Vulnerabilidades CVE
Base de datos de vulnerabilidades CVE enriquecida con datos de CISA KEV y NVD
| CVE ID | CVSS | Severidad | KEV | Avistamientos |
|---|---|---|---|---|
| CVE-2020-27868 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Qognify Ocularis 5.9.0.395. Authentication is not required to exploit this vulnerability. The specific... | 9.8 | CRITICAL | β | 0 |
| CVE-2020-27539 Heap overflow with full parsing of HTTP respose in Rostelecom CS-C2SHW 5.0.082.1. AgentUpdater service has a self-written HTTP parser and builder. HTTP parser has a heap buffer overflow (OOB write). I... | 9.8 | CRITICAL | β | 0 |
| CVE-2020-25784 An issue was discovered on Accfly Wireless Security IR Camera System 720P with software versions v3.10.73 through v4.15.77. There is an unauthenticated stack-based buffer overflow in the function CNet... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-1140 Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For m... | 9.8 | CRITICAL | β | 0 |
| CVE-2020-35308 CONQUEST DICOM SERVER before 1.5.0 has a code execution vulnerability which can be exploited by attackers to execute malicious code. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-3110 The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-26956 An issue was discovered in the xcb crate through 2021-02-04 for Rust. It has a soundness violation because bytes from an X server can be interpreted as any data type returned by xcb::xproto::GetProper... | 9.8 | CRITICAL | β | 0 |
| CVE-2020-29165 PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by incorrect access control, which can result in remotely gaining administrator privileges. | 9.8 | CRITICAL | β | 0 |
| CVE-2020-28653 Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-25139 A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsof... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-25140 A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsof... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-17582 A use-after-free in the _zip_dirent_read function of zip_dirent.c in libzip 1.2.0 allows attackers to have an unspecified impact by attempting to unzip a malformed ZIP archive. NOTE: the discoverer st... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-2108 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). The supported version that is affected is 12.1.3.0.0. Easily exploitable vulnerability all... | 9.8 | CRITICAL | β | 0 |
| CVE-2020-14343 A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or ... | 9.8 | CRITICAL | β | 0 |
| CVE-2020-28172 A SQL injection vulnerability in Simple College Website 1.0 allows remote unauthenticated attackers to bypass the admin authentication mechanism in college_website/admin/ajax.php?action=login, thus ga... | 9.8 | CRITICAL | β | 0 |
| CVE-2020-3686 Possible memory out of bound issue during music playback when an incorrect bit stream content is copied into array without checking the length of array in Snapdragon Auto, Snapdragon Compute, Snapdrag... | 9.8 | CRITICAL | β | 0 |
| CVE-2020-24391 mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this may overlap CVE-2019-10769. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-3190 The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-26897 Windows DNS Server Remote Code Execution Vulnerability | 9.8 | CRITICAL | β | 0 |
| CVE-2021-26895 Windows DNS Server Remote Code Execution Vulnerability | 9.8 | CRITICAL | β | 0 |
| CVE-2020-11851 Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remotely exploited resulting in the execution of arbitra... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-29936 An issue was discovered in the adtensor crate through 2021-01-11 for Rust. There is a drop of uninitialized memory via the FromIterator implementation for Vector and Matrix. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-26893 Windows DNS Server Remote Code Execution Vulnerability | 9.8 | CRITICAL | β | 0 |
| CVE-2021-26894 Windows DNS Server Remote Code Execution Vulnerability | 9.8 | CRITICAL | β | 0 |
| CVE-2020-11225 Out of bound access in WLAN driver due to lack of validation of array length before copying into array in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics ... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-24175 The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any u... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-30476 HashiCorp Terraformβs Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vaultβs GCP auth method. Fixed in 2.19.1. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-26877 Windows DNS Server Remote Code Execution Vulnerability | 9.8 | CRITICAL | β | 0 |
| CVE-2021-30455 An issue was discovered in the id-map crate through 2021-02-26 for Rust. A double free can occur in IdMap::clone_from upon a .clone panic. | 9.8 | CRITICAL | β | 0 |
| CVE-2020-23359 WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the identicalness of two passwords. Two non-identical passwords can ... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-24171 The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible to bypass this and upload a file with a PHP extensio... | 9.8 | CRITICAL | β | 0 |
| CVE-2020-11216 Buffer over read can happen in video driver when playing clip with atomsize having value UINT32_MAX in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-28132 LUCY Security Awareness Software through 4.7.x allows unauthenticated remote code execution because the Migration Tool (in the Support section) allows upload of .php files within a system.tar.gz file.... | 9.8 | CRITICAL | β | 0 |
| CVE-2020-27555 Use of default credentials for the telnet server in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to execute arbitrary system commands as the root user. | 9.8 | CRITICAL | β | 0 |
| CVE-2020-1900 When unserializing an object with dynamic properties HHVM needs to pre-reserve the full size of the dynamic property array before inserting anything into it. Otherwise the array might resize, invalida... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-28134 Clipper before 1.0.5 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal API... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-3188 phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports. | 9.8 | CRITICAL | β | 0 |
| CVE-2020-11213 Out of bound reads might occur in while processing Service descriptor due to improper validation of length of fields in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consume... | 9.8 | CRITICAL | β | 0 |
| CVE-2020-20269 A specially crafted Markdown document could cause the execution of malicious JavaScript code in Caret Editor before 4.0.0-rc22. | 9.8 | CRITICAL | β | 0 |
| CVE-2020-23360 oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the checks in /catalog/admin/administrators.php and /catalog/passwo... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-3185 A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause the stack to be smashed, memory corruption and possibly cod... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-3304 Sagemcom F@ST 3686 v2 3.495 devices have a buffer overflow via a long sessionKey to the goform/login URI. | 9.8 | CRITICAL | β | 0 |
| CVE-2020-11212 Out of bounds reads while parsing NAN beacons attributes and OUIs due to improper length of field check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-24030 The fbgames protocol handler registered as part of Facebook Gameroom does not properly quote arguments passed to the executable. That allows a malicious URL to cause code execution. This issue affects... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-24025 Due to incorrect string size calculations inside the preg_quote function, a large input string passed to the function can trigger an integer overflow leading to a heap overflow. This issue affects HHV... | 9.8 | CRITICAL | β | 0 |
| CVE-2020-28138 SourceCodester Online Clothing Store 1.0 is affected by a SQL Injection via the txtUserName parameter to login.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-0397 In sdp_copy_raw_data of sdp_discovery.cc, there is a possible system compromise due to a double free. This could lead to remote code execution with no additional execution privileges needed. User inte... | 9.8 | CRITICAL | β | 0 |
| CVE-2020-28140 SourceCodester Online Clothing Store 1.0 is affected by an arbitrary file upload via the image upload feature of Products.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-25907 An issue was discovered in the containers crate before 0.9.11 for Rust. When a panic occurs, a util::{mutate,mutate2} double drop can be performed. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-0396 In Builtins::Generate_ArgumentsAdaptorTrampoline of builtins-arm.cc and related files, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code executio... | 9.8 | CRITICAL | β | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.