Search Results (30268 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-42242 1 Jflyfox 1 Jfinal Cms 2024-11-21 9.8 Critical
A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor.
CVE-2021-42235 1 Enhancesoft 1 Osticket 2024-11-21 9.8 Critical
SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality.
CVE-2021-42232 1 Tp-link 2 Archer A7, Archer A7 Firmware 2024-11-21 9.8 Critical
TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the program taking part of the received data packet as part of the command. This will cause an attacker to execute arbitrary commands on the router.
CVE-2021-42230 1 Seowonintech 2 130-slc, 130-slc Firmware 2024-11-21 9.8 Critical
Seowon 130-SLC router all versions as of 2021-09-15 is vulnerable to Remote Code Execution via the queriesCnt parameter.
CVE-2021-42224 1 Phpgurukul 1 Ifsc Code Finder 2024-11-21 9.8 Critical
SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php.
CVE-2021-42216 1 Anonaddy 1 Anonaddy 2024-11-21 9.8 Critical
A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.
CVE-2021-42185 1 Wdja 1 Wdja 2024-11-21 9.8 Critical
wdja v2.1 is affected by a SQL injection vulnerability in the foreground search function.
CVE-2021-42169 1 Simple Payroll System With Dynamic Tax Bracket Project 1 Simple Payroll System With Dynamic Tax Bracket 2024-11-21 9.8 Critical
The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable from remote SQL-Injection-Bypass-Authentication for the admin account. The parameter (username) from the login form is not protected correctly and there is no security and escaping from malicious payloads.
CVE-2021-42139 1 Deno 1 Deno Standard Modules 2024-11-21 9.8 Critical
Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations.
CVE-2021-42136 1 Vanderbilt 1 Redcap 2024-11-21 9.0 Critical
A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute JavaScript code in the client's browser by storing said code as a Missing Data Code value. This can then be leveraged to execute a Cross-Site Request Forgery attack to escalate privileges to administrator.
CVE-2021-42128 1 Ivanti 1 Avalanche 2024-11-21 9.8 Critical
An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privilege Escalation via Enterprise Server Service.
CVE-2021-42127 1 Ivanti 1 Avalanche 2024-11-21 9.8 Critical
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via Data Repository Service.
CVE-2021-42114 3 Micron, Samsung, Skhynix 12 Ddr4 Sdram, Ddr4 Sdram Firmware, Lddr4 and 9 more 2024-11-21 9 Critical
Modern DRAM devices (PC-DDR4, LPDDR4X) are affected by a vulnerability in their internal Target Row Refresh (TRR) mitigation against Rowhammer attacks. Novel non-uniform Rowhammer access patterns, consisting of aggressors with different frequencies, phases, and amplitudes allow triggering bit flips on affected memory modules using our Blacksmith fuzzer. The patterns generated by Blacksmith were able to trigger bitflips on all 40 PC-DDR4 DRAM devices in our test pool, which cover the three major DRAM manufacturers: Samsung, SK Hynix, and Micron. This means that, even when chips advertised as Rowhammer-free are used, attackers may still be able to exploit Rowhammer. For example, this enables privilege-escalation attacks against the kernel or binaries such as the sudo binary, and also triggering bit flips in RSA-2048 keys (e.g., SSH keys) to gain cross-tenant virtual-machine access. We can confirm that DRAM devices acquired in July 2020 with DRAM chips from all three major DRAM vendors (Samsung, SK Hynix, Micron) are affected by this vulnerability. For more details, please refer to our publication.
CVE-2021-42109 1 Vitec 19 Avediastream M9305, Avediastream M9305 Firmware, Avediastream M9325 and 16 more 2024-11-21 9.8 Critical
VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root.
CVE-2021-42099 1 Zohocorp 1 Manageengine M365 Manager Plus 2024-11-21 9.8 Critical
Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.
CVE-2021-42094 1 Zammad 1 Zammad 2024-11-21 9.8 Critical
An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.
CVE-2021-42091 1 Zammad 1 Zammad 2024-11-21 9.1 Critical
An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration.
CVE-2021-42090 1 Zammad 1 Zammad 2024-11-21 9.8 Critical
An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.
CVE-2021-42077 1 Kaysongroup 1 Php Event Calendar 2024-11-21 9.8 Critical
PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username parameter. This can be used to execute SQL statements directly on the database, allowing an adversary in some cases to completely compromise the database system. It can also be used to bypass the login form.
CVE-2021-42071 1 Visual-tools 2 Dvr Vx16, Dvr Vx16 Firmware 2024-11-21 9.8 Critical
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header.