CVE-2023-39344 | CRITICAL | 10.0 | 0.01512 | 40.53 | No | No | 2023-08-04 | 2024-10-04 | euvd | social-media-skeleton is an uncompleted social media project. A SQL injection vulnerability in the project allows UNION based injections, wh…social-media-skeleton is an uncompleted social media project. A SQL injection vulnerability in the project allows UNION based injections, which indirectly leads to remote code execution. Commit 3cabdd35c3d874608883c9eaf9bf69b2014d25c1 contains a fix for this issue. |
CVE-2022-29130 | CRITICAL | 9.8 | 0.03805 | 40.53 | No | No | 2022-05-10 | 2025-01-02 | euvd | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityWindows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability |
CVE-2020-14859 | CRITICAL | 9.8 | 0.03797 | 40.53 | No | No | 2020-10-21 | 2024-09-26 | euvd | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are …Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). |
CVE-2021-2075 | CRITICAL | 9.8 | 0.03804 | 40.53 | No | No | 2021-01-20 | 2024-09-26 | euvd | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples). Supported versions that are affected a…Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). |
CVE-2021-27646 | CRITICAL | 9.8 | 0.03786 | 40.53 | No | No | 2021-03-12 | 2024-09-16 | euvd | Use After Free vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers …Use After Free vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via crafted web requests. |
CVE-2024-43918 | CRITICAL | 10.0 | 0.01474 | 40.52 | No | No | 2024-08-29 | 2026-04-28 | euvd | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW WBW Product Table PRO allows SQL I…Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW WBW Product Table PRO allows SQL Injection.This issue affects WBW Product Table PRO: from n/a through 1.9.4. |
CVE-2023-23596 | HIGH | 8.8 | 0.15198 | 40.52 | No | No | 2023-01-20 | 2025-04-03 | euvd | jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with …jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted username and/or password input that is concatenated without any validation, and is directly passed to the exec command, potentially allowing an authenticated attacker to execute arbitrary commands on the system. NOTE: this is not part of any NGINX software shipped by F5. |
CVE-2017-2890 | CRITICAL | 9.9 | 0.02631 | 40.52 | No | No | 2017-11-07 | 2024-09-16 | euvd | An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.1. Specially crafted…An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause an OS command injection. An attacker can send an HTTP request trigger this vulnerability. |
CVE-2019-19230 | CRITICAL | 9.8 | 0.03761 | 40.52 | No | No | 2019-12-09 | 2024-09-17 | euvd | An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remot…An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code. |
CVE-2024-0939 | MEDIUM | 6.3 | 0.43777 | 40.52 | No | No | 2024-01-26 | 2025-05-29 | euvd | A vulnerability has been found in Byzoro Smart S210 Management Platform up to 20240117 and classified as critical. This vulnerability affect…A vulnerability has been found in Byzoro Smart S210 Management Platform up to 20240117 and classified as critical. This vulnerability affects unknown code of the file /Tool/uploadfile.php. The manipulation of the argument file_upload leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252184. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. |
CVE-2024-49668 | CRITICAL | 10.0 | 0.01499 | 40.52 | No | No | 2024-10-23 | 2026-05-11 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in christopherdewese1099 Verbalize WP verbalize-wp allows Upload a Web Shell t…Unrestricted Upload of File with Dangerous Type vulnerability in christopherdewese1099 Verbalize WP verbalize-wp allows Upload a Web Shell to a Web Server.This issue affects Verbalize WP: from n/a through <= 1.0. |
CVE-2024-2912 | CRITICAL | 10.0 | 0.01497 | 40.52 | No | No | 2024-04-16 | 2024-08-01 | euvd | An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sending a specially craft…An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sending a specially crafted POST request. By exploiting this vulnerability, attackers can execute arbitrary commands on the server hosting the BentoML application. The vulnerability is triggered when a serialized object, crafted to execute OS commands upon deserialization, is sent to any valid BentoML endpoint. This issue poses a significant security risk, enabling attackers to compromise the server and potentially gain unauthorized access or control. |
CVE-2021-34458 | CRITICAL | 9.9 | 0.02625 | 40.52 | No | No | 2021-07-16 | 2026-08-10 | euvd, nvd | Windows Kernel Remote Code Execution VulnerabilityWindows Kernel Remote Code Execution Vulnerability |
CVE-2018-0037 | CRITICAL | 9.8 | 0.03769 | 40.52 | No | No | 2018-07-11 | 2024-09-16 | euvd | Junos OS routing protocol daemon (RPD) process may crash and restart or may lead to remote code execution while processing specific BGP NOTI…Junos OS routing protocol daemon (RPD) process may crash and restart or may lead to remote code execution while processing specific BGP NOTIFICATION messages. By continuously sending crafted BGP NOTIFICATION messages, an attacker can repeatedly crash the RPD process causing a sustained Denial of Service. Due to design improvements, this issue does not affect Junos OS 16.1R1, and all subsequent releases. This issue only affects the receiving BGP device and is non-transitive in nature. Affected releases are Juniper Networks Junos OS: 15.1F5 versions starting from 15.1F5-S7 and all subsequent releases; 15.1F6 versions starting from 15.1F6-S3 and later releases prior to 15.1F6-S10; 15.1F7 versions 15.1 versions starting from 15.1R5 and later releases, including the Service Releases based on 15.1R5 and on 15.1R6 prior to 15.1R6-S6 and 15.1R7; |
CVE-2022-31481 | CRITICAL | 10.0 | 0.015 | 40.52 | No | No | 2022-06-06 | 2024-09-16 | euvd | An unauthenticated attacker can send a specially crafted update file to the device that can overflow a buffer. This vulnerability impacts pr…An unauthenticated attacker can send a specially crafted update file to the device that can overflow a buffer. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.302 for the LP series and 1.296 for the EP series. The overflowed data can allow the attacker to manipulate the “normal” code execution to that of their choosing. An attacker with this level of access on the device can monitor all communications sent to and from this device, modify onboard relays, change configuration files, or cause the device to become unstable. |
CVE-2018-1567 | CRITICAL | 9.8 | 0.0376 | 40.52 | No | No | 2018-09-07 | 2024-09-16 | euvd | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through the SOAP connect…IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through the SOAP connector with a serialized object from untrusted sources. IBM X-Force ID: 143024. |
CVE-2021-26867 | CRITICAL | 9.9 | 0.0262 | 40.52 | No | No | 2021-03-11 | 2024-08-03 | euvd | Windows Hyper-V Remote Code Execution VulnerabilityWindows Hyper-V Remote Code Execution Vulnerability |
CVE-2021-21244 | CRITICAL | 10.0 | 0.01494 | 40.52 | No | No | 2021-01-15 | 2024-08-03 | euvd | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template…OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template injection via Bean validation message tampering. Full details in the reference GHSA. This issue was fixed in 4.0.3 by disabling validation interpolation completely. |
CVE-2014-125124 | CRITICAL | 10.0 | 0.0148 | 40.52 | No | No | 2025-07-31 | 2026-05-15 | euvd | An unauthenticated remote command execution vulnerability exists in Pandora FMS versions up to and including 5.0RC1 via the Anyterm web inte…An unauthenticated remote command execution vulnerability exists in Pandora FMS versions up to and including 5.0RC1 via the Anyterm web interface, which listens on TCP port 8023. The anyterm-module endpoint accepts unsanitized user input via the p parameter and directly injects it into a shell command, allowing arbitrary command execution as the pandora user. In certain versions (notably 4.1 and 5.0RC1), the pandora user can elevate privileges to root without a password using a chain involving the artica user account. This account is typically installed without a password and is configured to run sudo without authentication. Therefore, full system compromise is possible without any credentials. |
CVE-2023-25813 | CRITICAL | 10.0 | 0.01444 | 40.51 | No | No | 2023-02-22 | 2025-03-10 | euvd | Sequelize is a Node.js ORM tool. In versions prior to 6.19.1 a SQL injection exploit exists related to replacements. Parameters which are pa…Sequelize is a Node.js ORM tool. In versions prior to 6.19.1 a SQL injection exploit exists related to replacements. Parameters which are passed through replacements are not properly escaped which can lead to arbitrary SQL injection depending on the specific queries in use. The issue has been fixed in Sequelize 6.19.1. Users are advised to upgrade. Users unable to upgrade should not use the `replacements` and the `where` option in the same query. |
CVE-2025-71211 | CRITICAL | 9.8 | 0.03754 | 40.51 | No | No | 2026-05-21 | 2026-05-21 | euvd, nvd | A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands o…A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is similar in scope to CVE-2025-71210 but affects a different executable.
Please note: although this vulnerability carries a technical critical CVSS rating, this was reported via responsible disclosure via a researcher through the Zero Day Initiative. The SaaS versions of the product have already been mitigated and no customer action required.
For this particular vulnerability, an attacker must have access to the Trend Micro Apex One Management Console, so customers that have their console�s IP address exposed externally should consider mitigating factors such as source restrictions if not already applied. |
CVE-2024-51788 | CRITICAL | 10.0 | 0.01457 | 40.51 | No | No | 2024-11-11 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in Joshua Wolfe The Novel Design Store Directory noveldesign-store-directory a…Unrestricted Upload of File with Dangerous Type vulnerability in Joshua Wolfe The Novel Design Store Directory noveldesign-store-directory allows Upload a Web Shell to a Web Server.This issue affects The Novel Design Store Directory: from n/a through <= 4.3.0. |
CVE-2018-16228 | CRITICAL | 9.8 | 0.03739 | 40.51 | No | No | 2019-10-03 | 2025-12-03 | euvd | The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix().The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix(). |
CVE-2024-44411 | CRITICAL | 9.8 | 0.03742 | 40.51 | No | No | 2024-09-09 | 2024-09-10 | euvd | D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function. |
CVE-2013-10070 | CRITICAL | 10.0 | 0.01454 | 40.51 | No | No | 2025-08-05 | 2026-04-07 | euvd | PHP-Charts v1.0 contains a PHP code execution vulnerability in wizard/url.php, where user-supplied GET parameter names are passed directly t…PHP-Charts v1.0 contains a PHP code execution vulnerability in wizard/url.php, where user-supplied GET parameter names are passed directly to eval() without sanitization. A remote attacker can exploit this flaw by crafting a request that injects arbitrary PHP code, resulting in command execution under the web server's context. The vulnerability allows unauthenticated attackers to execute system-level commands via base64-encoded payloads embedded in parameter names, leading to full compromise of the host system. |
CVE-2025-47166 | HIGH | 8.8 | 0.15181 | 40.51 | No | No | 2025-06-10 | 2026-02-26 | euvd | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
CVE-2021-22859 | CRITICAL | 9.8 | 0.03751 | 40.51 | No | No | 2021-03-17 | 2024-09-16 | euvd | The users’ data querying function of EIC e-document system does not filter the special characters which resulted in remote attackers can inj…The users’ data querying function of EIC e-document system does not filter the special characters which resulted in remote attackers can inject SQL syntax and execute arbitrary commands without privilege. |
CVE-2023-48842 | CRITICAL | 9.8 | 0.03745 | 40.51 | No | No | 2023-12-01 | 2025-06-03 | euvd | D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at hedwig.cgi.D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at hedwig.cgi. |
CVE-2026-45087 | CRITICAL | 10.0 | 0.01471 | 40.51 | No | Yes | 2026-05-27 | 2026-05-28 | euvd, packetstorm | Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server m…Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalfox server), the server binds to 0.0.0.0:6664 by default and requires no API key unless the operator explicitly passes --api-key. Because model.Options — including FoundAction and FoundActionShell — is deserialized directly from attacker-supplied JSON in POST /scan, and because dalfox.Initialize explicitly propagates those two fields into the final scan options without stripping them, any unauthenticated caller who can reach the server port can supply an arbitrary shell command that the dalfox process will execute on the host whenever a scan finding is triggered. This vulnerability is fixed in 2.13.0. |
CVE-2023-3049 | CRITICAL | 9.8 | 0.03741 | 40.51 | No | No | 2023-06-13 | 2026-05-22 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in TMT Lockcell allows Command Injection.
This issue affects Lockcell: before…Unrestricted Upload of File with Dangerous Type vulnerability in TMT Lockcell allows Command Injection.
This issue affects Lockcell: before 15. |
CVE-2019-5162 | CRITICAL | 9.9 | 0.0259 | 40.51 | No | No | 2020-02-25 | 2024-08-04 | euvd | An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware ver…An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as that user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability. |
CVE-2023-0224 | CRITICAL | 9.8 | 0.03742 | 40.51 | No | No | 2024-01-16 | 2025-06-13 | euvd | The GiveWP WordPress plugin before 2.24.1 does not properly escape user input before it reaches SQL queries, which could let unauthenticated…The GiveWP WordPress plugin before 2.24.1 does not properly escape user input before it reaches SQL queries, which could let unauthenticated attackers perform SQL Injection attacks |
CVE-2024-6385 | CRITICAL | 9.6 | 0.06036 | 40.51 | No | No | 2024-07-11 | 2024-09-18 | euvd | An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and …An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances. |
CVE-2024-5488 | CRITICAL | 9.8 | 0.03744 | 40.51 | No | No | 2024-07-09 | 2024-08-01 | euvd | The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injectio…The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, compromising the site if a suitable chain is present. |
CVE-2024-31981 | CRITICAL | 10.0 | 0.01447 | 40.51 | No | No | 2024-04-10 | 2024-08-13 | euvd | XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, remote code exec…XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, remote code execution is possible via PDF export templates. This vulnerability has been patched in XWiki 14.10.20, 15.5.4 and 15.10-rc-1. If PDF templates are not typically used on the instance, an administrator can create the document `XWiki.PDFClass` and block its edition, after making sure that it does not contain a `style` attribute. Otherwise, there are no known workarounds aside from upgrading. |
CVE-2024-31983 | CRITICAL | 10.0 | 0.01447 | 40.51 | No | No | 2024-04-10 | 2024-08-13 | euvd | XWiki Platform is a generic wiki platform. In multilingual wikis, translations can be edited by any user who has edit right, circumventing t…XWiki Platform is a generic wiki platform. In multilingual wikis, translations can be edited by any user who has edit right, circumventing the rights that are normally required for authoring translations (script right for user-scope translations, wiki admin for translations on the wiki). Starting in version 4.3-milestone-2 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, this can be exploited for remote code execution if the translation value is not properly escaped where it is used. This has been patched in XWiki 14.10.20, 15.5.4 and 15.10RC1. As a workaround, one may restrict edit rights on documents that contain translations. |
CVE-2024-31987 | CRITICAL | 10.0 | 0.01447 | 40.51 | No | No | 2024-04-10 | 2024-08-20 | euvd | XWiki Platform is a generic wiki platform. Starting in version 6.4-milestone-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, any us…XWiki Platform is a generic wiki platform. Starting in version 6.4-milestone-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, any user who can edit any page like their profile can create a custom skin with a template override that is executed with programming right, thus allowing remote code execution. This has been patched in XWiki 14.10.19, 15.5.4 and 15.10RC1. No known workarounds are available except for upgrading. |
CVE-2023-1523 | CRITICAL | 10.0 | 0.01447 | 40.51 | No | No | 2023-09-01 | 2024-10-01 | euvd | Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to…Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary commands to be executed outside of the snap sandbox after the snap exits. Graphical terminal emulators like xterm, gnome-terminal and others are not affected - this can only be exploited when snaps are run on a virtual console. |
CVE-2023-43373 | CRITICAL | 9.8 | 0.03753 | 40.51 | No | No | 2023-09-20 | 2024-09-24 | euvd | Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php…Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php. |
CVE-2022-43109 | CRITICAL | 9.8 | 0.03735 | 40.51 | No | No | 2022-11-03 | 2025-05-05 | euvd | D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerabili…D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via a crafted packet. |
CVE-2022-29823 | CRITICAL | 10.0 | 0.01451 | 40.51 | No | No | 2022-10-25 | 2025-03-11 | euvd | Feather-Sequalize cleanQuery method uses insecure recursive logic to filter unsupported keys from the query object. This results in a Remote…Feather-Sequalize cleanQuery method uses insecure recursive logic to filter unsupported keys from the query object. This results in a Remote Code Execution (RCE) with privileges of application. |
CVE-2022-24665 | CRITICAL | 9.9 | 0.026 | 40.51 | No | No | 2022-02-16 | 2025-01-31 | euvd | PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via a WordPress gutenberg block by any user able …PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via a WordPress gutenberg block by any user able to edit posts. |
CVE-2020-26867 | CRITICAL | 9.8 | 0.03721 | 40.5 | No | No | 2020-10-12 | 2024-09-16 | euvd, nvd | ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to r…ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server. |
CVE-2024-39608 | CRITICAL | 10.0 | 0.01421 | 40.5 | No | No | 2025-01-14 | 2025-01-14 | euvd | A firmware update vulnerability exists in the login.cgi functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request…A firmware update vulnerability exists in the login.cgi functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary firmware update. An attacker can send an unauthenticated message to trigger this vulnerability. |
CVE-2026-22778 | CRITICAL | 9.8 | 0.03723 | 40.5 | No | No | 2026-02-02 | 2026-07-15 | euvd | vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM…vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a heap address. With this leak, we reduce ASLR from 4 billion guesses to ~8 guesses. This vulnerability can be chained a heap overflow with JPEG2000 decoder in OpenCV/FFmpeg to achieve remote code execution. This vulnerability is fixed in 0.14.1. |
CVE-2021-25914 | CRITICAL | 9.8 | 0.03702 | 40.5 | No | No | 2021-03-01 | 2025-04-30 | euvd | Prototype pollution vulnerability in 'object-collider' versions 1.0.0 through 1.0.3 allows attacker to cause a denial of service and may lea…Prototype pollution vulnerability in 'object-collider' versions 1.0.0 through 1.0.3 allows attacker to cause a denial of service and may lead to remote code execution. |
CVE-2022-36010 | CRITICAL | 10.0 | 0.01421 | 40.5 | No | No | 2022-08-15 | 2025-04-22 | euvd | This library allows strings to be parsed as functions and stored as a specialized component, [`JsonFunctionValue`](https://github.com/oxyno-…This library allows strings to be parsed as functions and stored as a specialized component, [`JsonFunctionValue`](https://github.com/oxyno-zeta/react-editable-json-tree/blob/09a0ca97835b0834ad054563e2fddc6f22bc5d8c/src/components/JsonFunctionValue.js). To do this, Javascript's [`eval`](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/eval) function is used to execute strings that begin with "function" as Javascript. This unfortunately could allow arbitrary code to be executed if it exists as a value within the JSON structure being displayed. Given that this component may often be used to display data from arbitrary, untrusted sources, this is extremely dangerous. One important note is that users who have defined a custom [`onSubmitValueParser`](https://github.com/oxyno-zeta/react-editable-json-tree/tree/09a0ca97835b0834ad054563e2fddc6f22bc5d8c#onsubmitvalueparser) callback prop on the [`JsonTree`](https://github.com/oxyno-zeta/react-editable-json-tree/blob/09a0ca97835b0834ad054563e2fddc6f22bc5d8c/src/JsonTree.js) component should be ***unaffected***. This vulnerability exists in the default `onSubmitValueParser` prop which calls [`parse`](https://github.com/oxyno-zeta/react-editable-json-tree/blob/master/src/utils/parse.js#L30). Prop is added to `JsonTree` called `allowFunctionEvaluation`. This prop will be set to `true` in v2.2.2, which allows upgrade without losing backwards-compatibility. In v2.2.2, we switched from using `eval` to using [`Function`](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Function) to construct anonymous functions. This is better than `eval` for the following reasons: - Arbitrary code should not be able to execute immediately, since the `Function` constructor explicitly *only creates* anonymous functions - Functions are created without local closures, so they only have access to the global scope If you use: - **Version `<2.2.2`**, you must upgrade as soon as possible. - **Version `^2.2.2`**, you must explicitly set `JsonTree`'s `allowFunctionEvaluation` prop to `false` to fully mitigate this vulnerability. - **Version `>=3.0.0`**, `allowFunctionEvaluation` is already set to `false` by default, so no further steps are necessary. |
CVE-2020-6072 | CRITICAL | 9.8 | 0.03727 | 40.5 | No | No | 2020-03-24 | 2024-08-04 | euvd | An exploitable code execution vulnerability exists in the label-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compresse…An exploitable code execution vulnerability exists in the label-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels in mDNS messages, the rr_decode function's return value is not checked, leading to a double free that could be exploited to execute arbitrary code. An attacker can send an mDNS message to trigger this vulnerability. |
CVE-2021-44453 | CRITICAL | 10.0 | 0.01421 | 40.5 | No | No | 2021-12-23 | 2024-09-17 | euvd | mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inje…mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands. |
CVE-2024-3234 | CRITICAL | 9.8 | 0.03726 | 40.5 | No | No | 2024-06-06 | 2024-08-01 | euvd | The gaizhenbiao/chuanhuchatgpt application is vulnerable to a path traversal attack due to its use of an outdated gradio component. The appl…The gaizhenbiao/chuanhuchatgpt application is vulnerable to a path traversal attack due to its use of an outdated gradio component. The application is designed to restrict user access to resources within the `web_assets` folder. However, the outdated version of gradio it employs is susceptible to path traversal, as identified in CVE-2023-51449. This vulnerability allows unauthorized users to bypass the intended restrictions and access sensitive files, such as `config.json`, which contains API keys. The issue affects the latest version of chuanhuchatgpt prior to the fixed version released on 20240305. |