Search
Search Results (310820 CVEs found)
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2021-33121 | 2025-09-04 | N/A | ||
This is unused. | ||||
CVE-2021-33116 | 2025-09-04 | N/A | ||
This is unused. | ||||
CVE-2021-33112 | 2025-09-04 | N/A | ||
This is unused. | ||||
CVE-2021-33111 | 2025-09-04 | N/A | ||
This is unused. | ||||
CVE-2021-33109 | 2025-09-04 | N/A | ||
This is unused. | ||||
CVE-2021-33102 | 2025-09-04 | N/A | ||
This is unused. | ||||
CVE-2021-33100 | 2025-09-04 | N/A | ||
This is unused. | ||||
CVE-2021-33099 | 2025-09-04 | N/A | ||
This is unused. | ||||
CVE-2021-33085 | 2025-09-04 | N/A | ||
This is unused. | ||||
CVE-2021-33084 | 2025-09-04 | N/A | ||
This is unused. | ||||
CVE-2021-33072 | 2025-09-04 | N/A | ||
This is unused. | ||||
CVE-2025-3935 | 1 Connectwise | 1 Screenconnect | 2025-09-03 | 8.1 High |
ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by machine keys. It is important to note that to obtain these machine keys, privileged system level access must be obtained. If these machine keys are compromised, attackers could create and send a malicious ViewState to the website, potentially leading to remote code execution on the server. The risk does not originate from a vulnerability introduced by ScreenConnect, but from platform level behavior. This had no direct impact to ScreenConnect Client. ScreenConnect 2025.4 patch disables ViewState and removes any dependency on it. | ||||
CVE-2025-9809 | 1 Libretro | 1 Libretro | 2025-09-03 | N/A |
Out-of-bounds write in cdfs_open_cue_track in libretro libretro-common latest on all platforms allows remote attackers to execute arbitrary code via a crafted .cue file with a file path exceeding PATH_MAX_LENGTH that is copied using memcpy into a fixed-size buffer. | ||||
CVE-2025-7519 | 1 Redhat | 3 Enterprise Linux, Openshift, Openshift Container Platform | 2025-09-03 | 6.7 Medium |
A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code execution is not discarded. To exploit this flaw, a high-privilege account is needed as it's required to place the malicious policy file properly. | ||||
CVE-2024-12924 | 1 Akinsoft | 1 Qr Menu | 2025-09-03 | 6.3 Medium |
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Akınsoft QR Menü allows Forceful Browsing, Phishing.This issue affects QR Menü: from s1.05.05 before v1.05.12. | ||||
CVE-2024-12914 | 1 Akinsoft | 1 Qr Menu | 2025-09-03 | 4.3 Medium |
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akınsoft QR Menü allows Cross-Site Scripting (XSS).This issue affects QR Menü: from s1.05.05 before v1.05.12. | ||||
CVE-2025-0610 | 1 Akinsoft | 1 Qr Menu | 2025-09-03 | 8.6 High |
Cross-Site Request Forgery (CSRF) vulnerability in Akınsoft QR Menü allows Cross Site Request Forgery.This issue affects QR Menü: from s1.05.06 before v1.05.12. | ||||
CVE-2024-12925 | 1 Akinsoft | 1 Qr Menu | 2025-09-03 | 7.3 High |
Improper Validation of Certificate with Host Mismatch vulnerability in Akınsoft QR Menü allows HTTP Response Splitting.This issue affects QR Menü: from s1.05.05 before v1.05.12. | ||||
CVE-2025-2412 | 1 Akinsoft | 1 Qr Menu | 2025-09-03 | 8.6 High |
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft QR Menu allows Authentication Bypass.This issue affects QR Menu: from s1.05.07 before v1.05.12. | ||||
CVE-2024-12974 | 1 Akinsoft | 1 Prokuaför | 2025-09-03 | 4.3 Medium |
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft ProKuaför allows Cross-Site Scripting (XSS).This issue affects ProKuaför: from s1.02.07 before v1.02.08. |