Vulnerabilidades CVE
Base de datos de vulnerabilidades CVE enriquecida con datos de CISA KEV y NVD
| CVE ID | CVSS | Severidad | KEV | Avistamientos |
|---|---|---|---|---|
| CVE-2021-43857 Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched in version 0.9.8. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-46377 There is a front-end sql injection vulnerability in cszcms 1.2.9 via cszcms/controllers/Member.php#viewUser | 9.8 | CRITICAL | β | 0 |
| CVE-2021-4161 The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login credential details. This could give an attacker admin rights through the HTTP we... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-45890 basic/BasicAuthProvider.java in AuthGuard before 0.9.0 allows authentication via an inactive identifier. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-46427 An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Master.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-46428 A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versions via the bot_avatar parameter in SystemSettings.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-45334 Sourcecodester Online Thesis Archiving System 1.0 is vulnerable to SQL Injection. An attacker can bypass admin authentication and gain access to admin panel using SQL Injection | 9.8 | CRITICAL | β | 0 |
| CVE-2021-42392 The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to... | 9.8 | CRITICAL | β | 0 |
| CVE-2020-21237 An issue in the user login box of LJCMS v1.11 allows attackers to hijack user accounts via brute force attacks. | 9.8 | CRITICAL | β | 0 |
| CVE-2020-21238 An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-33962 China Mobile An Lianbao WF-1 router v1.0.1 is affected by an OS command injection vulnerability in the web interface /api/ZRUsb/pop_usb_device component. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-40010 The bone voice ID TA has a heap overflow vulnerability.Successful exploitation of this vulnerability may result in malicious code execution. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-39996 There is a Heap-based buffer overflow vulnerability with the NFC module in smartphones. Successful exploitation of this vulnerability may cause memory overflow. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-39993 There is an Integer overflow vulnerability with ACPU in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-45898 SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-20082 ASUS RT-N53 3.0.0.4.376.3754 devices have a buffer overflow via a long lan_dns1_x or lan_dns2_x parameter to Advanced_LAN_Content.asp. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-37400 An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PLC user program may be uploaded, altered, and/or downloaded. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-37401 An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the PLC user program may be uploaded, altered, and/or downloaded. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-23594 All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-44249 Online Motorcycle (Bike) Rental System 1.0 is vulnerable to a Blind Time-Based SQL Injection attack within the login portal. This can lead attackers to remotely dump MySQL database credentials. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-45814 Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel with an administrative account. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-24044 By passing invalid javascript code where await and yield were called upon non-async and non-generator getter/setter functions, Hermes would invoke generator functions and error out on invalid await/yi... | 9.8 | CRITICAL | β | 0 |
| CVE-2020-7878 An arbitrary file download and execution vulnerability was found in the VideoOffice X2.9 and earlier versions (CVE-2020-7878). This issue is due to missing support for integrity check. | 9.8 | CRITICAL | β | 0 |
| CVE-2020-7883 Printchaser v2.2021.804.1 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. T... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-23543 All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-45435 An SQL Injection vulnerability exists in Sourcecodester Simple Cold Storage Management System using PHP/OOP 1.0 via the username field in login.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2020-25905 An SQL Injection vulnerabilty exists in Sourcecodester Mobile Shop System in PHP MySQL 1.0 via the email parameter in (1) login.php or (2) LoginAsAdmin.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-45899 SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-22294 A SQL injection vulnerability exists in ZFAKA<=1.43 which an attacker can use to complete SQL injection in the foreground and add a background administrator account. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-41609 SQL injection in the ID parameter of the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve data from the application's backe... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-44971 Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, ... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-45427 Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal. An attacker can browse and delete files without any authentication due to incorrect a... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-46067 In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-45456 Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch between what is being checked and what is being used a... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-22820 A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized access over a hijacked session to the charger station web server even after the ... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-31522 Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache ... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-45331 An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for the 2FA can be submitted correctly more than once. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-20149 Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient access controls for the WAN interface. The default iptables ruleset for governing access to services on the device only apply to IPv... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-24307 Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities. (JSON-LD signing has been supported since version 1.6.0.) | 9.8 | CRITICAL | β | 0 |
| CVE-2022-22704 The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that systemd would (in effect) determine part of the co... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-20155 Trendnet AC2600 TEW-827DRU version 2.08B01 makes use of hardcoded credentials. It is possible to backup and restore device configurations via the management web interface. These devices are encrypted ... | 9.8 | CRITICAL | β | 0 |
| CVE-2013-6295 PrestaShop 1.5.5 vulnerable to privilege escalation via a Salesman account via upload module | 9.8 | CRITICAL | β | 0 |
| CVE-2012-2087 ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface. | 9.8 | CRITICAL | β | 0 |
| CVE-2013-2259 Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview | 9.8 | CRITICAL | β | 0 |
| CVE-2013-2260 Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness | 9.8 | CRITICAL | β | 0 |
| CVE-2013-3323 A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session,... | 9.8 | CRITICAL | β | 0 |
| CVE-2020-9374 On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker sends specific shell metacharacters to the panel's tracerout... | 9.8 | CRITICAL | β | 0 |
| CVE-2020-8510 An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of admin+1+en (user+perms+lang), one can login as any user without a password. | 9.8 | CRITICAL | β | 0 |
| CVE-2013-6792 Google Android prior to 4.4 has an APK Signature Security Bypass Vulnerability | 9.8 | CRITICAL | β | 0 |
| CVE-2012-1124 SQL injection vulnerability in search.php in phxEventManager 2.0 beta 5 allows remote attackers to execute arbitrary SQL commands via the search_terms parameter. | 9.8 | CRITICAL | β | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.