Export limit exceeded: 367922 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (367922 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-26809 1 Phpgurukul 1 Car Rental Portal 2024-11-21 9.8 Critical
PHPGurukul Car Rental Project version 2.0 suffers from a remote shell upload vulnerability in changeimage1.php.
CVE-2021-26807 1 Gog 1 Galaxy 2024-11-21 7.8 High
GalaxyClient version 2.0.28.9 loads unsigned DLLs such as zlib1.dll, libgcc_s_dw2-1.dll and libwinpthread-1.dll from PATH, which allows an attacker to potentially run code locally through unsigned DLL loading.
CVE-2021-26805 1 Tsmuxer Project 1 Tsmuxer 2024-11-21 5.5 Medium
Buffer Overflow in tsMuxer 2.6.16 allows attackers to cause a Denial of Service (DoS) by running the application with a malicious WAV file.
CVE-2021-26804 1 Centreon 1 Centreon Web 2024-11-21 6.5 Medium
Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by changing any file extension to ".gif", then uploading it in the "Administration/ Parameters/ Images" section of the application.
CVE-2021-26800 1 User Management System In Php Stored Procedure Project 1 User Management System In Php Stored Procedure 2024-11-21 6.5 Medium
Cross Site Request Forgery (CSRF) vulnerability in Change-password.php in phpgurukul user management system in php using stored procedure V1.0, allows attackers to change the password to an arbitrary account.
CVE-2021-26799 1 Omeka 1 Omeka 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability in admin/files/edit in Omeka Classic <=2.7 allows remote attackers to inject arbitrary web script or HTML.
CVE-2021-26797 1 Hametech 2 Hame Sd1 Wi-fi, Hame Sd1 Wi-fi Firmware 2024-11-21 9.8 Critical
An access control vulnerability in Hame SD1 Wi-Fi firmware <=V.20140224154640 allows an attacker to get system administrator through an open Telnet service.
CVE-2021-26795 1 Talariax 1 Sendquick Alert Plus Server Admin 2024-11-21 8.8 High
A SQL Injection vulnerability in /appliance/shiftmgn.php in TalariaX sendQuick Alert Plus Server Admin 4.3 before 8HF11 allows attackers to obtain sensitive information via a Roster Time to Roster Management.
CVE-2021-26794 1 Frogcms Project 1 Frogcms 2024-11-21 9.8 Critical
Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php file.
CVE-2021-26788 1 Oryx-embedded 1 Cyclonetcp 2024-11-21 7.5 High
Oryx Embedded CycloneTCP 1.7.6 to 2.0.0, fixed in 2.0.2, is affected by incorrect input validation, which may cause a denial of service (DoS). To exploit the vulnerability, an attacker needs to have TCP connectivity to the target system. Receiving a maliciously crafted TCP packet from an unauthenticated endpoint is sufficient to trigger the bug.
CVE-2021-26786 1 Playtuber Project 1 Playtuber 2024-11-21 8.8 High
An issue was discoverered in in customercentric-selling-poland PlayTube, allows authenticated attackers to execute arbitrary code via the purchace code to the config.php.
CVE-2021-26777 1 Circutor 2 Compact Dc-s Basic, Compact Dc-s Basic Firmware 2024-11-21 9.8 Critical
Buffer overflow vulnerability in function SetFirewall in index.cgi in CIRCUTOR COMPACT DC-S BASIC smart metering concentrator Firwmare version CIR_CDC_v1.2.17, allows attackers to execute arbitrary code.
CVE-2021-26776 1 Cszcms 1 Csz Cms 2024-11-21 5.4 Medium
CSZ CMS 1.2.9 is affected by a cross-site scripting (XSS) vulnerability in multiple pages through the field name.
CVE-2021-26765 1 Phpgurukul 1 Student Record System 2024-11-21 9.8 Critical
SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the sid parameter to edit-sub.php.
CVE-2021-26764 1 Phpgurukul 1 Student Record System 2024-11-21 8.8 High
SQL injection vulnerability in PHPGurukul Student Record System v 4.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit-std.php.
CVE-2021-26762 1 Phpgurukul 1 Student Record System 2024-11-21 8.8 High
SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the cid parameter to edit-course.php.
CVE-2021-26758 1 Litespeedtech 1 Openlitespeed 2024-11-21 8.8 High
Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and execute commands on the host system.
CVE-2021-26754 1 Wpdatatables 1 Wpdatatables 2024-11-21 9.8 Critical
wpDataTables before 3.4.1 mishandles order direction for server-side tables, aka admin-ajax.php?action=get_wdtable order[0][dir] SQL injection.
CVE-2021-26753 1 Nedi 1 Nedi 2024-11-21 9.9 Critical
NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.
CVE-2021-26752 1 Nedi 1 Nedi 2024-11-21 8.8 High
NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php via the md or ag HTTP GET parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.