Export limit exceeded: 369876 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 369876 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (369876 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-32159 | 1 Webmin | 1 Webmin | 2024-11-21 | 8.8 High |
| A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Upload and Download feature. | ||||
| CVE-2021-32158 | 1 Webmin | 1 Webmin | 2024-11-21 | 6.1 Medium |
| A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Upload and Download feature. | ||||
| CVE-2021-32157 | 1 Webmin | 1 Webmin | 2024-11-21 | 9.6 Critical |
| A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature. | ||||
| CVE-2021-32156 | 1 Webmin | 1 Webmin | 2024-11-21 | 8.8 High |
| A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature. | ||||
| CVE-2021-32139 | 1 Gpac | 1 Gpac | 2024-11-21 | 5.5 Medium |
| The gf_isom_vp_config_get function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command. | ||||
| CVE-2021-32138 | 1 Gpac | 1 Gpac | 2024-11-21 | 5.5 Medium |
| The DumpTrackInfo function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command. | ||||
| CVE-2021-32137 | 1 Gpac | 1 Gpac | 2024-11-21 | 5.5 Medium |
| Heap buffer overflow in the URL_GetProtocolType function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file. | ||||
| CVE-2021-32136 | 1 Gpac | 1 Gpac | 2024-11-21 | 7.8 High |
| Heap buffer overflow in the print_udta function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file. | ||||
| CVE-2021-32135 | 1 Gpac | 1 Gpac | 2024-11-21 | 5.5 Medium |
| The trak_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command. | ||||
| CVE-2021-32134 | 1 Gpac | 1 Gpac | 2024-11-21 | 5.5 Medium |
| The gf_odf_desc_copy function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command. | ||||
| CVE-2021-32132 | 1 Gpac | 1 Gpac | 2024-11-21 | 5.5 Medium |
| The abst_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command. | ||||
| CVE-2021-32122 | 1 Netgear | 8 Ex3700, Ex3700 Firmware, Ex3800 and 5 more | 2024-11-21 | 9.8 Critical |
| Certain NETGEAR devices are affected by CSRF. This affects EX3700 before 1.0.0.90, EX3800 before 1.0.0.90, EX6120 before 1.0.0.64, and EX6130 before 1.0.0.44. | ||||
| CVE-2021-32106 | 1 Icecoder | 1 Icecoder | 2024-11-21 | 5.4 Medium |
| In ICEcoder 8.0 allows, a reflected XSS vulnerability was identified in the multipe-results.php page due to insufficient sanitization of the _GET['replace'] variable. As a result, arbitrary Javascript code can get executed. | ||||
| CVE-2021-32104 | 1 Open-emr | 1 Openemr | 2024-11-21 | 8.8 High |
| A SQL injection vulnerability exists (with user privileges) in interface/forms/eye_mag/save.php in OpenEMR 5.0.2.1. | ||||
| CVE-2021-32103 | 1 Open-emr | 1 Openemr | 2024-11-21 | 4.8 Medium |
| A Stored XSS vulnerability in interface/usergroup/usergroup_admin.php in OpenEMR before 5.0.2.1 allows a admin authenticated user to inject arbitrary web script or HTML via the lname parameter. | ||||
| CVE-2021-32102 | 1 Open-emr | 1 Openemr | 2024-11-21 | 8.8 High |
| A SQL injection vulnerability exists (with user privileges) in library/custom_template/ajax_code.php in OpenEMR 5.0.2.1. | ||||
| CVE-2021-32101 | 1 Open-emr | 1 Openemr | 2024-11-21 | 8.2 High |
| The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config.php. To exploit the vulnerability, an unauthenticated attacker can register an account, bypassing the permission check of this portal's API. Then, the attacker can then manipulate and read data of every registered patient. | ||||
| CVE-2021-32100 | 1 Artica | 1 Pandora Fms | 2024-11-21 | 6.5 Medium |
| A remote file inclusion vulnerability exists in Artica Pandora FMS 742, exploitable by the lowest privileged user. | ||||
| CVE-2021-32099 | 1 Artica | 1 Pandora Fms | 2024-11-21 | 9.8 Critical |
| A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass. | ||||
| CVE-2021-32098 | 1 Artica | 1 Pandora Fms | 2024-11-21 | 9.8 Critical |
| Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization. | ||||