Export limit exceeded: 383188 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (383188 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-42330 1 Xinheinformation 1 Xinhe Teaching Platform System 2024-11-21 8.8 High
The “Teacher Edit” function of ShinHer StudyOnline System does not perform authority control. After logging in with user’s privilege, remote attackers can access and edit other users’ credential and personal information by crafting URL parameters.
CVE-2021-42329 1 Xinheinformation 1 Xinhe Teaching Platform System 2024-11-21 5.4 Medium
The “List_Add” function of message board of ShinHer StudyOnline System does not filter special characters in the title parameter. After logging in with user’s privilege, remote attackers can inject JavaScript and execute stored XSS attacks.
CVE-2021-42327 3 Fedoraproject, Linux, Netapp 18 Fedora, Linux Kernel, H300e and 15 more 2024-11-21 6.7 Medium
dp_link_settings_write in drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_debugfs.c in the Linux kernel through 5.14.14 allows a heap-based buffer overflow by an attacker who can write a string to the AMD GPU display drivers debug filesystem. There are no checks on size within parse_write_buffer_into_params when it uses the size of copy_from_user to copy a userspace buffer into a 40-byte heap buffer.
CVE-2021-42326 2 Debian, Redmine 2 Debian Linux, Redmine 2024-11-21 5.3 Medium
Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.
CVE-2021-42325 1 Froxlor 1 Froxlor 2024-11-21 9.8 Critical
Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.
CVE-2021-42324 1 Dcnglobal 2 S4600-10p-si, S4600-10p-si Firmware 2024-11-21 7.4 High
An issue was discovered on DCN (Digital China Networks) S4600-10P-SI devices before R0241.0470. Due to improper parameter validation in the console interface, it is possible for a low-privileged authenticated attacker to escape the sandbox environment and execute system commands as root via shell metacharacters in the capture command parameters. Command output will be shown on the Serial interface of the device. Exploitation requires both credentials and physical access.
CVE-2021-42320 1 Microsoft 2 Sharepoint Enterprise Server, Sharepoint Server 2024-11-21 8 High
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2021-42315 1 Microsoft 1 Defender For Iot 2024-11-21 8.8 High
Microsoft Defender for IoT Remote Code Execution Vulnerability
CVE-2021-42314 1 Microsoft 1 Defender For Iot 2024-11-21 8.8 High
Microsoft Defender for IoT Remote Code Execution Vulnerability
CVE-2021-42313 1 Microsoft 1 Defender For Iot 2024-11-21 10 Critical
Microsoft Defender for IoT Remote Code Execution Vulnerability
CVE-2021-42312 1 Microsoft 1 Defender For Iot 2024-11-21 7.8 High
Microsoft Defender for IoT Elevation of Privilege Vulnerability
CVE-2021-42311 1 Microsoft 1 Defender For Iot 2024-11-21 10 Critical
Microsoft Defender for IoT Remote Code Execution Vulnerability
CVE-2021-42310 1 Microsoft 1 Defender For Iot 2024-11-21 8.1 High
Microsoft Defender for IoT Remote Code Execution Vulnerability
CVE-2021-42309 1 Microsoft 3 Sharepoint Enterprise Server, Sharepoint Foundation, Sharepoint Server 2024-11-21 8.8 High
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2021-42299 1 Microsoft 2 Surface Pro 3, Surface Pro 3 Firmware 2024-11-21 5.6 Medium
Microsoft Surface Pro 3 Security Feature Bypass Vulnerability
CVE-2021-42294 1 Microsoft 3 Sharepoint Enterprise Server, Sharepoint Foundation, Sharepoint Server 2024-11-21 7.2 High
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2021-42262 1 Softing 3 Datafeed Opc Suite, Opc Ua C\+\+ Software Development Kit, Secure Integration Server 2024-11-21 6.5 Medium
An issue was discovered in Softing OPC UA C++ SDK before 5.70. An invalid XML element in the type dictionary makes the OPC/UA client crash due to an out-of-memory condition.
CVE-2021-42261 1 Revisorlab 1 Video Management System 2024-11-21 7.5 High
Revisor Video Management System (VMS) before 2.0.0 has a directory traversal vulnerability. Successful exploitation could allow an attacker to traverse the file system to access files or directories that are outside of restricted directory on the remote server. This could lead to the disclosure of sensitive data on the vulnerable server.
CVE-2021-42257 1 Check Smart Project 1 Check Smart 2024-11-21 7.1 High
check_smart before 6.9.1 allows unintended drive access by an unprivileged user because it only checks for a substring match of a device path (the /dev/bus substring and a number), aka an unanchored regular expression.
CVE-2021-42255 1 Blueplanet-works 1 Appguard 2024-11-21 7.8 High
AppGuard Enterprise before 6.7.100.1 creates a Temporary File in a Directory with Insecure Permissions. Local users can gain SYSTEM privileges because a repair operation relies on the %TEMP% directory of an unprivileged user.