Vulnerabilidades CVE
Base de dados CVE enriquecida com CISA KEV e NVD
| CVE ID | CVSS | Severidade | KEV | Avistamentos |
|---|---|---|---|---|
| CVE-2023-39673 Tenda AC15 V1.0BR_V15.03.05.18_multi_TD01 was discovered to contain a buffer overflow via the function FUN_00010e34(). | 9.8 | CRITICAL | — | 0 |
| CVE-2023-39674 D-Link DIR-880 A1_FW107WWb08 was discovered to contain a buffer overflow via the function fgets. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-32626 Hidden functionality vulnerability in LAN-W300N/RS all versions, and LAN-W300N/PR5 all versions allows an unauthenticated attacker to log in to the product's certain management console and execute arb... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-35991 Hidden functionality vulnerability in LOGITEC wireless LAN routers allows an unauthenticated attacker to log in to the product's certain management console and execute arbitrary OS commands. Affected ... | 9.8 | CRITICAL | — | 0 |
| CVE-2021-33390 dpic 2021.04.10 has a use-after-free in thedeletestringbox() function in dpic.y. A different vulnerablility than CVE-2021-32421. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-33388 dpic 2021.04.10 has a Heap Buffer Overflow in themakevar() function in dpic.y | 9.8 | CRITICAL | — | 0 |
| CVE-2023-40069 OS command injection vulnerability in ELECOM wireless LAN routers allows an attacker who can access the product to execute an arbitrary OS command by sending a specially crafted request. Affected prod... | 9.8 | CRITICAL | — | 0 |
| CVE-2021-0889 In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow. This could lead to remote code execution with no additional execution privileges needed. User inter... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-24300 Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-44659 Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server Side Request Forgery (SSRF). NOTE: the vendor's po... | 9.8 | CRITICAL | — | 0 |
| CVE-2021-43631 Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the appointment_no parameter in payment.php. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-40323 Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-43629 Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-43628 Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the email parameter in hms-staff.php. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-43155 Projectsworlds Online Book Store PHP v1.0 is vulnerable to SQL injection via the "bookisbn" parameter in cart.php. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-24223 AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-36888 Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-40612 An issue was discovered in Opmantek Open-AudIT after 3.5.0. Without authentication, a vulnerability in code_igniter/application/controllers/util.php allows an attacker perform command execution withou... | 9.8 | CRITICAL | — | 0 |
| CVE-2021-45459 lib/cmd.js in the node-windows package before 1.0.0-beta.6 for Node.js allows command injection via the PID parameter. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-44031 An issue was discovered in Quest KACE Desktop Authority before 11.2. /dacomponentui/profiles/profileitems/outlooksettings/Insertimage.aspx contains a vulnerability that could allow pre-authentication ... | 9.8 | CRITICAL | — | 0 |
| CVE-2021-44029 An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remote code through a deserialization exploitation in the RadAsyncUpload function of... | 9.8 | CRITICAL | — | 0 |
| CVE-2021-39641 Product: AndroidVersions: Android kernelAndroid ID: A-126949257References: N/A | 9.8 | CRITICAL | — | 0 |
| CVE-2021-39644 Product: AndroidVersions: Android kernelAndroid ID: A-199809304References: N/A | 9.8 | CRITICAL | — | 0 |
| CVE-2021-39645 Product: AndroidVersions: Android kernelAndroid ID: A-199805112References: N/A | 9.8 | CRITICAL | — | 0 |
| CVE-2021-36336 Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticated attacker to execute code on the affected system. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-45090 Stormshield Endpoint Security before 2.1.2 allows remote code execution. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-39655 Product: AndroidVersions: Android kernelAndroid ID: A-192641593References: N/A | 9.8 | CRITICAL | — | 0 |
| CVE-2021-45255 The email parameter from ajax.php of Video Sharing Website 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC fil... | 9.8 | CRITICAL | — | 0 |
| CVE-2021-45253 The id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file fu... | 9.8 | CRITICAL | — | 0 |
| CVE-2021-27856 FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" that has administrative privileges and no password. Older versions of FatPipe so... | 9.8 | CRITICAL | — | 0 |
| CVE-2021-44350 SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-45252 Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be ... | 9.8 | CRITICAL | — | 0 |
| CVE-2021-24849 The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before ... | 9.8 | CRITICAL | — | 0 |
| CVE-2021-43439 RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely | 9.8 | CRITICAL | — | 0 |
| CVE-2022-24222 eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-4119 bookstack is vulnerable to Improper Access Control | 9.8 | CRITICAL | — | 0 |
| CVE-2021-44525 Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authentication is not required. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-44676 Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects of the application state. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-44675 Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which authentication is not required. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-44164 Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pass file type validation, upload malicious script an... | 9.8 | CRITICAL | — | 0 |
| CVE-2021-45092 Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-23803 This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the security of the application. When the template is set to allow/disallow the use of cert... | 9.8 | CRITICAL | — | 0 |
| CVE-2021-30351 An out of bound memory access can occur due to improper validation of number of frames being passed during music playback in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Co... | 9.8 | CRITICAL | — | 0 |
| CVE-2021-44159 4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files without authentication and execute arbitrary code in... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-18078 A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-24221 eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-24220 eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-24219 eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-46093 eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-41511 The username and password field of login in Lodging Reservation Management System V1 can give access to any user by using SQL injection to bypass authentication. | 9.8 | CRITICAL | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.