Search Results (119148 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-27224 1 Irfanview 2 Irfanview, Wpg 2024-11-21 7.5 High
The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a user-mode write access violation starting at WPG+0x0000000000012ec6, which might allow remote attackers to execute arbitrary code.
CVE-2021-27222 1 Obss 1 Time In Status 2024-11-21 5.4 Medium
In the "Time in Status" app before 4.13.0 for Jira, remote authenticated attackers can cause Stored XSS.
CVE-2021-27221 1 Mikrotik 1 Routeros 2024-11-21 8.1 High
MikroTik RouterOS 6.47.9 allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /export command. NOTE: the vendor's position is that this is intended behavior because of how user policies work
CVE-2021-27214 1 Zohocorp 1 Manageengine Adselfservice Plus 2024-11-21 6.1 Medium
A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attack against the administrative interface via an HTTP request, a different vulnerability than CVE-2019-3905.
CVE-2021-27210 1 Tp-link 2 Archer C5v, Archer C5v Firmware 2024-11-21 6.5 Medium
TP-Link Archer C5v 1.7_181221 devices allows remote attackers to retrieve cleartext credentials via [USER_CFG#0,0,0,0,0,0#0,0,0,0,0,0]0,0 to the /cgi?1&5 URI.
CVE-2021-27201 1 Endian 1 Firewall Community 2024-11-21 8.8 High
Endian Firewall Community (aka EFW) 3.3.2 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in a backup comment.
CVE-2021-27200 1 Wowonder 1 Wowonder 2024-11-21 9.8 Critical
In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day.
CVE-2021-27198 1 Visualware 1 Myconnection Server 2024-11-21 9.8 Critical
An issue was discovered in Visualware MyConnection Server before v11.1a. Unauthenticated Remote Code Execution can occur via Arbitrary File Upload in the web service when using a myspeed/sf?filename= URI. This application is written in Java and is thus cross-platform. The Windows installation runs as SYSTEM, which means that exploitation gives one Administrator privileges on the target system.
CVE-2021-27197 1 Pelco 1 Digital Sentry Server 2024-11-21 8.1 High
DSUtility.dll in Pelco Digital Sentry Server before 7.19.67 has an arbitrary file write vulnerability. The AppendToTextFile method doesn't check if it's being called from the application or from a malicious user. The vulnerability is triggered when a remote attacker crafts an HTML page (e.g., with "OBJECT classid=" and "<SCRIPT language='vbscript'>") to overwrite arbitrary files.
CVE-2021-27194 2 Microsoft, Netop 2 Windows, Vision Pro 2024-11-21 8.8 High
Cleartext transmission of sensitive information in Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to gather credentials including Windows login usernames and passwords.
CVE-2021-27193 2 Microsoft, Netop 2 Windows, Vision Pro 2024-11-21 9.8 Critical
Incorrect default permissions vulnerability in the API of Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to read and write files on the remote machine with system privileges resulting in a privilege escalation.
CVE-2021-27183 1 Altn 1 Mdaemon 2024-11-21 7.2 High
An issue was discovered in MDaemon before 20.0.4. Administrators can use Remote Administration to exploit an Arbitrary File Write vulnerability. An attacker is able to create new files in any location of the filesystem, or he may be able to modify existing files. This vulnerability may directly lead to Remote Code Execution.
CVE-2021-27181 1 Altn 1 Mdaemon 2024-11-21 8.8 High
An issue was discovered in MDaemon before 20.0.4. Remote Administration allows an attacker to perform a fixation of the anti-CSRF token. In order to exploit this issue, the user has to click on a malicious URL provided by the attacker and successfully authenticate into the application. Having the value of the anti-CSRF token, the attacker may trick the user into visiting his malicious page and performing any request with the privileges of attacked user.
CVE-2021-27135 4 Debian, Fedoraproject, Invisible-island and 1 more 5 Debian Linux, Fedora, Xterm and 2 more 2024-11-21 9.8 Critical
xterm before Patch #366 allows remote attackers to execute arbitrary code or cause a denial of service (segmentation fault) via a crafted UTF-8 combining character sequence.
CVE-2021-27112 1 Lightcms Project 1 Lightcms 2024-11-21 9.8 Critical
LightCMS v1.3.5 contains a remote code execution vulnerability in /app/Http/Controllers/Admin/NEditorController.php during the downloading of external images.
CVE-2021-27095 1 Microsoft 20 Windows 10, Windows 10 1507, Windows 10 1607 and 17 more 2024-11-21 7.8 High
Windows Media Video Decoder Remote Code Execution Vulnerability
CVE-2021-27089 1 Microsoft 20 Windows 10, Windows 10 1507, Windows 10 1607 and 17 more 2024-11-21 7.8 High
Microsoft Internet Messaging API Remote Code Execution Vulnerability
CVE-2021-27083 1 Microsoft 1 Remote Development 2024-11-21 7.8 High
Remote Development Extension for Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-27082 1 Microsoft 1 Quantum Development Kit 2024-11-21 7.8 High
Quantum Development Kit for Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-27078 1 Microsoft 1 Exchange Server 2024-11-21 9.1 Critical
Microsoft Exchange Server Remote Code Execution Vulnerability