Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-3169 1 Jumpserver 1 Jumpserver 2021-08-04 10.0 HIGH 9.8 CRITICAL
An issue in Jumpserver 2.6.2 and below allows attackers to create a connection token through an API which does not have access control and use it to access sensitive assets.
CVE-2021-20399 2 Ibm, Linux 2 Qradar Security Information And Event Manager, Linux Kernel 2021-08-04 6.4 MEDIUM 9.1 CRITICAL
IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196073.
CVE-2021-34165 1 Basic Shopping Cart Project 1 Basic Shopping Cart 2021-08-04 7.5 HIGH 9.8 CRITICAL
A SQL Injection vulnerability in Sourcecodester Basic Shopping Cart 1.0 allows a remote attacker to Bypass Authentication and become Admin.
CVE-2021-25200 1 Learning Management System Project 1 Learning Management System 2021-08-03 7.5 HIGH 9.8 CRITICAL
Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to \lms\student_avatar.php.
CVE-2020-21809 1 Nukeviet 1 Nukeviet 2021-08-03 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability in NukeViet CMS module Shops 4.0.29 and 4.3 via the (1) listid parameter in detail.php and the (2) group_price or groupid parameters in search_result.php.
CVE-2020-21808 1 Nukeviet 1 Nukeviet 2021-08-03 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability in NukeViet CMS 4.0.10 - 4.3.07 via:the topicsid parameter in modules/news/admin/addtotopics.php.
CVE-2020-18175 1 Metinfo 1 Metinfo 2021-08-03 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability in Metinfo 6.1.3 via a dosafety_emailadd action in basic.php.
CVE-2020-21806 1 Ectouch 1 Ectouch 2021-08-03 7.5 HIGH 9.8 CRITICAL
SQL Injection Vulnerability in ECTouch v2 via the shop page in index.php..
CVE-2020-17952 1 Twothink Project 1 Twothink 2021-08-03 7.5 HIGH 9.8 CRITICAL
A remote code execution (RCE) vulnerability in /library/think/App.php of Twothink v2.0 allows attackers to execute arbitrary PHP code.
CVE-2021-37478 1 Naviwebs 1 Navigatecms 2021-08-03 7.5 HIGH 9.8 CRITICAL
In NavigateCMS version 2.9.4 and below, function `block` is vulnerable to sql injection on parameter `block-order`, which results in arbitrary sql query execution in the backend database.
CVE-2020-18013 1 Whatsns 1 Whatsns 2021-08-03 7.5 HIGH 9.8 CRITICAL
SQL Injextion vulnerability exists in Whatsns 4.0 via the ip parameter in index.php?admin_banned/add.htm.
CVE-2020-18172 1 Trezor 1 Bridge 2021-08-03 7.5 HIGH 9.8 CRITICAL
A code injection vulnerability in the SeDebugPrivilege component of Trezor Bridge 2.0.27 allows attackers to escalate privileges.
CVE-2021-34690 2 Idrive, Microsoft 2 Remotepc, Windows 2021-08-03 7.5 HIGH 9.8 CRITICAL
iDrive RemotePC before 7.6.48 on Windows allows authentication bypass. A remote and unauthenticated attacker can bypass cloud authentication to connect and control a system via TCP port 5970 and 5980.
CVE-2020-7622 1 Jooby 1 Jooby 2021-08-03 7.5 HIGH 9.8 CRITICAL
This affects the package io.jooby:jooby-netty before 1.6.9, from 2.0.0 and before 2.2.1. The DefaultHttpHeaders is set to false which means it does not validates that the header isn't being abused for HTTP Response Splitting.
CVE-2020-17510 1 Apache 1 Shiro 2021-08-03 7.5 HIGH 9.8 CRITICAL
Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
CVE-2021-23412 1 Gitlogplus Project 1 Gitlogplus 2021-08-02 7.5 HIGH 9.8 CRITICAL
All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes are appended to the command to be executed without sanitization.
CVE-2021-35464 1 Forgerock 2 Am, Openam 2021-08-02 10.0 HIGH 9.8 CRITICAL
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the usage of Sun ONE Application Framework (JATO) found in versions of Java 8 or earlier
CVE-2021-26088 1 Fortinet 1 Fortinet Single Sign-on 2021-08-02 5.8 MEDIUM 9.6 CRITICAL
An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user to bypass a FSSO firewall policy and access the protected network via sending specifically crafted UDP login notification packets.
CVE-2021-35961 1 Secom 1 Dr.id Access Control 2021-08-02 10.0 HIGH 9.8 CRITICAL
Dr. ID Door Access Control and Personnel Attendance Management system uses the hard-code admin default credentials that allows remote attackers to access the system through the default password and obtain the highest permission.
CVE-2015-8011 3 Debian, Fedoraproject, Lldpd Project 3 Debian Linux, Fedora, Lldpd 2021-08-02 6.8 MEDIUM 9.8 CRITICAL
Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and TLV boundaries.
CVE-2019-17544 2 Canonical, Gnu 2 Ubuntu Linux, Aspell 2021-08-02 6.4 MEDIUM 9.1 CRITICAL
libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated \ character.
CVE-2018-10685 1 Long Range Zip Project 1 Long Range Zip 2021-08-02 7.5 HIGH 9.8 CRITICAL
In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the lzma_decompress_buf function of stream.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
CVE-2019-8457 4 Canonical, Fedoraproject, Opensuse and 1 more 4 Ubuntu Linux, Fedora, Leap and 1 more 2021-07-31 7.5 HIGH 9.8 CRITICAL
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.
CVE-2017-12627 1 Apache 1 Xerces-c\+\+ 2021-07-31 7.5 HIGH 9.8 CRITICAL
In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.
CVE-2021-22911 1 Rocket.chat 1 Rocket.chat 2021-07-30 7.5 HIGH 9.8 CRITICAL
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.
CVE-2021-25212 1 Alumni Management System Project 1 Alumni Management System 2021-07-30 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in SourceCodester Alumni Management System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to manage_event.php.
CVE-2021-25210 1 Alumni Management System Project 1 Alumni Management System 2021-07-30 7.5 HIGH 9.8 CRITICAL
Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to manage_event.php.
CVE-2021-25202 1 Sales And Inventory System Project 1 Sales And Inventory System 2021-07-30 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in SourceCodester Sales and Inventory System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to \ahira\admin\inventory.php.
CVE-2021-26223 1 Casap Automated Enrollment System Project 1 Casap Automated Enrollment System 2021-07-30 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to view_pay.php.
CVE-2021-26226 1 Casap Automated Enrollment System Project 1 Casap Automated Enrollment System 2021-07-30 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_user.php.
CVE-2020-36033 1 Water Billing System Project 1 Water Billing System 2021-07-30 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the id parameter to edituser.php.
CVE-2021-26232 1 Simple College Website Project 1 Simple College Website 2021-07-30 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in SourceCodester Simple College Website v 1.0 allows remote attackers to execute arbitrary SQL statements via the id parameter to news.php.
CVE-2021-26231 1 Fantastic Blog Cms Project 1 Fantastic Blog Cms 2021-07-30 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in SourceCodester Fantastic Blog CMS v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to category.php.
CVE-2021-26229 1 Casap Automated Enrollment System Project 1 Casap Automated Enrollment System 2021-07-30 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_stud.php.
CVE-2021-26228 1 Casap Automated Enrollment System Project 1 Casap Automated Enrollment System 2021-07-30 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_class1.php.
CVE-2020-15851 1 Nakivo 1 Backup \& Replication Transporter 2021-07-30 7.5 HIGH 9.8 CRITICAL
Lack of access control in Nakivo Backup & Replication Transporter version 9.4.0.r43656 allows remote users to access unencrypted backup repositories and the Nakivo Controller configuration via a network accessible transporter service. It is also possible to create or delete backup repositories.
CVE-2019-10202 1 Redhat 2 Enterprise Linux, Jboss Enterprise Application Platform 2021-07-30 7.5 HIGH 9.8 CRITICAL
A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086 reported for FasterXML jackson-databind by implementing a whitelist approach that will mitigate these vulnerabilities and future ones alike.
CVE-2020-18155 1 Intelliants 1 Subrion 2021-07-29 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability in Subrion CMS v4.2.1 in the search page if a website uses a PDO connection.
CVE-2021-25203 1 Victor Cms Project 1 Victor Cms 2021-07-29 7.5 HIGH 9.8 CRITICAL
Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload to \CMSsite-master\admin\includes\admin_add_post.php.
CVE-2020-7866 1 Tobesoft 1 Xplatform 2021-07-29 7.5 HIGH 9.8 CRITICAL
When using XPLATFORM 9.2.2.270 or earlier versions ActiveX component, arbitrary commands can be executed due to improper input validation
CVE-2021-33501 1 Overwolf 1 Overwolf 2021-07-29 9.3 HIGH 9.6 CRITICAL
Overwolf Client 0.169.0.22 allows XSS, with resultant Remote Code Execution, via an overwolfstore:// URL.
CVE-2020-4821 1 Ibm 2 Infosphere Change Data Capture, Infosphere Data Replication 2021-07-29 6.8 MEDIUM 9.8 CRITICAL
IBM InfoSphere Data Replication 11.4 and IBM InfoSphere Change Data Capture for z/OS 10.2.1, under certain configurations, could allow a user to bypass authentication mechanisms using an empty password string. IBM X-Force ID: 189834
CVE-2021-37155 1 Wolfssl 1 Wolfssl 2021-07-29 7.5 HIGH 9.8 CRITICAL
wolfSSL 4.6.x through 4.7.x before 4.8.0 does not produce a failure outcome when the serial number in an OCSP request differs from the serial number in the OCSP response.
CVE-2020-5322 1 Dell 1 Emc Openmanage Enterprise-modular 2021-07-29 9.0 HIGH 9.1 CRITICAL
Dell EMC OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain a command injection vulnerability. A remote authenticated malicious user with high privileges could potentially exploit the vulnerability to execute arbitrary shell commands on the affected system.
CVE-2020-5349 1 Dell 13 Emc Powerswitch S4112f-on, Emc Powerswitch S4112t-on, Emc Powerswitch S4128f-on and 10 more 2021-07-29 10.0 HIGH 9.8 CRITICAL
Dell EMC Networking S4100 and S5200 Series Switches manufactured prior to February 2020 contain a hardcoded credential vulnerability. A remote unauthenticated malicious user could exploit this vulnerability and gain administrative privileges.
CVE-2021-33592 1 Naver 1 Toolbar 2021-07-29 7.5 HIGH 9.8 CRITICAL
NAVER Toolbar before 4.0.30.323 allows remote attackers to execute arbitrary code via a crafted upgrade.xml file. Special characters in filename parameter can be the cause of bypassing code signing check function.
CVE-2021-25213 1 Travel Management System Project 1 Travel Management System 2021-07-29 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in SourceCodester Travel Management System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the catid parameter to subcat.php.
CVE-2021-25209 1 Theme Park Ticketing System Project 1 Theme Park Ticketing System 2021-07-29 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in SourceCodester Theme Park Ticketing System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to view_user.php .
CVE-2021-25205 1 E-commerce Website Project 1 E-commerce Website 2021-07-29 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in SourceCodester E-Commerce Website V 1.0 allows remote attackers to execute arbitrary SQL statements, via the update parameter to empViewUpdate.php .
CVE-2021-33027 1 Sylabs 1 Singularity 2021-07-28 7.5 HIGH 9.8 CRITICAL
Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce.