| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-40499 | Cri | 0.64 | 9.8 | 0.01 | Oct 12, 2021 | Client-side printing services SAP Cloud Print Manager and SAPSprint for SAP NetWeaver Application Server for ABAP - versions 7.70, 7.70 PI, 7.70 BYD, allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the… | ||
| CVE-2021-38180 | Cri | 0.64 | 9.8 | 0.02 | Oct 12, 2021 | SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitation during the data export. An attacker could thereby execute arbitrary commands on the victim's computer but only if the victim allows to… | ||
| CVE-2021-37726 | Cri | 0.64 | 9.8 | 0.02 | Oct 12, 2021 | A remote buffer overflow vulnerability was discovered in HPE Aruba Instant (IAP) version(s): Aruba Instant 8.7.x.x: 8.7.0.0 through 8.7.1.2. Aruba has released patches for Aruba Instant (IAP) that address this security vulnerability. | ||
| CVE-2021-38458 | Cri | 0.64 | 9.8 | 0.02 | Oct 12, 2021 | A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries. | ||
| CVE-2021-38456 | Cri | 0.64 | 9.8 | 0.01 | Oct 12, 2021 | A use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to gain access through accounts using default passwords | ||
| CVE-2021-38454 | Cri | 0.66 | 10.0 | 0.16 | Oct 12, 2021 | A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries. | ||
| CVE-2021-21941 | Cri | 0.59 | 9.0 | 0.02 | Oct 12, 2021 | A use-after-free vulnerability exists in the pushMuxer CreatePushThread functionality of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to remote code execution. | ||
| CVE-2021-21940 | Cri | 0.65 | 10.0 | 0.01 | Oct 12, 2021 | A heap-based buffer overflow vulnerability exists in the pushMuxer processRtspInfo functionality of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted network packet can lead to a heap buffer overflow. An attacker can send a malicious packet to trigger this vulnerability. | ||
| CVE-2021-33725 | Cri | 0.59 | 9.1 | 0.01 | Oct 12, 2021 | A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to delete arbitrary files or directories under a user controlled path and does not correctly check if the relative path is still within the intended target directory. | ||
| CVE-2021-33724 | Cri | 0.59 | 9.1 | 0.01 | Oct 12, 2021 | A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system contains an Arbitrary File Deletion vulnerability that possibly allows to delete an arbitrary file or directory under a user controlled path. | ||
| CVE-2021-40617 | Cri | 0.67 | 9.8 | 0.05 | Oct 11, 2021 | An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php. | ||
| CVE-2021-40239 | Cri | 0.64 | 9.8 | 0.01 | Oct 11, 2021 | A Buffer Overflow vulnerability exists in the latest version of Miniftpd in the do_retr function in ftpproto.c | ||
| CVE-2020-27372 | Cri | 0.64 | 9.8 | 0.01 | Oct 11, 2021 | A buffer overflow vulnerability exists in Brandy Basic V Interpreter 1.21 in the run_interpreter function. | ||
| CVE-2021-26588 | Cri | 0.64 | 9.8 | 0.02 | Oct 11, 2021 | A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This vulnerability impacts… | ||
| CVE-2021-37123 | Cri | 0.64 | 9.8 | 0.01 | Oct 11, 2021 | There is an improper authentication vulnerability in Hero-CT060 before 1.0.0.200. The vulnerability is due to that when an user wants to do certain operation, the software does not insufficiently validate the user's identity. Successful exploit could allow the attacker to do… | ||
| CVE-2021-27664 | Cri | 0.64 | 9.8 | 0.02 | Oct 11, 2021 | Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVision Server. | ||
| CVE-2021-40543 | — | Cri | 0.64 | 9.8 | 0.01 | Oct 11, 2021 | Opensis-Classic Version 8.0 is affected by a SQL injection vulnerability due to a lack of sanitization of input data at two parameters $_GET['usrid'] and $_GET['prof_id'] in the PasswordCheck.php file. | |
| CVE-2021-40887 | Cri | 0.64 | 9.8 | 0.02 | Oct 11, 2021 | Projectsend version r1295 is affected by a directory traversal vulnerability. Because of lacking sanitization input for files[] parameter, an attacker can add ../ to move all PHP files or any file on the system that has permissions to /upload/files/ folder. | ||
| CVE-2021-40889 | Cri | 0.64 | 9.8 | 0.02 | Oct 11, 2021 | CMSUno version 1.7.2 is affected by a PHP code execution vulnerability. sauvePass action in {webroot}/uno/central.php file calls to file_put_contents() function to write username in password.php file when a user successfully changed their password. The attacker can inject… | ||
| CVE-2021-42139 | Cri | 0.64 | 9.8 | 0.02 | Oct 11, 2021 | Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations. | ||
| CVE-2021-37973 | Cri | 0.75 | 9.6 | 0.12 | KEV | Oct 8, 2021 | Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | |
| CVE-2021-30633 | Cri | 0.77 | 9.6 | 0.33 | KEV | Oct 8, 2021 | Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | |
| CVE-2020-22617 | Cri | 0.64 | 9.8 | 0.01 | Oct 8, 2021 | Ardour v5.12 contains a use-after-free vulnerability in the component ardour/libs/pbd/xml++.cc when using xmlFreeDoc and xmlXPathFreeContext. | ||
| CVE-2021-42109 | Cri | 0.64 | 9.8 | 0.02 | Oct 8, 2021 | VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root. | ||
| CVE-2021-41974 | Cri | 0.59 | 9.1 | 0.01 | Oct 8, 2021 | Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view and modify arbitrary content of books without permission. | ||
| CVE-2021-41566 | Cri | 0.64 | 9.8 | 0.02 | Oct 8, 2021 | The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of files and execute arbitrary code without logging in. | ||
| CVE-2021-36767 | Cri | 0.64 | 9.8 | 0.01 | Oct 8, 2021 | In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making the protection ineffective. An attacker may send an unauthenticated request to the server. The server will reply with a weakly-hashed… | ||
| CVE-2021-35977 | Cri | 0.64 | 9.8 | 0.02 | Oct 8, 2021 | An issue was discovered in Digi RealPort for Windows through 4.8.488.0. A buffer overflow exists in the handling of ADDP discovery response messages. This could result in arbitrary code execution. | ||
| CVE-2021-38298 | Cri | 0.64 | 9.8 | 0.03 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE. | ||
| CVE-2020-21726 | Cri | 0.64 | 9.8 | 0.01 | Oct 7, 2021 | OpenSNS v6.1.0 contains a blind SQL injection vulnerability in /Controller/ChinaCityController.class.php via the cid parameter. | ||
| CVE-2020-21725 | Cri | 0.64 | 9.8 | 0.01 | Oct 7, 2021 | OpenSNS v6.1.0 contains a blind SQL injection vulnerability in /Controller/ChinaCityController.class.php via the pid parameter. | ||
| CVE-2021-42091 | Cri | 0.59 | 9.1 | 0.01 | Oct 7, 2021 | An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration. | ||
| CVE-2021-42090 | Cri | 0.64 | 9.8 | 0.02 | Oct 7, 2021 | An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled. | ||
| CVE-2020-21865 | Cri | 0.64 | 9.8 | 0.02 | Oct 7, 2021 | ThinkPHP50-CMS v1.0 contains a remote code execution (RCE) vulnerability in the component /public/?s=captcha. | ||
| CVE-2021-42094 | Cri | 0.64 | 9.8 | 0.02 | Oct 7, 2021 | An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages. | ||
| CVE-2021-42071 | Cri | 0.72 | 9.8 | 0.70 | Oct 7, 2021 | In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header. | ||
| CVE-2021-42013 | Cri | 0.86 | 9.8 | 1.00 | KEV | Oct 7, 2021 | It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by… | |
| CVE-2021-3833 | Cri | 0.64 | 9.8 | 0.01 | Oct 7, 2021 | Integria IMS login check uses a loose comparator ("==") to compare the MD5 hash of the password provided by the user and the MD5 hash stored in the database. An attacker with a specific formatted password could exploit this vulnerability in order to login in the system with… | ||
| CVE-2021-37931 | Cri | 0.64 | 9.8 | 0.10 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | ||
| CVE-2021-37930 | Cri | 0.64 | 9.8 | 0.10 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | ||
| CVE-2021-37929 | Cri | 0.64 | 9.8 | 0.10 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | ||
| CVE-2021-37928 | Cri | 0.64 | 9.8 | 0.10 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | ||
| CVE-2021-37926 | Cri | 0.70 | 9.8 | 0.74 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | ||
| CVE-2021-37924 | Cri | 0.65 | 9.8 | 0.11 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | ||
| CVE-2021-37923 | Cri | 0.65 | 9.8 | 0.11 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | ||
| CVE-2021-37921 | Cri | 0.65 | 9.8 | 0.11 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | ||
| CVE-2021-37920 | Cri | 0.65 | 9.8 | 0.11 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | ||
| CVE-2021-37919 | Cri | 0.65 | 9.8 | 0.11 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | ||
| CVE-2021-37918 | Cri | 0.70 | 9.8 | 0.74 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | ||
| CVE-2021-37762 | Cri | 0.64 | 9.8 | 0.08 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution. |
- risk 0.64cvss 9.8epss 0.01
Client-side printing services SAP Cloud Print Manager and SAPSprint for SAP NetWeaver Application Server for ABAP - versions 7.70, 7.70 PI, 7.70 BYD, allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the…
- risk 0.64cvss 9.8epss 0.02
SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitation during the data export. An attacker could thereby execute arbitrary commands on the victim's computer but only if the victim allows to…
- risk 0.64cvss 9.8epss 0.02
A remote buffer overflow vulnerability was discovered in HPE Aruba Instant (IAP) version(s): Aruba Instant 8.7.x.x: 8.7.0.0 through 8.7.1.2. Aruba has released patches for Aruba Instant (IAP) that address this security vulnerability.
- risk 0.64cvss 9.8epss 0.02
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
- risk 0.64cvss 9.8epss 0.01
A use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to gain access through accounts using default passwords
- risk 0.66cvss 10.0epss 0.16
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
- risk 0.59cvss 9.0epss 0.02
A use-after-free vulnerability exists in the pushMuxer CreatePushThread functionality of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to remote code execution.
- risk 0.65cvss 10.0epss 0.01
A heap-based buffer overflow vulnerability exists in the pushMuxer processRtspInfo functionality of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted network packet can lead to a heap buffer overflow. An attacker can send a malicious packet to trigger this vulnerability.
- risk 0.59cvss 9.1epss 0.01
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to delete arbitrary files or directories under a user controlled path and does not correctly check if the relative path is still within the intended target directory.
- risk 0.59cvss 9.1epss 0.01
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system contains an Arbitrary File Deletion vulnerability that possibly allows to delete an arbitrary file or directory under a user controlled path.
- risk 0.67cvss 9.8epss 0.05
An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.
- risk 0.64cvss 9.8epss 0.01
A Buffer Overflow vulnerability exists in the latest version of Miniftpd in the do_retr function in ftpproto.c
- risk 0.64cvss 9.8epss 0.01
A buffer overflow vulnerability exists in Brandy Basic V Interpreter 1.21 in the run_interpreter function.
- risk 0.64cvss 9.8epss 0.02
A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This vulnerability impacts…
- risk 0.64cvss 9.8epss 0.01
There is an improper authentication vulnerability in Hero-CT060 before 1.0.0.200. The vulnerability is due to that when an user wants to do certain operation, the software does not insufficiently validate the user's identity. Successful exploit could allow the attacker to do…
- risk 0.64cvss 9.8epss 0.02
Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVision Server.
- risk 0.64cvss 9.8epss 0.01
Opensis-Classic Version 8.0 is affected by a SQL injection vulnerability due to a lack of sanitization of input data at two parameters $_GET['usrid'] and $_GET['prof_id'] in the PasswordCheck.php file.
- risk 0.64cvss 9.8epss 0.02
Projectsend version r1295 is affected by a directory traversal vulnerability. Because of lacking sanitization input for files[] parameter, an attacker can add ../ to move all PHP files or any file on the system that has permissions to /upload/files/ folder.
- risk 0.64cvss 9.8epss 0.02
CMSUno version 1.7.2 is affected by a PHP code execution vulnerability. sauvePass action in {webroot}/uno/central.php file calls to file_put_contents() function to write username in password.php file when a user successfully changed their password. The attacker can inject…
- risk 0.64cvss 9.8epss 0.02
Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations.
- risk 0.75cvss 9.6epss 0.12
Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- risk 0.77cvss 9.6epss 0.33
Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- risk 0.64cvss 9.8epss 0.01
Ardour v5.12 contains a use-after-free vulnerability in the component ardour/libs/pbd/xml++.cc when using xmlFreeDoc and xmlXPathFreeContext.
- risk 0.64cvss 9.8epss 0.02
VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root.
- risk 0.59cvss 9.1epss 0.01
Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view and modify arbitrary content of books without permission.
- risk 0.64cvss 9.8epss 0.02
The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of files and execute arbitrary code without logging in.
- risk 0.64cvss 9.8epss 0.01
In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making the protection ineffective. An attacker may send an unauthenticated request to the server. The server will reply with a weakly-hashed…
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in Digi RealPort for Windows through 4.8.488.0. A buffer overflow exists in the handling of ADDP discovery response messages. This could result in arbitrary code execution.
- risk 0.64cvss 9.8epss 0.03
Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.
- risk 0.64cvss 9.8epss 0.01
OpenSNS v6.1.0 contains a blind SQL injection vulnerability in /Controller/ChinaCityController.class.php via the cid parameter.
- risk 0.64cvss 9.8epss 0.01
OpenSNS v6.1.0 contains a blind SQL injection vulnerability in /Controller/ChinaCityController.class.php via the pid parameter.
- risk 0.59cvss 9.1epss 0.01
An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.
- risk 0.64cvss 9.8epss 0.02
ThinkPHP50-CMS v1.0 contains a remote code execution (RCE) vulnerability in the component /public/?s=captcha.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.
- risk 0.72cvss 9.8epss 0.70
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header.
- risk 0.86cvss 9.8epss 1.00
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by…
- risk 0.64cvss 9.8epss 0.01
Integria IMS login check uses a loose comparator ("==") to compare the MD5 hash of the password provided by the user and the MD5 hash stored in the database. An attacker with a specific formatted password could exploit this vulnerability in order to login in the system with…
- risk 0.64cvss 9.8epss 0.10
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- risk 0.64cvss 9.8epss 0.10
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- risk 0.64cvss 9.8epss 0.10
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- risk 0.64cvss 9.8epss 0.10
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- risk 0.70cvss 9.8epss 0.74
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- risk 0.65cvss 9.8epss 0.11
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- risk 0.65cvss 9.8epss 0.11
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- risk 0.65cvss 9.8epss 0.11
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- risk 0.65cvss 9.8epss 0.11
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- risk 0.65cvss 9.8epss 0.11
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- risk 0.70cvss 9.8epss 0.74
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- risk 0.64cvss 9.8epss 0.08
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution.