VulnSea

CWE-74

CVEs classified under CWE-74, newest first.

439 CVEsRSS

CVE-2023-2377High· 7.2
3y ago

A vulnerability was detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6

A vulnerability was detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. The impacted element is an unknown function of the component Web Management Interface. The manipulation of the argument Name results in command injection. The at…

▾ Twilightui · er-x_firmwareEPSS 7.6%via NVD
CVE-2023-2376High· 7.2
3y ago

A security vulnerability has been detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6

A security vulnerability has been detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. The affected element is an unknown function of the component Web Management Interface. The manipulation of the argument dpi leads to command inject…

▾ Twilightui · er-x_firmwareEPSS 7.6%via NVD
CVE-2023-2375High· 7.2PoC
3y ago

A weakness has been identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6

A weakness has been identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. Impacted is an unknown function of the component Web Management Interface. Executing a manipulation of the argument src can lead to command injection. It is po…

▾ Midnightui · er-x_firmwareEPSS 9.3%via NVD
CVE-2023-2374High· 7.2
3y ago

A security flaw has been discovered in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6

A security flaw has been discovered in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This issue affects some unknown processing of the component Web Management Interface. Performing a manipulation of the argument ecn-down results in comman…

▾ Twilightui · er-x_firmwareEPSS 6.9%via NVD
CVE-2023-2373High· 7.2
3y ago

A vulnerability was identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6

A vulnerability was identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This vulnerability affects unknown code of the component Web Management Interface. Such manipulation of the argument ecn-up leads to command injection. The att…

▾ Twilightui · edgemax_edgerouter_firmwareEPSS 7.6%via NVD
CVE-2021-36668High· 7.8
4y ago

URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron App.

URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron App.

▾ Twilightdruva · insync_clientEPSS 0.58%via NVD
CVE-2022-23064High· 8.8
4y ago

snipe-IT vulnerable to host header injection

snipe-IT vulnerable to host header injection

▾ Twilightsnipe · snipe/snipe-itEPSS 1.3%via GHSA
CVE-2022-27924High· 7.5CISA KEVPoC
4y ago

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.

▾ Abyssalsynacor · zimbra_collaboration_suiteEPSS 85%via NVD
CVE-2021-36697Medium· 6.7
4y ago

With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component

With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file contains a Rewrite Rule with a type definition. A normal PHP file can be uploaded with this …

▾ Sunlitartica · pandora_fmsEPSS 0.32%via NVD
CVE-2021-35504High· 7.2
4y ago

Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the ffmpeg binary.

Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the ffmpeg binary.

▾ Twilightafian · filerunEPSS 3.2%via NVD
CVE-2021-35505High· 7.2
4y ago

Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the magick binary.

Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the magick binary.

▾ Twilightafian · filerunEPSS 2.8%via NVD
CVE-2021-40143High· 8.2
5y ago

Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection

Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vulnerable instance.

▾ Twilightsonatype · nexus_repository_managerEPSS 2.3%via NVD
CVE-2021-28979Medium· 6.5
5y ago

SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks

SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is …

▾ Sunlitthalesgroup · safenet_keysecureEPSS 1.2%via NVD
CVE-2019-25031Medium· 5.9
5y ago

Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session

Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. NOTE: The vendor does not consider this a vulnerability of the Unbound softw…

▾ Sunlitnlnetlabs · unboundEPSS 1.3%via NVD
CVE-2021-27132Critical· 9.8PoC
5y ago

SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.

SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.

▾ Abyssalsercomm · agcombo_vd625_firmwareEPSS 16%via NVD
CVE-2020-3561Medium· 4.7
5y ago

A vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to inject arbitrary HTTP headers in …

A vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to inject arbitrary HTTP headers in …

▾ Sunlitcisco · adaptive_security_applianceEPSS 1.3%via NVD
CVE-2014-5287High· 8.8PoC
6y ago

A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI).

A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI).

▾ Midnightprogress · loadmasterEPSS 8.0%via NVD
CVE-2019-11045Low· 3.7
6y ago

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in appli…

▾ Sunlitphp · phpEPSS 8.8%via NVD
CVE-2019-2725Critical· 9.8CISA KEVPoC
7y ago

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services)

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated a…

▾ Hadaloracle · agile_plmEPSS 100%via NVD
CWE-74 vulnerabilities (CVEs) — page 15 · VulnSea