Export limit exceeded: 374076 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (374076 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-33116 | 2025-09-04 | N/A | ||
| This is unused. | ||||
| CVE-2021-33112 | 2025-09-04 | N/A | ||
| This is unused. | ||||
| CVE-2021-33111 | 2025-09-04 | N/A | ||
| This is unused. | ||||
| CVE-2021-33109 | 2025-09-04 | N/A | ||
| This is unused. | ||||
| CVE-2021-33102 | 2025-09-04 | N/A | ||
| This is unused. | ||||
| CVE-2021-33100 | 2025-09-04 | N/A | ||
| This is unused. | ||||
| CVE-2021-33099 | 2025-09-04 | N/A | ||
| This is unused. | ||||
| CVE-2021-33085 | 2025-09-04 | N/A | ||
| This is unused. | ||||
| CVE-2021-33084 | 2025-09-04 | N/A | ||
| This is unused. | ||||
| CVE-2021-33072 | 2025-09-04 | N/A | ||
| This is unused. | ||||
| CVE-2024-36535 | 1 Layer5 | 1 Meshery | 2025-09-03 | 9.8 Critical |
| Insecure permissions in meshery v0.7.51 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. | ||||
| CVE-2024-42050 | 1 Splashtop | 1 Streamer | 2025-09-03 | 7 High |
| The MSI installer for Splashtop Streamer for Windows before 3.7.0.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM via an oplock on CredProvider_Inst.reg. | ||||
| CVE-2024-42051 | 1 Splashtop | 1 Streamer | 2025-09-03 | 7.8 High |
| The MSI installer for Splashtop Streamer for Windows before 3.6.2.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM by replacing InstRegExp.reg. | ||||
| CVE-2024-42053 | 1 Splashtop | 1 Streamer | 2025-09-03 | 7.8 High |
| The MSI installer for Splashtop Streamer for Windows before 3.6.0.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM by placing a version.dll file in the folder. | ||||
| CVE-2024-45165 | 1 Uci | 1 Idol2 | 2025-09-03 | 5.3 Medium |
| An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is sent between client and server with encryption. However, the key is derived from the string "(c)2007 UCI Software GmbH B.Boll" (without quotes). The key is both static and hardcoded. With access to messages, this results in message decryption and encryption by an attacker. Thus, it enables passive and active man-in-the-middle attacks. | ||||
| CVE-2024-45166 | 1 Uci | 2 Idol2, Idol 2 | 2025-09-03 | 9.8 Critical |
| An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper restriction of operations within the bounds of a memory buffer, IDOL2 is vulnerable to Denial-of-Service (DoS) attacks and possibly remote code execution. There is an access violation and EIP overwrite after five logins. | ||||
| CVE-2024-45167 | 1 Uci | 2 Idol2, Idol 2 | 2025-09-03 | 9.8 Critical |
| An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper restriction of operations within the bounds of a memory buffer, IDOL2 is vulnerable to Denial-of-Service (DoS) attacks and possibly remote code execution. A certain XmlMessage document causes 100% CPU consumption. | ||||
| CVE-2024-45168 | 1 Uci | 2 Idol2, Idol 2 | 2025-09-03 | 9.1 Critical |
| An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is transferred over a raw socket without any authentication mechanism. Thus, communication endpoints are not verifiable. | ||||
| CVE-2024-43031 | 2 Autman, Dlink | 2 Autman, Autman | 2025-09-03 | 4.3 Medium |
| autMan v2.9.6 was discovered to contain an access control issue. | ||||
| CVE-2024-43032 | 2 Autman, Dlink | 2 Autman, Autman | 2025-09-03 | 4.3 Medium |
| autMan v2.9.6 allows attackers to bypass authentication via a crafted web request. | ||||