Search Results (336926 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-32172 1 Maianscriptworld 1 Maian Cart 2024-11-21 9.8 Critical
Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.
CVE-2021-32162 1 Webmin 1 Webmin 2024-11-21 8.8 High
A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 through the File Manager feature.
CVE-2021-32161 1 Webmin 1 Webmin 2024-11-21 6.1 Medium
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the File Manager feature.
CVE-2021-32160 1 Webmin 1 Webmin 2024-11-21 6.1 Medium
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the Add Users feature.
CVE-2021-32159 1 Webmin 1 Webmin 2024-11-21 8.8 High
A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Upload and Download feature.
CVE-2021-32158 1 Webmin 1 Webmin 2024-11-21 6.1 Medium
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Upload and Download feature.
CVE-2021-32157 1 Webmin 1 Webmin 2024-11-21 9.6 Critical
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.
CVE-2021-32156 1 Webmin 1 Webmin 2024-11-21 8.8 High
A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.
CVE-2021-32139 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
The gf_isom_vp_config_get function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
CVE-2021-32138 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
The DumpTrackInfo function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
CVE-2021-32137 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
Heap buffer overflow in the URL_GetProtocolType function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.
CVE-2021-32136 1 Gpac 1 Gpac 2024-11-21 7.8 High
Heap buffer overflow in the print_udta function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.
CVE-2021-32135 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
The trak_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
CVE-2021-32134 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
The gf_odf_desc_copy function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
CVE-2021-32132 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
The abst_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
CVE-2021-32122 1 Netgear 8 Ex3700, Ex3700 Firmware, Ex3800 and 5 more 2024-11-21 9.8 Critical
Certain NETGEAR devices are affected by CSRF. This affects EX3700 before 1.0.0.90, EX3800 before 1.0.0.90, EX6120 before 1.0.0.64, and EX6130 before 1.0.0.44.
CVE-2021-32106 1 Icecoder 1 Icecoder 2024-11-21 5.4 Medium
In ICEcoder 8.0 allows, a reflected XSS vulnerability was identified in the multipe-results.php page due to insufficient sanitization of the _GET['replace'] variable. As a result, arbitrary Javascript code can get executed.
CVE-2021-32104 1 Open-emr 1 Openemr 2024-11-21 8.8 High
A SQL injection vulnerability exists (with user privileges) in interface/forms/eye_mag/save.php in OpenEMR 5.0.2.1.
CVE-2021-32103 1 Open-emr 1 Openemr 2024-11-21 4.8 Medium
A Stored XSS vulnerability in interface/usergroup/usergroup_admin.php in OpenEMR before 5.0.2.1 allows a admin authenticated user to inject arbitrary web script or HTML via the lname parameter.
CVE-2021-32102 1 Open-emr 1 Openemr 2024-11-21 8.8 High
A SQL injection vulnerability exists (with user privileges) in library/custom_template/ajax_code.php in OpenEMR 5.0.2.1.