Search Results (336905 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-31947 1 Microsoft 1 Hevc Video Extensions 2024-11-21 7.8 High
HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-31946 1 Microsoft 1 Paint 3d 2024-11-21 7.8 High
Paint 3D Remote Code Execution Vulnerability
CVE-2021-31945 1 Microsoft 1 Paint 3d 2024-11-21 7.8 High
Paint 3D Remote Code Execution Vulnerability
CVE-2021-31944 1 Microsoft 1 3d Viewer 2024-11-21 5 Medium
3D Viewer Information Disclosure Vulnerability
CVE-2021-31943 1 Microsoft 1 3d Viewer 2024-11-21 7.8 High
3D Viewer Remote Code Execution Vulnerability
CVE-2021-31942 1 Microsoft 1 3d Viewer 2024-11-21 7.8 High
3D Viewer Remote Code Execution Vulnerability
CVE-2021-31941 1 Microsoft 3 365 Apps, Office, Outlook 2024-11-21 7.8 High
Microsoft Office Graphics Remote Code Execution Vulnerability
CVE-2021-31940 1 Microsoft 2 365 Apps, Office 2024-11-21 7.8 High
Microsoft Office Graphics Remote Code Execution Vulnerability
CVE-2021-31939 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2024-11-21 7.8 High
Microsoft Excel Remote Code Execution Vulnerability
CVE-2021-31938 1 Microsoft 1 Kubernetes Tools 2024-11-21 7.3 High
Microsoft VsCode Kubernetes Tools Extension Elevation of Privilege Vulnerability
CVE-2021-31936 1 Microsoft 1 Accessibility Insights For Web 2024-11-21 7.4 High
Microsoft Accessibility Insights for Web Information Disclosure Vulnerability
CVE-2021-31935 1 Open-xchange 1 Open-xchange Appsuite 2024-11-21 6.1 Medium
OX App Suite 7.10.4 and earlier allows XSS via a crafted distribution list (payload in the common name) that is mishandled in the scheduling view.
CVE-2021-31934 1 Open-xchange 1 Open-xchange Appsuite 2024-11-21 6.1 Medium
OX App Suite 7.10.4 and earlier allows XSS via a crafted contact object (payload in the position or company field) that is mishandled in the App Suite UI on a smartphone.
CVE-2021-31933 1 Chamilo 1 Chamilo 2024-11-21 7.2 High
A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filtering for certain filenames (e.g., .phar or .pht). A remote authenticated administrator is able to upload a file containing arbitrary PHP code into specific directories via main/inc/lib/fileUpload.lib.php directory traversal to achieve PHP code execution.
CVE-2021-31932 1 Nokia 1 Bts Trs Web Console 2024-11-21 9.8 Critical
Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can get access to all the functionalities exposed via the web panel, circumventing the authentication process, by using URL encoding for the . (dot) character.
CVE-2021-31930 1 Concerto-signage 1 Concerto 2024-11-21 6.1 Medium
Persistent cross-site scripting (XSS) in the web interface of Concerto through 2.3.6 allows an unauthenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into the First Name or Last Name parameter upon registration. When a privileged user attempts to delete the account, the XSS payload will be executed.
CVE-2021-31929 1 Annexcloud 1 Loyalty Experience Platform 2024-11-21 4.3 Medium
Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify loyalty campaigns and settings, such as fraud prevention, coupon groups, email templates, or referrals.
CVE-2021-31928 1 Annexcloud 1 Loyalty Experience Platform 2024-11-21 8.8 High
Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to escalate privileges to superadministrator. It was fixed in v2021.1.0.2.
CVE-2021-31927 1 Annexcloud 1 Loyalty Experience Platform 2024-11-21 4.3 Medium
An Insecure Direct Object Reference (IDOR) vulnerability in Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify any existing user, including users assigned to different environments and clients. It was fixed in v2021.1.0.2.
CVE-2021-31926 1 Cubecoders 1 Amp 2024-11-21 6.5 Medium
AMP Application Deployment Service in CubeCoders AMP 2.1.x before 2.1.1.2 allows a remote, authenticated user to open ports in the local system firewall by crafting an HTTP(S) request directly to the applicable API endpoint (despite not having permission to make changes to the system's network configuration).