt memory or crash the application. | ||
| CVE-2021-44486 | Cri | 0.64 | 9.8 | 0.02 | Apr 15, 2022 | An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can manipulate the value of a function pointer used in op_write in sr_port/op_write.c in order to gain control of the flow of execution. | ||
| CVE-2021-42230 | Cri | 0.64 | 9.8 | 0.06 | Apr 15, 2022 | Seowon 130-SLC router all versions as of 2021-09-15 is vulnerable to Remote Code Execution via the queriesCnt parameter. | ||
| CVE-2022-23865 | Cri | 0.64 | 9.8 | 0.02 | Apr 15, 2022 | Nyron 1.0 is affected by a SQL injection vulnerability through Nyron/Library/Catalog/winlibsrch.aspx. To exploit this vulnerability, an attacker must inject '"> on the thes1 parameter. | ||
| CVE-2022-20695 | Cri | 0.67 | 10.0 | 0.20 | Apr 15, 2022 | A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass authentication controls and log in to the device through the management interface This vulnerability is due to the… | ||
| CVE-2022-28044 | Cri | 0.00 | 9.8 | 0.02 | Apr 15, 2022 | Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control. | ||
| CVE-2022-26651 | Cri | 0.64 | 9.8 | 0.07 | Apr 15, 2022 | An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escaping functionality for backslash characters in SQL queries, resulting in user-provided data creating a broken SQL query or possibly… | ||
| CVE-2022-26499 | Cri | 0.60 | 9.1 | 0.08 | Apr 15, 2022 | An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as localhost by using the Identity header. This is fixed in 16.25.2, 18.11.2, and 19.3.2. | ||
| CVE-2021-40386 | Cri | 0.64 | 9.8 | 0.02 | Apr 15, 2022 | Kaseya Unitrends Client/Agent through 10.5,5 allows remote attackers to execute arbitrary code. | ||
| CVE-2022-26034 | Cri | 0.59 | 9.1 | 0.01 | Apr 15, 2022 | Improper authentication vulnerability in the communication protocol provided by AD (Automation Design) server of CENTUM VP R6.01.10 to R6.09.00, CENTUM VP Small R6.01.10 to R6.09.00, CENTUM VP Basic R6.01.10 to R6.09.00, and B/M9000 VP R8.01.01 to R8.03.01 allows an attacker to… | ||
| CVE-2022-24846 | Cri | 0.59 | 9.1 | 0.01 | Apr 14, 2022 | GeoWebCache is a tile caching server implemented in Java. The GeoWebCache disk quota mechanism can perform an unchecked JNDI lookup, which in turn can be used to perform class deserialization and result in arbitrary code execution. While in GeoWebCache the JNDI strings are… | ||
| CVE-2022-28711 | Cri | 0.64 | 9.8 | 0.02 | Apr 14, 2022 | A memory corruption vulnerability exists in the cgi.c unescape functionality of ArduPilot APWeb master branch 50b6b7ac - master branch 46177cb9. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability. | ||
| CVE-2021-40422 | Cri | 0.65 | 10.0 | 0.06 | Apr 14, 2022 | An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway SG3-1010. A specially-crafted network request can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability. | ||
| CVE-2021-40390 | Cri | 0.64 | 9.8 | 0.02 | Apr 14, 2022 | An authentication bypass vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. A specially-crafted HTTP request can lead to unauthorized access. An attacker can send an HTTP request to trigger this vulnerability. | ||
| CVE-2021-21938 | Cri | 0.64 | 9.8 | 0.02 | Apr 14, 2022 | A heap-based buffer overflow vulnerability exists in the Palette box parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability. | ||
| CVE-2022-27007 | Cri | 0.00 | 9.8 | 0.02 | Apr 14, 2022 | nginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try to invoke from a restored frame saved with njs_function_frame_save(). | ||
| CVE-2022-26507 | Cri | 0.64 | 9.8 | 0.02 | Apr 14, 2022 | A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825,… | ||
| CVE-2021-43290 | Cri | 0.00 | 9.8 | 0.03 | Apr 14, 2022 | An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into a directory of a GoCD server. They can control the filename but the directory is placed inside of a directory that they can't control. | ||
| CVE-2022-24816 | Cri | 0.13 | 10.0 | 0.99 | KEV | Apr 13, 2022 | JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution as the Jiffle script is compiled into Java code via Janino, and executed. In… | |
| CVE-2022-27479 | Cri | 0.64 | 9.8 | 0.03 | Apr 13, 2022 | Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue. | ||
| CVE-2022-1345 | Cri | 0.00 | 9.0 | 0.01 | Apr 13, 2022 | Stored XSS viva .svg file upload in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse. | ||
| CVE-2022-22956 | Cri | 0.71 | 9.8 | 0.51 | Apr 13, 2022 | VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework. | ||
| CVE-2022-22955 | Cri | 0.64 | 9.8 | 0.08 | Apr 13, 2022 | VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework. | ||
| CVE-2022-1346 | Cri | 0.00 | 9.0 | 0.01 | Apr 13, 2022 | Multiple Stored XSS in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse. | ||
| CVE-2022-1344 | Cri | 0.00 | 9.0 | 0.01 | Apr 13, 2022 | Stored XSS due to no sanitization in the filename in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse. | ||
| CVE-2021-42136 | Cri | 0.62 | 9.0 | 0.05 | Apr 13, 2022 | A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute JavaScript code in the client's browser by storing said code as a Missing Data Code value. This can then be leveraged to execute a… | ||
| CVE-2021-22795 | Cri | 0.59 | 9.1 | 0.03 | Apr 13, 2022 | A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when performed over the network. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior) | ||
| CVE-2021-22794 | Cri | 0.59 | 9.1 | 0.02 | Apr 13, 2022 | A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior) | ||
| CVE-2021-43741 | Cri | 0.64 | 9.8 | 0.04 | Apr 13, 2022 | CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on config.php leading to remote code execution. | ||
| CVE-2022-28397 | — | Cri | 0.64 | 9.8 | 0.03 | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be uploaded and published by trusted users, this… | |
| CVE-2022-27952 | — | Cri | 0.64 | 9.8 | 0.02 | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbitrary code via a crafted SVG file. | |
| CVE-2022-27263 | Cri | 0.64 | 9.8 | 0.03 | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file. | ||
| CVE-2022-27262 | Cri | 0.64 | 9.8 | 0.02 | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted file. | ||
| CVE-2022-27260 | — | Cri | 0.64 | 9.8 | 0.03 | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file. | |
| CVE-2022-27140 | Cri | 0.64 | 9.8 | 0.03 | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload module of express-fileupload 1.3.1 allows attackers to execute arbitrary code via a crafted PHP file. NOTE: the vendor's position is that the observed behavior can only occur with "intentional misusing of the API": the… | ||
| CVE-2022-27139 | Cri | 0.64 | 9.8 | 0.04 | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted SVG file. NOTE: Vendor states that as outlined in Ghost's security documentation, upload of SVGs is only possible by trusted authenticated… | ||
| CVE-2022-28036 | Cri | 0.64 | 9.8 | 0.01 | Apr 12, 2022 | AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_navigation.php |
- risk 0.93cvss 9.8epss 1.00
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a…
- risk 0.66cvss 9.8epss 0.26
The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does not validate the callback…
- risk 0.64cvss 9.8epss 0.09
The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using it in a SQL statement via the get_monthly_timetable AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection
- risk 0.66cvss 10.0epss 0.11
ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?cmd=connect' by obtaining a valid SID without any kind of authentication. It is possible to achieve code execution on the server by sending keyboard or mouse…
- risk 0.64cvss 9.8epss 0.02
Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.
- risk 0.64cvss 9.8epss 0.01
Automatic Question Paper Generator v1.0 contains a Time-Based Blind SQL injection vulnerability via the id GET parameter.
- risk 0.64cvss 9.8epss 0.01
Chamilo LMS v1.11.13 was discovered to contain a SQL injection vulnerability via the blog_id parameter at /blog/blog.php.
- risk 0.71cvss 9.8epss 0.91
Remote Procedure Call Runtime Remote Code Execution Vulnerability
- risk 0.66cvss 9.8epss 0.35
Windows Network File System Remote Code Execution Vulnerability
- risk 0.66cvss 9.8epss 0.33
Windows Network File System Remote Code Execution Vulnerability
- risk 0.00cvss 9.8epss 0.01
pearweb < 1.32 suffers from Deserialization of Untrusted Data.
- risk 0.00cvss 9.8epss 0.01
pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can control the size variable and buffer that is passed to a call to memcpy. An attacker can use this to overwrite key data structures and gain control of…
- risk 0.59cvss 9.1epss 0.01
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can control the size and input to calls to memcpy in op_fnfnumber in sr_port/op_fnfnumber.c in order to corrupt memory or crash the application.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can manipulate the value of a function pointer used in op_write in sr_port/op_write.c in order to gain control of the flow of execution.
- risk 0.64cvss 9.8epss 0.06
Seowon 130-SLC router all versions as of 2021-09-15 is vulnerable to Remote Code Execution via the queriesCnt parameter.
- risk 0.64cvss 9.8epss 0.02
Nyron 1.0 is affected by a SQL injection vulnerability through Nyron/Library/Catalog/winlibsrch.aspx. To exploit this vulnerability, an attacker must inject '"> on the thes1 parameter.
- risk 0.67cvss 10.0epss 0.20
A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass authentication controls and log in to the device through the management interface This vulnerability is due to the…
- risk 0.00cvss 9.8epss 0.02
Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control.
- risk 0.64cvss 9.8epss 0.07
An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escaping functionality for backslash characters in SQL queries, resulting in user-provided data creating a broken SQL query or possibly…
- risk 0.60cvss 9.1epss 0.08
An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as localhost by using the Identity header. This is fixed in 16.25.2, 18.11.2, and 19.3.2.
- risk 0.64cvss 9.8epss 0.02
Kaseya Unitrends Client/Agent through 10.5,5 allows remote attackers to execute arbitrary code.
- risk 0.59cvss 9.1epss 0.01
Improper authentication vulnerability in the communication protocol provided by AD (Automation Design) server of CENTUM VP R6.01.10 to R6.09.00, CENTUM VP Small R6.01.10 to R6.09.00, CENTUM VP Basic R6.01.10 to R6.09.00, and B/M9000 VP R8.01.01 to R8.03.01 allows an attacker to…
- risk 0.59cvss 9.1epss 0.01
GeoWebCache is a tile caching server implemented in Java. The GeoWebCache disk quota mechanism can perform an unchecked JNDI lookup, which in turn can be used to perform class deserialization and result in arbitrary code execution. While in GeoWebCache the JNDI strings are…
- risk 0.64cvss 9.8epss 0.02
A memory corruption vulnerability exists in the cgi.c unescape functionality of ArduPilot APWeb master branch 50b6b7ac - master branch 46177cb9. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.
- risk 0.65cvss 10.0epss 0.06
An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway SG3-1010. A specially-crafted network request can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.
- risk 0.64cvss 9.8epss 0.02
An authentication bypass vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. A specially-crafted HTTP request can lead to unauthorized access. An attacker can send an HTTP request to trigger this vulnerability.
- risk 0.64cvss 9.8epss 0.02
A heap-based buffer overflow vulnerability exists in the Palette box parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
- risk 0.00cvss 9.8epss 0.02
nginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try to invoke from a restored frame saved with njs_function_frame_save().
- risk 0.64cvss 9.8epss 0.02
A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825,…
- risk 0.00cvss 9.8epss 0.03
An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into a directory of a GoCD server. They can control the filename but the directory is placed inside of a directory that they can't control.
- risk 0.13cvss 10.0epss 0.99
JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution as the Jiffle script is compiled into Java code via Janino, and executed. In…
- risk 0.64cvss 9.8epss 0.03
Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.
- risk 0.00cvss 9.0epss 0.01
Stored XSS viva .svg file upload in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.
- risk 0.71cvss 9.8epss 0.51
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
- risk 0.64cvss 9.8epss 0.08
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
- risk 0.00cvss 9.0epss 0.01
Multiple Stored XSS in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.
- risk 0.00cvss 9.0epss 0.01
Stored XSS due to no sanitization in the filename in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.
- risk 0.62cvss 9.0epss 0.05
A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute JavaScript code in the client's browser by storing said code as a Missing Data Code value. This can then be leveraged to execute a…
- risk 0.59cvss 9.1epss 0.03
A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when performed over the network. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior)
- risk 0.59cvss 9.1epss 0.02
A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior)
- risk 0.64cvss 9.8epss 0.04
CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on config.php leading to remote code execution.
- risk 0.64cvss 9.8epss 0.03
An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be uploaded and published by trusted users, this…
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbitrary code via a crafted SVG file.
- risk 0.64cvss 9.8epss 0.03
An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file.
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted file.
- risk 0.64cvss 9.8epss 0.03
An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file.
- risk 0.64cvss 9.8epss 0.03
An arbitrary file upload vulnerability in the file upload module of express-fileupload 1.3.1 allows attackers to execute arbitrary code via a crafted PHP file. NOTE: the vendor's position is that the observed behavior can only occur with "intentional misusing of the API": the…
- risk 0.64cvss 9.8epss 0.04
An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted SVG file. NOTE: Vendor states that as outlined in Ghost's security documentation, upload of SVGs is only possible by trusted authenticated…
- risk 0.64cvss 9.8epss 0.01
AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_navigation.php