| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-25402 | Cri | 0.59 | 9.1 | 0.02 | Feb 24, 2022 | An incorrect access control issue in HMS v1.0 allows unauthenticated attackers to read and modify all PHP files. | ||
| CVE-2022-25098 | Cri | 0.59 | 9.1 | 0.01 | Feb 24, 2022 | ECTouch v2 suffers from arbitrary file deletion due to insufficient filtering of the filename parameter. | ||
| CVE-2022-25084 | Cri | 0.66 | 9.8 | 0.25 | Feb 24, 2022 | TOTOLink T6 V5.9c.4085_B20190428 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter. | ||
| CVE-2022-25083 | Cri | 0.64 | 9.8 | 0.03 | Feb 24, 2022 | TOTOLink A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter. | ||
| CVE-2022-25082 | Cri | 0.65 | 9.8 | 0.16 | Feb 24, 2022 | TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter. | ||
| CVE-2022-25081 | Cri | 0.64 | 9.8 | 0.03 | Feb 24, 2022 | TOTOLink T10 V5.9c.5061_B20200511 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter. | ||
| CVE-2022-25080 | Cri | 0.64 | 9.8 | 0.03 | Feb 24, 2022 | TOTOLink A830R V5.9c.4729_B20191112 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter. | ||
| CVE-2022-25079 | Cri | 0.64 | 9.8 | 0.03 | Feb 24, 2022 | TOTOLink A810R V4.1.2cu.5182_B20201026 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter. | ||
| CVE-2022-25078 | Cri | 0.64 | 9.8 | 0.03 | Feb 24, 2022 | TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter. | ||
| CVE-2022-25077 | Cri | 0.66 | 9.8 | 0.33 | Feb 24, 2022 | TOTOLink A3100R V4.1.2cu.5050_B20200504 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter. | ||
| CVE-2022-25076 | Cri | 0.64 | 9.8 | 0.03 | Feb 24, 2022 | TOTOLink A800R V4.1.2cu.5137_B20200730 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter. | ||
| CVE-2022-25075 | Cri | 0.68 | 9.8 | 0.56 | Feb 24, 2022 | TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter. | ||
| CVE-2022-25074 | Cri | 0.65 | 9.8 | 0.13 | Feb 24, 2022 | TP-Link TL-WR902AC(US)_V3_191209 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr(). This vulnerability allows unauthenticated attackers to execute arbitrary code. | ||
| CVE-2022-25073 | Cri | 0.65 | 9.8 | 0.13 | Feb 24, 2022 | TL-WR841Nv14_US_0.9.1_4.18 routers were discovered to contain a stack overflow in the function dm_fillObjByStr(). This vulnerability allows unauthenticated attackers to execute arbitrary code. | ||
| CVE-2022-25072 | Cri | 0.65 | 9.8 | 0.13 | Feb 24, 2022 | TP-Link Archer A54 Archer A54(US)_V1_210111 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr(). This vulnerability allows unauthenticated attackers to execute arbitrary code. | ||
| CVE-2022-21142 | Cri | 0.64 | 9.8 | 0.02 | Feb 24, 2022 | Authentication bypass vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.74, Ver.2.9.x series versions prior to Ver.2.9.39, Ver.2.10.x series versions prior to Ver.2.10.43, and Ver.2.11.x series versions prior to Ver.2.11.41 allows a remote unauthenticated… | ||
| CVE-2021-44610 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2022 | Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) default_group, and (8) page group parameters in the settings mode in admin/index.php. | ||
| CVE-2021-44567 | Cri | 0.69 | 9.8 | 0.23 | Feb 24, 2022 | An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php. | ||
| CVE-2021-44550 | Cri | 0.57 | 9.8 | 0.01 | Feb 24, 2022 | An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159). | ||
| CVE-2022-25330 | Cri | 0.64 | 9.8 | 0.05 | Feb 24, 2022 | Integer overflow conditions that exist in Trend Micro ServerProtect 6.0/5.8 Information Server could allow a remote attacker to crash the process or achieve remote code execution. | ||
| CVE-2022-25329 | Cri | 0.64 | 9.8 | 0.03 | Feb 24, 2022 | Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and… | ||
| CVE-2021-35689 | Cri | 0.64 | 9.8 | 0.02 | Feb 24, 2022 | A potential vulnerability in the Oracle Talent Acquisition Cloud - Taleo Enterprise Edition. This high severity potential vulnerability allows attackers to perform remote code execution on Taleo Enterprise Edition system. Successful attacks of this vulnerability can result in… | ||
| CVE-2021-4070 | — | Cri | 0.52 | 9.1 | 0.01 | Feb 23, 2022 | Off-by-one Error in GitHub repository v2fly/v2ray-core prior to 4.44.0. | |
| CVE-2022-0717 | Cri | 0.00 | 9.1 | 0.01 | Feb 23, 2022 | Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2. | ||
| CVE-2021-27797 | Cri | 0.64 | 9.8 | 0.01 | Feb 21, 2022 | Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded credentials, which could allow attackers to gain access to the system. | ||
| CVE-2022-24553 | Cri | 0.64 | 9.8 | 0.03 | Feb 21, 2022 | An issue was found in Zfaka <= 1.4.5. The verification of the background file upload function check is not strict, resulting in remote command execution. | ||
| CVE-2021-24867 | Cri | 0.65 | 9.8 | 0.18 | Feb 21, 2022 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were… | ||
| CVE-2022-0691 | Cri | 0.57 | 9.8 | 0.02 | Feb 21, 2022 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9. | ||
| CVE-2022-23848 | Cri | 0.64 | 9.8 | 0.01 | Feb 20, 2022 | In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability. | ||
| CVE-2022-0686 | Cri | 0.52 | 9.1 | 0.02 | Feb 20, 2022 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8. | ||
| CVE-2016-1239 | Cri | 0.64 | 9.8 | 0.01 | Feb 19, 2022 | duck before 0.10 did not properly handle loading of untrusted code from the current directory. | ||
| CVE-2022-25137 | Cri | 0.64 | 9.8 | 0.02 | Feb 19, 2022 | A command injection vulnerability in the function recvSlaveUpgstatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet. | ||
| CVE-2022-25136 | Cri | 0.64 | 9.8 | 0.02 | Feb 19, 2022 | A command injection vulnerability in the function meshSlaveUpdate of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet. | ||
| CVE-2022-25135 | Cri | 0.64 | 9.8 | 0.03 | Feb 19, 2022 | A command injection vulnerability in the function recv_mesh_info_sync of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet. | ||
| CVE-2022-25134 | Cri | 0.64 | 9.8 | 0.03 | Feb 19, 2022 | A command injection vulnerability in the function setUpgradeFW of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet. | ||
| CVE-2022-25133 | Cri | 0.64 | 9.8 | 0.03 | Feb 19, 2022 | A command injection vulnerability in the function isAssocPriDevice of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet. | ||
| CVE-2022-25132 | Cri | 0.64 | 9.8 | 0.03 | Feb 19, 2022 | A command injection vulnerability in the function meshSlaveDlfw of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet. | ||
| CVE-2022-25131 | Cri | 0.64 | 9.8 | 0.02 | Feb 19, 2022 | A command injection vulnerability in the function recvSlaveCloudCheckStatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet. | ||
| CVE-2022-25130 | Cri | 0.64 | 9.8 | 0.02 | Feb 19, 2022 | A command injection vulnerability in the function updateWifiInfo of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet. | ||
| CVE-2021-29656 | Cri | 0.64 | 9.8 | 0.01 | Feb 18, 2022 | Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation. The allow list is not properly checked. | ||
| CVE-2021-29655 | Cri | 0.64 | 9.8 | 0.01 | Feb 18, 2022 | Pexip Infinity Connect before 1.8.0 omits certain provisioning authenticity checks. Thus, untrusted code may execute. | ||
| CVE-2021-46110 | Cri | 0.64 | 9.8 | 0.01 | Feb 18, 2022 | Online Shopping Portal v3.1 was discovered to contain multiple time-based SQL injection vulnerabilities via the email and contactno parameters. | ||
| CVE-2022-24049 | Cri | 0.64 | 9.8 | 0.07 | Feb 18, 2022 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 systems) and 11.2.13 build 57923290 (S1 systems). Authentication is not required to exploit this vulnerability. The specific flaw exists within… | ||
| CVE-2022-24047 | Cri | 0.64 | 9.8 | 0.02 | Feb 18, 2022 | This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102. Authentication is not required to exploit this vulnerability. The specific flaw exists within the authorization of HTTP requests. The issue results from… | ||
| CVE-2022-0543 | Cri | 0.88 | 10.0 | 0.99 | KEV | Feb 18, 2022 | It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution. | |
| CVE-2021-46063 | Cri | 0.59 | 9.1 | 0.03 | Feb 18, 2022 | MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management module. | ||
| CVE-2021-46036 | Cri | 0.64 | 9.8 | 0.04 | Feb 18, 2022 | An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code. | ||
| CVE-2022-25337 | Cri | 0.64 | 9.8 | 0.01 | Feb 18, 2022 | Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows injection attacks via image filenames. | ||
| CVE-2022-21215 | Cri | 0.65 | 10.0 | 0.01 | Feb 18, 2022 | This vulnerability could allow an attacker to force the server to create and execute a web request granting access to backend APIs that are only accessible to the Mimosa MMP server, or request pages that could perform some actions themselves. The attacker could force the server… | ||
| CVE-2022-21196 | Cri | 0.65 | 10.0 | 0.04 | Feb 18, 2022 | MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization and authentication checks on multiple API routes. An attacker may gain access to these API… |
- risk 0.59cvss 9.1epss 0.02
An incorrect access control issue in HMS v1.0 allows unauthenticated attackers to read and modify all PHP files.
- risk 0.59cvss 9.1epss 0.01
ECTouch v2 suffers from arbitrary file deletion due to insufficient filtering of the filename parameter.
- risk 0.66cvss 9.8epss 0.25
TOTOLink T6 V5.9c.4085_B20190428 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
- risk 0.64cvss 9.8epss 0.03
TOTOLink A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
- risk 0.65cvss 9.8epss 0.16
TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
- risk 0.64cvss 9.8epss 0.03
TOTOLink T10 V5.9c.5061_B20200511 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
- risk 0.64cvss 9.8epss 0.03
TOTOLink A830R V5.9c.4729_B20191112 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
- risk 0.64cvss 9.8epss 0.03
TOTOLink A810R V4.1.2cu.5182_B20201026 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
- risk 0.64cvss 9.8epss 0.03
TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
- risk 0.66cvss 9.8epss 0.33
TOTOLink A3100R V4.1.2cu.5050_B20200504 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
- risk 0.64cvss 9.8epss 0.03
TOTOLink A800R V4.1.2cu.5137_B20200730 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
- risk 0.68cvss 9.8epss 0.56
TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
- risk 0.65cvss 9.8epss 0.13
TP-Link TL-WR902AC(US)_V3_191209 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr(). This vulnerability allows unauthenticated attackers to execute arbitrary code.
- risk 0.65cvss 9.8epss 0.13
TL-WR841Nv14_US_0.9.1_4.18 routers were discovered to contain a stack overflow in the function dm_fillObjByStr(). This vulnerability allows unauthenticated attackers to execute arbitrary code.
- risk 0.65cvss 9.8epss 0.13
TP-Link Archer A54 Archer A54(US)_V1_210111 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr(). This vulnerability allows unauthenticated attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.02
Authentication bypass vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.74, Ver.2.9.x series versions prior to Ver.2.9.39, Ver.2.10.x series versions prior to Ver.2.10.43, and Ver.2.11.x series versions prior to Ver.2.11.41 allows a remote unauthenticated…
- risk 0.64cvss 9.8epss 0.01
Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) default_group, and (8) page group parameters in the settings mode in admin/index.php.
- risk 0.69cvss 9.8epss 0.23
An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php.
- risk 0.57cvss 9.8epss 0.01
An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159).
- risk 0.64cvss 9.8epss 0.05
Integer overflow conditions that exist in Trend Micro ServerProtect 6.0/5.8 Information Server could allow a remote attacker to crash the process or achieve remote code execution.
- risk 0.64cvss 9.8epss 0.03
Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and…
- risk 0.64cvss 9.8epss 0.02
A potential vulnerability in the Oracle Talent Acquisition Cloud - Taleo Enterprise Edition. This high severity potential vulnerability allows attackers to perform remote code execution on Taleo Enterprise Edition system. Successful attacks of this vulnerability can result in…
- risk 0.52cvss 9.1epss 0.01
Off-by-one Error in GitHub repository v2fly/v2ray-core prior to 4.44.0.
- risk 0.00cvss 9.1epss 0.01
Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2.
- risk 0.64cvss 9.8epss 0.01
Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded credentials, which could allow attackers to gain access to the system.
- risk 0.64cvss 9.8epss 0.03
An issue was found in Zfaka <= 1.4.5. The verification of the background file upload function check is not strict, resulting in remote command execution.
- risk 0.65cvss 9.8epss 0.18
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were…
- risk 0.57cvss 9.8epss 0.02
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.
- risk 0.64cvss 9.8epss 0.01
In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability.
- risk 0.52cvss 9.1epss 0.02
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.
- risk 0.64cvss 9.8epss 0.01
duck before 0.10 did not properly handle loading of untrusted code from the current directory.
- risk 0.64cvss 9.8epss 0.02
A command injection vulnerability in the function recvSlaveUpgstatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.
- risk 0.64cvss 9.8epss 0.02
A command injection vulnerability in the function meshSlaveUpdate of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.
- risk 0.64cvss 9.8epss 0.03
A command injection vulnerability in the function recv_mesh_info_sync of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.
- risk 0.64cvss 9.8epss 0.03
A command injection vulnerability in the function setUpgradeFW of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.
- risk 0.64cvss 9.8epss 0.03
A command injection vulnerability in the function isAssocPriDevice of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.
- risk 0.64cvss 9.8epss 0.03
A command injection vulnerability in the function meshSlaveDlfw of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.
- risk 0.64cvss 9.8epss 0.02
A command injection vulnerability in the function recvSlaveCloudCheckStatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.
- risk 0.64cvss 9.8epss 0.02
A command injection vulnerability in the function updateWifiInfo of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.
- risk 0.64cvss 9.8epss 0.01
Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation. The allow list is not properly checked.
- risk 0.64cvss 9.8epss 0.01
Pexip Infinity Connect before 1.8.0 omits certain provisioning authenticity checks. Thus, untrusted code may execute.
- risk 0.64cvss 9.8epss 0.01
Online Shopping Portal v3.1 was discovered to contain multiple time-based SQL injection vulnerabilities via the email and contactno parameters.
- risk 0.64cvss 9.8epss 0.07
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 systems) and 11.2.13 build 57923290 (S1 systems). Authentication is not required to exploit this vulnerability. The specific flaw exists within…
- risk 0.64cvss 9.8epss 0.02
This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102. Authentication is not required to exploit this vulnerability. The specific flaw exists within the authorization of HTTP requests. The issue results from…
- risk 0.88cvss 10.0epss 0.99
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
- risk 0.59cvss 9.1epss 0.03
MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management module.
- risk 0.64cvss 9.8epss 0.04
An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows injection attacks via image filenames.
- risk 0.65cvss 10.0epss 0.01
This vulnerability could allow an attacker to force the server to create and execute a web request granting access to backend APIs that are only accessible to the Mimosa MMP server, or request pages that could perform some actions themselves. The attacker could force the server…
- risk 0.65cvss 10.0epss 0.04
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization and authentication checks on multiple API routes. An attacker may gain access to these API…