Search Results (336825 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-31779 1 Yoast 1 Yoast Seo 2024-11-21 6.4 Medium
The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account.
CVE-2021-31778 1 Media2click Project 1 Media2click 2024-11-21 5.4 Medium
The media2click (aka 2 Clicks for External Media) extension 1.x before 1.3.3 for TYPO3 allows XSS by a backend user account.
CVE-2021-31776 2 Aviatrix, Microsoft 2 Vpn Client, Windows 2024-11-21 7.8 High
Aviatrix VPN Client before 2.14.14 on Windows has an unquoted search path that enables local privilege escalation to the SYSTEM user, if the machine is misconfigured to allow unprivileged users to write to directories that are supposed to be restricted to administrators.
CVE-2021-31769 1 Myq-solution 1 Myq Server 2024-11-21 8.8 High
MyQ Server in MyQ X Smart before 8.2 allows remote code execution by unprivileged users because administrative session data can be read in the %PROGRAMFILES%\MyQ\PHP\Sessions directory. The "Select server file" feature is only intended for administrators but actually does not require authorization. An attacker can inject arbitrary OS commands (such as commands to create new .php files) via the Task Scheduler component.
CVE-2021-31762 1 Webmin 1 Webmin 2024-11-21 8.8 High
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse shell through Webmin's running process feature.
CVE-2021-31761 1 Webmin 1 Webmin 2024-11-21 9.6 Critical
Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature.
CVE-2021-31760 1 Webmin 1 Webmin 2024-11-21 8.8 High
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's running process feature.
CVE-2021-31758 1 Tenda 2 Ac11, Ac11 Firmware 2024-11-21 9.8 Critical
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setportList allows attackers to execute arbitrary code on the system via a crafted post request.
CVE-2021-31757 1 Tenda 2 Ac11, Ac11 Firmware 2024-11-21 9.8 Critical
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setVLAN allows attackers to execute arbitrary code on the system via a crafted post request.
CVE-2021-31756 1 Tenda 2 Ac11, Ac11 Firmware 2024-11-21 9.8 Critical
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /gofrom/setwanType allows attackers to execute arbitrary code on the system via a crafted post request. This occurs when input vector controlled by malicious attack get copied to the stack variable.
CVE-2021-31747 1 Pluck-cms 1 Pluck 2024-11-21 4.8 Medium
Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-middle attacks.
CVE-2021-31746 1 Pluck-cms 1 Pluck 2024-11-21 9.8 Critical
Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal and potentially arbitrary code execution.
CVE-2021-31745 1 Pluck-cms 1 Pluck 2024-11-21 7.5 High
Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access can be sustained even after an administrator performs regular remediation attempts such as resetting their password.
CVE-2021-31738 1 Adiscon 1 Loganalyzer 2024-11-21 6.1 Medium
Adiscon LogAnalyzer 4.1.10 and 4.1.11 allow login.php XSS.
CVE-2021-31737 1 Emlog 1 Emlog 2024-11-21 9.8 Critical
emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/data.php.
CVE-2021-31731 1 Kitesky 1 Kitecms 2024-11-21 6.5 Medium
A directory traversal issue in KiteCMS 1.1.1 allows remote administrators to overwrite arbitrary files via ../ in the path parameter to index.php/admin/Template/fileedit, with PHP code in the html parameter.
CVE-2021-31728 1 Malwarefox 1 Antimalware 2024-11-21 7.8 High
Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 allows a non-privileged process to open a handle to \.\ZemanaAntiMalware, register itself with the driver by sending IOCTL 0x80002010, allocate executable memory using a flaw in IOCTL 0x80002040, install a hook with IOCTL 0x80002044 and execute the executable memory using this hook with IOCTL 0x80002014 or 0x80002018, this exposes ring 0 code execution in the context of the driver allowing the non-privileged process to elevate privileges.
CVE-2021-31727 1 Malwarefox 1 Antimalware 2024-11-21 7.8 High
Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 where IOCTL's 0x80002014, 0x80002018 expose unrestricted disk read/write capabilities respectively. A non-privileged process can open a handle to \.\ZemanaAntiMalware, register with the driver using IOCTL 0x80002010 and send these IOCTL's to escalate privileges by overwriting the boot sector or overwriting critical code in the pagefile.
CVE-2021-31726 1 Akuvox 2 C315, C315 Firmware 2024-11-21 9.8 Critical
Akuvox C315 115.116.2613 allows remote command Injection via the cfgd_server service. The attack vector is sending a payload to port 189 (default root 0.0.0.0).
CVE-2021-31721 1 Chevereto 1 Chevereto 2024-11-21 6.1 Medium
Chevereto before 3.17.1 allows Cross Site Scripting (XSS) via an image title at the image upload stage.