Export limit exceeded: 372754 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (372757 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-45834 | 1 Opendocman | 1 Opendocman | 2024-11-21 | 9.8 Critical |
| An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically processed within the product's environment or lead to arbitrary code execution. | ||||
| CVE-2021-45833 | 1 Hdfgroup | 1 Hdf5 | 2024-11-21 | 5.5 Medium |
| A Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 via the H5D__create_chunk_file_map_hyper function in /hdf5/src/H5Dchunk.c, which causes a Denial of Service (context-dependent). | ||||
| CVE-2021-45832 | 1 Hdfgroup | 1 Hdf5 | 2024-11-21 | 5.5 Medium |
| A Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 at at hdf5/src/H5Eint.c, which causes a Denial of Service (context-dependent). | ||||
| CVE-2021-45831 | 1 Gpac | 1 Gpac | 2024-11-21 | 5.5 Medium |
| A Null Pointer Dereference vulnerability exitgs in GPAC 1.0.1 in MP4Box via __strlen_avx2, which causes a Denial of Service. | ||||
| CVE-2021-45830 | 1 Hdfgroup | 1 Hdf5 | 2024-11-21 | 5.5 Medium |
| A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_decode_len in /hdf5/src/H5Fint.c, which could cause a Denial of Service. | ||||
| CVE-2021-45829 | 1 Hdfgroup | 1 Hdf5 | 2024-11-21 | 5.5 Medium |
| HDF5 1.13.1-1 is affected by: segmentation fault, which causes a Denial of Service. | ||||
| CVE-2021-45822 | 1 Btiteam | 1 Xbtit | 2024-11-21 | 6.1 Medium |
| A cross-site scripting vulnerability is present in Xbtit 3.1. The stored XSS vulnerability occurs because /ajaxchat/sendChatData.php does not properly validate the value of the "n" (POST) parameter. Through this vulnerability, an attacker is capable to execute malicious JavaScript code. | ||||
| CVE-2021-45821 | 1 Btiteam | 1 Xbtit | 2024-11-21 | 8.8 High |
| A blind SQL injection vulnerability exists in Xbtit 3.1 via the sid parameter in ajaxchat/getHistoryChatData.php file that is accessible by a registered user. As a result, a malicious user can extract sensitive data such as usernames and passwords and in some cases use this vulnerability in order to get a remote code execution on the remote web server. | ||||
| CVE-2021-45819 | 1 Wordline | 1 Hidccemonitorsvc | 2024-11-21 | 6.4 Medium |
| Wordline HIDCCEMonitorSVC before v5.2.4.3 contains an unquoted service path which allows attackers to escalate privileges to the system level. | ||||
| CVE-2021-45818 | 1 Safarimontage | 1 Safari Montage | 2024-11-21 | 6.1 Medium |
| SAFARI Montage 8.7.32 is affected by a CRLF injection vulnerability which can lead to HTTP response splitting. | ||||
| CVE-2021-45815 | 1 Quectel | 2 Uc20, Uc20 Firmware | 2024-11-21 | 6.1 Medium |
| Quectel UC20 UMTS/HSPA+ UC20 6.3.14 is affected by a Cross Site Scripting (XSS) vulnerability. | ||||
| CVE-2021-45814 | 1 Nettemp | 1 Nnt | 2024-11-21 | 9.8 Critical |
| Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel with an administrative account. | ||||
| CVE-2021-45813 | 1 Slican | 1 Webcti | 2024-11-21 | 6.1 Medium |
| SLICAN WebCTI 1.01 2015 is affected by a Cross Site Scripting (XSS) vulnerability. The attacker can steal the user's session by injecting malicious JavaScript codes which leads to Session Hijacking and cause user's credentials theft. | ||||
| CVE-2021-45812 | 1 Nuuo | 2 Nvrsolo, Nvrsolo Firmware | 2024-11-21 | 6.1 Medium |
| NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability. An attacker can steal the user's session by injecting malicious JavaScript codes which leads to session hijacking. | ||||
| CVE-2021-45811 | 1 Enhancesoft | 1 Osticket | 2024-11-21 | 6.5 Medium |
| A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination. | ||||
| CVE-2021-45810 | 1 Globalprotect-openconnect Project | 1 Globalprotect-openconnect | 2024-11-21 | 7.5 High |
| GlobalProtect-openconnect versions prior to 2.0.0 (exclusive) are affected by incorrect access control in GPService through DBUS, GUI. The way GlobalProtect-Openconnect is set up enables arbitrary users to start a VPN connection to arbitrary servers. By hosting an openconnect compatible server, the attack can redirect the entire host's traffic via their own server. | ||||
| CVE-2021-45809 | 1 Globalprotect-openconnect Project | 1 Globalprotect-openconnect | 2024-11-21 | 9.8 Critical |
| GlobalProtect-openconnect versions prior to 1.4.3 are affected by incorrect access control in GPService through DBUS, GUI Application. The way GlobalProtect-Openconnect is set up enables arbitrary users to execute commands as root by submitting the `--script=<script>` parameter. | ||||
| CVE-2021-45808 | 1 Jpress | 1 Jpress | 2024-11-21 | 8.8 High |
| jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the server. | ||||
| CVE-2021-45807 | 1 Jpress | 1 Jpress | 2024-11-21 | 9.8 Critical |
| jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall. | ||||
| CVE-2021-45806 | 1 Jpress | 1 Jpress | 2024-11-21 | 8.8 High |
| jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code. | ||||