TROYANOSYVIRUS

Vulnerabilidades CVE

Base de dados CVE enriquecida com CISA KEV e NVD

Total: 332,405 CVEs
CVE IDCVSSSeveridadeKEVAvistamentos
CVE-2023-39673

Tenda AC15 V1.0BR_V15.03.05.18_multi_TD01 was discovered to contain a buffer overflow via the function FUN_00010e34().

9.8CRITICAL0
CVE-2023-39674

D-Link DIR-880 A1_FW107WWb08 was discovered to contain a buffer overflow via the function fgets.

9.8CRITICAL0
CVE-2023-32626

Hidden functionality vulnerability in LAN-W300N/RS all versions, and LAN-W300N/PR5 all versions allows an unauthenticated attacker to log in to the product's certain management console and execute arb...

9.8CRITICAL0
CVE-2023-35991

Hidden functionality vulnerability in LOGITEC wireless LAN routers allows an unauthenticated attacker to log in to the product's certain management console and execute arbitrary OS commands. Affected ...

9.8CRITICAL0
CVE-2021-33390

dpic 2021.04.10 has a use-after-free in thedeletestringbox() function in dpic.y. A different vulnerablility than CVE-2021-32421.

9.8CRITICAL0
CVE-2021-33388

dpic 2021.04.10 has a Heap Buffer Overflow in themakevar() function in dpic.y

9.8CRITICAL0
CVE-2023-40069

OS command injection vulnerability in ELECOM wireless LAN routers allows an attacker who can access the product to execute an arbitrary OS command by sending a specially crafted request. Affected prod...

9.8CRITICAL0
CVE-2021-0889

In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow. This could lead to remote code execution with no additional execution privileges needed. User inter...

9.8CRITICAL0
CVE-2022-24300

Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection.

9.8CRITICAL0
CVE-2021-44659

Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server Side Request Forgery (SSRF). NOTE: the vendor's po...

9.8CRITICAL0
CVE-2021-43631

Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the appointment_no parameter in payment.php.

9.8CRITICAL0
CVE-2021-40323

Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.

9.8CRITICAL0
CVE-2021-43629

Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php.

9.8CRITICAL0
CVE-2021-43628

Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the email parameter in hms-staff.php.

9.8CRITICAL0
CVE-2021-43155

Projectsworlds Online Book Store PHP v1.0 is vulnerable to SQL injection via the "bookisbn" parameter in cart.php.

9.8CRITICAL0
CVE-2022-24223

AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.

9.8CRITICAL0
CVE-2021-36888

Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin.

9.8CRITICAL0
CVE-2021-40612

An issue was discovered in Opmantek Open-AudIT after 3.5.0. Without authentication, a vulnerability in code_igniter/application/controllers/util.php allows an attacker perform command execution withou...

9.8CRITICAL0
CVE-2021-45459

lib/cmd.js in the node-windows package before 1.0.0-beta.6 for Node.js allows command injection via the PID parameter.

9.8CRITICAL0
CVE-2021-44031

An issue was discovered in Quest KACE Desktop Authority before 11.2. /dacomponentui/profiles/profileitems/outlooksettings/Insertimage.aspx contains a vulnerability that could allow pre-authentication ...

9.8CRITICAL0
CVE-2021-44029

An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remote code through a deserialization exploitation in the RadAsyncUpload function of...

9.8CRITICAL0
CVE-2021-39641

Product: AndroidVersions: Android kernelAndroid ID: A-126949257References: N/A

9.8CRITICAL0
CVE-2021-39644

Product: AndroidVersions: Android kernelAndroid ID: A-199809304References: N/A

9.8CRITICAL0
CVE-2021-39645

Product: AndroidVersions: Android kernelAndroid ID: A-199805112References: N/A

9.8CRITICAL0
CVE-2021-36336

Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticated attacker to execute code on the affected system.

9.8CRITICAL0
CVE-2021-45090

Stormshield Endpoint Security before 2.1.2 allows remote code execution.

9.8CRITICAL0
CVE-2021-39655

Product: AndroidVersions: Android kernelAndroid ID: A-192641593References: N/A

9.8CRITICAL0
CVE-2021-45255

The email parameter from ajax.php of Video Sharing Website 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC fil...

9.8CRITICAL0
CVE-2021-45253

The id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file fu...

9.8CRITICAL0
CVE-2021-27856

FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" that has administrative privileges and no password. Older versions of FatPipe so...

9.8CRITICAL0
CVE-2021-44350

SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php.

9.8CRITICAL0
CVE-2021-45252

Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be ...

9.8CRITICAL0
CVE-2021-24849

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before ...

9.8CRITICAL0
CVE-2021-43439

RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely

9.8CRITICAL0
CVE-2022-24222

eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php.

9.8CRITICAL0
CVE-2021-4119

bookstack is vulnerable to Improper Access Control

9.8CRITICAL0
CVE-2021-44525

Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authentication is not required.

9.8CRITICAL0
CVE-2021-44676

Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects of the application state.

9.8CRITICAL0
CVE-2021-44675

Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which authentication is not required.

9.8CRITICAL0
CVE-2021-44164

Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pass file type validation, upload malicious script an...

9.8CRITICAL0
CVE-2021-45092

Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.

9.8CRITICAL0
CVE-2021-23803

This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the security of the application. When the template is set to allow/disallow the use of cert...

9.8CRITICAL0
CVE-2021-30351

An out of bound memory access can occur due to improper validation of number of frames being passed during music playback in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Co...

9.8CRITICAL0
CVE-2021-44159

4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files without authentication and execute arbitrary code in...

9.8CRITICAL0
CVE-2020-18078

A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password.

9.8CRITICAL0
CVE-2022-24221

eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php.

9.8CRITICAL0
CVE-2022-24220

eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php.

9.8CRITICAL0
CVE-2022-24219

eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php.

9.8CRITICAL0
CVE-2021-46093

eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php.

9.8CRITICAL0
CVE-2021-41511

The username and password field of login in Lodging Reservation Management System V1 can give access to any user by using SQL injection to bypass authentication.

9.8CRITICAL0
Pagina 89 de 6649

This product uses data from the NVD API but is not endorsed or certified by the NVD.