Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | KevinLAB BEMS has an undocumented backdoor account, and these sets of credentials are never exposed to the end-user and cannot be changed through any normal operation of the solution through the RMI. An attacker could exploit this vulnerability by logging in using the backdoor account with highest privileges for administration and gain full system control. The backdoor user cannot be seen in the users settings in the admin panel, and it also uses an undocumented privilege level (admin_pk=1) which allows full availability of the features that the BEMS is offering remotely. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-37292.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-32162 | Webmin 跨站请求伪造漏洞 | |
| CVE-2021-37291 | KevinLAB Building Energy Management System SQL注入漏洞 | |
| CVE-2021-40219 | Bolt CMS 代码注入漏洞 | |
| CVE-2022-27111 | Jfinal CMS跨站脚本漏洞 | |
| CVE-2022-27156 | Daylight Studio Fuel CMS跨站脚本漏洞 | |
| CVE-2022-27115 | elFinder 代码问题漏洞 | |
| CVE-2022-27088 | Ivanti DSM Remote 及 代码问题漏洞 | |
| CVE-2022-27089 | Fujitsu PlugFree Network 代码问题漏洞 | |
| CVE-2022-27041 | openSIS SQL注入漏洞 | |
| CVE-2021-37293 | KevinLAB Building Energy Management System 路径遍历漏洞 | |
| CVE-2021-32161 | Webmin 跨站脚本漏洞 | |
| CVE-2021-32160 | Webmin 跨站脚本漏洞 | |
| CVE-2021-32159 | Webmin 跨站请求伪造漏洞 | |
| CVE-2021-32158 | Webmin 跨站脚本漏洞 | |
| CVE-2021-32157 | Webmin 跨站脚本漏洞 | |
| CVE-2021-32156 | Webmin 跨站请求伪造漏洞 | |
| CVE-2022-28893 | Linux kernel 资源管理错误漏洞 | |
| CVE-2022-25794 | Autodesk FBX Review 缓冲区错误漏洞 | |
| CVE-2022-25790 | Autodesk AutoCAD 缓冲区错误漏洞 | |
| CVE-2021-4047 | Red Hat OpenShift 输入验证错误漏洞 |
Showing top 20 of 37 CVEs. View all on vendor page → →
No comments yet