Search

Search Results (374130 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-38787 1 Allwinnertech 2 Android Q Sdk, R818 2024-11-21 7.5 High
There is an integer overflow in the ION driver "/dev/ion" of Allwinner R818 SoC Android Q SDK V1.0 that could use the ioctl cmd "COMPAT_ION_IOC_SUNXI_FLUSH_RANGE" to cause a system crash (denial of service).
CVE-2021-38786 1 Allwinnertech 2 Android Q Sdk, R818 2024-11-21 7.5 High
There is a NULL pointer dereference in media/libcedarc/vdecoder of Allwinner R818 SoC Android Q SDK V1.0, which could cause a media crash (denial of service).
CVE-2021-38785 1 Allwinnertech 2 Android Q Sdk, R818 2024-11-21 7.5 High
There is a NULL pointer deference in the Allwinner R818 SoC Android Q SDK V1.0 camera driver /dev/cedar_dev that could use the ioctl cmd IOCTL_GET_IOMMU_ADDR to cause a system crash.
CVE-2021-38784 1 Allwinnertech 2 Android Q Sdk, R818 2024-11-21 7.5 High
There is a NULL pointer dereference in the syscall open_exec function of Allwinner R818 SoC Android Q SDK V1.0 that could executable a malicious file to cause a system crash.
CVE-2021-38783 1 Allwinnertech 2 Android Q Sdk, R818 2024-11-21 7.5 High
There is a Out-of-Bound Write in the Allwinner R818 SoC Android Q SDK V1.0 camera driver "/dev/cedar_dev" through iotcl cmd IOCTL_SET_PROC_INFO and IOCTL_COPY_PROC_INFO, which could cause a system crash or EoP.
CVE-2021-38772 1 Tendacn 2 Ac10, Ac10 Firmware 2024-11-21 7.5 High
Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind function.
CVE-2021-38759 1 Raspberrypi 1 Raspberry Pi Os Lite 2024-11-21 9.8 Critical
Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain administrator privileges.
CVE-2021-38758 1 Online Catering Reservation System Project 1 Online Catering Reservation System 2024-11-21 7.5 High
Directory traversal vulnerability in Online Catering Reservation System 1.0 exists due to lack of validation in index.php.
CVE-2021-38757 1 Hospital Management System Project 1 Hospital Management System 2024-11-21 6.1 Medium
Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php.
CVE-2021-38756 1 Hospital Management System Project 1 Hospital Management System 2024-11-21 6.1 Medium
Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through prescribe.php.
CVE-2021-38755 1 Hospital Management System Project 1 Hospital Management System 2024-11-21 5.3 Medium
Unauthenticated doctor entry deletion in Hospital Management System in admin-panel1.php.
CVE-2021-38754 1 Hospital Management System Project 1 Hospital Management System 2024-11-21 9.8 Critical
SQL Injection vulnerability in Hospital Management System due to lack of input validation in messearch.php.
CVE-2021-38753 1 Simple Image Gallery Web App Project 1 Simple Image Gallery Web App 2024-11-21 9.8 Critical
An unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain unauthorized access to the server hosting the web app.
CVE-2021-38752 1 Online Catering Reservation System Project 1 Online Catering Reservation System 2024-11-21 5.4 Medium
A cross-site scripting (XSS) vulnerability in Online Catering Reservation System using PHP on Sourcecodester allows an attacker to arbitrarily inject code in the search bar.
CVE-2021-38751 1 Exponentcms 1 Exponentcms 2024-11-21 4.3 Medium
A HTTP Host header attack exists in ExponentCMS 2.6 and below in /exponent_constants.php. A modified HTTP header can change links on the webpage to an arbitrary value, leading to a possible attack vector for MITM.
CVE-2021-38745 1 Chamilo 1 Chamilo 2024-11-21 6.8 Medium
Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a crafted plugin. This vulnerability is triggered through user interaction with the attacker's profile page.
CVE-2021-38727 1 Thedaylightstudio 1 Fuel Cms 2024-11-21 9.8 Critical
FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items
CVE-2021-38725 1 Thedaylightstudio 1 Fuel Cms 2024-11-21 5.3 Medium
Fuel CMS 1.5.0 has a brute force vulnerability in fuel/modules/fuel/controllers/Login.php
CVE-2021-38723 1 Thedaylightstudio 1 Fuel Cms 2024-11-21 8.8 High
FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/pages/items
CVE-2021-38721 1 Thedaylightstudio 1 Fuel Cms 2024-11-21 6.5 Medium
FUEL CMS 1.5.0 login.php contains a cross-site request forgery (CSRF) vulnerability