Search Results (325341 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-45833 1 Hdfgroup 1 Hdf5 2024-11-21 5.5 Medium
A Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 via the H5D__create_chunk_file_map_hyper function in /hdf5/src/H5Dchunk.c, which causes a Denial of Service (context-dependent).
CVE-2021-45832 1 Hdfgroup 1 Hdf5 2024-11-21 5.5 Medium
A Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 at at hdf5/src/H5Eint.c, which causes a Denial of Service (context-dependent).
CVE-2021-45831 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
A Null Pointer Dereference vulnerability exitgs in GPAC 1.0.1 in MP4Box via __strlen_avx2, which causes a Denial of Service.
CVE-2021-45830 1 Hdfgroup 1 Hdf5 2024-11-21 5.5 Medium
A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_decode_len in /hdf5/src/H5Fint.c, which could cause a Denial of Service.
CVE-2021-45829 1 Hdfgroup 1 Hdf5 2024-11-21 5.5 Medium
HDF5 1.13.1-1 is affected by: segmentation fault, which causes a Denial of Service.
CVE-2021-45822 1 Btiteam 1 Xbtit 2024-11-21 6.1 Medium
A cross-site scripting vulnerability is present in Xbtit 3.1. The stored XSS vulnerability occurs because /ajaxchat/sendChatData.php does not properly validate the value of the "n" (POST) parameter. Through this vulnerability, an attacker is capable to execute malicious JavaScript code.
CVE-2021-45821 1 Btiteam 1 Xbtit 2024-11-21 8.8 High
A blind SQL injection vulnerability exists in Xbtit 3.1 via the sid parameter in ajaxchat/getHistoryChatData.php file that is accessible by a registered user. As a result, a malicious user can extract sensitive data such as usernames and passwords and in some cases use this vulnerability in order to get a remote code execution on the remote web server.
CVE-2021-45819 1 Wordline 1 Hidccemonitorsvc 2024-11-21 6.4 Medium
Wordline HIDCCEMonitorSVC before v5.2.4.3 contains an unquoted service path which allows attackers to escalate privileges to the system level.
CVE-2021-45818 1 Safarimontage 1 Safari Montage 2024-11-21 6.1 Medium
SAFARI Montage 8.7.32 is affected by a CRLF injection vulnerability which can lead to HTTP response splitting.
CVE-2021-45815 1 Quectel 2 Uc20, Uc20 Firmware 2024-11-21 6.1 Medium
Quectel UC20 UMTS/HSPA+ UC20 6.3.14 is affected by a Cross Site Scripting (XSS) vulnerability.
CVE-2021-45814 1 Nettemp 1 Nnt 2024-11-21 9.8 Critical
Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel with an administrative account.
CVE-2021-45813 1 Slican 1 Webcti 2024-11-21 6.1 Medium
SLICAN WebCTI 1.01 2015 is affected by a Cross Site Scripting (XSS) vulnerability. The attacker can steal the user's session by injecting malicious JavaScript codes which leads to Session Hijacking and cause user's credentials theft.
CVE-2021-45812 1 Nuuo 2 Nvrsolo, Nvrsolo Firmware 2024-11-21 6.1 Medium
NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability. An attacker can steal the user's session by injecting malicious JavaScript codes which leads to session hijacking.
CVE-2021-45811 1 Enhancesoft 1 Osticket 2024-11-21 6.5 Medium
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.
CVE-2021-45810 1 Globalprotect-openconnect Project 1 Globalprotect-openconnect 2024-11-21 7.5 High
GlobalProtect-openconnect versions prior to 2.0.0 (exclusive) are affected by incorrect access control in GPService through DBUS, GUI. The way GlobalProtect-Openconnect is set up enables arbitrary users to start a VPN connection to arbitrary servers. By hosting an openconnect compatible server, the attack can redirect the entire host's traffic via their own server.
CVE-2021-45809 1 Globalprotect-openconnect Project 1 Globalprotect-openconnect 2024-11-21 9.8 Critical
GlobalProtect-openconnect versions prior to 1.4.3 are affected by incorrect access control in GPService through DBUS, GUI Application. The way GlobalProtect-Openconnect is set up enables arbitrary users to execute commands as root by submitting the `--script=<script>` parameter.
CVE-2021-45808 1 Jpress 1 Jpress 2024-11-21 8.8 High
jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the server.
CVE-2021-45807 1 Jpress 1 Jpress 2024-11-21 9.8 Critical
jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.
CVE-2021-45806 1 Jpress 1 Jpress 2024-11-21 8.8 High
jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code.
CVE-2021-45803 1 Iresturant Project 1 Iresturant 2024-11-21 8.8 High
MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because this view parameter value is added to the SQL query without additional verification when viewing reservation.