CVE-2024-41874 | CRITICAL | 9.8 | 0.30315 | 49.81 | No | No | 2024-09-13 | 2024-09-16 | euvd | ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbit…ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability by providing crafted input to the application, which when deserialized, leads to execution of malicious code. Exploitation of this issue does not require user interaction. |
CVE-2024-42008 | CRITICAL | 9.3 | 0.35902 | 49.77 | No | No | 2024-08-05 | 2025-03-13 | euvd | A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote att…A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header. |
CVE-2009-2055 | MEDIUM | 5.9 | 0.03326 | 49.76 | Yes | No | 2009-08-19 | 2026-01-12 | cisa.gov, euvd | Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an inval…Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009. |
CVE-2015-4000 | LOW | 3.7 | 0.9986 | 49.75 | No | No | 2015-05-21 | 2026-05-27 | euvd | The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_E…The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue. |
CVE-2024-47011 | HIGH | 7.5 | 0.56345 | 49.72 | No | No | 2024-10-08 | 2024-10-08 | euvd | Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive informationPath Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information |
CVE-2021-25370 | MEDIUM | 6.1 | 0.0089 | 49.71 | Yes | No | 2021-03-26 | 2026-01-14 | cisa.gov, euvd | An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to k…An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic. |
CVE-2024-22836 | CRITICAL | 9.8 | 0.30036 | 49.71 | No | No | 2024-02-08 | 2025-06-20 | euvd | An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing …An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to execute system commands on the hosting server. |
CVE-2025-48988 | HIGH | 7.5 | 0.56286 | 49.7 | No | No | 2025-06-16 | 2025-11-03 | cnvd, euvd | Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 throu…Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions
may also be affected.
Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue. |
CVE-2019-9516 | HIGH | 7.5 | 0.56262 | 49.69 | No | No | 2019-08-13 | 2024-08-04 | euvd | Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of head…Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and keep the allocation alive until the session dies. This can consume excess memory. |
CVE-2021-25372 | MEDIUM | 6.1 | 0.00804 | 49.68 | Yes | No | 2021-03-26 | 2026-01-14 | cisa.gov, euvd | An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access. |
CVE-2021-25371 | MEDIUM | 6.1 | 0.00802 | 49.68 | Yes | No | 2021-03-26 | 2025-10-21 | cisa.gov, euvd | A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP. |
CVE-2024-12847 | CRITICAL | 9.8 | 0.29939 | 49.68 | No | No | 2025-01-10 | 2026-04-07 | euvd | NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute …NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been observed to be exploited in the wild since at least 2017 and specifically by the Shadowserver Foundation on 2025-02-06 UTC. |
CVE-2020-10882 | HIGH | 8.8 | 0.41359 | 49.68 | No | No | 2020-03-25 | 2024-08-04 | euvd | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: …This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tdpServer service, which listens on UDP port 20002 by default. When parsing the slave_mac parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the root user. Was ZDI-CAN-9650. |
CVE-2021-31213 | HIGH | 7.8 | 0.52751 | 49.66 | No | No | 2021-05-11 | 2024-08-03 | euvd | Visual Studio Code Remote Containers Extension Remote Code Execution VulnerabilityVisual Studio Code Remote Containers Extension Remote Code Execution Vulnerability |
CVE-2024-28156 | MEDIUM | 5.4 | 0.80173 | 49.66 | No | No | 2024-03-06 | 2025-03-27 | euvd | Jenkins Build Monitor View Plugin 1.14-860.vd06ef2568b_3f and earlier does not escape Build Monitor View names, resulting in a stored cross-…Jenkins Build Monitor View Plugin 1.14-860.vd06ef2568b_3f and earlier does not escape Build Monitor View names, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure Build Monitor Views. |
CVE-2023-38124 | HIGH | 7.2 | 0.59609 | 49.66 | No | No | 2024-05-03 | 2024-08-02 | euvd | Inductive Automation Ignition OPC UA Quick Client Task Scheduling Exposed Dangerous Function Remote Code Execution Vulnerability. This vulne…Inductive Automation Ignition OPC UA Quick Client Task Scheduling Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is required to exploit this vulnerability.
The specific flaw exists within the Ignition Gateway server. The issue results from the exposure of a dangerous function. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-20541. |
CVE-2022-30129 | HIGH | 8.8 | 0.41317 | 49.66 | No | No | 2022-05-10 | 2025-01-02 | euvd | Visual Studio Code Remote Code Execution VulnerabilityVisual Studio Code Remote Code Execution Vulnerability |
CVE-2020-24435 | HIGH | 7.8 | 0.52718 | 49.65 | No | No | 2020-11-05 | 2024-09-17 | euvd | Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a hea…Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a heap-based buffer overflow vulnerability in the submitForm function, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted .pdf file in Acrobat Reader. |
CVE-2020-7357 | CRITICAL | 9.6 | 0.32094 | 49.63 | No | No | 2020-08-06 | 2024-09-17 | euvd | Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to in…Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue affects several branches and versions of the CMS application, including CME-SE, CMS-60, CMS-40, CMS-20, and CMS version 8.2, 8.0, and 7.5. |
CVE-2023-50260 | HIGH | 8.8 | 0.4116 | 49.61 | No | No | 2024-04-19 | 2024-08-02 | euvd | Wazuh is a free and open source platform used for threat prevention, detection, and response. A wrong validation in the `host_deny` script a…Wazuh is a free and open source platform used for threat prevention, detection, and response. A wrong validation in the `host_deny` script allows to write any string in the `hosts.deny` file, which can end in an arbitrary command execution on the target system. This vulnerability is part of the active response feature, which can automatically triggers actions in response to alerts. By default, active responses are limited to a set of pre defined executables. This is enforced by only allowing executables stored under `/var/ossec/active-response/bin` to be run as an active response. However, the `/var/ossec/active-response/bin/host_deny` can be exploited. `host_deny` is used to add IP address to the `/etc/hosts.deny` file to block incoming connections on a service level by using TCP wrappers. Attacker can inject arbitrary command into the `/etc/hosts.deny` file and execute arbitrary command by using the spawn directive. The active response can be triggered by writing events either to the local `execd` queue on server or to the `ar` queue which forwards the events to agents. So, it can leads to LPE on server as root and RCE on agent as root. This vulnerability is fixed in 4.7.2. |
CVE-2023-4474 | CRITICAL | 9.8 | 0.2974 | 49.61 | No | No | 2023-11-30 | 2025-12-16 | euvd | The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware…The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device. |
CVE-2023-24950 | MEDIUM | 6.5 | 0.67452 | 49.61 | No | No | 2023-05-09 | 2025-07-10 | euvd | Microsoft SharePoint Server Spoofing VulnerabilityMicrosoft SharePoint Server Spoofing Vulnerability |
CVE-2023-39367 | CRITICAL | 9.1 | 0.37678 | 49.59 | No | No | 2024-04-17 | 2025-11-04 | euvd | An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0 (in QEMU). A special…An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. |
CVE-2024-45388 | HIGH | 7.5 | 0.5585 | 49.55 | No | No | 2024-09-02 | 2024-09-03 | euvd | Hoverfly is a lightweight service virtualization/ API simulation / API mocking tool for developers and testers. The `/api/v2/simulation` POS…Hoverfly is a lightweight service virtualization/ API simulation / API mocking tool for developers and testers. The `/api/v2/simulation` POST handler allows users to create new simulation views from the contents of a user-specified file. This feature can be abused by an attacker to read arbitrary files from the Hoverfly server. Note that, although the code prevents absolute paths from being specified, an attacker can escape out of the `hf.Cfg.ResponsesBodyFilesPath` base path by using `../` segments and reach any arbitrary files. This issue was found using the Uncontrolled data used in path expression CodeQL query for python. Users are advised to make sure the final path (`filepath.Join(hf.Cfg.ResponsesBodyFilesPath, filePath)`) is contained within the expected base path (`filepath.Join(hf.Cfg.ResponsesBodyFilesPath, "/")`). This issue is also tracked as GHSL-2023-274. |
CVE-2025-53118 | CRITICAL | 9.8 | 0.2946 | 49.51 | No | No | 2025-08-25 | 2025-08-25 | euvd | An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to…An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM. |
CVE-2022-40881 | CRITICAL | 9.8 | 0.29451 | 49.51 | No | No | 2022-11-17 | 2025-04-29 | euvd | SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.phpSolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php |
CVE-2020-6074 | HIGH | 8.8 | 0.40879 | 49.51 | No | No | 2020-05-18 | 2024-08-04 | euvd | An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155. A specially crafted PDF document can cause a u…An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155. A specially crafted PDF document can cause a use-after-free which can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability. |
CVE-2024-4548 | CRITICAL | 9.8 | 0.29425 | 49.5 | No | No | 2024-05-06 | 2024-08-01 | euvd | An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, w…An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field. |
CVE-2025-20188 | CRITICAL | 10.0 | 0.27136 | 49.5 | No | No | 2025-05-07 | 2025-06-06 | euvd | A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features…A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system.
This vulnerability is due to the presence of a hard-coded JSON Web Token (JWT) on an affected system. An attacker could exploit this vulnerability by sending crafted HTTPS requests to the AP file upload interface. A successful exploit could allow the attacker to upload files, perform path traversal, and execute arbitrary commands with root privileges. |
CVE-2012-1891 | CRITICAL | 9.8 | 0.29406 | 49.49 | No | No | 2012-07-10 | 2024-10-17 | euvd | Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows r…Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote attackers to execute arbitrary code via crafted XML data that triggers access to an uninitialized object in memory, aka "ADO Cachesize Heap Overflow RCE Vulnerability." |
CVE-2023-34800 | CRITICAL | 9.8 | 0.29348 | 49.47 | No | No | 2023-06-15 | 2024-12-16 | euvd | D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main.D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main. |
CVE-2023-20032 | CRITICAL | 9.8 | 0.29314 | 49.46 | No | No | 2023-02-16 | 2024-08-02 | euvd | On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed:
A vulnerability in the HFS+ partition file p…On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed:
A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code.
This vulnerability is due to a missing buffer size check that may result in a heap buffer overflow write. An attacker could exploit this vulnerability by submitting a crafted HFS+ partition file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the ClamAV scanning process, or else crash the process, resulting in a denial of service (DoS) condition.
For a description of this vulnerability, see the ClamAV blog ["https://blog.clamav.net/"]. |
CVE-2021-42756 | CRITICAL | 9.3 | 0.34978 | 49.44 | No | No | 2023-02-16 | 2024-10-23 | euvd | Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and …Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbitrary code execution via specifically crafted HTTP requests. |
CVE-2023-2745 | MEDIUM | 5.4 | 0.79527 | 49.43 | No | No | 2023-05-17 | 2026-04-08 | euvd | WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthen…WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form, this could be also used to perform a Cross-Site Scripting attack. |
CVE-2023-33157 | HIGH | 8.8 | 0.40644 | 49.43 | No | No | 2023-07-11 | 2025-02-28 | euvd | Microsoft SharePoint Remote Code Execution VulnerabilityMicrosoft SharePoint Remote Code Execution Vulnerability |
CVE-2024-5723 | HIGH | 8.8 | 0.40669 | 49.43 | No | No | 2024-08-21 | 2024-08-21 | euvd | Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar…Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability.
The specific flaw exists within the updateServiceHost function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the apache user. Was ZDI-CAN-23294. |
CVE-2024-39907 | CRITICAL | 9.8 | 0.29183 | 49.41 | No | No | 2024-07-18 | 2024-08-02 | euvd | 1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well fil…1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. These sql injections have been resolved in version 1.10.12-tls. Users are advised to upgrade. There are no known workarounds for these issues. |
CVE-2024-46906 | HIGH | 8.8 | 0.40584 | 49.4 | No | No | 2024-12-02 | 2024-12-02 | euvd | In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Repor…In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account. |
CVE-2022-31161 | CRITICAL | 10.0 | 0.26819 | 49.39 | No | No | 2022-07-15 | 2025-04-23 | euvd | Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remot…Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Version 6.1.1.0 contains a patch for this issue. |
CVE-2025-48927 | MEDIUM | 5.3 | 0.09074 | 49.38 | Yes | No | 2025-05-28 | 2026-02-26 | cisa.gov, euvd | The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploit…The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025. |
CVE-2024-31817 | HIGH | 7.5 | 0.5534 | 49.37 | No | No | 2024-04-08 | 2024-08-02 | euvd | In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStat…In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg. |
CVE-2025-68926 | CRITICAL | 9.8 | 0.2903 | 49.36 | No | No | 2025-12-30 | 2026-01-05 | euvd | RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication usin…RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication using a hardcoded static token `"rustfs rpc"` that is publicly exposed in the source code repository, hardcoded on both client and server sides, non-configurable with no mechanism for token rotation, and universally valid across all RustFS deployments. Any attacker with network access to the gRPC port can authenticate using this publicly known token and execute privileged operations including data destruction, policy manipulation, and cluster configuration changes. Version 1.0.0-alpha.78 contains a fix for the issue. |
CVE-2021-1499 | MEDIUM | 5.3 | 0.80426 | 49.35 | No | No | 2021-05-06 | 2024-11-08 | euvd | A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to…A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to upload files to an affected device. This vulnerability is due to missing authentication for the upload function. An attacker could exploit this vulnerability by sending a specific HTTP request to an affected device. A successful exploit could allow the attacker to upload files to the affected device with the permissions of the tomcat8 user. |
CVE-2023-51364 | HIGH | 8.7 | 0.4158 | 49.35 | No | No | 2024-04-26 | 2024-08-02 | euvd | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could all…A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.4.2596 build 20231128 and later
QTS 4.5.4.2627 build 20231225 and later
QuTS hero h5.1.3.2578 build 20231110 and later
QuTS hero h4.5.4.2626 build 20231225 and later
QuTScloud c5.1.5.2651 and later |
CVE-2023-41182 | HIGH | 7.2 | 0.58622 | 49.32 | No | No | 2024-05-03 | 2024-09-18 | euvd | NETGEAR ProSAFE Network Management System ZipUtils Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote…NETGEAR ProSAFE Network Management System ZipUtils Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
The specific flaw exists within the ZipUtils class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-19716. |
CVE-2024-10525 | HIGH | 7.2 | 0.58546 | 49.29 | No | No | 2024-10-30 | 2025-11-03 | euvd | In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client …In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients. |
CVE-2025-20282 | CRITICAL | 10.0 | 0.26516 | 49.28 | No | No | 2025-06-25 | 2026-02-26 | euvd | A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files …A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root.
This vulnerability is due a lack of file validation checks that would prevent uploaded files from being placed in privileged directories on an affected system. An attacker could exploit this vulnerability by uploading a crafted file to the affected device. A successful exploit could allow the attacker to store malicious files on the affected system and then execute arbitrary code or obtain root privileges on the system. |
CVE-2021-40487 | HIGH | 8.1 | 0.48205 | 49.27 | No | No | 2021-10-13 | 2025-02-28 | euvd | Microsoft SharePoint Server Remote Code Execution VulnerabilityMicrosoft SharePoint Server Remote Code Execution Vulnerability |
CVE-2025-1128 | CRITICAL | 9.8 | 0.28766 | 49.27 | No | No | 2025-02-25 | 2026-04-08 | euvd | The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbit…The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file upload, read, and deletion due to missing file type and path validation in the 'format' method of the EVF_Form_Fields_Upload class in all versions up to, and including, 3.0.9.4. This makes it possible for unauthenticated attackers to upload, read, and delete arbitrary files on the affected site's server which may make remote code execution, sensitive information disclosure, or a site takeover possible. |
CVE-2025-34036 | CRITICAL | 10.0 | 0.26421 | 49.25 | No | No | 2025-06-24 | 2026-04-07 | euvd | An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting a custom HTTP service called "Cross Web Se…An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting a custom HTTP service called "Cross Web Server" that listens on TCP ports 81 and 82. The web interface fails to sanitize input in the URI path passed to the language extraction functionality. When the server processes a request to /language/[lang]/index.html, it uses the [lang] input unsafely in a tar extraction command without proper escaping. This allows an unauthenticated remote attacker to inject shell commands and achieve arbitrary command execution as root. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC. |