Search Results (359796 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-41432 1 Flatpress 1 Flatpress 2024-11-21 5.4 Medium
A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands through blog content.
CVE-2021-41427 1 Beeline 2 Smart Box, Smart Box Firmware 2024-11-21 6.1 Medium
Beeline Smart Box 2.0.38 is vulnerable to Cross Site Scripting (XSS) via the choose_mac parameter to setup.cgi.
CVE-2021-41426 1 Beeline 2 Smart Box, Smart Box Firmware 2024-11-21 8.8 High
Beeline Smart box 2.0.38 is vulnerable to Cross Site Request Forgery (CSRF) via mgt_end_user.htm.
CVE-2021-41421 1 Maianmedia 1 Maianaffiliate 2024-11-21 4.8 Medium
A PHP code injection vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker to gain RCE through the MaianAffiliate admin panel.
CVE-2021-41420 1 Maianmedia 1 Maianaffiliate 2024-11-21 5.4 Medium
A stored XSS vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker for arbitrary JavaScript code execution in the context of authenticated and unauthenticated users through the MaianAffiliate admin panel.
CVE-2021-41419 1 Qvis 4 Dvr, Dvr Firmware, Nvr and 1 more 2024-11-21 9.8 Critical
QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization.
CVE-2021-41418 1 Ariang Project 1 Ariang 2024-11-21 9.8 Critical
AriaNg v0.1.0~v1.2.2 is affected by an incorrect access control vulnerability through not authenticating visitors' access rights.
CVE-2021-41415 1 Subscription-manager Project 1 Subscription-manager 2024-11-21 6.1 Medium
Subscription-Manager v1.0 /main.js has a cross-site scripting (XSS) vulnerability in the machineDetail parameter.
CVE-2021-41413 1 Ok-file-formats Project 1 Ok-file-formats 2024-11-21 7.8 High
ok-file-formats master 2021-9-12 is affected by a buffer overflow in ok_jpg_convert_data_unit_grayscale and ok_jpg_convert_YCbCr_to_RGB.
CVE-2021-41411 1 Redhat 1 Drools 2024-11-21 9.8 Critical
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.
CVE-2021-41408 1 Voipmonitor 1 Voipmonitor 2024-11-21 9.8 Critical
VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter.
CVE-2021-41403 1 Flatcore 1 Flatcore-cms 2024-11-21 9.8 Critical
flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities.
CVE-2021-41402 1 Flatcore 1 Flatcore-cms 2024-11-21 8.8 High
flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP code.
CVE-2021-41396 1 Live555 1 Live555 2024-11-21 7.5 High
Live555 through 1.08 does not handle socket connections properly. A huge number of incoming socket connections in a short time invokes the error-handling module, in which a heap-based buffer overflow happens. An attacker can leverage this to launch a DoS attack.
CVE-2021-41395 1 Goteleport 1 Teleport 2024-11-21 6.5 Medium
Teleport before 6.2.12 and 7.x before 7.1.1 allows attackers to control a database connection string, in some situations, via a crafted database name or username.
CVE-2021-41394 1 Goteleport 1 Teleport 2024-11-21 5.3 Medium
Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows alteration of build artifacts in some situations.
CVE-2021-41393 1 Goteleport 1 Teleport 2024-11-21 9.8 Critical
Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows forgery of SSH host certificates in some situations.
CVE-2021-41392 1 Boostnote 1 Boostnote 2024-11-21 9.8 Critical
static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal Electron API.
CVE-2021-41391 1 Ericsson 1 Enterprise Content Management 2024-11-21 5.4 Medium
In Ericsson ECM before 18.0, it was observed that Security Management Endpoint in User Profile Management Section is vulnerable to stored XSS via a name, leading to session hijacking and full account takeover.
CVE-2021-41390 1 Ericsson 1 Enterprise Content Management 2024-11-21 8.0 High
In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injection.