| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-28901 | Cri | 0.64 | 9.8 | 0.09 | May 24, 2021 | Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt component installation in cmd_subsys.php. | ||
| CVE-2020-28900 | Cri | 0.64 | 9.8 | 0.02 | May 24, 2021 | Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh. | ||
| CVE-2020-25409 | Cri | 0.64 | 9.8 | 0.02 | May 24, 2021 | Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters. | ||
| CVE-2021-21001 | Cri | 0.59 | 9.1 | 0.01 | May 24, 2021 | On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges. | ||
| CVE-2021-33497 | Cri | 0.59 | 9.1 | 0.02 | May 24, 2021 | Dutchcoders transfer.sh before 1.2.4 allows Directory Traversal for deleting files. | ||
| CVE-2021-33509 | Cri | 0.65 | 9.9 | 0.02 | May 21, 2021 | Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Python script. | ||
| CVE-2020-36331 | Cri | 0.52 | 9.1 | 0.02 | May 21, 2021 | A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability. | ||
| CVE-2020-36330 | Cri | 0.52 | 9.1 | 0.02 | May 21, 2021 | A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability. | ||
| CVE-2020-36329 | Cri | 0.57 | 9.8 | 0.02 | May 21, 2021 | A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | ||
| CVE-2020-36328 | Cri | 0.57 | 9.8 | 0.03 | May 21, 2021 | A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system… | ||
| CVE-2018-25014 | Cri | 0.64 | 9.8 | 0.02 | May 21, 2021 | A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol(). | ||
| CVE-2018-25013 | Cri | 0.59 | 9.1 | 0.02 | May 21, 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes(). | ||
| CVE-2018-25012 | Cri | 0.59 | 9.1 | 0.02 | May 21, 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24(). | ||
| CVE-2018-25011 | Cri | 0.64 | 9.8 | 0.03 | May 21, 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16(). | ||
| CVE-2018-25010 | Cri | 0.59 | 9.1 | 0.02 | May 21, 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter(). | ||
| CVE-2018-25009 | Cri | 0.59 | 9.1 | 0.02 | May 21, 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16(). | ||
| CVE-2021-31474 | Cri | 0.71 | 9.8 | 0.94 | May 21, 2021 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SolarWinds.Serialization library.… | ||
| CVE-2020-12061 | Cri | 0.64 | 9.8 | 0.02 | May 21, 2021 | An issue was discovered in Nitrokey FIDO U2F firmware through 1.1. Communication between the microcontroller and the secure element transmits credentials in plain. This allows an adversary to eavesdrop the communication and derive the secrets stored in the microcontroller. As a… | ||
| CVE-2021-32630 | Cri | 0.63 | 9.6 | 0.02 | May 20, 2021 | Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.0.4, there is an authenticated RCE via .phar file upload. A php web shell can be uploaded via the Documents & Files upload feature. Someone with upload… | ||
| CVE-2021-27459 | Cri | 0.64 | 9.8 | 0.02 | May 20, 2021 | A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The webserver of the affected products allows unvalidated files to be uploaded, which an attacker could utilize to execute arbitrary code. | ||
| CVE-2021-20721 | Cri | 0.64 | 9.8 | 0.02 | May 20, 2021 | KonaWiki2 versions prior to 2.2.4 allows a remote attacker to upload arbitrary files via unspecified vectors. If the file contains PHP scripts, arbitrary code may be executed. | ||
| CVE-2021-20720 | Cri | 0.64 | 9.8 | 0.01 | May 20, 2021 | SQL injection vulnerability in the KonaWiki2 versions prior to 2.2.4 allows remote attackers to execute arbitrary SQL commands and to obtain/alter the information stored in the database via unspecified vectors. | ||
| CVE-2020-36364 | Cri | 0.52 | 9.1 | 0.02 | May 19, 2021 | An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0. Administration/Controllers/ImportController.cs allows path traversal (for copy and delete actions) in the ImportController.Create method via a TempFileName field. | ||
| CVE-2021-33204 | Cri | 0.64 | 9.8 | 0.02 | May 19, 2021 | In the pg_partman (aka PG Partition Manager) extension before 4.5.1 for PostgreSQL, arbitrary code execution can be achieved via SECURITY DEFINER functions because an explicit search_path is not set. | ||
| CVE-2017-17674 | Cri | 0.64 | 9.8 | 0.02 | May 19, 2021 | BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Side Request Forgery (SSRF), or remote code… | ||
| CVE-2021-31324 | Cri | 0.66 | 9.8 | 0.35 | May 18, 2021 | The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution. | ||
| CVE-2021-31316 | Cri | 0.65 | 9.8 | 0.13 | May 18, 2021 | The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter. | ||
| CVE-2020-18178 | Cri | 0.64 | 9.8 | 0.02 | May 18, 2021 | Path Traversal in HongCMS v4.0.0 allows remote attackers to view, edit, and delete arbitrary files via a crafted POST request to the component "/hcms/admin/index.php/language/ajax." | ||
| CVE-2021-32305 | Cri | 0.74 | 9.8 | 0.87 | May 18, 2021 | WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter. | ||
| CVE-2020-20951 | Cri | 0.64 | 9.8 | 0.04 | May 18, 2021 | In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files. | ||
| CVE-2021-32454 | Cri | 0.62 | 9.6 | 0.00 | May 17, 2021 | SITEL CAP/PRX firmware version 5.2.01 makes use of a hardcoded password. An attacker with access to the device could modify these credentials, leaving the administrators of the device without access. | ||
| CVE-2021-24314 | Cri | 0.64 | 9.8 | 0.02 | May 17, 2021 | The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing page before using it in a SQL statement, leading to an Unauthenticated SQL injection issue | ||
| CVE-2020-4670 | Cri | 0.59 | 9.1 | 0.02 | May 17, 2021 | IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, running on the remote host is not protected by password authentication. A remote attacker can exploit this to gain unauthorized access to the server. IBM X-Force ID:… | ||
| CVE-2020-4669 | Cri | 0.59 | 9.1 | 0.02 | May 17, 2021 | IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the… | ||
| CVE-2021-27734 | Cri | 0.64 | 9.8 | 0.01 | May 17, 2021 | Hirschmann HiOS 07.1.01, 07.1.02, and 08.1.00 through 08.5.xx and HiSecOS 03.3.00 through 03.5.01 allow remote attackers to change the credentials of existing users. | ||
| CVE-2021-22668 | Cri | 0.64 | 9.8 | 0.02 | May 16, 2021 | Delta Industrial Automation CNCSoft ScreenEditor Versions 1.01.28 (with ScreenEditor Version 1.01.2) and prior are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to execute arbitrary code. | ||
| CVE-2021-3402 | Cri | 0.59 | 9.1 | 0.02 | May 14, 2021 | An integer overflow and several buffer overflow reads in libyara/modules/macho/macho.c in YARA v4.0.3 and earlier could allow an attacker to either cause denial of service or information disclosure via a malicious Mach-O file. Affects all versions before libyara 4.0.4 | ||
| CVE-2020-23691 | Cri | 0.64 | 9.8 | 0.03 | May 14, 2021 | YFCMF v2.3.1 has a Remote Command Execution (RCE) vulnerability in the index.php. | ||
| CVE-2021-25943 | — | Cri | 0.64 | 9.8 | 0.03 | May 14, 2021 | Prototype pollution vulnerability in '101' versions 1.0.0 through 1.6.3 allows an attacker to cause a denial of service and may lead to remote code execution. | |
| CVE-2021-25941 | Cri | 0.57 | 9.8 | 0.03 | May 14, 2021 | Prototype pollution vulnerability in 'deep-override' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution. | ||
| CVE-2020-18166 | Cri | 0.64 | 9.8 | 0.02 | May 14, 2021 | Unrestricted File Upload in LAOBANCMS v2.0 allows remote attackers to upload arbitrary files by attaching a file with a ".jpg.php" extension to the component "admin/wenjian.php?wj=../templets/pc". | ||
| CVE-2021-24285 | Cri | 0.65 | 9.8 | 0.15 | May 14, 2021 | The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitise, validate or escape the order_id POST parameter before using it in a SQL statement, leading… | ||
| CVE-2021-24284 | Cri | 0.67 | 9.8 | 0.42 | May 14, 2021 | The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'uploadFontIcon' AJAX action. The supplied zipfile being unzipped in the wp-content/uploads/kaswara/fonts_icon directory with no checks for malicious files such as… | ||
| CVE-2021-33026 | Cri | 0.64 | 9.8 | 0.07 | May 13, 2021 | The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code execution or local privilege escalation. If an attacker gains access to cache storage (e.g., filesystem, Memcached, Redis, etc.), they can construct a crafted… | ||
| CVE-2021-32615 | Cri | 0.64 | 9.8 | 0.02 | May 13, 2021 | Piwigo 11.4.0 allows admin/user_list_backend.php order[0][dir] SQL Injection. | ||
| CVE-2020-28063 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2021 | A file upload issue exists in all versions of ArticleCMS which allows malicious users to getshell. | ||
| CVE-2020-20092 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2021 | File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type to image/jpeg and placing PHP code after the JPEG data, which could let a remote malicious user execute arbitrary PHP code. | ||
| CVE-2021-20999 | Cri | 0.61 | 9.4 | 0.01 | May 13, 2021 | In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via external network interfaces. By exploiting this vulnerability the device may be manipulated or the operation may be stopped. | ||
| CVE-2021-20998 | Cri | 0.65 | 10.0 | 0.01 | May 13, 2021 | In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it is possible to create users. | ||
| CVE-2021-28799 | Cri | 0.89 | 10.0 | 0.78 | KEV | May 13, 2021 | An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2;… |
- risk 0.64cvss 9.8epss 0.09
Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt component installation in cmd_subsys.php.
- risk 0.64cvss 9.8epss 0.02
Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh.
- risk 0.64cvss 9.8epss 0.02
Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters.
- risk 0.59cvss 9.1epss 0.01
On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.
- risk 0.59cvss 9.1epss 0.02
Dutchcoders transfer.sh before 1.2.4 allows Directory Traversal for deleting files.
- risk 0.65cvss 9.9epss 0.02
Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Python script.
- risk 0.52cvss 9.1epss 0.02
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability.
- risk 0.52cvss 9.1epss 0.02
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.
- risk 0.57cvss 9.8epss 0.02
A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
- risk 0.57cvss 9.8epss 0.03
A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system…
- risk 0.64cvss 9.8epss 0.02
A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().
- risk 0.59cvss 9.1epss 0.02
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().
- risk 0.59cvss 9.1epss 0.02
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().
- risk 0.64cvss 9.8epss 0.03
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().
- risk 0.59cvss 9.1epss 0.02
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().
- risk 0.59cvss 9.1epss 0.02
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().
- risk 0.71cvss 9.8epss 0.94
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SolarWinds.Serialization library.…
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in Nitrokey FIDO U2F firmware through 1.1. Communication between the microcontroller and the secure element transmits credentials in plain. This allows an adversary to eavesdrop the communication and derive the secrets stored in the microcontroller. As a…
- risk 0.63cvss 9.6epss 0.02
Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.0.4, there is an authenticated RCE via .phar file upload. A php web shell can be uploaded via the Documents & Files upload feature. Someone with upload…
- risk 0.64cvss 9.8epss 0.02
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The webserver of the affected products allows unvalidated files to be uploaded, which an attacker could utilize to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.02
KonaWiki2 versions prior to 2.2.4 allows a remote attacker to upload arbitrary files via unspecified vectors. If the file contains PHP scripts, arbitrary code may be executed.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in the KonaWiki2 versions prior to 2.2.4 allows remote attackers to execute arbitrary SQL commands and to obtain/alter the information stored in the database via unspecified vectors.
- risk 0.52cvss 9.1epss 0.02
An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0. Administration/Controllers/ImportController.cs allows path traversal (for copy and delete actions) in the ImportController.Create method via a TempFileName field.
- risk 0.64cvss 9.8epss 0.02
In the pg_partman (aka PG Partition Manager) extension before 4.5.1 for PostgreSQL, arbitrary code execution can be achieved via SECURITY DEFINER functions because an explicit search_path is not set.
- risk 0.64cvss 9.8epss 0.02
BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Side Request Forgery (SSRF), or remote code…
- risk 0.66cvss 9.8epss 0.35
The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.
- risk 0.65cvss 9.8epss 0.13
The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.
- risk 0.64cvss 9.8epss 0.02
Path Traversal in HongCMS v4.0.0 allows remote attackers to view, edit, and delete arbitrary files via a crafted POST request to the component "/hcms/admin/index.php/language/ajax."
- risk 0.74cvss 9.8epss 0.87
WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.
- risk 0.64cvss 9.8epss 0.04
In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.
- risk 0.62cvss 9.6epss 0.00
SITEL CAP/PRX firmware version 5.2.01 makes use of a hardcoded password. An attacker with access to the device could modify these credentials, leaving the administrators of the device without access.
- risk 0.64cvss 9.8epss 0.02
The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing page before using it in a SQL statement, leading to an Unauthenticated SQL injection issue
- risk 0.59cvss 9.1epss 0.02
IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, running on the remote host is not protected by password authentication. A remote attacker can exploit this to gain unauthorized access to the server. IBM X-Force ID:…
- risk 0.59cvss 9.1epss 0.02
IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the…
- risk 0.64cvss 9.8epss 0.01
Hirschmann HiOS 07.1.01, 07.1.02, and 08.1.00 through 08.5.xx and HiSecOS 03.3.00 through 03.5.01 allow remote attackers to change the credentials of existing users.
- risk 0.64cvss 9.8epss 0.02
Delta Industrial Automation CNCSoft ScreenEditor Versions 1.01.28 (with ScreenEditor Version 1.01.2) and prior are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to execute arbitrary code.
- risk 0.59cvss 9.1epss 0.02
An integer overflow and several buffer overflow reads in libyara/modules/macho/macho.c in YARA v4.0.3 and earlier could allow an attacker to either cause denial of service or information disclosure via a malicious Mach-O file. Affects all versions before libyara 4.0.4
- risk 0.64cvss 9.8epss 0.03
YFCMF v2.3.1 has a Remote Command Execution (RCE) vulnerability in the index.php.
- risk 0.64cvss 9.8epss 0.03
Prototype pollution vulnerability in '101' versions 1.0.0 through 1.6.3 allows an attacker to cause a denial of service and may lead to remote code execution.
- risk 0.57cvss 9.8epss 0.03
Prototype pollution vulnerability in 'deep-override' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
- risk 0.64cvss 9.8epss 0.02
Unrestricted File Upload in LAOBANCMS v2.0 allows remote attackers to upload arbitrary files by attaching a file with a ".jpg.php" extension to the component "admin/wenjian.php?wj=../templets/pc".
- risk 0.65cvss 9.8epss 0.15
The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitise, validate or escape the order_id POST parameter before using it in a SQL statement, leading…
- risk 0.67cvss 9.8epss 0.42
The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'uploadFontIcon' AJAX action. The supplied zipfile being unzipped in the wp-content/uploads/kaswara/fonts_icon directory with no checks for malicious files such as…
- risk 0.64cvss 9.8epss 0.07
The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code execution or local privilege escalation. If an attacker gains access to cache storage (e.g., filesystem, Memcached, Redis, etc.), they can construct a crafted…
- risk 0.64cvss 9.8epss 0.02
Piwigo 11.4.0 allows admin/user_list_backend.php order[0][dir] SQL Injection.
- risk 0.64cvss 9.8epss 0.01
A file upload issue exists in all versions of ArticleCMS which allows malicious users to getshell.
- risk 0.64cvss 9.8epss 0.01
File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type to image/jpeg and placing PHP code after the JPEG data, which could let a remote malicious user execute arbitrary PHP code.
- risk 0.61cvss 9.4epss 0.01
In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via external network interfaces. By exploiting this vulnerability the device may be manipulated or the operation may be stopped.
- risk 0.65cvss 10.0epss 0.01
In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it is possible to create users.
- risk 0.89cvss 10.0epss 0.78
An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2;…