9.3

CVSS4.0

CVE-2021-47707 - COMMAX CVD-Axx DVR Weak Default Credentials Stream Disclosure

COMMAX CVD-Axx DVR 5.1.4 contains weak default administrative credentials that allow remote password attacks and disclose RTSP stream. Attackers can exploit this by sending a POST request with the 'passkey' parameter set to '1234', allowing them to access the web control panel.

πŸ“… Published: Dec. 9, 2025, 8:39 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 9:33 p.m.

8.7

CVSS4.0

CVE-2021-47706 - COMMAX Biometric Access Control System Authentication Bypass

COMMAX Biometric Access Control System 1.0.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access sensitive information and circumvent physical controls in smart homes and buildings by exploiting cookie poisoning. Attackers can forge cookies to bypass auth…

πŸ“… Published: Dec. 9, 2025, 8:37 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 9:33 p.m.

8.7

CVSS4.0

CVE-2021-47705 - CNC_Ctrl DllUnregisterServer Access Violation

COMMAX UMS Client ActiveX Control 1.7.0.2 contains a heap-based buffer overflow vulnerability that allows attackers to execute arbitrary code by providing excessively long string arrays through multiple functions. Attackers can exploit improper boundary validation in CNC_Ctrl.dll to cause heap corr…

πŸ“… Published: Dec. 9, 2025, 8:37 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 9:33 p.m.

8.7

CVSS4.0

CVE-2021-47704 - OpenBMCS SQL Injection via obix_test.php

OpenBMCS 2.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting arbitrary SQL code. Attackers can send GET requests to /debug/obix_test.php with malicious 'id' values to extract database information.

πŸ“… Published: Dec. 9, 2025, 8:36 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 9:33 p.m.

6.9

CVSS4.0

CVE-2021-47703 - OpenBMCS Server Side Request Forgery (SSRF) via /php/query.php

OpenBMCS 2.4 contains an unauthenticated SSRF vulnerability that allows attackers to bypass firewalls and initiate service and network enumeration on the internal network through the affected application, allowing hijacking of current sessions. Attackers can specify an external domain in the 'ip' p…

πŸ“… Published: Dec. 9, 2025, 8:36 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 9:33 p.m.

5.3

CVSS4.0

CVE-2021-47702 - OpenBMCS Cross Site Request Forgery (CSRF) via sendFeedback.php

OpenBMCS 2.4 contains a CSRF vulnerability that allows attackers to perform actions with administrative privileges by exploiting the sendFeedback.php endpoint. Attackers can submit malicious requests to trigger unintended actions, such as sending emails or modifying system settings.

πŸ“… Published: Dec. 9, 2025, 8:35 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 9:33 p.m.

8.7

CVSS4.0

CVE-2021-47701 - OpenBMCS User Management Privilege Escalation

OpenBMCS 2.4 allows an attacker to escalate privileges from a read user to an admin user by manipulating permissions and exploiting a vulnerability in the update_user_permissions.php script. Attackers can submit a malicious HTTP POST request to PHP scripts in '/plugins/useradmin/' directory.

πŸ“… Published: Dec. 9, 2025, 8:35 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 9:33 p.m.

7.8

CVSS3.1

CVE-2025-67488 - SiYuan: ZipSlip -> Arbitrary File Overwrite -> RCE

SiYuan is self-hosted, open source personal knowledge management software. Versions 0.0.0-20251202123337-6ef83b42c7ce and below contain function importZipMd which is vulnerable to ZipSlips, allowing an authenticated user to overwrite files on the system. An authenticated user with access to the imp…

πŸ“… Published: Dec. 9, 2025, 8:32 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 5:48 p.m.

7.8

CVSS3.1

CVE-2025-64899 - Acrobat Reader | Out-of-bounds Read (CWE-125)

Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulne…

πŸ“… Published: Dec. 9, 2025, 8:21 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 5:49 p.m.

7.8

CVSS3.1

CVE-2025-64785 - Acrobat Reader | Untrusted Search Path (CWE-426)

Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a search path to locate cr…

πŸ“… Published: Dec. 9, 2025, 8:21 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 5:49 p.m.
Total resulsts: 321667
Page 31 of 32,167
Β« previous page Β» next page
Filters