Critical-severity advisories
60 alerts in this category.
CVEs and security advisories rated CRITICAL — exploitation is trivial or already observed in the wild and impact is severe. These are the alerts that get prioritized first in any sane vulnerability-management program.
DSA-6485-1 tryton-server - security update
https://security-tracker.debian.org/tracker/DSA-6485-1
DebianCritical Vulnerability: CVE-2021-3193 — nagios — nagios_xi
Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated attacker to execute remote code as the apache user.
nagiosCVE-2021-3193Critical Vulnerability: CVE-2021-3190 — async-git_project — async-git
The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag.
async-git_projectCVE-2021-3190Critical Vulnerability: CVE-2020-35270 — student_result_management_system_project — student_result_management_system
Student Result Management System In PHP With Source Code is affected by SQL injection. An attacker can able to access of Admin Panel and manage every account of Result.
student_result_management_system_projectCVE-2020-35270Critical Vulnerability: CVE-2020-27583 — ibm — infosphere_information_server
IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unauthenticated attackers to execute arbitrary code. NOTE: This vulnerability only a
ibmCVE-2020-27583Critical Vulnerability: CVE-2020-20269 — caret — caret
A specially crafted Markdown document could cause the execution of malicious JavaScript code in Caret Editor before 4.0.0-rc22.
caretCVE-2020-20269Critical Vulnerability: CVE-2021-3325 — fibranet, fedoraproject — monitorix, fedora
Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option). This issue occurred because a new access-control
fibranetCVE-2021-3325Critical Vulnerability: CVE-2020-28221 — schneider-electric — ecostruxure_operator_terminal_expert, hmi_sto_501
A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when
schneider-electricCVE-2020-28221Critical Vulnerability: CVE-2020-23448 — newbee-mall_project — newbee-mall
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginInterceptor.java. The authentication logic of the system's background /admin is in code
newbee-mall_projectCVE-2020-23448Critical Vulnerability: CVE-2020-27539 — company — cs-c2shw_firmware, cs-c2shw
Heap overflow with full parsing of HTTP respose in Rostelecom CS-C2SHW 5.0.082.1. AgentUpdater service has a self-written HTTP parser and builder. HTTP parser has a heap buffer overflow (OOB write). I
companyCVE-2020-27539Critical Vulnerability: CVE-2020-6779 — bosch — fsm-2500_firmware, fsm-2500
Use of Hard-coded Credentials in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows an unauthenticated remote attacker to log into the database with
boschCVE-2020-6779Critical Vulnerability: CVE-2021-25905 — bra_project — bra
An issue was discovered in the bra crate before 0.1.1 for Rust. It lacks soundness because it can read uninitialized memory.
bra_projectCVE-2021-25905Critical Vulnerability: CVE-2021-3278 — local_services_search_engine_management_system_project — local_services_search_engine_management_system
Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection . Using this vulnerability, an attacker can bypass the login page.
local_services_search_engine_management_system_projectCVE-2021-3278Critical Vulnerability: CVE-2021-23901 — apache, netapp — nutch, snap_creator_framework
An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web sec
apacheCVE-2021-23901Critical Vulnerability: CVE-2021-3199 — onlyoffice — document_server
Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.
onlyofficeCVE-2021-3199Critical Vulnerability: CVE-2020-28998 — mygeeni — gnc-cw013_firmware, gnc-cw013
An issue was discovered on Geeni GNC-CW013 doorbell 1.8.1 devices. A vulnerability exists in the Telnet service that allows a remote attacker to take full control of the device with a high-privileged
mygeeniCVE-2020-28998Critical Vulnerability: CVE-2020-27540 — company — cs-c2shw_firmware, cs-c2shw
Bash injection vulnerability and bypass of signature verification in Rostelecom CS-C2SHW 5.0.082.1. The camera reads firmware update configuration from SD card file vc\version.json. fw-sign parameter
companyCVE-2020-27540Critical Vulnerability: CVE-2021-3185 — freedesktop — gst-plugins-bad
A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause the stack to be smashed, memory corruption and possibly cod
freedesktopCVE-2021-3185Critical Vulnerability: CVE-2021-3304 — sagemcom — f\@st_3686_firmware, f\@st_3686
Sagemcom F@ST 3686 v2 3.495 devices have a buffer overflow via a long sessionKey to the goform/login URI.
sagemcomCVE-2021-3304Critical Vulnerability: CVE-2021-3188 — phplist — phplist
phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.
phplistCVE-2021-3188Critical Vulnerability: CVE-2021-25311 — wisc — htcondor
condor_credd in HTCondor before 8.9.11 allows Directory Traversal outside the SEC_CREDENTIAL_DIRECTORY_OAUTH directory, as demonstrated by creating a file under /etc that will later be executed by roo
wiscCVE-2021-25311Critical Vulnerability: CVE-2020-23360 — oscommerce — oscommerce
oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the checks in /catalog/admin/administrators.php and /catalog/passwo
oscommerceCVE-2020-23360Critical Vulnerability: CVE-2020-23359 — webidsupport — webid
WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the identicalness of two passwords. Two non-identical passwords can
webidsupportCVE-2020-23359Critical Vulnerability: CVE-2020-23262 — mingsoft — mcms
An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do.
mingsoftCVE-2020-23262Critical Vulnerability: CVE-2020-35263 — egavilanmedia — user_registration_and_login_system_with_admin_panel
EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution.
egavilanmediaCVE-2020-35263Critical Vulnerability: CVE-2021-3286 — spotweb_project — spotweb
SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variation of the payload may be used. NOTE: this issue exists because of an incomplete
spotweb_projectCVE-2021-3286Critical Vulnerability: CVE-2021-25900 — servo — smallvec
An issue was discovered in the smallvec crate before 0.6.14 and 1.x before 1.6.1 for Rust. There is a heap-based buffer overflow in SmallVec::insert_many.
servoCVE-2021-25900Critical Vulnerability: CVE-2020-23361 — phplist — phplist
phpList 3.5.3 allows type juggling for login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.
phplistCVE-2020-23361Critical Vulnerability: CVE-2020-27297 — honeywell — opc_ua_tunneller
The affected product is vulnerable to a heap-based buffer overflow, which may allow an attacker to manipulate memory with controlled values and remotely execute code on the OPC UA Tunneller (versions
honeywellCVE-2020-27297Critical Vulnerability: CVE-2021-25907 — containers_project — containers
An issue was discovered in the containers crate before 0.9.11 for Rust. When a panic occurs, a util::{mutate,mutate2} double drop can be performed.
containers_projectCVE-2021-25907Critical Vulnerability: CVE-2020-27299 — honeywell — opc_ua_tunneller
The affected product is vulnerable to an out-of-bounds read, which may allow an attacker to obtain and disclose sensitive data information or cause the device to crash on the OPC UA Tunneller (version
honeywellCVE-2020-27299Critical Vulnerability: CVE-2020-36199 — kaspersky — tinycheck
TinyCheck before commits 9fd360d and ea53de8 was vulnerable to command injection due to insufficient checks of input parameters in several places.
kasperskyCVE-2020-36199Critical Vulnerability: CVE-2020-11136 — qualcomm — apq8009, apq8009w
Buffer Over-read in audio driver while using malloc management function due to not returning NULL for zero sized memory requirement in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Sna
qualcommCVE-2020-11136Critical Vulnerability: CVE-2021-2101 — oracle — one-to-one_fulfillment
Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Print Server). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily explo
oracleCVE-2021-2101Critical Vulnerability: CVE-2020-11140 — qualcomm — apq8017, apq8037
Out of bound memory access during music playback with ALAC modified content due to improper validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdra
qualcommCVE-2020-11140Critical Vulnerability: CVE-2021-1142 — cisco — smart_software_manager_satellite
Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For m
ciscoCVE-2021-1142Critical Vulnerability: CVE-2020-3686 — qualcomm — apq8009, apq8009w
Possible memory out of bound issue during music playback when an incorrect bit stream content is copied into array without checking the length of array in Snapdragon Auto, Snapdragon Compute, Snapdrag
qualcommCVE-2020-3686Critical Vulnerability: CVE-2020-11143 — qualcomm — apq8009, apq8017
Out of bound memory access during music playback with modified content due to copying data without checking destination buffer size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Sna
qualcommCVE-2020-11143Critical Vulnerability: CVE-2020-3691 — qualcomm — apq8009, apq8009w
Possible out of bound memory access in audio due to integer underflow while processing modified contents in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapd
qualcommCVE-2020-3691Critical Vulnerability: CVE-2021-1139 — cisco — smart_software_manager_satellite
Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For m
ciscoCVE-2021-1139Critical Vulnerability: CVE-2021-2075 — oracle — weblogic_server
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1
oracleCVE-2021-2075Critical Vulnerability: CVE-2020-11212 — qualcomm — apq8009, apq8016
Out of bounds reads while parsing NAN beacons attributes and OUIs due to improper length of field check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics
qualcommCVE-2020-11212Critical Vulnerability: CVE-2021-1141 — cisco — smart_software_manager_satellite
Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For m
ciscoCVE-2021-1141Critical Vulnerability: CVE-2020-11138 — qualcomm — apq8009, apq8009w
Uninitialized pointers accessed during music play back with incorrect bit stream due to an uninitialized heap memory result in instability in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivi
qualcommCVE-2020-11138Critical Vulnerability: CVE-2020-11137 — qualcomm — apq8009, apq8009w
Integer multiplication overflow resulting in lower buffer size allocation than expected causes memory access out of bounds resulting in possible device instability in Snapdragon Auto, Snapdragon Compu
qualcommCVE-2020-11137Critical Vulnerability: CVE-2021-2100 — oracle — one-to-one_fulfillment
Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Print Server). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily explo
oracleCVE-2021-2100Critical Vulnerability: CVE-2020-11197 — qualcomm — apq8009, apq8009w
Possible integer overflow can occur when stream info update is called when total number of streams detected are zero while parsing TS clip with invalid data in Snapdragon Auto, Snapdragon Compute, Sna
qualcommCVE-2020-11197Critical Vulnerability: CVE-2021-1300 — cisco — ios_xe_sd-wan, sd-wan_firmware
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute attacks against an affected device. For more information about these vulnerabilities, see t
ciscoCVE-2021-1300Critical Vulnerability: CVE-2021-1301 — cisco — ios_xe_sd-wan, sd-wan_firmware
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute attacks against an affected device. For more information about these vulnerabilities, see t
ciscoCVE-2021-1301Critical Vulnerability: CVE-2020-8570 — kubernetes — java
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a malici
kubernetesCVE-2020-8570Critical Vulnerability: CVE-2020-11216 — qualcomm — apq8009, apq8009w
Buffer over read can happen in video driver when playing clip with atomsize having value UINT32_MAX in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon
qualcommCVE-2020-11216Critical Vulnerability: CVE-2020-27221 — eclipse — openj9
In Eclipse OpenJ9 up to and including version 0.23, there is potential for a stack-based buffer overflow when the virtual machine or JNI natives are converting from UTF-8 characters to platform encodi
eclipseCVE-2020-27221Critical Vulnerability: CVE-2020-11225 — qualcomm — apq8064au, apq8096au
Out of bound access in WLAN driver due to lack of validation of array length before copying into array in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics
qualcommCVE-2020-11225Critical Vulnerability: CVE-2021-1138 — cisco — smart_software_manager_satellite
Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For m
ciscoCVE-2021-1138Critical Vulnerability: CVE-2020-11213 — qualcomm — apq8009, apq8009w
Out of bound reads might occur in while processing Service descriptor due to improper validation of length of fields in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consume
qualcommCVE-2020-11213Critical Vulnerability: CVE-2020-11215 — qualcomm — aqt1000, ar8031
An out of bounds read can happen when processing VSA attribute due to improper minimum required length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electr
qualcommCVE-2020-11215Critical Vulnerability: CVE-2020-11167 — qualcomm — apq8009w, apq8017
Memory corruption while calculating L2CAP packet length in reassembly logic when remote sends more data than expected in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consum
qualcommCVE-2020-11167Critical Vulnerability: CVE-2021-2108 — oracle — weblogic_server
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). The supported version that is affected is 12.1.3.0.0. Easily exploitable vulnerability all
oracleCVE-2021-2108Critical Vulnerability: CVE-2021-1264 — cisco — catalyst_center
A vulnerability in the Command Runner tool of Cisco DNA Center could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability is due to insufficient input valid
ciscoCVE-2021-1264Critical Vulnerability: CVE-2020-11144 — qualcomm — apq8009, apq8009w
Buffer over-read while UE process invalid DL ROHC packet for decompression due to lack of check of size of compresses packet in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon
qualcommCVE-2020-11144
Get alerts that match YOUR environment
This page shows everything in the category. Vulnios narrows it down to alerts that affect your actual asset inventory — only the CVEs you need to act on.
Start a free scan