Export limit exceeded: 371938 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (371938 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-29263 | 1 Jetbrains | 1 Intellij Idea | 2024-11-21 | 7.8 High |
| In JetBrains IntelliJ IDEA 2020.3.3, local code execution was possible because of insufficient checks when getting the project from VCS. | ||||
| CVE-2021-29262 | 1 Apache | 1 Solr | 2024-11-21 | 7.5 High |
| When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the optional read-only user is configured then Solr would not treat that node as a sensitive path and would allow it to be readable. Additionally, with any ZkACLProvider, if the security.json is already present, Solr will not automatically update the ACLs. | ||||
| CVE-2021-29261 | 1 Svelte | 1 Svelte | 2024-11-21 | 7.8 High |
| The unofficial Svelte extension before 104.8.0 for Visual Studio Code allows attackers to execute arbitrary code via a crafted workspace configuration. | ||||
| CVE-2021-29258 | 2 Envoyproxy, Redhat | 2 Envoy, Service Mesh | 2024-11-21 | 7.5 High |
| An issue was discovered in Envoy 1.14.0. There is a remotely exploitable crash for HTTP2 Metadata, because an empty METADATA map triggers a Reachable Assertion. | ||||
| CVE-2021-29255 | 1 Microseven | 2 Mym71080i-b, Mym71080i-b Firmware | 2024-11-21 | 7.5 High |
| MicroSeven MYM71080i-B 2.0.5 through 2.0.20 devices send admin credentials in cleartext to pnp.microseven.com TCP port 7007. An attacker on the same network as the device can capture these credentials. | ||||
| CVE-2021-29253 | 1 Rsa | 1 Archer | 2024-11-21 | 5.1 Medium |
| The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential storage vulnerability. An malicious attacker with access to the Tableau workbook file may obtain access to credential information to use it in further attacks. | ||||
| CVE-2021-29252 | 1 Rsa | 1 Archer | 2024-11-21 | 5.4 Medium |
| RSA Archer before 6.9 SP1 P1 (6.9.1.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user with access to modify link name fields could potentially exploit this vulnerability to execute code in a victim's browser. | ||||
| CVE-2021-29251 | 1 Btcpayserver | 1 Btcpay Server | 2024-11-21 | 6.5 Medium |
| BTCPay Server before 1.0.7.1 mishandles the policy setting in which users can register (in Server Settings > Policies). This affects Docker use cases in which a mail server is configured. | ||||
| CVE-2021-29250 | 1 Btcpayserver | 1 Btcpay Server | 2024-11-21 | 5.4 Medium |
| BTCPay Server through 1.0.7.0 suffers from a Stored Cross Site Scripting (XSS) vulnerability within the POS Add Products functionality. This enables cookie stealing. | ||||
| CVE-2021-29249 | 1 Btcpayserver | 1 Btcpay Server | 2024-11-21 | 7.5 High |
| BTCPay Server before 1.0.6.0, when the payment button is used, has a privacy vulnerability. | ||||
| CVE-2021-29248 | 1 Btcpayserver | 1 Btcpay Server | 2024-11-21 | 5.3 Medium |
| BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the Secure flag for a cookie. | ||||
| CVE-2021-29247 | 1 Btcpayserver | 1 Btcpay Server | 2024-11-21 | 5.3 Medium |
| BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the HTTPOnly flag for a cookie. | ||||
| CVE-2021-29246 | 1 Btcpayserver | 1 Btcpay Server | 2024-11-21 | 6.7 Medium |
| BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacker must craft a malicious plugin file with special characters to upload the file outside of the restricted directory. | ||||
| CVE-2021-29245 | 1 Btcpayserver | 1 Btcpay Server | 2024-11-21 | 5.3 Medium |
| BTCPay Server through 1.0.7.0 uses a weak method Next to produce pseudo-random values to generate a legacy API key. | ||||
| CVE-2021-29243 | 1 Cloudera | 1 Cloudera Manager | 2024-11-21 | 6.1 Medium |
| Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS. | ||||
| CVE-2021-29242 | 1 Codesys | 22 Control For Beaglebone Sl, Control For Empc-a\/imx6 Sl, Control For Iot2000 Sl and 19 more | 2024-11-21 | 7.3 High |
| CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages. | ||||
| CVE-2021-29240 | 1 Codesys | 1 Development System | 2024-11-21 | 7.8 High |
| The Package Manager of CODESYS Development System 3 before 3.5.17.0 does not check the validity of packages before installation and may be used to install CODESYS packages with malicious content. | ||||
| CVE-2021-29239 | 1 Codesys | 1 Development System | 2024-11-21 | 7.8 High |
| CODESYS Development System 3 before 3.5.17.0 displays or executes malicious documents or files embedded in libraries without first checking their validity. | ||||
| CVE-2021-29238 | 1 Codesys | 1 Automation Server | 2024-11-21 | 8.8 High |
| CODESYS Automation Server before 1.16.0 allows cross-site request forgery (CSRF). | ||||
| CVE-2021-29221 | 2 Erlang, Microsoft | 2 Erlang\/otp, Windows | 2024-11-21 | 7.0 High |
| A local privilege escalation vulnerability was discovered in Erlang/OTP prior to version 23.2.3. By adding files to an existing installation's directory, a local attacker could hijack accounts of other users running Erlang programs or possibly coerce a service running with "erlsrv.exe" to execute arbitrary code as Local System. This can occur only under specific conditions on Windows with unsafe filesystem permissions. | ||||