Search Results (360057 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-42913 1 Samsung 3 Scx-6555, Scx-6555n, Syncthru Web Service 2024-11-21 7.5 High
The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and cleartext passwords by reading the HTML source code. Authentication is not required.
CVE-2021-42912 1 Fiberhome 12 Aan5506-04-g2g Firmware, An5506-01-a, An5506-01-a Firmware and 9 more 2024-11-21 8.8 High
FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root user via the ping diagnostic tool, bypassing the IP address field, and concatenating OS commands with a semicolon.
CVE-2021-42911 1 Draytek 6 Vigor2960, Vigor2960 Firmware, Vigor300b and 3 more 2024-11-21 9.8 Critical
A Format String vulnerability exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor 300B <= 1.5.1.3 in the mainfunction.cgi file via a crafted HTTP message containing malformed QUERY STRING, which could let a remote malicious user execute arbitrary code.
CVE-2021-42897 1 Feminer Wms Project 1 Feminer Wms 2024-11-21 9.8 Critical
A remote command execution (RCE) vulnerability was found in FeMiner wms V1.0 in /wms/src/system/datarec.php. The $_POST[r_name] is directly passed into the $mysqlstr and is executed by exec.
CVE-2021-42893 1 Totolink 2 Ex1200t, Ex1200t Firmware 2024-11-21 7.5 High
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization through getSysStatusCfg.
CVE-2021-42892 1 Totolink 2 Ex1200t, Ex1200t Firmware 2024-11-21 4.3 Medium
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can start telnet without authorization because the default username and password exists in the firmware.
CVE-2021-42891 1 Totolink 2 Ex1200t, Ex1200t Firmware 2024-11-21 7.5 High
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization.
CVE-2021-42890 1 Totolink 2 Ex1200t, Ex1200t Firmware 2024-11-21 9.8 Critical
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function NTPSyncWithHost of the file system.so which can control hostTime to attack.
CVE-2021-42889 1 Totolink 2 Ex1200t, Ex1200t Firmware 2024-11-21 7.5 High
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname, etc.) without authorization.
CVE-2021-42888 1 Totolink 2 Ex1200t, Ex1200t Firmware 2024-11-21 9.8 Critical
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setLanguageCfg of the file global.so which can control langType to attack.
CVE-2021-42887 1 Totolink 2 Ex1200t, Ex1200t Firmware 2024-11-21 9.8 Critical
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
CVE-2021-42886 1 Totolink 2 Ex1200t, Ex1200t Firmware 2024-11-21 7.5 High
TOTOLINK EX1200T V4.1.2cu.5215 contains an information disclosure vulnerability where an attacker can get the apmib configuration file without authorization, and usernames and passwords can be found in the decoded file.
CVE-2021-42885 1 Totolink 2 Ex1200t, Ex1200t Firmware 2024-11-21 9.8 Critical
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceMac of the file global.so which can control deviceName to attack.
CVE-2021-42884 1 Totolink 2 Ex1200t, Ex1200t Firmware 2024-11-21 9.8 Critical
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceName of the file global.so which can control thedeviceName to attack.
CVE-2021-42877 1 Totolink 2 Ex1200t, Ex1200t Firmware 2024-11-21 7.5 High
TOTOLINK EX1200T V4.1.2cu.5215 contains a denial of service vulnerability in function RebootSystem of the file lib/cste_modules/system which can reboot the system.
CVE-2021-42875 1 Totolink 2 Ex1200t, Ex1200t Firmware 2024-11-21 9.8 Critical
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the file lib/cste_modules/system.so to control the ipDoamin.
CVE-2021-42872 1 Totolink 2 Ex1200t, Ex1200t Firmware 2024-11-21 9.8 Critical
TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code.
CVE-2021-42870 1 Accel-ppp 1 Accel-ppp 2024-11-21 7.5 High
ACCEL-PPP 1.12.0 has an out-of-bounds read in post_msg when processing a call_clear_request.
CVE-2021-42869 1 Chikitsa 1 Patient Management Software 2024-11-21 4.8 Medium
A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 via the last_name parameter in the (1) patient/insert, (2) patient_report, (3) /appointment_report, (4) visit_report, and (5) /bill_detail_report pages.
CVE-2021-42868 1 Chikitsa 1 Patient Management Software 2024-11-21 4.8 Medium
A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 in the first_name parameter in (1) patient/insert, (2) patient_report, (3) appointment_report, (4) visit_report, and (5) bill_detail_report pages. .