Export limit exceeded: 372093 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (372093 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-28317 | 1 Microsoft | 20 Windows 10, Windows 10 1507, Windows 10 1607 and 17 more | 2024-11-21 | 5.5 Medium |
| Microsoft Windows Codecs Library Information Disclosure Vulnerability | ||||
| CVE-2021-28316 | 1 Microsoft | 19 Windows 10, Windows 10 1507, Windows 10 1607 and 16 more | 2024-11-21 | 4.2 Medium |
| Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability | ||||
| CVE-2021-28315 | 1 Microsoft | 20 Windows 10, Windows 10 1507, Windows 10 1607 and 17 more | 2024-11-21 | 7.8 High |
| Windows Media Video Decoder Remote Code Execution Vulnerability | ||||
| CVE-2021-28314 | 1 Microsoft | 9 Windows 10, Windows 10 1809, Windows 10 1909 and 6 more | 2024-11-21 | 7.8 High |
| Windows Hyper-V Elevation of Privilege Vulnerability | ||||
| CVE-2021-28313 | 1 Microsoft | 13 Visual Studio, Visual Studio 2017, Visual Studio 2019 and 10 more | 2024-11-21 | 7.8 High |
| Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability | ||||
| CVE-2021-28312 | 1 Microsoft | 9 Windows 10, Windows 10 1809, Windows 10 1909 and 6 more | 2024-11-21 | 3.3 Low |
| Windows NTFS Denial of Service Vulnerability | ||||
| CVE-2021-28311 | 1 Microsoft | 11 Windows 10, Windows 10 1607, Windows 10 1803 and 8 more | 2024-11-21 | 6.5 Medium |
| Windows Application Compatibility Cache Denial of Service Vulnerability | ||||
| CVE-2021-28309 | 1 Microsoft | 20 Windows 10, Windows 10 1507, Windows 10 1607 and 17 more | 2024-11-21 | 5.5 Medium |
| Windows Kernel Information Disclosure Vulnerability | ||||
| CVE-2021-28308 | 1 Fltk Project | 1 Fltk | 2024-11-21 | 9.1 Critical |
| An issue was discovered in the fltk crate before 0.15.3 for Rust. There is an out-of bounds read because the pixmap constructor lacks pixmap input validation. | ||||
| CVE-2021-28307 | 1 Fltk Project | 1 Fltk | 2024-11-21 | 7.5 High |
| An issue was discovered in the fltk crate before 0.15.3 for Rust. There is a NULL pointer dereference during attempted use of a non-raster image for a window icon. | ||||
| CVE-2021-28306 | 1 Fltk Project | 1 Fltk | 2024-11-21 | 7.5 High |
| An issue was discovered in the fltk crate before 0.15.3 for Rust. There is a NULL pointer dereference during attempted use of a multi label type if the image is nonexistent. | ||||
| CVE-2021-28305 | 1 Diesel | 1 Diesel | 2024-11-21 | 9.8 Critical |
| An issue was discovered in the diesel crate before 1.4.6 for Rust. There is a use-after-free in the SQLite backend because the semantics of sqlite3_column_name are not followed. | ||||
| CVE-2021-28302 | 1 Pupnp Project | 1 Pupnp | 2024-11-21 | 7.5 High |
| A stack overflow in pupnp before version 1.14.5 can cause the denial of service through the Parser_parseDocument() function. ixmlNode_free() will release a child node recursively, which will consume stack space and lead to a crash. | ||||
| CVE-2021-28300 | 1 Gpac | 1 Gpac | 2024-11-21 | 9.8 Critical |
| NULL Pointer Dereference in the "isomedia/track.c" module's "MergeTrack()" function of GPAC v0.5.2 allows attackers to execute arbitrary code or cause a Denial-of-Service (DoS) by uploading a malicious MP4 file. | ||||
| CVE-2021-28295 | 1 Online Ordering System Project | 1 Online Ordering System | 2024-11-21 | 7.5 High |
| Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure. | ||||
| CVE-2021-28294 | 1 Online Ordering System Project | 1 Online Ordering System | 2024-11-21 | 9.8 Critical |
| Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE). | ||||
| CVE-2021-28293 | 1 Seceon | 1 Aisiem | 2024-11-21 | 9.8 Critical |
| Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Password feature. The lack of correct configuration leads to recovery of the password reset link generated via the password reset functionality, and thus an unauthenticated attacker can set an arbitrary password for any user. | ||||
| CVE-2021-28290 | 1 Identityserver4.admin Project | 1 Identityserver4.admin | 2024-11-21 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in Skoruba IdentityServer4.Admin before 2.0.0 via unencoded value passed to the data-secret-value parameter. | ||||
| CVE-2021-28280 | 1 Php-fusion | 1 Phpfusion | 2024-11-21 | 6.1 Medium |
| CSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject arbitrary web script or HTML | ||||
| CVE-2021-28278 | 1 Jhead Project | 1 Jhead | 2024-11-21 | 7.8 High |
| A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c. | ||||