| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-34187 | Cri | 0.65 | 9.8 | 0.16 | Jun 28, 2021 | main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter. | ||
| CVE-2021-35456 | Cri | 0.64 | 9.8 | 0.02 | Jun 28, 2021 | Online Pet Shop We App 1.0 is vulnerable to remote SQL injection and shell upload | ||
| CVE-2021-31337 | Cri | 0.64 | 9.8 | 0.02 | Jun 28, 2021 | The Telnet service of the SIMATIC HMI Comfort Panels system component in affected products does not require authentication, which may allow a remote attacker to gain access to the device if the service is enabled. Telnet is disabled by default on the SINAMICS Medium Voltage… | ||
| CVE-2021-35514 | Cri | 0.57 | 9.8 | 0.01 | Jun 28, 2021 | Narou (aka Narou.rb) before 3.8.0 allows Ruby Code Injection via the title name or author name of a novel. | ||
| CVE-2021-35502 | Cri | 0.64 | 9.8 | 0.01 | Jun 25, 2021 | app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data related to generic-template:index. | ||
| CVE-2021-34427 | Cri | 0.68 | 9.8 | 0.58 | Jun 25, 2021 | In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance. | ||
| CVE-2021-34074 | Cri | 0.64 | 9.8 | 0.07 | Jun 25, 2021 | PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a relative path is used in the requests. | ||
| CVE-2021-34184 | Cri | 0.64 | 9.8 | 0.01 | Jun 25, 2021 | Miniaudio 0.10.35 has a Double free vulnerability that could cause a buffer overflow in ma_default_vfs_close__stdio in miniaudio.h. | ||
| CVE-2021-35049 | Cri | 0.65 | 9.9 | 0.05 | Jun 25, 2021 | Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could allow a specially crafted HTTP request to execute system commands on the CommandPost and return results in an HTTP response in an… | ||
| CVE-2021-35048 | Cri | 0.64 | 9.8 | 0.01 | Jun 25, 2021 | Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interface. The vulnerability could lead to exposure of authentication tokens in some versions of Fidelis software. The vulnerability is present in Fidelis Network and… | ||
| CVE-2021-35047 | Cri | 0.64 | 9.9 | 0.02 | Jun 25, 2021 | Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with user level access to the CLI to inject root level commands into the component and neighboring Fidelis components. The vulnerability is present in Fidelis… | ||
| CVE-2021-28958 | Cri | 0.70 | 9.8 | 0.73 | Jun 25, 2021 | Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password. | ||
| CVE-2021-32711 | Cri | 0.52 | 9.1 | 0.01 | Jun 24, 2021 | Shopware is an open source eCommerce platform. Versions prior to 6.3.5.1 may leak of information via Store-API. The vulnerability could only be fixed by changing the API system, which involves a non-backward-compatible change. Only consumers of the Store-API should be affected… | ||
| CVE-2020-17752 | Cri | 0.64 | 9.8 | 0.02 | Jun 24, 2021 | Integer overflow vulnerability in payable function of a smart contract implementation for an Ethereum token, as demonstrated by the smart contract implemented at address 0xB49E984A83d7A638E7F2889fc8328952BA951AbE, an implementation for MillionCoin (MON). | ||
| CVE-2021-32708 | Cri | 0.57 | 9.8 | 0.03 | Jun 24, 2021 | Flysystem is an open source file storage library for PHP. The whitespace normalisation using in 1.x and 2.x removes any unicode whitespace. Under certain specific conditions this could potentially allow a malicious user to execute code remotely. The conditions are: A user is… | ||
| CVE-2020-18667 | Cri | 0.64 | 9.8 | 0.01 | Jun 24, 2021 | SQL Injection vulnerability in WebPort <=1.19.1 via the new connection, parameter name in type-conn. | ||
| CVE-2021-33346 | Cri | 0.64 | 9.8 | 0.01 | Jun 24, 2021 | There is an arbitrary password modification vulnerability in a D-LINK DSL-2888A router product. An attacker can use this vulnerability to modify the password of the admin user without authorization. | ||
| CVE-2021-31649 | Cri | 0.64 | 9.8 | 0.02 | Jun 24, 2021 | In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerable to remote code execute | ||
| CVE-2020-21786 | Cri | 0.64 | 9.8 | 0.01 | Jun 24, 2021 | In IBOS 4.5.4 Open, Arbitrary File Inclusion causes getshell via /system/modules/dashboard/controllers/CronController.php. | ||
| CVE-2020-21784 | Cri | 0.64 | 9.8 | 0.01 | Jun 24, 2021 | phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php. | ||
| CVE-2020-18662 | Cri | 0.67 | 9.8 | 0.05 | Jun 24, 2021 | SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php. | ||
| CVE-2020-21787 | Cri | 0.64 | 9.8 | 0.02 | Jun 24, 2021 | CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php. | ||
| CVE-2021-29954 | Cri | 0.64 | 9.8 | 0.01 | Jun 24, 2021 | Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, including the metadata service. This vulnerability affects Hubs Cloud < mozillareality/reticulum/1.0.1/20210428201255. | ||
| CVE-2021-21809 | Cri | 0.64 | 9.1 | 0.24 | Jun 23, 2021 | A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities. | ||
| CVE-2020-20392 | Cri | 0.64 | 9.8 | 0.01 | Jun 23, 2021 | SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php. | ||
| CVE-2021-21998 | Cri | 0.65 | 9.8 | 0.11 | Jun 23, 2021 | VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass. A malicious actor with network access to the VMware Carbon Black App Control management server might be able to obtain administrative access to the product without… | ||
| CVE-2021-27649 | Cri | 0.64 | 9.8 | 0.02 | Jun 23, 2021 | Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors. | ||
| CVE-2021-32700 | Cri | 0.59 | 9.1 | 0.01 | Jun 22, 2021 | Ballerina is an open source programming language and platform for cloud application programmers. Ballerina versions 1.2.x and SL releases up to alpha 3 have a potential for a supply chain attack via MiTM against users. Http connections did not make use of TLS and certificate… | ||
| CVE-2021-3044 | Cri | 0.64 | 9.8 | 0.01 | Jun 22, 2021 | An improper authorization vulnerability in Palo Alto Networks Cortex XSOAR enables a remote unauthenticated attacker with network access to the Cortex XSOAR server to perform unauthorized actions through the REST API. This issue impacts: Cortex XSOAR 6.1.0 builds later than… | ||
| CVE-2021-20736 | Cri | 0.59 | 9.1 | 0.01 | Jun 22, 2021 | NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the information stored in the database via unspecified vectors. | ||
| CVE-2010-1435 | Cri | 0.64 | 9.8 | 0.01 | Jun 21, 2021 | Joomla! Core is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently retrieve password reset tokens from the database through an already existing SQL injection vector. Joomla! Core versions… | ||
| CVE-2010-1433 | Cri | 0.64 | 9.8 | 0.01 | Jun 21, 2021 | Joomla! Core is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This… | ||
| CVE-2021-35066 | Cri | 0.64 | 9.8 | 0.01 | Jun 21, 2021 | An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132. | ||
| CVE-2021-24376 | Cri | 0.64 | 9.8 | 0.04 | Jun 21, 2021 | The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archive via the "Import Settings" feature, after its extraction. However, the extracted folders are not checked and it is possible to upload a zip which contained a… | ||
| CVE-2021-24370 | Cri | 0.67 | 9.8 | 0.47 | Jun 21, 2021 | The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution. | ||
| CVE-2021-24361 | Cri | 0.64 | 9.8 | 0.02 | Jun 21, 2021 | In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then used in a SQL statement, leading to unauthenticated SQL Injection issues. | ||
| CVE-2020-19510 | Cri | 0.64 | 9.8 | 0.01 | Jun 21, 2021 | Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php. | ||
| CVE-2021-26461 | Cri | 0.64 | 9.8 | 0.05 | Jun 21, 2021 | Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution. | ||
| CVE-2021-0516 | Cri | 0.64 | 9.8 | 0.02 | Jun 21, 2021 | In p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2018-25016 | Cri | 0.64 | 9.8 | 0.01 | Jun 21, 2021 | Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection. | ||
| CVE-2020-20466 | Cri | 0.64 | 9.8 | 0.02 | Jun 21, 2021 | White Shark System (WSS) 1.3.2 is vulnerable to unauthorized access via user_edit_password.php, remote attackers can modify the password of any user. | ||
| CVE-2021-31272 | Cri | 0.64 | 9.8 | 0.03 | Jun 18, 2021 | SerenityOS before commit 3844e8569689dd476064a0759d704bc64fb3ca2c contains a directory traversal vulnerability in tar/unzip that may lead to command execution or privilege escalation. | ||
| CVE-2021-3604 | Cri | 0.64 | 9.8 | 0.02 | Jun 18, 2021 | Secure 8 (Evalos) does not validate user input data correctly, allowing a remote attacker to perform a Blind SQL Injection. An attacker could exploit this vulnerability in order to extract information of users and administrator accounts stored in the database. | ||
| CVE-2021-33576 | Cri | 0.64 | 9.8 | 0.02 | Jun 18, 2021 | An issue was discovered in Cleo LexiCom 5.5.0.0. Within the AS2 message, the sender can specify a filename. This filename can include path-traversal characters, allowing the file to be written to an arbitrary location on disk. | ||
| CVE-2021-21669 | Cri | 0.59 | 9.8 | 0.26 | Jun 18, 2021 | Jenkins Generic Webhook Trigger Plugin 1.72 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | ||
| CVE-2021-34810 | Cri | 0.64 | 9.9 | 0.01 | Jun 18, 2021 | Improper privilege management vulnerability in cgi component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to execute arbitrary code via unspecified vectors. | ||
| CVE-2021-34809 | Cri | 0.65 | 9.9 | 0.02 | Jun 18, 2021 | Improper neutralization of special elements used in a command ('Command Injection') vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to execute arbitrary code via unspecified vectors. | ||
| CVE-2013-20002 | Cri | 0.64 | 9.8 | 0.04 | Jun 17, 2021 | Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/themify-ajax.php file. | ||
| CVE-2020-25414 | Cri | 0.64 | 9.8 | 0.02 | Jun 17, 2021 | A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitrary PHP code. | ||
| CVE-2021-21777 | Cri | 0.65 | 10.0 | 0.02 | Jun 17, 2021 | An information disclosure vulnerability exists in the Ethernet/IP UDP handler functionality of EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A specially crafted network request can lead to an out-of-bounds read. |
- risk 0.65cvss 9.8epss 0.16
main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.
- risk 0.64cvss 9.8epss 0.02
Online Pet Shop We App 1.0 is vulnerable to remote SQL injection and shell upload
- risk 0.64cvss 9.8epss 0.02
The Telnet service of the SIMATIC HMI Comfort Panels system component in affected products does not require authentication, which may allow a remote attacker to gain access to the device if the service is enabled. Telnet is disabled by default on the SINAMICS Medium Voltage…
- risk 0.57cvss 9.8epss 0.01
Narou (aka Narou.rb) before 3.8.0 allows Ruby Code Injection via the title name or author name of a novel.
- risk 0.64cvss 9.8epss 0.01
app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data related to generic-template:index.
- risk 0.68cvss 9.8epss 0.58
In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance.
- risk 0.64cvss 9.8epss 0.07
PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a relative path is used in the requests.
- risk 0.64cvss 9.8epss 0.01
Miniaudio 0.10.35 has a Double free vulnerability that could cause a buffer overflow in ma_default_vfs_close__stdio in miniaudio.h.
- risk 0.65cvss 9.9epss 0.05
Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could allow a specially crafted HTTP request to execute system commands on the CommandPost and return results in an HTTP response in an…
- risk 0.64cvss 9.8epss 0.01
Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interface. The vulnerability could lead to exposure of authentication tokens in some versions of Fidelis software. The vulnerability is present in Fidelis Network and…
- risk 0.64cvss 9.9epss 0.02
Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with user level access to the CLI to inject root level commands into the component and neighboring Fidelis components. The vulnerability is present in Fidelis…
- risk 0.70cvss 9.8epss 0.73
Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.
- risk 0.52cvss 9.1epss 0.01
Shopware is an open source eCommerce platform. Versions prior to 6.3.5.1 may leak of information via Store-API. The vulnerability could only be fixed by changing the API system, which involves a non-backward-compatible change. Only consumers of the Store-API should be affected…
- risk 0.64cvss 9.8epss 0.02
Integer overflow vulnerability in payable function of a smart contract implementation for an Ethereum token, as demonstrated by the smart contract implemented at address 0xB49E984A83d7A638E7F2889fc8328952BA951AbE, an implementation for MillionCoin (MON).
- risk 0.57cvss 9.8epss 0.03
Flysystem is an open source file storage library for PHP. The whitespace normalisation using in 1.x and 2.x removes any unicode whitespace. Under certain specific conditions this could potentially allow a malicious user to execute code remotely. The conditions are: A user is…
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in WebPort <=1.19.1 via the new connection, parameter name in type-conn.
- risk 0.64cvss 9.8epss 0.01
There is an arbitrary password modification vulnerability in a D-LINK DSL-2888A router product. An attacker can use this vulnerability to modify the password of the admin user without authorization.
- risk 0.64cvss 9.8epss 0.02
In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerable to remote code execute
- risk 0.64cvss 9.8epss 0.01
In IBOS 4.5.4 Open, Arbitrary File Inclusion causes getshell via /system/modules/dashboard/controllers/CronController.php.
- risk 0.64cvss 9.8epss 0.01
phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.
- risk 0.67cvss 9.8epss 0.05
SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.
- risk 0.64cvss 9.8epss 0.02
CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.
- risk 0.64cvss 9.8epss 0.01
Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, including the metadata service. This vulnerability affects Hubs Cloud < mozillareality/reticulum/1.0.1/20210428201255.
- risk 0.64cvss 9.1epss 0.24
A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php.
- risk 0.65cvss 9.8epss 0.11
VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass. A malicious actor with network access to the VMware Carbon Black App Control management server might be able to obtain administrative access to the product without…
- risk 0.64cvss 9.8epss 0.02
Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.
- risk 0.59cvss 9.1epss 0.01
Ballerina is an open source programming language and platform for cloud application programmers. Ballerina versions 1.2.x and SL releases up to alpha 3 have a potential for a supply chain attack via MiTM against users. Http connections did not make use of TLS and certificate…
- risk 0.64cvss 9.8epss 0.01
An improper authorization vulnerability in Palo Alto Networks Cortex XSOAR enables a remote unauthenticated attacker with network access to the Cortex XSOAR server to perform unauthorized actions through the REST API. This issue impacts: Cortex XSOAR 6.1.0 builds later than…
- risk 0.59cvss 9.1epss 0.01
NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the information stored in the database via unspecified vectors.
- risk 0.64cvss 9.8epss 0.01
Joomla! Core is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently retrieve password reset tokens from the database through an already existing SQL injection vector. Joomla! Core versions…
- risk 0.64cvss 9.8epss 0.01
Joomla! Core is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This…
- risk 0.64cvss 9.8epss 0.01
An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.
- risk 0.64cvss 9.8epss 0.04
The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archive via the "Import Settings" feature, after its extraction. However, the extracted folders are not checked and it is possible to upload a zip which contained a…
- risk 0.67cvss 9.8epss 0.47
The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.
- risk 0.64cvss 9.8epss 0.02
In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then used in a SQL statement, leading to unauthenticated SQL Injection issues.
- risk 0.64cvss 9.8epss 0.01
Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.
- risk 0.64cvss 9.8epss 0.05
Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
- risk 0.64cvss 9.8epss 0.02
In p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.64cvss 9.8epss 0.01
Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection.
- risk 0.64cvss 9.8epss 0.02
White Shark System (WSS) 1.3.2 is vulnerable to unauthorized access via user_edit_password.php, remote attackers can modify the password of any user.
- risk 0.64cvss 9.8epss 0.03
SerenityOS before commit 3844e8569689dd476064a0759d704bc64fb3ca2c contains a directory traversal vulnerability in tar/unzip that may lead to command execution or privilege escalation.
- risk 0.64cvss 9.8epss 0.02
Secure 8 (Evalos) does not validate user input data correctly, allowing a remote attacker to perform a Blind SQL Injection. An attacker could exploit this vulnerability in order to extract information of users and administrator accounts stored in the database.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in Cleo LexiCom 5.5.0.0. Within the AS2 message, the sender can specify a filename. This filename can include path-traversal characters, allowing the file to be written to an arbitrary location on disk.
- risk 0.59cvss 9.8epss 0.26
Jenkins Generic Webhook Trigger Plugin 1.72 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- risk 0.64cvss 9.9epss 0.01
Improper privilege management vulnerability in cgi component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to execute arbitrary code via unspecified vectors.
- risk 0.65cvss 9.9epss 0.02
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to execute arbitrary code via unspecified vectors.
- risk 0.64cvss 9.8epss 0.04
Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/themify-ajax.php file.
- risk 0.64cvss 9.8epss 0.02
A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitrary PHP code.
- risk 0.65cvss 10.0epss 0.02
An information disclosure vulnerability exists in the Ethernet/IP UDP handler functionality of EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A specially crafted network request can lead to an out-of-bounds read.