Unknown · CVSS Not scored
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored).
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmlist?folder= (reflected).
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentdelete?file=/.. for file deletion.
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /planprop?id= (reflected).
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored).
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via the Mailbox name (stored).
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
NCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion.
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored).
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Amazon Echo Dot devices through 2021-07-02 sometimes allow attackers, who have physical access to a device after a factory reset, to obtain sensitive information via a series of complex hardware and software attacks. NOTE: reportedly, there were vendor marketing statements about safely removing personal content via a factory reset. Also, the vendor has reportedly indicated that they are working on mitigations.
Published Jul 24, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored).
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configuration files.
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
wolfSSL 4.6.x through 4.7.x before 4.8.0 does not produce a failure outcome when the serial number in an OCSP request differs from the serial number in the OCSP response.
Published Jul 21, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentprop?file=/.. for file reading.
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In NCH Quorum v2.03 and earlier, XSS exists via User Display Name (stored).
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In RPCMS v1.8 and below, the "nickname" variable is not properly sanitized before being displayed on page. Attacker can use "update password" function to inject XSS payloads into nickname variable, and achieve stored XSS. Users who view the articles published by the injected user will trigger the XSS.
Published Jul 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the outbound dialing plan (stored).
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to code execution if a ZIP element's pathname is set to a Windows startup folder, a file for the inbuilt Out-Going Message function, or a file for the the inbuilt Autodial function.
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
NCH Axon PBX v2.22 and earlier allows path traversal for file deletion via the logdelete?file=/.. substring.
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
NCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/.. substring.
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
NCH FlexiServer v6.00 suffers from a syslog?file=/.. path traversal vulnerability.
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/.. to read files.
Published Jul 25, 2021 · Updated Aug 4, 2024
Critical · CVSS 9.8
RCE (Remote Code Execution) vulnerability was found in some Furukawa ONU models, this vulnerability allows remote unauthenticated users to send arbitrary commands to the device via web interface.
Published Jul 17, 2023 · Updated Aug 4, 2024
Unknown · CVSS Not scored
hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED state, leading to a use-after-free and a double free.
Published Jul 21, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In RPCMS v1.8 and below, the "nickname" variable is not properly sanitized before being displayed on page. When the API functions are enabled, the attacker can use API to update user nickname with XSS payload and achieve stored XSS. Users who view the articles published by the injected user will trigger the XSS.
Published Jul 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In RPCMS v1.8 and below, attackers can interact with API and change variable "role" to "admin" to achieve admin user registration.
Published Jul 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.
Published Jul 21, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user input might affect portions of or the whole affected parameter, which represents the path of the file to remove, without sufficient sanitization.
Published Jul 29, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
matio (aka MAT File I/O Library) 1.5.20 and 1.5.21 has a heap-based buffer overflow in H5MM_memcpy (called from H5MM_malloc and H5C_load_entry), related to use of HDF5 1.12.0.
Published Jul 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Unicorn Engine 1.0.2 has an out-of-bounds write in tb_flush_armeb (called from cpu_arm_exec_armeb and tcg_cpu_exec_armeb).
Published Jul 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
replay-sorcery-kms in Replay Sorcery 0.6.0 allows a local attacker to gain root privileges via a symlink attack on /tmp/replay-sorcery or /tmp/replay-sorcery/device.sock.
Published Jul 28, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Victron Energy Venus OS through 2.72, root access is granted by default to anyone with physical access to the device. NOTE: the vendor disagrees with the reporter's opinion about an alleged "security best practices" violation
Published Jul 19, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Nightscout Web Monitor (aka cgm-remote-monitor) 14.2.2 allows XSS via a crafted X-Forwarded-For header.
Published Jul 15, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Blackboard Learn through 9.1 allows XSS by an authenticated user via the Feedback to Learner form.
Published Jul 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
sharkdp BAT before 0.18.2 executes less.exe from the current working directory.
Published Jul 15, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A ReDoS (regular expression denial of service) flaw was found in the Segment is-email package before 1.0.1 for Node.js. An attacker that is able to provide crafted input to the isEmail(input) function may cause an application to consume an excessive amount of CPU.
Published Jul 14, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
KNX ETS5 through 5.7.6 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Published Jul 19, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of service (unbounded recursion that can trigger memory consumption and a loss of all blocking functionality).
Published Jul 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Concrete5 through 8.5.5 deserializes Untrusted Data. The vulnerable code is located within the controllers/single_page/dashboard/system/environment/logging.php Logging::update_logging() method. User input passed through the logFile request parameter is not properly sanitized before being used in a call to the file_exists() PHP function. This can be exploited by malicious users to inject arbitrary PHP objects into the application scope (PHP Object Injection via phar:// stream wrapper), allowing them to carry out a variety of attacks, such as executing arbitrary PHP code.
Published Jul 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zoho ManageEngine ADManager Plus before 7110 allows reflected XSS.
Published Jul 17, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zoho ManageEngine ADManager Plus before 7110 allows stored XSS.
Published Jul 17, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Blackboard Learn through 9.1 allows XSS by an authenticated user via the Assignment Instructions HTML editor.
Published Jul 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access tokens that can be used to perform privilege escalation. Malicious users authorized to create Secrets Automation access tokens can create tokens that have access beyond what the user is authorized to access, but limited to the existing authorizations of the Secret Automation the token is created in.
Published Jul 15, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A reordering issue exists in Telegram before 7.8.1 for Android, Telegram before 7.8.3 for iOS, and Telegram Desktop before 2.8.8. An attacker can cause the server to receive messages in a different order than they were sent a client.
Published Jul 16, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x and 6.x before 6.5.2, 6.6.x before 6.6.1, and 6.0 LTS before 6.0.8.
Published Jul 14, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE 65535) that causes an out-of-bounds exception.
Published Jul 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled.
Published Jul 16, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Sourcecodester Phone Shop Sales Managements System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
Published Jul 29, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Sourcecodester Online Covid Vaccination Scheduler System 1.0 is vulnerable to SQL Injection. The username parameter is vulnerable to time-based SQL injection. Upon successful dumping the admin password hash, an attacker can decrypt and obtain the plain-text password. Hence, the attacker could authenticate as Administrator.
Published Jul 29, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
engineercms 1.03 is vulnerable to Cross Site Scripting (XSS). There is no escaping in the nickname field on the user list page. When viewing this page, the JavaScript code will be executed in the user's browser.
Published Jul 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The CheckMK management web console (versions 1.5.0 to 2.0.0) does not sanitise user input in various parameters of the WATO module. This allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as JavaScript or other client-side scripts), the XSS payload will be triggered when the user accesses some specific sections of the application. In the same sense a very dangerous potential way would be when an attacker who has the monitor role (not administrator) manages to get a stored XSS to steal the secretAutomation (for the use of the API in administrator mode) and thus be able to create another administrator user who has high privileges on the CheckMK monitoring web console. Another way is that persistent XSS allows an attacker to modify the displayed content or change the victim's information. Successful exploitation requires access to the web management interface, either with valid credentials or with a hijacked session.
Published Jul 26, 2021 · Updated Aug 4, 2024