Search Results (323460 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-26220 1 Ezxml Project 1 Ezxml 2024-11-21 8.1 High
The ezxml_toxml function in ezxml 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool.
CVE-2021-26216 1 Seeddms 1 Seeddms 2024-11-21 4.3 Medium
SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditFolder.php.
CVE-2021-26215 1 Seeddms 1 Seeddms 2024-11-21 4.3 Medium
SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditDocument.php.
CVE-2021-26201 1 Casap Automated Enrollment System Project 1 Casap Automated Enrollment System 2024-11-21 9.8 Critical
The Login Panel of CASAP Automated Enrollment System 1.0 is vulnerable to SQL injection authentication bypass. An attacker can obtain access to the admin panel by injecting a SQL query in the username field of the login page.
CVE-2021-26200 1 Library System Project 1 Library System 2024-11-21 9.8 Critical
The user area for Library System 1.0 is vulnerable to SQL injection where a user can bypass the authentication and login as the admin user.
CVE-2021-26199 1 Jerryscript 1 Jerryscript 2024-11-21 6.5 Medium
An issue was discovered in JerryScript 2.4.0. There is a heap-use-after-free in ecma_bytecode_ref in ecma-helpers.c file.
CVE-2021-26198 1 Jerryscript 1 Jerryscript 2024-11-21 6.5 Medium
An issue was discovered in JerryScript 2.4.0. There is a SEVG in ecma_deref_bigint in ecma-helpers.c file.
CVE-2021-26197 1 Jerryscript 1 Jerryscript 2024-11-21 6.5 Medium
An issue was discovered in JerryScript 2.4.0. There is a SEGV in main_print_unhandled_exception in main-utils.c file.
CVE-2021-26195 1 Jerryscript 1 Jerryscript 2024-11-21 8.8 High
An issue was discovered in JerryScript 2.4.0. There is a heap-buffer-overflow in lexer_parse_number in js-lexer.c file.
CVE-2021-26194 1 Jerryscript 1 Jerryscript 2024-11-21 6.5 Medium
An issue was discovered in JerryScript 2.4.0. There is a heap-use-after-free in ecma_is_lexical_environment in the ecma-helpers.c file.
CVE-2021-26123 1 Livinglogic 1 Xist4c 2024-11-21 6.1 Medium
LivingLogic XIST4C before 0.107.8 allows XSS via login.htm, login.wihtm, or login-form.htm.
CVE-2021-26122 1 Livinglogic 1 Xist4c 2024-11-21 6.1 Medium
LivingLogic XIST4C before 0.107.8 allows XSS via feedback.htm or feedback.wihtm.
CVE-2021-26120 2 Debian, Smarty 2 Debian Linux, Smarty 2024-11-21 9.8 Critical
Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.
CVE-2021-26119 2 Debian, Smarty 2 Debian Linux, Smarty 2024-11-21 7.5 High
Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode.
CVE-2021-26117 5 Apache, Debian, Netapp and 2 more 10 Activemq, Activemq Artemis, Debian Linux and 7 more 2024-11-21 7.5 High
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.
CVE-2021-26116 1 Fortinet 1 Fortiauthenticator 2024-11-21 6.7 Medium
An improper neutralization of special elements used in an OS command vulnerability in the command line interpreter of FortiAuthenticator before 6.3.1 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.
CVE-2021-26114 1 Fortinet 1 Fortiwan 2024-11-21 9.8 Critical
Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiWAN before 4.5.9 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
CVE-2021-26113 1 Fortinet 1 Fortiwan 2024-11-21 6.2 Medium
A use of a one-way hash with a predictable salt vulnerability [CWE-760] in FortiWAN before 4.5.9 may allow an attacker who has previously come in possession of the password file to potentially guess passwords therein stored.
CVE-2021-26112 1 Fortinet 1 Fortiwan 2024-11-21 8.1 High
Multiple stack-based buffer overflow vulnerabilities [CWE-121] both in network daemons and in the command line interpreter of FortiWAN before 4.5.9 may allow an unauthenticated attacker to potentially corrupt control data in memory and execute arbitrary code via specifically crafted requests.
CVE-2021-26111 1 Fortinet 1 Fortiswitch 2024-11-21 6.5 Medium
A missing release of memory after effective lifetime vulnerability in FortiSwitch 6.4.0 to 6.4.6, 6.2.0 to 6.2.6, 6.0.0 to 6.0.6, 3.6.11 and below may allow an attacker on an adjacent network to exhaust available memory by sending specifically crafted LLDP/CDP/EDP packets to the device.