Search Results (119144 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-26935 1 Wowonder 1 Wowonder 2024-11-21 7.5 High
In WoWonder < 3.1, remote attackers can gain access to the database by exploiting a requests.php?f=search-my-followers SQL Injection vulnerability via the event_id parameter.
CVE-2021-26916 1 Nopcommerce 1 Nopcommerce 2024-11-21 6.1 Medium
In nopCommerce 4.30, a Reflected XSS issue in the Discount Coupon component allows remote attackers to inject arbitrary web script or HTML through the Filters/CheckDiscountCouponAttribute.cs discountcode parameter.
CVE-2021-26915 1 Netmotionsoftware 1 Netmotion Mobility 2024-11-21 8.1 High
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in webrepdb StatusServlet.
CVE-2021-26914 1 Netmotionsoftware 1 Netmotion Mobility 2024-11-21 8.1 High
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in MvcUtil valueStringToObject.
CVE-2021-26913 1 Netmotionsoftware 1 Netmotion Mobility 2024-11-21 8.1 High
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in RpcServlet.
CVE-2021-26912 1 Netmotionsoftware 1 Netmotion Mobility 2024-11-21 8.1 High
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in SupportRpcServlet.
CVE-2021-26906 1 Digium 2 Asterisk, Certified Asterisk 2024-11-21 5.9 Medium
An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.x through 18.2.0, and Certified Asterisk through 16.8-cert5. An SDP negotiation vulnerability in PJSIP allows a remote server to potentially crash Asterisk by sending specific SIP responses that cause an SDP negotiation failure.
CVE-2021-26902 1 Microsoft 1 High Efficiency Video Coding 2024-11-21 7.8 High
HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-26897 1 Microsoft 10 Windows Server 1909, Windows Server 2004, Windows Server 2008 and 7 more 2024-11-21 9.8 Critical
Windows DNS Server Remote Code Execution Vulnerability
CVE-2021-26895 1 Microsoft 10 Windows Server 1909, Windows Server 2004, Windows Server 2008 and 7 more 2024-11-21 9.8 Critical
Windows DNS Server Remote Code Execution Vulnerability
CVE-2021-26894 1 Microsoft 10 Windows Server 1909, Windows Server 2004, Windows Server 2008 and 7 more 2024-11-21 9.8 Critical
Windows DNS Server Remote Code Execution Vulnerability
CVE-2021-26893 1 Microsoft 10 Windows Server 1909, Windows Server 2004, Windows Server 2008 and 7 more 2024-11-21 9.8 Critical
Windows DNS Server Remote Code Execution Vulnerability
CVE-2021-26890 1 Microsoft 9 Windows 10, Windows 10 1809, Windows 10 1909 and 6 more 2024-11-21 7.8 High
Application Virtualization Remote Code Execution Vulnerability
CVE-2021-26882 1 Microsoft 20 Windows 10, Windows 10 1507, Windows 10 1607 and 17 more 2024-11-21 7.8 High
Remote Access API Elevation of Privilege Vulnerability
CVE-2021-26881 1 Microsoft 19 Windows 10, Windows 10 1507, Windows 10 1607 and 16 more 2024-11-21 7.5 High
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2021-26877 1 Microsoft 10 Windows Server 1909, Windows Server 2004, Windows Server 2008 and 7 more 2024-11-21 9.8 Critical
Windows DNS Server Remote Code Execution Vulnerability
CVE-2021-26876 1 Microsoft 10 Windows 10, Windows 10 1803, Windows 10 1809 and 7 more 2024-11-21 8.8 High
OpenType Font Parsing Remote Code Execution Vulnerability
CVE-2021-26867 1 Microsoft 7 Windows 10, Windows 10 1809, Windows 10 1909 and 4 more 2024-11-21 9.9 Critical
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2021-26861 1 Microsoft 20 Windows 10, Windows 10 1507, Windows 10 1607 and 17 more 2024-11-21 7.8 High
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2021-26854 1 Microsoft 1 Exchange Server 2024-11-21 6.6 Medium
Microsoft Exchange Server Remote Code Execution Vulnerability