| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-25912 | Cri | 0.59 | 9.1 | 0.01 | Oct 31, 2021 | A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS). | ||
| CVE-2020-25911 | Cri | 0.59 | 9.1 | 0.02 | Oct 31, 2021 | A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS). | ||
| CVE-2021-41646 | Cri | 0.64 | 9.8 | 0.07 | Oct 29, 2021 | Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters.. | ||
| CVE-2021-41644 | Cri | 0.64 | 9.8 | 0.03 | Oct 29, 2021 | Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses the image upload filters. | ||
| CVE-2021-41643 | Cri | 0.64 | 9.8 | 0.05 | Oct 29, 2021 | Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field. | ||
| CVE-2021-41676 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2021 | An SQL Injection vulnerabilty exists in the oretnom23 Pharmacy Point of Sale System 1.0 in the login function in actions.php. | ||
| CVE-2021-41674 | Cri | 0.64 | 9.8 | 0.02 | Oct 29, 2021 | An SQL Injection vulnerability exists in Sourcecodester E-Negosyo System 1.0 via the user_email parameter in /admin/login.php. | ||
| CVE-2021-3756 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2021 | libmysofa is vulnerable to Heap-based Buffer Overflow | ||
| CVE-2020-22079 | Cri | 0.64 | 9.8 | 0.04 | Oct 29, 2021 | Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attackers to execute arbitrary code via the timeZone parameter to goform/SetSysTimeCfg. | ||
| CVE-2021-41194 | Cri | 0.52 | 9.1 | 0.01 | Oct 28, 2021 | FirstUseAuthenticator is a JupyterHub authenticator that helps new users set their password on their first login to JupyterHub. When JupyterHub is used with FirstUseAuthenticator, a vulnerability in versions prior to 1.0.0 allows unauthorized access to any user's account if… | ||
| CVE-2021-36548 | Cri | 0.64 | 9.8 | 0.03 | Oct 28, 2021 | A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4 allows attackers to execute arbitrary commands via a crafted PHP file. | ||
| CVE-2021-36547 | Cri | 0.64 | 9.8 | 0.03 | Oct 28, 2021 | A remote code execution (RCE) vulnerability in the component /codebase/dir.php?type=filenew of Mara v7.5 allows attackers to execute arbitrary commands via a crafted PHP file. | ||
| CVE-2021-37002 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2021 | There is a Memory out-of-bounds access vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause malicious code to be executed. | ||
| CVE-2021-36990 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2021 | There is a vulnerability of tampering with the kernel in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions. | ||
| CVE-2021-36989 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2021 | There is a Kernel crash vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions. | ||
| CVE-2021-36986 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2021 | There is a vulnerability of tampering with the kernel in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions. | ||
| CVE-2021-22474 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2021 | There is an Out-of-bounds memory access in Huawei Smartphone.Successful exploitation of this vulnerability may cause process exceptions. | ||
| CVE-2021-22436 | Cri | 0.59 | 9.1 | 0.01 | Oct 28, 2021 | There is a Logic Bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service integrity and availability. | ||
| CVE-2021-22403 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2021 | There is a vulnerability of hijacking unverified providers in Huawei Smartphone.Successful exploitation of this vulnerability may allow attackers to hijack the device and forge UIs to induce users to execute malicious commands. | ||
| CVE-2019-19810 | Cri | 0.65 | 10.0 | 0.05 | Oct 28, 2021 | Zoom Call Recording 6.3.1 from Eleveo is vulnerable to Java Deserialization attacks targeting the inbuilt RMI service. A remote unauthenticated attacker can exploit this vulnerability by sending crafted RMI requests to execute arbitrary code on the target host. | ||
| CVE-2020-21250 | Cri | 0.64 | 9.8 | 0.01 | Oct 27, 2021 | CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php. | ||
| CVE-2021-41589 | Cri | 0.64 | 9.8 | 0.02 | Oct 27, 2021 | In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and remote code execution when running the build cache node with its default configuration. This configuration allows anonymous access to the configuration user… | ||
| CVE-2020-24932 | Cri | 0.64 | 9.8 | 0.02 | Oct 27, 2021 | An SQL Injection vulnerability exists in Sourcecodester Complaint Management System 1.0 via the cid parameter in complaint-details.php. | ||
| CVE-2021-38450 | Cri | 0.64 | 9.9 | 0.01 | Oct 27, 2021 | The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software. | ||
| CVE-2011-4574 | Cri | 0.64 | 9.8 | 0.01 | Oct 27, 2021 | PolarSSL versions prior to v1.1 use the HAVEGE random number generation algorithm. At its heart, this uses timing information based on the processor's high resolution timer (the RDTSC instruction). This instruction can be virtualized, and some virtual machine hosts have chosen… | ||
| CVE-2011-4125 | Cri | 0.64 | 9.8 | 0.02 | Oct 27, 2021 | A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root. | ||
| CVE-2011-4124 | Cri | 0.64 | 9.8 | 0.02 | Oct 27, 2021 | Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of privileges. | ||
| CVE-2021-37371 | Cri | 0.64 | 9.8 | 0.02 | Oct 26, 2021 | Online Student Admission System 1.0 is affected by an unauthenticated SQL injection bypass vulnerability in /admin/login.php. | ||
| CVE-2011-4119 | Cri | 0.64 | 9.8 | 0.02 | Oct 26, 2021 | caml-light <= 0.75 uses mktemp() insecurely, and also does unsafe things in /tmp during make install. | ||
| CVE-2011-2195 | Cri | 0.64 | 9.8 | 0.03 | Oct 26, 2021 | A flaw was found in WebSVN 2.3.2. Without prior authentication, if the 'allowDownload' option is enabled in config.php, an attacker can invoke the dl.php script and pass a well formed 'path' argument to execute arbitrary commands against the underlying operating system. | ||
| CVE-2021-41873 | Cri | 0.65 | 10.0 | 0.01 | Oct 26, 2021 | Penguin Aurora TV Box 41502 is a high-end network HD set-top box produced by Tencent Video and Skyworth Digital. An unauthorized access vulnerability exists in the Penguin Aurora Box. An attacker can use the vulnerability to gain unauthorized access to a specific link to… | ||
| CVE-2021-42343 | Cri | 0.57 | 9.8 | 0.03 | Oct 26, 2021 | An issue was discovered in the Dask distributed package before 2021.10.0 for Python. Single machine Dask clusters started with dask.distributed.LocalCluster or dask.distributed.Client (which defaults to using LocalCluster) would mistakenly configure their respective Dask workers… | ||
| CVE-2021-34584 | Cri | 0.59 | 9.1 | 0.01 | Oct 26, 2021 | Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22. | ||
| CVE-2021-20837 | Cri | 0.74 | 9.8 | 0.88 | Oct 26, 2021 | Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002 and earlier (Movable Type Advanced 7 Series), Movable Type Advanced 6.8.2 and earlier (Movable Type Advanced 6 Series), Movable Type… | ||
| CVE-2021-41035 | Cri | 0.64 | 9.8 | 0.02 | Oct 25, 2021 | In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods. | ||
| CVE-2021-24884 | Cri | 0.63 | 9.6 | 0.03 | Oct 25, 2021 | The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like ,,, and.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick… | ||
| CVE-2021-40865 | Cri | 0.62 | 9.8 | 0.64 | Oct 25, 2021 | An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1.… | ||
| CVE-2021-38294 | Cri | 0.66 | 9.8 | 0.84 | Oct 25, 2021 | A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentication. | ||
| CVE-2021-40371 | Cri | 0.64 | 9.8 | 0.07 | Oct 25, 2021 | Gridpro Request Management for Windows Azure Pack before 2.0.7912 allows Directory Traversal for remote code execution, as demonstrated by ..\\ in a scriptName JSON value to ServiceManagerTenant/GetVisibilityMap. | ||
| CVE-2021-42258 | Cri | 0.91 | 9.8 | 0.74 | KEV | Oct 22, 2021 | BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) parameter. Successful… | |
| CVE-2020-28960 | Cri | 0.64 | 9.8 | 0.02 | Oct 22, 2021 | Chichen Tech CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the file product_list.php via the id and cid parameters. | ||
| CVE-2020-23037 | Cri | 0.64 | 9.8 | 0.01 | Oct 22, 2021 | Portable Ltd Playable v9.18 contains a code injection vulnerability in the filename parameter, which allows attackers to execute arbitrary web scripts or HTML via a crafted POST request. | ||
| CVE-2021-42169 | Cri | 0.64 | 9.8 | 0.03 | Oct 22, 2021 | The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable from remote SQL-Injection-Bypass-Authentication for the admin account. The parameter (username) from the login form is not protected correctly and there is no… | ||
| CVE-2021-41745 | Cri | 0.57 | 9.8 | 0.01 | Oct 22, 2021 | ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions. | ||
| CVE-2021-41744 | Cri | 0.64 | 9.8 | 0.02 | Oct 22, 2021 | All versions of yongyou PLM are affected by a command injection issue. UFIDA PLM (Product Life Cycle Management) is a strategic management method. It applies a series of enterprise application systems to support the entire process from conceptual design to the end of product… | ||
| CVE-2021-38477 | Cri | 0.64 | 9.8 | 0.01 | Oct 22, 2021 | There are multiple API function codes that permit reading and writing data to or from files and directories, which could lead to the manipulation and/or the deletion of files. | ||
| CVE-2021-38471 | Cri | 0.59 | 9.1 | 0.01 | Oct 22, 2021 | There are multiple API function codes that permit data writing to any file, which may allow an attacker to modify existing files or create new files. | ||
| CVE-2021-38469 | Cri | 0.59 | 9.1 | 0.01 | Oct 22, 2021 | Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker can exploit the uncontrolled search path by implanting their own DLL near the affected product’s binaries, thus hijacking the loaded DLL. | ||
| CVE-2021-38457 | Cri | 0.64 | 9.8 | 0.01 | Oct 22, 2021 | The server permits communication without any authentication procedure, allowing the attacker to initiate a session with the server without providing any form of authentication. | ||
| CVE-2021-38453 | Cri | 0.59 | 9.1 | 0.01 | Oct 22, 2021 | Some API functions allow interaction with the registry, which includes reading values as well as data modification. |
- risk 0.59cvss 9.1epss 0.01
A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).
- risk 0.59cvss 9.1epss 0.02
A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).
- risk 0.64cvss 9.8epss 0.07
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters..
- risk 0.64cvss 9.8epss 0.03
Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses the image upload filters.
- risk 0.64cvss 9.8epss 0.05
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field.
- risk 0.64cvss 9.8epss 0.01
An SQL Injection vulnerabilty exists in the oretnom23 Pharmacy Point of Sale System 1.0 in the login function in actions.php.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in Sourcecodester E-Negosyo System 1.0 via the user_email parameter in /admin/login.php.
- risk 0.64cvss 9.8epss 0.01
libmysofa is vulnerable to Heap-based Buffer Overflow
- risk 0.64cvss 9.8epss 0.04
Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attackers to execute arbitrary code via the timeZone parameter to goform/SetSysTimeCfg.
- risk 0.52cvss 9.1epss 0.01
FirstUseAuthenticator is a JupyterHub authenticator that helps new users set their password on their first login to JupyterHub. When JupyterHub is used with FirstUseAuthenticator, a vulnerability in versions prior to 1.0.0 allows unauthorized access to any user's account if…
- risk 0.64cvss 9.8epss 0.03
A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4 allows attackers to execute arbitrary commands via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.03
A remote code execution (RCE) vulnerability in the component /codebase/dir.php?type=filenew of Mara v7.5 allows attackers to execute arbitrary commands via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.01
There is a Memory out-of-bounds access vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause malicious code to be executed.
- risk 0.64cvss 9.8epss 0.01
There is a vulnerability of tampering with the kernel in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions.
- risk 0.64cvss 9.8epss 0.01
There is a Kernel crash vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions.
- risk 0.64cvss 9.8epss 0.01
There is a vulnerability of tampering with the kernel in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions.
- risk 0.64cvss 9.8epss 0.01
There is an Out-of-bounds memory access in Huawei Smartphone.Successful exploitation of this vulnerability may cause process exceptions.
- risk 0.59cvss 9.1epss 0.01
There is a Logic Bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service integrity and availability.
- risk 0.64cvss 9.8epss 0.01
There is a vulnerability of hijacking unverified providers in Huawei Smartphone.Successful exploitation of this vulnerability may allow attackers to hijack the device and forge UIs to induce users to execute malicious commands.
- risk 0.65cvss 10.0epss 0.05
Zoom Call Recording 6.3.1 from Eleveo is vulnerable to Java Deserialization attacks targeting the inbuilt RMI service. A remote unauthenticated attacker can exploit this vulnerability by sending crafted RMI requests to execute arbitrary code on the target host.
- risk 0.64cvss 9.8epss 0.01
CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php.
- risk 0.64cvss 9.8epss 0.02
In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and remote code execution when running the build cache node with its default configuration. This configuration allows anonymous access to the configuration user…
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in Sourcecodester Complaint Management System 1.0 via the cid parameter in complaint-details.php.
- risk 0.64cvss 9.9epss 0.01
The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.
- risk 0.64cvss 9.8epss 0.01
PolarSSL versions prior to v1.1 use the HAVEGE random number generation algorithm. At its heart, this uses timing information based on the processor's high resolution timer (the RDTSC instruction). This instruction can be virtualized, and some virtual machine hosts have chosen…
- risk 0.64cvss 9.8epss 0.02
A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root.
- risk 0.64cvss 9.8epss 0.02
Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of privileges.
- risk 0.64cvss 9.8epss 0.02
Online Student Admission System 1.0 is affected by an unauthenticated SQL injection bypass vulnerability in /admin/login.php.
- risk 0.64cvss 9.8epss 0.02
caml-light <= 0.75 uses mktemp() insecurely, and also does unsafe things in /tmp during make install.
- risk 0.64cvss 9.8epss 0.03
A flaw was found in WebSVN 2.3.2. Without prior authentication, if the 'allowDownload' option is enabled in config.php, an attacker can invoke the dl.php script and pass a well formed 'path' argument to execute arbitrary commands against the underlying operating system.
- risk 0.65cvss 10.0epss 0.01
Penguin Aurora TV Box 41502 is a high-end network HD set-top box produced by Tencent Video and Skyworth Digital. An unauthorized access vulnerability exists in the Penguin Aurora Box. An attacker can use the vulnerability to gain unauthorized access to a specific link to…
- risk 0.57cvss 9.8epss 0.03
An issue was discovered in the Dask distributed package before 2021.10.0 for Python. Single machine Dask clusters started with dask.distributed.LocalCluster or dask.distributed.Client (which defaults to using LocalCluster) would mistakenly configure their respective Dask workers…
- risk 0.59cvss 9.1epss 0.01
Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.
- risk 0.74cvss 9.8epss 0.88
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002 and earlier (Movable Type Advanced 7 Series), Movable Type Advanced 6.8.2 and earlier (Movable Type Advanced 6 Series), Movable Type…
- risk 0.64cvss 9.8epss 0.02
In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.
- risk 0.63cvss 9.6epss 0.03
The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like ,,, and.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick…
- risk 0.62cvss 9.8epss 0.64
An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1.…
- risk 0.66cvss 9.8epss 0.84
A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentication.
- risk 0.64cvss 9.8epss 0.07
Gridpro Request Management for Windows Azure Pack before 2.0.7912 allows Directory Traversal for remote code execution, as demonstrated by ..\\ in a scriptName JSON value to ServiceManagerTenant/GetVisibilityMap.
- risk 0.91cvss 9.8epss 0.74
BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) parameter. Successful…
- risk 0.64cvss 9.8epss 0.02
Chichen Tech CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the file product_list.php via the id and cid parameters.
- risk 0.64cvss 9.8epss 0.01
Portable Ltd Playable v9.18 contains a code injection vulnerability in the filename parameter, which allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.
- risk 0.64cvss 9.8epss 0.03
The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable from remote SQL-Injection-Bypass-Authentication for the admin account. The parameter (username) from the login form is not protected correctly and there is no…
- risk 0.57cvss 9.8epss 0.01
ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions.
- risk 0.64cvss 9.8epss 0.02
All versions of yongyou PLM are affected by a command injection issue. UFIDA PLM (Product Life Cycle Management) is a strategic management method. It applies a series of enterprise application systems to support the entire process from conceptual design to the end of product…
- risk 0.64cvss 9.8epss 0.01
There are multiple API function codes that permit reading and writing data to or from files and directories, which could lead to the manipulation and/or the deletion of files.
- risk 0.59cvss 9.1epss 0.01
There are multiple API function codes that permit data writing to any file, which may allow an attacker to modify existing files or create new files.
- risk 0.59cvss 9.1epss 0.01
Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker can exploit the uncontrolled search path by implanting their own DLL near the affected product’s binaries, thus hijacking the loaded DLL.
- risk 0.64cvss 9.8epss 0.01
The server permits communication without any authentication procedure, allowing the attacker to initiate a session with the server without providing any form of authentication.
- risk 0.59cvss 9.1epss 0.01
Some API functions allow interaction with the registry, which includes reading values as well as data modification.