Nomisec Exploits

22,933 exploits tracked across all sources.

Sort: Activity Stars
CVE-2020-23589 NOMISEC MEDIUM
OPTILINK OP-XT71000N V2.2 Firmware OP_V3.3.1-191028 - Unauthenticated Denial of Service via CSRF to Reboot Endpoint
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to cause a Denial of Service by Rebooting the router through " /mgm_dev_reboot.asp."
by huzaifahussain98
CVSS 6.5
CVE-2020-23590 NOMISEC MEDIUM
Optilink OP-XT71000N V2.2 Firmware OP_V3.3.1-191028 - Unauthenticated Cross-Site Request Forgery via wlwpa.asp
A vulnerability in Optilink OP-XT71000N Hardware version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated remote attacker to conduct a cross-site request forgery (CSRF) attack to change the Password for "WLAN SSID" through "wlwpa.asp".
by huzaifahussain98
CVSS 6.5
CVE-2020-23591 NOMISEC CRITICAL
OPTILINK OP-XT71000N V2.2 - File Upload
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an attacker to upload arbitrary files through " /mgm_dev_upgrade.asp " which can "delete every file for Denial of Service (using 'rm -rf *.*' in the code), reverse connection (using '.asp' webshell), backdoor.
by huzaifahussain98
CVSS 9.8
CVE-2020-23592 NOMISEC HIGH
OPTILINK OP-XT71000N V2.2 Firmware OP_V3.3.1-191028 - Unauthenticated Cross-Site Request Forgery via mgm_dev_reset.asp
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to Reset ONU to Factory Default through ' /mgm_dev_reset.asp.' Resetting to default leads to Escalation of Privileges by logging-in with default credentials.
by huzaifahussain98
CVSS 8.8
CVE-2020-23593 NOMISEC MEDIUM
OPTILINK OP-XT71000N V2.2 Firmware OP_V3.3.1-191028 - Unauthenticated Cross-Site Request Forgery via mgm_log_cfg.asp
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2, Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross site request forgery (CSRF) attack to enable syslog mode through ' /mgm_log_cfg.asp.' The system starts to log events, 'Remote' mode or 'Both' mode on "Syslog -- Configuration page" logs events and sends to remote syslog server IP and Port.
by huzaifahussain98
CVSS 6.5
CVE-2020-23585 NOMISEC HIGH
OPTILINK OP-XT71000N V2.2 Firmware OP_V3.3.1-191028 - Cross-Site Request Forgery via mgm_config_file.asp
A remote attacker can conduct a cross-site request forgery (CSRF) attack on OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028. The vulnerability is due to insufficient CSRF protections for the "mgm_config_file.asp" because of which attacker can create a crafted "csrf form" which sends " malicious xml data" to "/boaform/admin/formMgmConfigUpload". the exploit allows attacker to "gain full privileges" and to "fully compromise of router & network".
by huzaifahussain98
CVSS 8.8
CVE-2020-23584 NOMISEC CRITICAL
OPTILINK OP-XT71000N V2.2 - Unauthenticated Remote Code Execution via PingTest Parameter Command Injection
Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDRESS using " | " to execute commands on " /diag_tracert_admin.asp " in the "PingTest" parameter that leads to command execution.
by huzaifahussain98
CVSS 9.8
CVE-2020-23583 NOMISEC CRITICAL
OPTILINK OP-XT71000N V2.2 - Remote Code Execution via PingTest Interface
OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on "/diag_ping_admin.asp" to "PingTest" interface that leads to COMMAND EXECUTION. An attacker can successfully trigger the COMMAND and can compromise full system.
by huzaifahussain98
CVSS 9.8
CVE-2020-23582 NOMISEC MEDIUM
optilink OP-XT71000N V2.2 - Unauthenticated Cross-Site Request Forgery via wlmultipleap.asp
A vulnerability in the "/admin/wlmultipleap.asp" of optilink OP-XT71000N version: V2.2 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to create Multiple WLAN BSSID.
by huzaifahussain98
CVSS 6.5
CVE-2022-44830 NOMISEC HIGH
Sourcecodester Event Registration App v1.0 - Code Injection
Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and Remarks fields. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.
by RashidKhanPathan
1 stars
CVSS 7.8
CVE-2022-43117 NOMISEC MEDIUM
Sourcecodester Password Storage App <1.0 - XSS
Sourcecodester Password Storage Application in PHP/OOP and MySQL 1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Name, Username, Description and Site Feature parameters.
by RashidKhanPathan
1 stars
CVSS 5.4
CVE-2022-30075 NOMISEC HIGH
TP-Link Archer AX50 Firmware < 210730 - Remote Code Execution via Malicious Backup File Import
In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code execution due to improper validation.
by aaronsvk
231 stars
CVSS 8.8
CVE-2021-44228 NOMISEC CRITICAL
Log4Shell HTTP Header Injection
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
by TPower2112
1 stars
CVSS 10.0
CVE-2022-30190 NOMISEC HIGH
Microsoft Office Word MSDTJS
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability.
by abbarhissarh
8 stars
CVSS 7.8
CVE-2022-30190 NOMISEC HIGH
Microsoft Office Word MSDTJS
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability.
by ar2o3
8 stars
CVSS 7.8
CVE-2022-3992 NOMISEC LOW
Sanitization Management System - Cross-Site Scripting in Banner Image Handler
A vulnerability classified as problematic was found in SourceCodester Sanitization Management System. Affected by this vulnerability is an unknown functionality of the file admin/?page=system_info of the component Banner Image Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-213571.
by Urban4
CVSS 2.4
CVE-2022-40127 NOMISEC HIGH
Apache Airflow < 2.4.0 - Authenticated Remote Code Execution via Run ID Parameter
A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually provided run_id parameter. This issue affects Apache Airflow Apache Airflow versions prior to 2.4.0.
by Mr-xn
41 stars
CVSS 8.8
CVE-2021-3166 NOMISEC HIGH
ASUS DSL-N14U-B1 1.1.2.3_805 - Unrestricted Firmware Upload via Settings_DSL-N14U-B1.trx
An issue was discovered on ASUS DSL-N14U-B1 1.1.2.3_805 devices. An attacker can upload arbitrary file content as a firmware update when the filename Settings_DSL-N14U-B1.trx is used. Once this file is loaded, shutdown measures on a wide range of services are triggered as if it were a real update, resulting in a persistent outage of those services.
by kaisersource
CVSS 7.5
CVE-2022-3602 NOMISEC HIGH
OpenSSL 3.0.0-3.0.6 - Buffer Overflow in X.509 Certificate Name Constraint Checking
A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer. An attacker can craft a malicious email address to overflow four attacker-controlled bytes on the stack. This buffer overflow could result in a crash (causing a denial of service) or potentially remote code execution. Many platforms implement stack overflow protections which would mitigate against the risk of remote code execution. The risk may be further mitigated based on stack layout for any given platform/compiler. Pre-announcements of CVE-2022-3602 described this issue as CRITICAL. Further analysis based on some of the mitigating factors described above have led this to be downgraded to HIGH. Users are still encouraged to upgrade to a new version as soon as possible. In a TLS client, this can be triggered by connecting to a malicious server. In a TLS server, this can be triggered if the server requests client authentication and a malicious client connects. Fixed in OpenSSL 3.0.7 (Affected 3.0.0,3.0.1,3.0.2,3.0.3,3.0.4,3.0.5,3.0.6).
by NCSC-NL
532 stars
CVSS 7.5
CVE-2022-0824 NOMISEC HIGH
webmin < 1.990 - Improper Access Control to Remote Code Execution
Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.
by gokul-ramesh
CVSS 8.8
CVE-2020-35847 NOMISEC CRITICAL
Cockpit CMS NoSQLi to RCE
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
by w33vils
CVSS 9.8
CVE-2022-0441 NOMISEC CRITICAL
MasterStudy LMS <2.7.6 - Info Disclosure
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin
by SDragon1205
1 stars
CVSS 9.8
CVE-2016-10033 NOMISEC CRITICAL
PHPMailer Sendmail Argument Injection
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
by CAOlvchonger
CVSS 9.8
CVE-2021-29156 NOMISEC HIGH
ForgeRock OpenAM < 13.5.1 - Unauthenticated LDAP Injection via Webfinger Protocol
ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-character retrieval of password hashes, or retrieve a session token or a private key.
by guidepointsecurity
3 stars
CVSS 7.5
CVE-2022-31691 NOMISEC CRITICAL
Vmware Bosh Editor < 1.40.0 - Code Injection
Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor and Cloudfoundry Manifest YML Support version 1.39.0 and below all use Snakeyaml library for YAML editing support. This library allows for some special syntax in the YAML that under certain circumstances allows for potentially harmful remote code execution by the attacker.
by blipzip
1 stars
CVSS 9.8