Export limit exceeded: 372128 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (372128 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-28312 | 1 Microsoft | 9 Windows 10, Windows 10 1809, Windows 10 1909 and 6 more | 2024-11-21 | 3.3 Low |
| Windows NTFS Denial of Service Vulnerability | ||||
| CVE-2021-28311 | 1 Microsoft | 11 Windows 10, Windows 10 1607, Windows 10 1803 and 8 more | 2024-11-21 | 6.5 Medium |
| Windows Application Compatibility Cache Denial of Service Vulnerability | ||||
| CVE-2021-28309 | 1 Microsoft | 20 Windows 10, Windows 10 1507, Windows 10 1607 and 17 more | 2024-11-21 | 5.5 Medium |
| Windows Kernel Information Disclosure Vulnerability | ||||
| CVE-2021-28308 | 1 Fltk Project | 1 Fltk | 2024-11-21 | 9.1 Critical |
| An issue was discovered in the fltk crate before 0.15.3 for Rust. There is an out-of bounds read because the pixmap constructor lacks pixmap input validation. | ||||
| CVE-2021-28307 | 1 Fltk Project | 1 Fltk | 2024-11-21 | 7.5 High |
| An issue was discovered in the fltk crate before 0.15.3 for Rust. There is a NULL pointer dereference during attempted use of a non-raster image for a window icon. | ||||
| CVE-2021-28306 | 1 Fltk Project | 1 Fltk | 2024-11-21 | 7.5 High |
| An issue was discovered in the fltk crate before 0.15.3 for Rust. There is a NULL pointer dereference during attempted use of a multi label type if the image is nonexistent. | ||||
| CVE-2021-28305 | 1 Diesel | 1 Diesel | 2024-11-21 | 9.8 Critical |
| An issue was discovered in the diesel crate before 1.4.6 for Rust. There is a use-after-free in the SQLite backend because the semantics of sqlite3_column_name are not followed. | ||||
| CVE-2021-28302 | 1 Pupnp Project | 1 Pupnp | 2024-11-21 | 7.5 High |
| A stack overflow in pupnp before version 1.14.5 can cause the denial of service through the Parser_parseDocument() function. ixmlNode_free() will release a child node recursively, which will consume stack space and lead to a crash. | ||||
| CVE-2021-28300 | 1 Gpac | 1 Gpac | 2024-11-21 | 9.8 Critical |
| NULL Pointer Dereference in the "isomedia/track.c" module's "MergeTrack()" function of GPAC v0.5.2 allows attackers to execute arbitrary code or cause a Denial-of-Service (DoS) by uploading a malicious MP4 file. | ||||
| CVE-2021-28295 | 1 Online Ordering System Project | 1 Online Ordering System | 2024-11-21 | 7.5 High |
| Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure. | ||||
| CVE-2021-28294 | 1 Online Ordering System Project | 1 Online Ordering System | 2024-11-21 | 9.8 Critical |
| Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE). | ||||
| CVE-2021-28293 | 1 Seceon | 1 Aisiem | 2024-11-21 | 9.8 Critical |
| Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Password feature. The lack of correct configuration leads to recovery of the password reset link generated via the password reset functionality, and thus an unauthenticated attacker can set an arbitrary password for any user. | ||||
| CVE-2021-28290 | 1 Identityserver4.admin Project | 1 Identityserver4.admin | 2024-11-21 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in Skoruba IdentityServer4.Admin before 2.0.0 via unencoded value passed to the data-secret-value parameter. | ||||
| CVE-2021-28280 | 1 Php-fusion | 1 Phpfusion | 2024-11-21 | 6.1 Medium |
| CSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject arbitrary web script or HTML | ||||
| CVE-2021-28278 | 1 Jhead Project | 1 Jhead | 2024-11-21 | 7.8 High |
| A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c. | ||||
| CVE-2021-28277 | 1 Jhead Project | 1 Jhead | 2024-11-21 | 7.8 High |
| A Heap-based Buffer Overflow vulnerabilty exists in jhead 3.04 and 3.05 is affected by: Buffer Overflow via the RemoveUnknownSections function in jpgfile.c. | ||||
| CVE-2021-28276 | 1 Jhead Project | 1 Jhead | 2024-11-21 | 7.5 High |
| A Denial of Service vulnerability exists in jhead 3.04 and 3.05 via a wild address read in the ProcessCanonMakerNoteDir function in makernote.c. | ||||
| CVE-2021-28275 | 1 Jhead Project | 1 Jhead | 2024-11-21 | 5.5 Medium |
| A Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the Get16u function in exif.c in will cause segmentation fault via a crafted_file. | ||||
| CVE-2021-28271 | 1 Soyal | 3 701clientsql, 701server, 701serversql | 2024-11-21 | 8.8 High |
| Soyal Technologies SOYAL 701Server 9.0.1 suffers from an elevation of privileges vulnerability which can be used by an authenticated user to change the executable file with a binary choice. The vulnerability is due to improper permissions with the 'F' flag (Full) for 'Everyone'and 'Authenticated Users' group. | ||||
| CVE-2021-28269 | 1 Soyal | 1 701client | 2024-11-21 | 8.8 High |
| Soyal Technology 701Client 9.0.1 is vulnerable to Insecure permissions via client.exe binary with Authenticated Users group with Full permissions. | ||||