CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2021-33220

    Last Modified: 21 Nov 2024

    An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. Hard-coded API Keys exist.

    Published: 7 Jul 2021
    9.8
    Critical

    CVE-2021-33219

    Last Modified: 21 Nov 2024

    An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded Web Application Administrator Passwords for the admin and nplus1user accounts.

    Published: 7 Jul 2021
    9.8
    Critical

    CVE-2021-32538

    Last Modified: 21 Nov 2024

    ARTWARE CMS parameter of image upload function does not filter the type of upload files which allows remote attackers can upload arbitrary files without logging in, and further execute code unrestrictedly.

    Published: 7 Jul 2021
    6.5
    Medium

    CVE-2021-32537

    Last Modified: 21 Nov 2024

    Realtek HAD contains a driver crashed vulnerability which allows local side attackers to send a special string to the kernel driver in a user’s mode. Due to unexpected commands, the kernel driver will cause the system crashed.

    Published: 7 Jul 2021
    9.8
    Critical

    CVE-2021-32535

    Last Modified: 21 Nov 2024

    The vulnerability of hard-coded default credentials in QSAN SANOS allows unauthenticated remote attackers to obtain administrator’s permission and execute arbitrary functions. The referred vulnerability has been solved with the updated version of QSAN SANOS v2.1.0.

    Published: 7 Jul 2021
    9.8
    Critical

    CVE-2021-32534

    Last Modified: 21 Nov 2024

    QSAN SANOS factory reset function does not filter special parameters. Remote attackers can use this vulnerability to inject and execute arbitrary commands without permissions. The referred vulnerability has been solved with the updated version of QSAN SANOS v2.1.0.

    Published: 7 Jul 2021
    9.8
    Critical

    CVE-2021-32533

    Last Modified: 21 Nov 2024

    The QSAN SANOS setting page does not filter special parameters. Remote attackers can use this vulnerability to inject and execute arbitrary commands without permissions. The referred vulnerability has been solved with the updated version of QSAN SANOS v2.1.0.

    Published: 7 Jul 2021
    7.5
    High

    CVE-2021-32532

    Last Modified: 21 Nov 2024

    Path traversal vulnerability in back-end analysis function in QSAN XEVO allows remote attackers to download arbitrary files without permissions. The referred vulnerability has been solved with the updated version of QSAN XEVO v2.1.0.

    Published: 7 Jul 2021
    9.8
    Critical

    CVE-2021-32531

    Last Modified: 21 Nov 2024

    OS command injection vulnerability in Init function in QSAN XEVO allows remote attackers to execute arbitrary commands without permissions. The referred vulnerability has been solved with the updated version of QSAN XEVO v2.1.0.

    Published: 7 Jul 2021
    9.8
    Critical

    CVE-2021-32530

    Last Modified: 21 Nov 2024

    OS command injection vulnerability in Array function in QSAN XEVO allows remote unauthenticated attackers to execute arbitrary commands via status parameter. The referred vulnerability has been solved with the updated version of QSAN XEVO v2.1.0.

    Published: 7 Jul 2021
    9.8
    Critical

    CVE-2021-32529

    Last Modified: 21 Nov 2024

    Command injection vulnerability in QSAN XEVO, SANOS allows remote unauthenticated attackers to execute arbitrary commands. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

    Published: 7 Jul 2021
    5.3
    Medium

    CVE-2021-32528

    Last Modified: 21 Nov 2024

    Observable behavioral discrepancy vulnerability in QSAN Storage Manager allows remote attackers to obtain the system information without permissions. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

    Published: 7 Jul 2021
    7.5
    High

    CVE-2021-32527

    Last Modified: 21 Nov 2024

    Path traversal vulnerability in QSAN Storage Manager allows remote unauthenticated attackers to download arbitrary files thru injecting file path in download function. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

    Published: 7 Jul 2021
    6.5
    Medium

    CVE-2021-32526

    Last Modified: 21 Nov 2024

    Incorrect permission assignment for critical resource vulnerability in QSAN Storage Manager allows authenticated remote attackers to access arbitrary password files. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

    Published: 7 Jul 2021
    9.1
    Critical

    CVE-2021-32525

    Last Modified: 21 Nov 2024

    The same hard-coded password in QSAN Storage Manager's in the firmware allows remote attackers to access the control interface with the administrator’s credential, entering the hard-coded password of the debug mode to execute the restricted system instructions. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

    Published: 7 Jul 2021
    9.1
    Critical

    CVE-2021-32524

    Last Modified: 21 Nov 2024

    Command injection vulnerability in QSAN Storage Manager allows remote privileged users to execute arbitrary commands. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

    Published: 7 Jul 2021
    9.1
    Critical

    CVE-2021-32523

    Last Modified: 21 Nov 2024

    Improper authorization vulnerability in QSAN Storage Manager allows remote privileged users to bypass the access control and execute arbitrary commands. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

    Published: 7 Jul 2021
    9.8
    Critical

    CVE-2021-32522

    Last Modified: 21 Nov 2024

    Improper restriction of excessive authentication attempts vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to discover users’ credentials and obtain access via a brute force attack. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

    Published: 7 Jul 2021
    7.3
    High

    CVE-2021-32521

    Last Modified: 21 Nov 2024

    Use of MAC address as an authenticated password in QSAN Storage Manager, XEVO, SANOS allows local attackers to escalate privileges. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

    Published: 7 Jul 2021
    9.8
    Critical

    CVE-2021-32520

    Last Modified: 21 Nov 2024

    Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials and related permissions. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

    Published: 7 Jul 2021
    9.8
    Critical

    CVE-2021-32519

    Last Modified: 21 Nov 2024

    Use of password hash with insufficient computational effort vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to recover the plain-text password by brute-forcing the MD5 hash. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.2, QSAN XEVO v2.1.0, and QSAN SANOS v2.1.0.

    Published: 7 Jul 2021
    7.5
    High

    CVE-2021-32518

    Last Modified: 21 Nov 2024

    A vulnerability in share_link in QSAN Storage Manager allows remote attackers to create a symbolic link then access arbitrary files. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

    Published: 7 Jul 2021
    7.5
    High

    CVE-2021-32517

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in share_link in QSAN Storage Manager allows remote attackers to download arbitrary files using particular parameter in download function. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

    Published: 7 Jul 2021
    7.5
    High

    CVE-2021-32516

    Last Modified: 21 Nov 2024

    Path traversal vulnerability in share_link in QSAN Storage Manager allows remote attackers to download arbitrary files. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

    Published: 7 Jul 2021
    9.8
    Critical

    CVE-2021-33218

    Last Modified: 21 Nov 2024

    An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded System Passwords that provide shell access.

    Published: 7 Jul 2021
    5.3
    Medium

    CVE-2021-32515

    Last Modified: 21 Nov 2024

    Directory listing vulnerability in share_link in QSAN Storage Manager allows attackers to list arbitrary directories and further access credential information. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

    Published: 7 Jul 2021
    7.5
    High

    CVE-2021-32514

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in FirmwareUpgrade in QSAN Storage Manager allows remote attackers to reboot and discontinue the device. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

    Published: 7 Jul 2021
    9.8
    Critical

    CVE-2021-32513

    Last Modified: 21 Nov 2024

    QsanTorture in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute arbitrary commands. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

    Published: 7 Jul 2021
    9.8
    Critical

    CVE-2021-32512

    Last Modified: 21 Nov 2024

    QuickInstall in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute arbitrary commands. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

    Published: 7 Jul 2021
    4.3
    Medium

    CVE-2021-32511

    Last Modified: 21 Nov 2024

    QSAN Storage Manager through directory listing vulnerability in ViewBroserList allows remote authenticated attackers to list arbitrary directories via the file path parameter. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

    Published: 7 Jul 2021
    4.3
    Medium

    CVE-2021-32510

    Last Modified: 21 Nov 2024

    QSAN Storage Manager through directory listing vulnerability in antivirus function allows remote authenticated attackers to list arbitrary directories by injecting file path parameter. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

    Published: 7 Jul 2021
    6.5
    Medium

    CVE-2021-32509

    Last Modified: 21 Nov 2024

    Absolute Path Traversal vulnerability in FileviewDoc in QSAN Storage Manager allows remote authenticated attackers access arbitrary files by injecting the Symbolic Link following the Url path parameter. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

    Published: 7 Jul 2021
    6.5
    Medium

    CVE-2021-32508

    Last Modified: 21 Nov 2024

    Absolute Path Traversal vulnerability in FileStreaming in QSAN Storage Manager allows remote authenticated attackers access arbitrary files by injecting the Symbolic Link following the Url path parameter. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

    Published: 7 Jul 2021
    6.5
    Medium

    CVE-2021-32507

    Last Modified: 21 Nov 2024

    Absolute Path Traversal vulnerability in FileDownload in QSAN Storage Manager allows remote authenticated attackers download arbitrary files via the Url path parameter. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

    Published: 7 Jul 2021
    6.5
    Medium

    CVE-2021-32506

    Last Modified: 21 Nov 2024

    Absolute Path Traversal vulnerability in GetImage in QSAN Storage Manager allows remote authenticated attackers download arbitrary files via the Url path parameter. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3 .

    Published: 7 Jul 2021
    8.8
    High

    CVE-2021-33217

    Last Modified: 21 Nov 2024

    An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The Web Application allows Arbitrary Read/Write actions by authenticated users. The API allows an HTTP POST of arbitrary content into any file on the filesystem as root.

    Published: 7 Jul 2021
    9.8
    Critical

    CVE-2021-33216

    Last Modified: 21 Nov 2024

    An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowing shell access via a developer account.

    Published: 7 Jul 2021
    4.3
    Medium

    CVE-2021-33215

    Last Modified: 21 Nov 2024

    An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The API allows Directory Traversal.

    Published: 7 Jul 2021
    7.5
    High

    CVE-2021-31925

    Last Modified: 21 Nov 2024

    Pexip Infinity 25.x before 25.4 has Improper Input Validation, and thus an unauthenticated remote attacker can cause a denial of service via the administrative web interface.

    Published: 7 Jul 2021
    8.8
    High

    CVE-2021-28931

    Last Modified: 21 Nov 2024

    Arbitrary file upload vulnerability in Fork CMS 5.9.2 allows attackers to create or replace arbitrary files in the /themes directory via a crafted zip file uploaded to the Themes panel.

    Published: 7 Jul 2021
    7.1
    High

    CVE-2021-26274

    Last Modified: 21 Nov 2024

    The Agent in NinjaRMM 5.0.909 has Insecure Permissions.

    Published: 7 Jul 2021
    7.8
    High

    CVE-2021-26273

    Last Modified: 21 Nov 2024

    The Agent in NinjaRMM 5.0.909 has Incorrect Access Control.

    Published: 7 Jul 2021
    6.1
    Medium

    CVE-2020-25925

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in Webmail Calender in IceWarp WebClient 10.3.5 allows remote attackers to inject arbitrary web script or HTML via the "p4" field.

    Published: 7 Jul 2021
    7.5
    High

    CVE-2020-25868

    Last Modified: 21 Nov 2024

    Pexip Infinity 22.x through 24.x before 24.2 has Improper Input Validation for call setup. An unauthenticated remote attacker can trigger a software abort (temporary loss of service).

    Published: 7 Jul 2021
    7.5
    High

    CVE-2020-24149

    Last Modified: 21 Nov 2024

    Server-side request forgery (SSRF) in the Podcast Importer SecondLine (podcast-importer-secondline) plugin 1.1.4 for WordPress via the podcast_feed parameter in a secondline_import_initialize action to the secondlinepodcastimport page.

    Published: 7 Jul 2021
    9.1
    Critical

    CVE-2020-24148

    Last Modified: 21 Nov 2024

    Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_read_xml action.

    Published: 7 Jul 2021
    9.1
    Critical

    CVE-2020-24147

    Last Modified: 21 Nov 2024

    Server-side request forgery (SSR) vulnerability in the WP Smart Import (wp-smart-import) plugin 1.0.0 for WordPress via the file field.

    Published: 7 Jul 2021
    8.1
    High

    CVE-2020-24146

    Last Modified: 21 Nov 2024

    Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized users to delete arbitrary files and possibly cause a denial of service via the fileName parameter in a deletescreenshot action.

    Published: 7 Jul 2021
    6.1
    Medium

    CVE-2020-24145

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted deletescreenshot action.

    Published: 7 Jul 2021
    8.6
    High

    CVE-2020-24144

    Last Modified: 21 Nov 2024

    Directory traversal in the Media File Organizer (aka media-file-organizer) plugin 1.0.1 for WordPress lets an attacker get access to files that are stored outside the web root folder via the items[] parameter in a move operation.

    Published: 7 Jul 2021