CVE-2025-23211 | CRITICAL | 10.0 | 0.03524 | 41.23 | No | No | 2025-01-28 | 2025-01-28 | euvd | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any …Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any user to execute commands on the server. In the case of the provided Docker Compose file as root. This vulnerability is fixed in 1.5.24. |
CVE-2018-6667 | CRITICAL | 10.0 | 0.03523 | 41.23 | No | No | 2018-06-26 | 2024-08-05 | euvd | Authentication Bypass vulnerability in the administrative user interface in McAfee Web Gateway 7.8.1.0 through 7.8.1.5 allows remote attacke…Authentication Bypass vulnerability in the administrative user interface in McAfee Web Gateway 7.8.1.0 through 7.8.1.5 allows remote attackers to execute arbitrary code via Java management extensions (JMX). |
CVE-2021-34684 | CRITICAL | 9.8 | 0.05776 | 41.22 | No | No | 2021-11-08 | 2024-08-04 | euvd | Hitachi Vantara Pentaho Business Analytics through 9.1 allows an unauthenticated user to execute arbitrary SQL queries on any Pentaho data s…Hitachi Vantara Pentaho Business Analytics through 9.1 allows an unauthenticated user to execute arbitrary SQL queries on any Pentaho data source and thus retrieve data from the related databases, as demonstrated by an api/repos/dashboards/editor URI. |
CVE-2024-44349 | CRITICAL | 9.8 | 0.05778 | 41.22 | No | No | 2024-10-08 | 2024-10-10 | euvd | A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute arbitrary SQL commands…A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute arbitrary SQL commands via the username parameter and disclosure of some data in the underlying DB. |
CVE-2021-35049 | CRITICAL | 9.9 | 0.04615 | 41.22 | No | No | 2021-06-25 | 2024-09-16 | euvd | Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerabil…Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could allow a specially crafted HTTP request to execute system commands on the CommandPost and return results in an HTTP response in an authenticated session. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.7 and in version 9.4. Patches and updates are available to address this vulnerability. |
CVE-2021-27468 | CRITICAL | 10.0 | 0.03493 | 41.22 | No | No | 2022-03-23 | 2025-04-16 | euvd | The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication…The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements. |
CVE-2025-57201 | HIGH | 8.8 | 0.17198 | 41.22 | No | No | 2025-12-03 | 2026-07-05 | euvd | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability i…AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the SMB server function. This vulnerability allows attackers to execute arbitrary commands via a crafted input. |
CVE-2021-27464 | CRITICAL | 10.0 | 0.03481 | 41.22 | No | No | 2022-03-23 | 2025-04-16 | euvd | The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentica…The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements. |
CVE-2020-3323 | CRITICAL | 9.8 | 0.05747 | 41.21 | No | No | 2020-07-16 | 2024-11-15 | euvd | A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unaut…A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system of the affected device. |
CVE-2025-49619 | HIGH | 8.5 | 0.20593 | 41.21 | No | No | 2025-06-07 | 2025-06-17 | euvd | Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation …Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation v2 Block. Improper sanitization of Jinja2 template input allows authenticated users to inject crafted expressions that are evaluated on the server, leading to blind remote code execution (RCE). |
CVE-2024-20674 | HIGH | 8.8 | 0.17168 | 41.21 | No | No | 2024-01-09 | 2025-05-03 | euvd | Windows Kerberos Security Feature Bypass VulnerabilityWindows Kerberos Security Feature Bypass Vulnerability |
CVE-2022-1509 | CRITICAL | 9.9 | 0.04589 | 41.21 | No | No | 2022-04-28 | 2024-08-30 | euvd | Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges…Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context. |
CVE-2024-3596 | CRITICAL | 9.0 | 0.14859 | 41.2 | No | No | 2024-07-09 | 2026-06-09 | euvd | RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Acces…RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature. |
CVE-2023-1424 | CRITICAL | 10.0 | 0.0344 | 41.2 | No | No | 2023-05-24 | 2025-03-05 | euvd | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series C…Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules and MELSEC iQ-R Series CPU modules allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or execute malicious code on a target product by sending specially crafted packets. A system reset of the product is required for recovery from a denial of service (DoS) condition and malicious code execution. |
CVE-2026-25939 | CRITICAL | 9.3 | 0.11393 | 41.19 | No | No | 2026-02-09 | 2026-02-11 | euvd | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10,
an authorization bypass vulner…FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10,
an authorization bypass vulnerability in the FUXA allows an unauthenticated, remote attacker to create and modify arbitrary schedulers, exposing connected ICS/SCADA environments to follow-on actions. This has been patched in FUXA version 1.2.11. |
CVE-2022-1529 | HIGH | 8.8 | 0.17103 | 41.19 | No | No | 2022-12-22 | 2025-04-16 | euvd | An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScript object, leading t…An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScript object, leading to prototype pollution and ultimately attacker-controlled JavaScript executing in the privileged parent process. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox for Android < 100.3.0, and Thunderbird < 91.9.1. |
CVE-2022-45460 | CRITICAL | 9.8 | 0.05673 | 41.19 | No | No | 2023-03-28 | 2025-02-19 | euvd | Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.0000…Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow an unauthenticated and remote user to exploit a stack-based buffer overflow and crash the web server, resulting in a system reboot. An unauthenticated and remote attacker can execute arbitrary code by sending a crafted HTTP request that triggers the overflow condition via a long URI passed to a sprintf call. NOTE: this is different than CVE-2018-10088, but this may overlap CVE-2017-16725. |
CVE-2016-15042 | CRITICAL | 9.8 | 0.05672 | 41.19 | No | No | 2024-10-16 | 2026-04-08 | euvd | The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary f…The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_file` and `nm_postfront_upload_file` AJAX actions. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible. |
CVE-2024-7855 | HIGH | 8.8 | 0.17128 | 41.19 | No | No | 2024-10-02 | 2026-04-08 | euvd | The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review()…The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function in all versions up to, and including, 2.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. |
CVE-2025-6058 | CRITICAL | 9.8 | 0.05649 | 41.18 | No | No | 2025-07-12 | 2026-04-08 | euvd | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() f…The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_booking_type' route in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. |
CVE-2021-2302 | CRITICAL | 9.8 | 0.05667 | 41.18 | No | No | 2021-04-22 | 2024-09-26 | euvd | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: OPSS). Supported versions that are af…Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: OPSS). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). |
CVE-2020-6112 | HIGH | 8.8 | 0.17093 | 41.18 | No | No | 2020-09-17 | 2024-08-04 | euvd | An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2…An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when decoding sub-samples. While initializing tiles with sub-sample data, the application can miscalculate a pointer for the stripes in the tile which allow for the decoder to write out of-bounds and cause memory corruption. This can result in code execution. A specially crafted image can be embedded inside a PDF and loaded by a victim in order to trigger this vulnerability. |
CVE-2017-2853 | CRITICAL | 10.0 | 0.03383 | 41.18 | No | No | 2018-04-05 | 2024-09-17 | euvd | An exploitable Code Execution vulnerability exists in the RequestForPatientInfoEEGfile functionality of Natus Xltek NeuroWorks 8. A speciall…An exploitable Code Execution vulnerability exists in the RequestForPatientInfoEEGfile functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause a stack buffer overflow resulting in arbitrary command execution. An attacker can send a malicious packet to trigger this vulnerability. |
CVE-2014-9515 | CRITICAL | 9.8 | 0.05645 | 41.18 | No | No | 2017-12-29 | 2024-08-22 | euvd | Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbitrary code via a cra…Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbitrary code via a crafted serialized object. |
CVE-2022-33192 | CRITICAL | 10.0 | 0.03351 | 41.17 | No | No | 2022-10-25 | 2025-04-15 | euvd | Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9…Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability specifically focuses on the unsafe use of the `WL_SSID` and `WL_SSID_HEX` configuration values in the function at offset `0x1c7d28` of firmware 6.9Z. |
CVE-2022-32773 | CRITICAL | 10.0 | 0.03351 | 41.17 | No | No | 2022-10-25 | 2025-04-15 | euvd | An OS command injection vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and …An OS command injection vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to arbitrary command execution. An attacker can send a malicious XML payload to trigger this vulnerability. |
CVE-2022-33195 | CRITICAL | 10.0 | 0.03351 | 41.17 | No | No | 2022-10-25 | 2025-04-15 | euvd | Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9…Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability focuses on the unsafe use of the `WL_DefaultKeyID` in the function located at offset `0x1c7d28` of firmware 6.9Z, and even more specifically on the command execution occuring at offset `0x1c7fac`. |
CVE-2026-4670 | CRITICAL | 9.8 | 0.05633 | 41.17 | No | No | 2026-04-30 | 2026-05-01 | euvd | Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass.
This issue aff…Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass.
This issue affects MOVEit Automation: from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0. |
CVE-2022-1812 | HIGH | 7.6 | 0.30778 | 41.17 | No | No | 2023-01-14 | 2025-04-07 | euvd | Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10.Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10. |
CVE-2024-45256 | CRITICAL | 9.8 | 0.05635 | 41.17 | No | No | 2024-08-26 | 2024-08-26 | euvd | An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overwrite SQLite database…An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overwrite SQLite databases and bypass authentication via an unauthenticated HTTP request with a crafted parameter. This occurs in file_add in api/files/routes.py. |
CVE-2020-25066 | CRITICAL | 10.0 | 0.03348 | 41.17 | No | No | 2020-12-22 | 2024-08-04 | euvd | A heap-based buffer overflow in the Treck HTTP Server component before 6.0.1.68 allows remote attackers to cause a denial of service (crash/…A heap-based buffer overflow in the Treck HTTP Server component before 6.0.1.68 allows remote attackers to cause a denial of service (crash/reset) or to possibly execute arbitrary code. |
CVE-2021-21803 | CRITICAL | 9.6 | 0.07902 | 41.17 | No | No | 2021-07-16 | 2024-08-03 | euvd | This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially craft…This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution. |
CVE-2023-4708 | MEDIUM | 6.3 | 0.45639 | 41.17 | No | No | 2023-09-01 | 2024-10-01 | euvd | A vulnerability was found in Infosoftbd Clcknshop 1.0.0. It has been rated as critical. This issue affects some unknown processing of the fi…A vulnerability was found in Infosoftbd Clcknshop 1.0.0. It has been rated as critical. This issue affects some unknown processing of the file /collection/all of the component GET Parameter Handler. The manipulation of the argument tag leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-238571. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. |
CVE-2022-33189 | CRITICAL | 10.0 | 0.03351 | 41.17 | No | No | 2022-10-25 | 2025-04-15 | euvd | An OS command injection vulnerability exists in the XCMD setAlexa functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. A …An OS command injection vulnerability exists in the XCMD setAlexa functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. A specially-crafted XCMD can lead to arbitrary command execution. An attacker can send a malicious XML payload to trigger this vulnerability. |
CVE-2021-42338 | CRITICAL | 9.8 | 0.05628 | 41.17 | No | No | 2021-11-19 | 2024-09-17 | euvd | 4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to bypass authentication b…4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to bypass authentication by code injection in cookie, and arbitrarily manipulate the system or interrupt services by upload and execution of arbitrary files. |
CVE-2025-69985 | CRITICAL | 9.8 | 0.05633 | 41.17 | No | No | 2026-02-24 | 2026-02-25 | euvd | FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the…FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP "Referer" header to validate internal requests. A remote unauthenticated attacker can bypass JWT authentication by spoofing the Referer header to match the server's host. Successful exploitation allows the attacker to access the protected /api/runscript endpoint and execute arbitrary Node.js code on the server. |
CVE-2021-27856 | CRITICAL | 9.8 | 0.05598 | 41.16 | No | No | 2021-12-15 | 2024-09-17 | euvd | FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" that has administrat…FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" that has administrative privileges and no password. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA002. |
CVE-2025-41243 | CRITICAL | 10.0 | 0.03311 | 41.16 | No | No | 2025-09-16 | 2026-02-26 | euvd | Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification.
An application should be considered vuln…Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification.
An application should be considered vulnerable when all the following are true:
* The application is using Spring Cloud Gateway Server Webflux (Spring Cloud Gateway Server WebMVC is not vulnerable).
* Spring Boot actuator is a dependency.
* The Spring Cloud Gateway Server Webflux actuator web endpoint is enabled via management.endpoints.web.exposure.include=gateway.
* The actuator endpoints are available to attackers.
* The actuator endpoints are unsecured. |
CVE-2017-7876 | CRITICAL | 10.0 | 0.033 | 41.16 | No | No | 2017-06-15 | 2024-08-05 | euvd | This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fix…This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the issue in QTS 4.2.6 build 20170517, QTS 4.3.3.0174 build 20170503 and later versions. |
CVE-2026-28409 | CRITICAL | 10.0 | 0.03315 | 41.16 | No | No | 2026-02-27 | 2026-03-02 | euvd | WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in t…WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's database restoration functionality. An attacker with administrative access (which can be obtained via the previously reported Authentication Bypass) can execute arbitrary OS commands on the server by uploading a backup file with a specifically crafted filename. Version 3.6.5 fixes the issue. |
CVE-2025-44005 | CRITICAL | 10.0 | 0.03318 | 41.16 | No | Yes | 2025-12-17 | 2025-12-17 | euvd, packetstorm | An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain p…An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain protocol authorization checks. |
CVE-2024-1403 | CRITICAL | 10.0 | 0.033 | 41.16 | No | No | 2024-02-27 | 2024-08-12 | euvd | In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an …In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentication bypass vulnerability has been identified. The
vulnerability is a bypass to authentication based on a failure to properly
handle username and password. Certain unexpected
content passed into the credentials can lead to unauthorized access without proper
authentication. |
CVE-2025-42880 | CRITICAL | 9.9 | 0.0444 | 41.15 | No | No | 2025-12-09 | 2026-02-26 | euvd | Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enable…Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality, integrity and availability of the system. |
CVE-2020-10917 | CRITICAL | 9.8 | 0.05574 | 41.15 | No | No | 2020-07-22 | 2024-08-04 | euvd | This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.42. Authentication is…This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.42. Authentication is not required to exploit this vulnerability. The specific flaw exists within the RMI service. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10007. |
CVE-2022-30541 | CRITICAL | 10.0 | 0.03279 | 41.15 | No | No | 2022-10-25 | 2025-04-15 | euvd | An OS command injection vulnerability exists in the XCMD setUPnP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and …An OS command injection vulnerability exists in the XCMD setUPnP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to arbitrary command execution. An attacker can send a malicious XML payload to trigger this vulnerability. |
CVE-2020-35636 | CRITICAL | 10.0 | 0.03292 | 41.15 | No | No | 2021-03-04 | 2025-04-23 | euvd | A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h SNC_io_p…A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sface() sfh->volume() OOB read. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger this vulnerability. |
CVE-2023-50780 | HIGH | 8.8 | 0.16984 | 41.14 | No | No | 2024-10-14 | 2025-03-19 | euvd | Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticate…Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29.0, this also included the Log4J2 MBean. This MBean is not meant for exposure to non-administrative users. This could eventually allow an authenticated attacker to write arbitrary files to the filesystem and indirectly achieve RCE.
Users are recommended to upgrade to version 2.29.0 or later, which fixes the issue. |
CVE-2023-29301 | HIGH | 7.5 | 0.31823 | 41.14 | No | No | 2023-07-12 | 2025-03-05 | euvd | Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Restrict…Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Restriction of Excessive Authentication Attempts vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the confidentiality of the user. Exploitation of this issue does not require user interaction. |
CVE-2026-22812 | HIGH | 8.8 | 0.16973 | 41.14 | No | Yes | 2026-01-12 | 2026-01-13 | euvd, packetstorm | OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any l…OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local process (or any website via permissive CORS) to execute arbitrary shell commands with the user's privileges. This vulnerability is fixed in 1.0.216. |
CVE-2023-29827 | CRITICAL | 9.8 | 0.05552 | 41.14 | No | No | 2023-05-04 | 2025-01-29 | euvd | ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through t…ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter. NOTE: this is disputed by the vendor because the render function is not intended to be used with untrusted input. |