CVE-2022-41138 | CRITICAL | 9.8 | 0.01804 | 39.83 | No | No | 2022-09-20 | 2025-05-29 | euvd | In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution.In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution. |
CVE-2024-54370 | CRITICAL | 9.9 | 0.00646 | 39.83 | No | No | 2024-12-16 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member gallery-for-ultimate…Unrestricted Upload of File with Dangerous Type vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member gallery-for-ultimate-member allows Upload a Web Shell to a Web Server.This issue affects Video & Photo Gallery for Ultimate Member: from n/a through <= 1.1.0. |
CVE-2024-30500 | CRITICAL | 9.9 | 0.00643 | 39.83 | No | No | 2024-03-29 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in CubeWP CubeWP – All-in-One Dynamic Content Framework.This issue affects Cub…Unrestricted Upload of File with Dangerous Type vulnerability in CubeWP CubeWP – All-in-One Dynamic Content Framework.This issue affects CubeWP – All-in-One Dynamic Content Framework: from n/a through 1.1.12. |
CVE-2023-32095 | CRITICAL | 9.9 | 0.00655 | 39.83 | No | No | 2023-12-29 | 2026-04-28 | euvd | Improper Control of Generation of Code ('Code Injection') vulnerability in Milan Dinić Rename Media Files.This issue affects Rename Media Fi…Improper Control of Generation of Code ('Code Injection') vulnerability in Milan Dinić Rename Media Files.This issue affects Rename Media Files: from n/a through 1.0.1. |
CVE-2023-24148 | CRITICAL | 9.8 | 0.01799 | 39.83 | No | No | 2023-02-03 | 2025-03-26 | euvd | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadUserData…TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadUserData function. |
CVE-2020-25196 | CRITICAL | 9.8 | 0.01792 | 39.83 | No | No | 2020-12-23 | 2024-09-17 | euvd | The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows SSH/Telnet sessions, which may be vulnerable to bru…The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows SSH/Telnet sessions, which may be vulnerable to brute force attacks to bypass authentication. |
CVE-2024-36057 | CRITICAL | 9.8 | 0.01803 | 39.83 | No | No | 2026-04-07 | 2026-04-09 | euvd | Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code execution. The line "q…Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code execution. The line "qx/unzip $filename -d $dirname/;" in upload-cover-image.pl is vulnerable to command injection via shell metacharacters because input data can be controlled by an attacker and is directly included in a system command, i.e., an attack can occur via malicious filenames after uploading a .zip file and clicking Process Images. |
CVE-2026-22666 | HIGH | 8.6 | 0.15527 | 39.83 | No | No | 2026-04-07 | 2026-07-14 | euvd | Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_standard() function t…Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_standard() function that fails to apply forbidden string checks in whitelist mode and does not detect PHP dynamic callable syntax. Attackers with administrator privileges can inject malicious payloads through computed extrafields or other evaluation paths using PHP dynamic callable syntax to bypass validation and achieve arbitrary command execution via eval(). |
CVE-2022-3062 | MEDIUM | 6.1 | 0.44095 | 39.83 | No | No | 2022-09-26 | 2025-05-22 | euvd | The Simple File List WordPress plugin before 4.4.12 does not escape parameters before outputting them back in attributes, leading to Reflect…The Simple File List WordPress plugin before 4.4.12 does not escape parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting |
CVE-2021-4347 | CRITICAL | 9.9 | 0.00654 | 39.83 | No | No | 2023-06-07 | 2026-04-08 | euvd | The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vul…The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vulnerable to authenticated arbitrary options update. The function allows attackers (including those at customer level) to update any WordPress option in the database. Version 3.2.5 was initially released as a fix, but doesn't fully address the issue. |
CVE-2024-32514 | CRITICAL | 9.9 | 0.0065 | 39.83 | No | No | 2024-04-17 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in Poll Maker & Voting Plugin Team (InfoTheme) WP Poll Maker.This issue affect…Unrestricted Upload of File with Dangerous Type vulnerability in Poll Maker & Voting Plugin Team (InfoTheme) WP Poll Maker.This issue affects WP Poll Maker: from n/a through 3.4. |
CVE-2023-40890 | CRITICAL | 9.8 | 0.01787 | 39.83 | No | No | 2023-08-29 | 2025-11-04 | euvd | A stack-based buffer overflow vulnerability exists in the lookup_sequence function of ZBar 0.23.90. Specially crafted QR codes may lead to i…A stack-based buffer overflow vulnerability exists in the lookup_sequence function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or prepare it to be physically scanned by the vulnerable scanner. |
CVE-2021-23230 | CRITICAL | 9.9 | 0.0066 | 39.83 | No | No | 2021-06-11 | 2024-08-03 | euvd | A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command Centre Operator to mod…A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command Centre Operator to modify Command Centre databases undetected. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 versions prior to 8.30.1359 (MR3); 8.20 versions prior to 8.20.1259 (MR5); 8.10 versions prior to 8.10.1284 (MR7); version 8.00 and prior versions. |
CVE-2023-24145 | CRITICAL | 9.8 | 0.01799 | 39.83 | No | No | 2023-02-03 | 2025-03-26 | euvd | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the plugin_version parameter in the setUnloadUs…TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the plugin_version parameter in the setUnloadUserData function. |
CVE-2025-42950 | CRITICAL | 9.9 | 0.00657 | 39.83 | No | No | 2025-08-12 | 2026-02-26 | euvd | SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC…SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system. |
CVE-2023-31231 | CRITICAL | 9.9 | 0.00652 | 39.83 | No | No | 2023-12-20 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, …Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates).This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.65. |
CVE-2024-21795 | CRITICAL | 9.8 | 0.01791 | 39.83 | No | No | 2024-02-20 | 2025-11-04 | euvd | A heap-based buffer overflow vulnerability exists in the .egi parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch …A heap-based buffer overflow vulnerability exists in the .egi parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .egi file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. |
CVE-2023-27603 | CRITICAL | 9.8 | 0.01808 | 39.83 | No | No | 2023-04-10 | 2024-10-22 | euvd | In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which …In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead to a potential RCE vulnerability.
We recommend users upgrade the version of Linkis to version 1.3.2. |
CVE-2025-45986 | CRITICAL | 9.8 | 0.0179 | 39.83 | No | No | 2025-06-13 | 2025-06-13 | euvd | Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450…Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 werediscovered to contain a command injection vulnerability via the mac parameter in the bs_SetMacBlack function. |
CVE-2022-40037 | CRITICAL | 9.8 | 0.01774 | 39.82 | No | No | 2023-01-24 | 2025-04-02 | euvd | An issue discovered in Rawchen blog-ssm v1.0 allows remote attacker to escalate privileges and execute arbitrary commands via the component …An issue discovered in Rawchen blog-ssm v1.0 allows remote attacker to escalate privileges and execute arbitrary commands via the component /upFile. |
CVE-2025-23918 | CRITICAL | 9.9 | 0.00638 | 39.82 | No | No | 2025-01-22 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in Enrico Sandoli Smallerik File Browser smallerik-file-browser allows Upload …Unrestricted Upload of File with Dangerous Type vulnerability in Enrico Sandoli Smallerik File Browser smallerik-file-browser allows Upload a Web Shell to a Web Server.This issue affects Smallerik File Browser: from n/a through <= 1.1. |
CVE-2006-5024 | CRITICAL | 9.8 | 0.01785 | 39.82 | No | No | 2006-09-27 | 2025-04-03 | euvd | Multiple unspecified vulnerabilities in Paisterist Simple HTTP Scanner (sHTTPScanner) before 0.4 have unknown impact and attack vectors.Multiple unspecified vulnerabilities in Paisterist Simple HTTP Scanner (sHTTPScanner) before 0.4 have unknown impact and attack vectors. |
CVE-2023-34385 | CRITICAL | 9.9 | 0.00631 | 39.82 | No | No | 2023-12-20 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in Akshay Menariya Export Import Menus.This issue affects Export Import Menus:…Unrestricted Upload of File with Dangerous Type vulnerability in Akshay Menariya Export Import Menus.This issue affects Export Import Menus: from n/a through 1.8.0. |
CVE-2021-43310 | CRITICAL | 9.8 | 0.01771 | 39.82 | No | No | 2022-09-21 | 2025-05-27 | euvd | A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent were…A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent were being re-added to a verifier. This could lead to a remote code execution. |
CVE-2023-52182 | CRITICAL | 9.9 | 0.00627 | 39.82 | No | No | 2023-12-31 | 2026-04-28 | euvd | Deserialization of Untrusted Data vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder.This issue affects ARI Stream Quiz –…Deserialization of Untrusted Data vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder.This issue affects ARI Stream Quiz – WordPress Quizzes Builder: from n/a through 1.3.0. |
CVE-2025-24211 | CRITICAL | 9.8 | 0.01774 | 39.82 | No | No | 2025-03-31 | 2026-07-09 | euvd | This issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, …This issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory. |
CVE-2020-36195 | CRITICAL | 9.8 | 0.01765 | 39.82 | No | No | 2021-04-17 | 2024-09-16 | euvd | An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, …An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulnerability in the following versions of Multimedia Console and the Media Streaming add-on. QTS 4.3.3: Media Streaming add-on 430.1.8.10 and later QTS 4.3.6: Media Streaming add-on 430.1.8.8 and later QTS 4.4.x and later: Multimedia Console 1.3.4 and later We have also fixed this vulnerability in the following versions of QTS 4.3.3 and QTS 4.3.6, respectively: QTS 4.3.3.1624 Build 20210416 or later QTS 4.3.6.1620 Build 20210322 or later |
CVE-2026-59115 | CRITICAL | 9.9 | 0.00635 | 39.82 | No | No | 2026-08-06 | 2026-08-14 | euvd, nvd | '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. |
CVE-2023-52219 | CRITICAL | 9.9 | 0.00621 | 39.82 | No | No | 2024-01-08 | 2026-04-28 | euvd | Deserialization of Untrusted Data vulnerability in Gecka Gecka Terms Thumbnails.This issue affects Gecka Terms Thumbnails: from n/a through …Deserialization of Untrusted Data vulnerability in Gecka Gecka Terms Thumbnails.This issue affects Gecka Terms Thumbnails: from n/a through 1.1. |
CVE-2024-39864 | CRITICAL | 9.8 | 0.01772 | 39.82 | No | No | 2024-07-05 | 2025-03-19 | euvd | The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via i…The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via integration.api.port global setting) for internal portal integrations and for testing purposes. By default, the integration API service port is disabled and is considered disabled when integration.api.port is set to 0 or negative. Due to an improper initialisation logic, the integration API service would listen on a random port when its port value is set to 0 (default value). An attacker that can access the CloudStack management network could scan and find the randomised integration API service port and exploit it to perform unauthorised administrative actions and perform remote code execution on CloudStack managed hosts and result in complete compromise of the confidentiality, integrity, and availability of CloudStack managed infrastructure.
Users are recommended to restrict the network access on the CloudStack management server hosts to only essential ports. Users are recommended to upgrade to version 4.18.2.1, 4.19.0.2 or later, which addresses this issue. |
CVE-2024-8950 | CRITICAL | 9.9 | 0.00619 | 39.82 | No | No | 2024-12-25 | 2026-06-02 | euvd | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arne Informatics Piramit Automation al…Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arne Informatics Piramit Automation allows Blind SQL Injection.
This issue affects Piramit Automation: before 27.09.2024. |
CVE-2026-62893 | CRITICAL | 9.8 | 0.01784 | 39.82 | No | No | 2026-08-11 | 2026-08-14 | euvd, nvd | Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. |
CVE-2021-23543 | CRITICAL | 9.8 | 0.01762 | 39.82 | No | No | 2022-01-07 | 2024-09-16 | euvd | All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector. |
CVE-2020-10282 | CRITICAL | 9.8 | 0.01763 | 39.82 | No | No | 2020-07-03 | 2024-09-16 | euvd | The Micro Air Vehicle Link (MAVLink) protocol presents no authentication mechanism on its version 1.0 (nor authorization) whichs leads to a …The Micro Air Vehicle Link (MAVLink) protocol presents no authentication mechanism on its version 1.0 (nor authorization) whichs leads to a variety of attacks including identity spoofing, unauthorized access, PITM attacks and more. According to literature, version 2.0 optionally allows for package signing which mitigates this flaw. Another source mentions that MAVLink 2.0 only provides a simple authentication system based on HMAC. This implies that the flying system overall should add the same symmetric key into all devices of network. If not the case, this may cause a security issue, that if one of the devices and its symmetric key are compromised, the whole authentication system is not reliable. |
CVE-2021-43361 | CRITICAL | 9.9 | 0.00618 | 39.82 | No | No | 2022-09-29 | 2025-05-20 | euvd | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData HBYS allows SQL Injection.This…Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData HBYS allows SQL Injection.This issue affects HBYS: from unspecified before 1.1. |
CVE-2023-3701 | CRITICAL | 9.9 | 0.00629 | 39.82 | No | No | 2023-10-04 | 2024-09-19 | euvd | Aqua Drive, in its 2.4 version, is vulnerable to a relative path traversal vulnerability. By exploiting this vulnerability, an authenticated…Aqua Drive, in its 2.4 version, is vulnerable to a relative path traversal vulnerability. By exploiting this vulnerability, an authenticated non privileged user could access/modify stored resources of other users. It could also be possible to access and modify the source and configuration files of the cloud disk platform, affecting the integrity and availability of the entire platform. |
CVE-2022-4498 | CRITICAL | 9.8 | 0.01781 | 39.82 | No | No | 2023-01-11 | 2025-11-04 | euvd | In TP-Link routers, Archer C5 and WR710N-V1, running the latest available code, when receiving HTTP Basic Authentication the httpd service c…In TP-Link routers, Archer C5 and WR710N-V1, running the latest available code, when receiving HTTP Basic Authentication the httpd service can be sent a crafted packet that causes a heap overflow. This can result in either a DoS (by crashing the httpd process) or an arbitrary code execution. |
CVE-2024-2599 | CRITICAL | 9.9 | 0.00623 | 39.82 | No | No | 2024-03-18 | 2024-08-12 | euvd | File upload restriction evasion vulnerability in AMSS++ version 4.31. This vulnerability could allow an authenticated user to potentially ob…File upload restriction evasion vulnerability in AMSS++ version 4.31. This vulnerability could allow an authenticated user to potentially obtain RCE through webshell, compromising the entire infrastructure. |
CVE-2023-0016 | CRITICAL | 9.9 | 0.00616 | 39.82 | No | No | 2023-01-10 | 2025-04-09 | euvd | SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of this issue could lea…SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of this issue could lead to SQL injection vulnerability and could allow an attacker to access, modify, and/or delete data from the backend database. |
CVE-2025-26512 | CRITICAL | 9.9 | 0.00639 | 39.82 | No | No | 2025-03-24 | 2026-02-26 | euvd | SnapCenter versions prior to
6.0.1P1 and 6.1P1 are susceptible to a vulnerability which may allow an
authenticated SnapCenter Server user …SnapCenter versions prior to
6.0.1P1 and 6.1P1 are susceptible to a vulnerability which may allow an
authenticated SnapCenter Server user to become an admin user on a remote
system where a SnapCenter plug-in has been installed. |
CVE-2023-27849 | CRITICAL | 9.8 | 0.01782 | 39.82 | No | No | 2023-04-24 | 2025-02-04 | euvd | rails-routes-to-json v1.0.0 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.rails-routes-to-json v1.0.0 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function. |
CVE-2025-21556 | CRITICAL | 9.9 | 0.00628 | 39.82 | No | No | 2025-01-21 | 2026-02-26 | euvd | Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported vers…Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM Framework. While the vulnerability is in Oracle Agile PLM Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM Framework. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). |
CVE-2023-21803 | CRITICAL | 9.8 | 0.01765 | 39.82 | No | No | 2023-02-14 | 2025-01-01 | euvd | Windows iSCSI Discovery Service Remote Code Execution VulnerabilityWindows iSCSI Discovery Service Remote Code Execution Vulnerability |
CVE-2023-35365 | CRITICAL | 9.8 | 0.01768 | 39.82 | No | No | 2023-07-11 | 2025-01-01 | euvd | Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityWindows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
CVE-2019-9096 | CRITICAL | 9.8 | 0.01764 | 39.82 | No | No | 2020-03-11 | 2024-08-04 | euvd | An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3,…An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. Insufficient password requirements for the MGate web application may allow an attacker to gain access by brute-forcing account passwords. |
CVE-2022-4774 | CRITICAL | 9.8 | 0.01785 | 39.82 | No | No | 2023-05-15 | 2025-01-24 | euvd | The Bit Form WordPress plugin before 1.9 does not validate the file types uploaded via it's file upload form field, allowing unauthenticated…The Bit Form WordPress plugin before 1.9 does not validate the file types uploaded via it's file upload form field, allowing unauthenticated users to upload arbitrary files types such as PHP or HTML files to the server, leading to Remote Code Execution. |
CVE-2023-28408 | CRITICAL | 9.8 | 0.01776 | 39.82 | No | No | 2023-05-23 | 2025-01-17 | euvd | Directory traversal vulnerability in MW WP Form versions v4.4.2 and earlier allows a remote unauthenticated attacker to alter the website or…Directory traversal vulnerability in MW WP Form versions v4.4.2 and earlier allows a remote unauthenticated attacker to alter the website or cause a denial-of-service (DoS) condition, and obtain sensitive information depending on settings. |
CVE-2022-36950 | CRITICAL | 9.8 | 0.01766 | 39.82 | No | No | 2022-07-27 | 2024-08-03 | euvd | In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may be able to perform remote command execution through a Java classloade…In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may be able to perform remote command execution through a Java classloader manipulation. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10. |
CVE-2021-1619 | CRITICAL | 9.8 | 0.01758 | 39.82 | No | No | 2021-09-23 | 2024-11-07 | euvd | A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated,…A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass NETCONF or RESTCONF authentication and do either of the following: Install, manipulate, or delete the configuration of an affected device Cause memory corruption that results in a denial of service (DoS) on an affected device This vulnerability is due to an uninitialized variable. An attacker could exploit this vulnerability by sending a series of NETCONF or RESTCONF requests to an affected device. A successful exploit could allow the attacker to use NETCONF or RESTCONF to install, manipulate, or delete the configuration of a network device or to corrupt memory on the device, resulting a DoS. |
CVE-2019-19589 | CRITICAL | 9.8 | 0.01771 | 39.82 | No | No | 2019-12-05 | 2024-08-05 | euvd | The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid JAR archives. Note:…The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid JAR archives. Note: It has been argued that "The vulnerability reported in PDF Embedder Plugin is not valid as the plugin itself doesn't control or manage the file upload process. It only serves the uploaded PDF files and the responsibility of uploading PDF file remains with the Site owner of Wordpress installation, the upload of PDF file is managed by Wordpress core and not by PDF Embedder Plugin. Control & block of polyglot file is required to be taken care at the time of upload, not on showing the file. Moreover, the reference mentions retrieving the files from the browser cache and manually renaming it to jar for executing the file. That refers to a two step non-connected steps which has nothing to do with PDF Embedder. |