Export limit exceeded: 373062 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 373062 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (373062 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-34280 1 Polarisoffice 1 Polaris Office 2024-11-21 7.8 High
Polaris Office v9.103.83.44230 is affected by a Uninitialized Pointer Vulnerability in PolarisOffice.exe and EngineDLL.dll that may cause a Remote Code Execution. To exploit the vulnerability, someone must open a crafted PDF file.
CVE-2021-34273 1 B2x Project 1 B2x 2024-11-21 7.5 High
A security flaw in the 'owned' function of a smart contract implementation for BTC2X (B2X), a tradeable Ethereum ERC20 token, allows attackers to hijack victim accounts and arbitrarily increase the digital supply of assets.
CVE-2021-34272 1 Robotbtc Project 1 Robotbtc 2024-11-21 7.5 High
A security flaw in the 'owned' function of a smart contract implementation for RobotCoin (RBTC), a tradeable Ethereum ERC20 token, allows attackers to hijack victim accounts and arbitrarily increase the digital supply of assets.
CVE-2021-34270 1 Doft 1 Doftcoin 2024-11-21 7.5 High
An integer overflow in the mintToken function of a smart contract implementation for Doftcoin Token, an Ethereum ERC20 token, allows the owner to cause unexpected financial losses.
CVE-2021-34268 1 St 2 Stm32cube Middleware, Stm32h7b3 2024-11-21 4.6 Medium
An issue in the USBH_ParseDevDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial of service (DOS) via a malformed USB device packet.
CVE-2021-34267 1 St 2 Stm32cube Middleware, Stm32h7b3 2024-11-21 4.6 Medium
An in the USBH_MSC_InterfaceInit() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial of service (DOS) when the system tries to communicate with the connected endpoint.
CVE-2021-34262 1 St 2 Stm32cube Middleware, Stm32h7b3 2024-11-21 6.8 Medium
A buffer overflow vulnerability in the USBH_ParseEPDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code.
CVE-2021-34261 1 St 2 Stm32cube Middleware, Stm32h7b3 2024-11-21 4.6 Medium
An issue in USBH_ParseCfgDesc() of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial of service due to the system hanging when trying to set a remote wake-up feature.
CVE-2021-34260 1 St 2 Stm32cube Middleware, Stm32h7b3 2024-11-21 6.8 Medium
A buffer overflow vulnerability in the USBH_ParseInterfaceDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code.
CVE-2021-34259 1 St 2 Stm32cube Middleware, Stm32h7b3 2024-11-21 6.8 Medium
A buffer overflow vulnerability in the USBH_ParseCfgDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code.
CVE-2021-34257 1 Wpanel Cms Project 1 Wpanel Cms 2024-11-21 8.8 High
Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload to (1) Dashboard's Avatar image, (2) Posts Folder image, (3) Pages Folder image and (4) Gallery Folder image.
CVE-2021-34254 1 Umbraco 1 Umbraco Cms 2024-11-21 6.1 Medium
Umbraco CMS before 7.15.7 is vulnerable to Open Redirection due to insufficient url sanitization on booting.aspx.
CVE-2021-34244 1 Icehrm 1 Icehrm 2024-11-21 8.8 High
A cross site request forgery (CSRF) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to create new admin accounts or change users' passwords.
CVE-2021-34243 1 Icehrm 1 Icehrm 2024-11-21 5.4 Medium
A stored cross site scripting (XSS) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to execute arbitrary web scripts or HTML via a crafted file uploaded into the Document Management tab. The exploit is triggered when a user visits the upload location of the crafted file.
CVE-2021-34236 1 Netgear 2 R8000, R8000 Firmware 2024-11-21 9.8 Critical
Buffer Overflow in Netgear R8000 Router with firmware v1.0.4.56 allows remote attackers to execute arbitrary code or cause a denial-of-service by sending a crafted POST to '/bd_genie_create_account.cgi' with a sufficiently long parameter 'register_country'.
CVE-2021-34228 1 Totolink 2 A3002r, A3002r Firmware 2024-11-21 6.1 Medium
Cross-site scripting in parent_control.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Description" field and "Service Name" field.
CVE-2021-34223 1 Totolink 2 A3002r, A3002r Firmware 2024-11-21 6.1 Medium
Cross-site scripting in urlfilter.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "URL Address" field.
CVE-2021-34220 1 Totolink 2 A3002r, A3002r Firmware 2024-11-21 6.1 Medium
Cross-site scripting in tr069config.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "User Name" field or "Password" field.
CVE-2021-34218 1 Totolink 2 A3002r, A3002r Firmware 2024-11-21 5.3 Medium
Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /add/ , /img/, /js/, and /mobile directories via GET Parameter.
CVE-2021-34215 1 Totolink 2 A3002r, A3002r Firmware 2024-11-21 6.1 Medium
Cross-site scripting in tcpipwan.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Service Name" field.