Search Results (119493 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-32092 1 Nsa 1 Emissary 2024-11-21 6.1 Medium
A Cross-site scripting (XSS) vulnerability in the DocumentAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows remote attackers to inject arbitrary web script or HTML via the uuid parameter.
CVE-2021-32073 1 Dedecms 1 Dedecms 2024-11-21 8.8 High
DedeCMS V5.7 SP2 contains a CSRF vulnerability that allows a remote attacker to send a malicious request to to the web manager allowing remote code execution.
CVE-2021-32056 2 Cyrus, Fedoraproject 2 Imap, Fedora 2024-11-21 4.3 Medium
Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall.
CVE-2021-31985 1 Microsoft 1 Malware Protection Engine 2024-11-21 7.8 High
Microsoft Defender Remote Code Execution Vulnerability
CVE-2021-31984 1 Microsoft 1 Power Bi Report Server 2024-11-21 7.6 High
Power BI Remote Code Execution Vulnerability
CVE-2021-31980 1 Microsoft 1 Intune Management Extension 2024-11-21 8.1 High
Microsoft Intune Management Extension Remote Code Execution Vulnerability
CVE-2021-31968 1 Microsoft 18 Windows 10, Windows 10 1507, Windows 10 1607 and 15 more 2024-11-21 7.5 High
Windows Remote Desktop Services Denial of Service Vulnerability
CVE-2021-31967 1 Microsoft 1 Vp9 Video Extensions 2024-11-21 7.8 High
VP9 Video Extensions Remote Code Execution Vulnerability
CVE-2021-31966 1 Microsoft 2 Sharepoint Foundation, Sharepoint Server 2024-11-21 7.2 High
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2021-31963 1 Microsoft 2 Sharepoint Foundation, Sharepoint Server 2024-11-21 7.1 High
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2021-31947 1 Microsoft 1 Hevc Video Extensions 2024-11-21 7.8 High
HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-31945 1 Microsoft 1 Paint 3d 2024-11-21 7.8 High
Paint 3D Remote Code Execution Vulnerability
CVE-2021-31943 1 Microsoft 1 3d Viewer 2024-11-21 7.8 High
3D Viewer Remote Code Execution Vulnerability
CVE-2021-31941 1 Microsoft 3 365 Apps, Office, Outlook 2024-11-21 7.8 High
Microsoft Office Graphics Remote Code Execution Vulnerability
CVE-2021-31940 1 Microsoft 2 365 Apps, Office 2024-11-21 7.8 High
Microsoft Office Graphics Remote Code Execution Vulnerability
CVE-2021-31939 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2024-11-21 7.8 High
Microsoft Excel Remote Code Execution Vulnerability
CVE-2021-31933 1 Chamilo 1 Chamilo 2024-11-21 7.2 High
A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filtering for certain filenames (e.g., .phar or .pht). A remote authenticated administrator is able to upload a file containing arbitrary PHP code into specific directories via main/inc/lib/fileUpload.lib.php directory traversal to achieve PHP code execution.
CVE-2021-31930 1 Concerto-signage 1 Concerto 2024-11-21 6.1 Medium
Persistent cross-site scripting (XSS) in the web interface of Concerto through 2.3.6 allows an unauthenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into the First Name or Last Name parameter upon registration. When a privileged user attempts to delete the account, the XSS payload will be executed.
CVE-2021-31926 1 Cubecoders 1 Amp 2024-11-21 6.5 Medium
AMP Application Deployment Service in CubeCoders AMP 2.1.x before 2.1.1.2 allows a remote, authenticated user to open ports in the local system firewall by crafting an HTTP(S) request directly to the applicable API endpoint (despite not having permission to make changes to the system's network configuration).
CVE-2021-31925 1 Pexip 1 Pexip Infinity 2024-11-21 7.5 High
Pexip Infinity 25.x before 25.4 has Improper Input Validation, and thus an unauthenticated remote attacker can cause a denial of service via the administrative web interface.