CVE-2021-44142 | HIGH | 8.8 | 0.73539 | 60.94 | No | No | 2022-02-21 | 2025-04-23 | euvd | The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and intero…The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root. |
CVE-2025-29824 | HIGH | 7.8 | 0.13475 | 60.92 | Yes | Yes | 2025-04-08 | 2025-04-08 | cisa.gov, euvd, packetstorm | Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate…Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. |
CVE-2026-3910 | HIGH | 8.8 | 0.02 | 60.9 | Yes | No | 2026-03-13 | 2026-03-13 | cisa.gov, euvd | Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remo…Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. |
CVE-2021-33739 | HIGH | 8.4 | 0.06555 | 60.89 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Microsoft Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.Microsoft Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation. |
CVE-2025-34030 | CRITICAL | 10.0 | 0.59649 | 60.88 | No | No | 2025-06-20 | 2026-04-07 | euvd | An OS command injection vulnerability exists in sar2html version 3.2.2 and prior via the plot parameter in index.php. The application fails …An OS command injection vulnerability exists in sar2html version 3.2.2 and prior via the plot parameter in index.php. The application fails to sanitize user-supplied input before using it in a system-level context. Remote, unauthenticated attackers can inject shell commands by appending them to the plot parameter (e.g., ?plot=;id) in a crafted GET request. The output of the command is displayed in the application's interface after interacting with the host selection UI. Successful exploitation leads to arbitrary command execution on the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-04 UTC. |
CVE-2025-21043 | HIGH | 8.8 | 0.019 | 60.87 | Yes | No | 2025-10-02 | 2025-10-02 | cisa.gov, euvd | Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbit…Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbitrary code. |
CVE-2026-20262 | MEDIUM | 6.5 | 0.28171 | 60.86 | Yes | No | 2026-06-15 | 2026-06-15 | cisa.gov, euvd, nvd | Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to cre…Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. |
CVE-2020-35730 | MEDIUM | 6.1 | 0.32688 | 60.84 | Yes | No | 2023-06-22 | 2023-06-22 | cisa.gov, euvd | Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows an attacker to send a plain text e-mail message with Javas…Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows an attacker to send a plain text e-mail message with Javascript in a link reference element that is mishandled by linkref_addinindex in rcube_string_replacer.php. |
CVE-2021-2198 | HIGH | 8.2 | 0.79936 | 60.78 | No | No | 2021-04-22 | 2024-09-26 | euvd | Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Setup, Admin). Supported versions that are a…Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Setup, Admin). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Knowledge Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Knowledge Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Knowledge Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N). |
CVE-2026-3909 | HIGH | 8.8 | 0.01629 | 60.77 | Yes | No | 2026-03-13 | 2026-03-13 | cisa.gov, euvd | Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a cr…Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products. |
CVE-2019-8720 | HIGH | 8.8 | 0.01543 | 60.74 | Yes | No | 2022-05-23 | 2022-05-23 | cisa.gov, euvd | WebKitGTK contains a memory corruption vulnerability which can allow an attacker to perform remote code execution.WebKitGTK contains a memory corruption vulnerability which can allow an attacker to perform remote code execution. |
CVE-2020-3251 | CRITICAL | 9.8 | 0.61516 | 60.73 | No | No | 2020-04-15 | 2024-11-15 | euvd | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to by…Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. |
CVE-2025-31277 | HIGH | 8.8 | 0.01481 | 60.72 | Yes | No | 2026-03-20 | 2026-03-20 | cisa.gov, euvd | Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of mal…Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corruption. |
CVE-2021-44832 | MEDIUM | 6.6 | 0.97906 | 60.67 | No | No | 2021-12-28 | 2026-05-29 | euvd | Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution…Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2. |
CVE-2022-29517 | CRITICAL | 9.9 | 0.60199 | 60.67 | No | No | 2022-12-19 | 2025-04-15 | euvd | A directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweeper 10.1.1.0. A speci…A directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request to trigger this vulnerability. |
CVE-2020-3566 | HIGH | 8.6 | 0.03631 | 60.67 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Explo…Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash. |
CVE-2022-22675 | HIGH | 7.8 | 0.12642 | 60.62 | Yes | No | 2022-04-04 | 2022-04-04 | cisa.gov, euvd | macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privilege…macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges. |
CVE-2020-3153 | MEDIUM | 6.5 | 0.27451 | 60.61 | Yes | No | 2022-10-24 | 2022-10-24 | cisa.gov, euvd | Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on …Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. |
CVE-2021-21801 | CRITICAL | 9.6 | 0.63415 | 60.6 | No | No | 2021-07-16 | 2024-08-03 | euvd | This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially craft…This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution. |
CVE-2020-13579 | HIGH | 8.8 | 0.72559 | 60.6 | No | No | 2021-02-04 | 2024-08-04 | euvd | An exploitable integer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMaker Office 2021’s PlanMaker ap…An exploitable integer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMaker Office 2021’s PlanMaker application. A specially crafted document can cause the document parser perform arithmetic that may overflow which can result in an undersized heap allocation. Later when copying data from the file into this allocation, a heap-based buffer overflow will occur which can corrupt memory. These types of memory corruptions can allow for code execution under the context of the application. An attacker can entice the victim to open a document to trigger this vulnerability. |
CVE-2020-13580 | HIGH | 8.8 | 0.72559 | 60.6 | No | No | 2021-02-04 | 2024-08-04 | euvd | An exploitable heap-based buffer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMaker Office 2021’s Pl…An exploitable heap-based buffer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMaker Office 2021’s PlanMaker application. A specially crafted document can cause the document parser to explicitly trust a length from a particular record type and use it to write a 16-bit null relative to a buffer allocated on the stack. Due to a lack of bounds-checking on this value, this can allow an attacker to write to memory outside of the buffer and controllably corrupt memory. This can allow an attacker to earn code execution under the context of the application. An attacker can entice the victim to open a document to trigger this vulnerability. |
CVE-2023-36744 | HIGH | 8.0 | 0.81713 | 60.6 | No | No | 2023-09-12 | 2025-10-30 | euvd | Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Exchange Server Remote Code Execution Vulnerability |
CVE-2019-9515 | HIGH | 7.5 | 0.87399 | 60.59 | No | No | 2019-08-13 | 2024-08-04 | euvd | Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of S…Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both. |
CVE-2023-28502 | CRITICAL | 9.8 | 0.61102 | 60.59 | No | No | 2023-03-29 | 2025-02-18 | euvd | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from…Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "udadmin" service that can lead to remote code execution as the root user. |
CVE-2023-31446 | CRITICAL | 9.8 | 0.61081 | 60.58 | No | No | 2024-01-10 | 2025-06-20 | euvd | In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. T…In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and executing it with root privileges on device startup. |
CVE-2022-20775 | HIGH | 7.8 | 0.12475 | 60.57 | Yes | No | 2026-02-25 | 2026-02-25 | cisa.gov, euvd | Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via im…Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands within the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. |
CVE-2024-23478 | HIGH | 8.0 | 0.81588 | 60.56 | No | No | 2024-02-15 | 2024-08-12 | euvd | SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerabilit…SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service, resulting in remote code execution. |
CVE-2020-3569 | HIGH | 8.6 | 0.03293 | 60.55 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Explo…Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash. |
CVE-2025-3928 | HIGH | 8.7 | 0.02089 | 60.53 | Yes | No | 2025-04-28 | 2025-04-28 | cisa.gov, euvd | Commvault Web Server contains an unspecified vulnerability that allows a remote, authenticated attacker to create and execute webshells.Commvault Web Server contains an unspecified vulnerability that allows a remote, authenticated attacker to create and execute webshells. |
CVE-2023-3486 | HIGH | 8.2 | 0.79159 | 60.51 | No | No | 2023-07-25 | 2024-10-23 | euvd | An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbi…An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG host’s file storage. This could exhaust system resources and prevent the service from operating as expected. |
CVE-2024-0637 | HIGH | 8.8 | 0.72319 | 60.51 | No | No | 2024-04-01 | 2024-08-01 | euvd | Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary …Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability.
The specific flaw exists within the updateDirectory function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-22294. |
CVE-2022-36098 | HIGH | 8.9 | 0.71043 | 60.47 | No | No | 2022-09-08 | 2025-04-22 | euvd | XWiki Platform Mentions UI is a user interface for mentioning users in wiki content for XWiki Platform, a generic wiki platform. Starting in…XWiki Platform Mentions UI is a user interface for mentioning users in wiki content for XWiki Platform, a generic wiki platform. Starting in version 12.5-rc-1 and prior to versions 13.10.6 and 14.4, it's possible to store Javascript or groovy scripts in a mention, macro anchor, or reference field. The stored code is executed by anyone visiting the page with the mention. This issue has been patched on XWiki 14.4 and 13.10.6. As a workaround, one may update `XWiki.Mentions.MentionsMacro` and edit the `Macro code` field of the `XWiki.WikiMacroClass` XObject. |
CVE-2023-36424 | HIGH | 7.8 | 0.12184 | 60.46 | Yes | No | 2026-04-13 | 2026-04-13 | cisa.gov, euvd | Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges …Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation |
CVE-2010-3904 | HIGH | 7.8 | 0.12159 | 60.46 | Yes | No | 2023-05-12 | 2023-05-12 | cisa.gov, euvd | Linux Kernel contains an improper input validation vulnerability in the Reliable Datagram Sockets (RDS) protocol implementation that allows …Linux Kernel contains an improper input validation vulnerability in the Reliable Datagram Sockets (RDS) protocol implementation that allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls. |
CVE-2020-27871 | HIGH | 7.2 | 0.9039 | 60.44 | No | No | 2021-02-10 | 2024-08-04 | euvd | This vulnerability allows remote attackers to create arbitrary files on affected installations of SolarWinds Orion Platform 2020.2.1. Althou…This vulnerability allows remote attackers to create arbitrary files on affected installations of SolarWinds Orion Platform 2020.2.1. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within VulnerabilitySettings.aspx. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-11902. |
CVE-2023-36745 | HIGH | 8.0 | 0.81138 | 60.4 | No | No | 2023-09-12 | 2025-10-30 | euvd | Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Exchange Server Remote Code Execution Vulnerability |
CVE-2026-22200 | HIGH | 8.7 | 0.73125 | 60.39 | No | Yes | 2026-01-12 | 2026-07-14 | euvd, packetstorm | Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket P…Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing crafted rich-text HTML that includes PHP filter expressions which are insufficiently sanitized before being processed by the mPDF PDF generator during export. When the attacker exports the ticket to PDF, the generated PDF can embed the contents of attacker-selected files from the server filesystem as bitmap images, allowing disclosure of sensitive local files in the context of the osTicket application user. This issue is exploitable in default configurations where guests may create tickets and access ticket status, or where self-registration is enabled. |
CVE-2025-48543 | HIGH | 8.8 | 0.00531 | 60.39 | Yes | No | 2025-09-04 | 2025-09-04 | cisa.gov, euvd | Android Runtime contains a use-after-free vulnerability potentially allowing a chrome sandbox escape leading to local privilege escalation.Android Runtime contains a use-after-free vulnerability potentially allowing a chrome sandbox escape leading to local privilege escalation. |
CVE-2023-36033 | HIGH | 7.8 | 0.11977 | 60.39 | Yes | No | 2023-11-14 | 2023-11-14 | cisa.gov, euvd | Microsoft Windows Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.Microsoft Windows Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation. |
CVE-2023-46264 | HIGH | 7.2 | 0.9019 | 60.37 | No | No | 2023-12-19 | 2024-09-04 | euvd | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker t…An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution. |
CVE-2024-27919 | HIGH | 7.5 | 0.86746 | 60.36 | No | No | 2024-04-04 | 2025-11-04 | euvd | Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol stack is vulnerable to …Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol stack is vulnerable to the flood of CONTINUATION frames. Envoy's HTTP/2 codec does not reset a request when header map limits have been exceeded. This allows an attacker to send an sequence of CONTINUATION frames without the END_HEADERS bit set causing unlimited memory consumption. This can lead to denial of service through memory exhaustion. Users should upgrade to versions 1.29.2 to mitigate the effects of the CONTINUATION flood. Note that this vulnerability is a regression in Envoy version 1.29.0 and 1.29.1 only. As a workaround, downgrade to version 1.28.1 or earlier or disable HTTP/2 protocol for downstream connections. |
CVE-2025-40553 | CRITICAL | 9.8 | 0.6039 | 60.34 | No | No | 2026-01-28 | 2026-02-27 | euvd | SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execu…SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication. |
CVE-2022-21972 | HIGH | 8.1 | 0.79827 | 60.34 | No | No | 2022-05-10 | 2025-01-02 | euvd | Windows Point-to-Point Tunneling Protocol Remote Code Execution VulnerabilityWindows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability |
CVE-2021-30118 | CRITICAL | 9.8 | 0.60348 | 60.32 | No | No | 2021-07-09 | 2024-08-03 | euvd | An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Management (RMM) 9.5.4.…An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Management (RMM) 9.5.4.2149 and subsequently use these files to execute asp commands The api /SystemTab/uploader.aspx is vulnerable to an unauthenticated arbitrary file upload leading to RCE. An attacker can upload files with the privilege of the Web Server process and subsequently use these files to execute asp commands. Detailed description --- Given the following request: ``` POST /SystemTab/uploader.aspx?Filename=shellz.aspx&PathData=C%3A%5CKaseya%5CWebPages%5C&__RequestValidationToken=ac1906a5-d511-47e3-8500-47cc4b0ec219&qqfile=shellz.aspx HTTP/1.1 Host: 192.168.1.194 Cookie: sessionId=92812726; %5F%5FRequestValidationToken=ac1906a5%2Dd511%2D47e3%2D8500%2D47cc4b0ec219 Content-Length: 12 <%@ Page Language="C#" Debug="true" validateRequest="false" %> <%@ Import namespace="System.Web.UI.WebControls" %> <%@ Import namespace="System.Diagnostics" %> <%@ Import namespace="System.IO" %> <%@ Import namespace="System" %> <%@ Import namespace="System.Data" %> <%@ Import namespace="System.Data.SqlClient" %> <%@ Import namespace="System.Security.AccessControl" %> <%@ Import namespace="System.Security.Principal" %> <%@ Import namespace="System.Collections.Generic" %> <%@ Import namespace="System.Collections" %> <script runat="server"> private const string password = "pass"; // The password ( pass ) private const string style = "dark"; // The style ( light / dark ) protected void Page_Load(object sender, EventArgs e) { //this.Remote(password); this.Login(password); this.Style(); this.ServerInfo(); <snip> ``` The attacker can control the name of the file written via the qqfile parameter and the location of the file written via the PathData parameter. Even though the call requires that a sessionId cookie is passed we have determined that the sessionId is not actually validated and any numeric value is accepted as valid. Security issues discovered --- * a sessionId cookie is required by /SystemTab/uploader.aspx, but is not actually validated, allowing an attacker to bypass authentication * /SystemTab/uploader.aspx allows an attacker to create a file with arbitrary content in any place the webserver has write access * The web server process has write access to the webroot where the attacker can execute it by requesting the URL of the newly created file. Impact --- This arbitrary file upload allows an attacker to place files of his own choosing on any location on the hard drive of the server the webserver process has access to, including (but not limited to) the webroot. If the attacker uploads files with code to the webroot (e.g. aspx code) he can then execute this code in the context of the webserver to breach either the integrity, confidentiality, or availability of the system or to steal credentials of other users. In other words, this can lead to a full system compromise. |
CVE-2025-25256 | CRITICAL | 9.8 | 0.60344 | 60.32 | No | No | 2025-08-12 | 2026-02-26 | euvd | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSIEM v…An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSIEM version 7.3.0 through 7.3.1, 7.2.0 through 7.2.5, 7.1.0 through 7.1.7, 7.0.0 through 7.0.3 and before 6.7.9 allows an unauthenticated attacker to execute unauthorized code or commands via crafted CLI requests. |
CVE-2025-6554 | HIGH | 8.1 | 0.08322 | 60.31 | Yes | No | 2025-07-02 | 2025-07-02 | cisa.gov, euvd | Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted …Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. |
CVE-2023-29919 | CRITICAL | 9.8 | 0.60221 | 60.28 | No | No | 2023-05-23 | 2025-01-17 | euvd | SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not…SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted. |
CVE-2019-1253 | HIGH | 7.8 | 0.11616 | 60.27 | Yes | No | 2022-03-15 | 2022-03-15 | cisa.gov, euvd | A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions. |
CVE-2024-49035 | HIGH | 8.7 | 0.01339 | 60.27 | Yes | No | 2025-02-25 | 2025-02-25 | cisa.gov, euvd | Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges.Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges. |
CVE-2020-3250 | CRITICAL | 9.8 | 0.60158 | 60.26 | No | No | 2020-04-15 | 2024-11-15 | euvd | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to by…Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. |