Search Results (348026 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-31762 1 Webmin 1 Webmin 2024-11-21 8.8 High
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse shell through Webmin's running process feature.
CVE-2021-31761 1 Webmin 1 Webmin 2024-11-21 9.6 Critical
Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature.
CVE-2021-31760 1 Webmin 1 Webmin 2024-11-21 8.8 High
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's running process feature.
CVE-2021-31758 1 Tenda 2 Ac11, Ac11 Firmware 2024-11-21 9.8 Critical
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setportList allows attackers to execute arbitrary code on the system via a crafted post request.
CVE-2021-31757 1 Tenda 2 Ac11, Ac11 Firmware 2024-11-21 9.8 Critical
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setVLAN allows attackers to execute arbitrary code on the system via a crafted post request.
CVE-2021-31756 1 Tenda 2 Ac11, Ac11 Firmware 2024-11-21 9.8 Critical
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /gofrom/setwanType allows attackers to execute arbitrary code on the system via a crafted post request. This occurs when input vector controlled by malicious attack get copied to the stack variable.
CVE-2021-31747 1 Pluck-cms 1 Pluck 2024-11-21 4.8 Medium
Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-middle attacks.
CVE-2021-31746 1 Pluck-cms 1 Pluck 2024-11-21 9.8 Critical
Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal and potentially arbitrary code execution.
CVE-2021-31745 1 Pluck-cms 1 Pluck 2024-11-21 7.5 High
Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access can be sustained even after an administrator performs regular remediation attempts such as resetting their password.
CVE-2021-31738 1 Adiscon 1 Loganalyzer 2024-11-21 6.1 Medium
Adiscon LogAnalyzer 4.1.10 and 4.1.11 allow login.php XSS.
CVE-2021-31737 1 Emlog 1 Emlog 2024-11-21 9.8 Critical
emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/data.php.
CVE-2021-31731 1 Kitesky 1 Kitecms 2024-11-21 6.5 Medium
A directory traversal issue in KiteCMS 1.1.1 allows remote administrators to overwrite arbitrary files via ../ in the path parameter to index.php/admin/Template/fileedit, with PHP code in the html parameter.
CVE-2021-31728 1 Malwarefox 1 Antimalware 2024-11-21 7.8 High
Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 allows a non-privileged process to open a handle to \.\ZemanaAntiMalware, register itself with the driver by sending IOCTL 0x80002010, allocate executable memory using a flaw in IOCTL 0x80002040, install a hook with IOCTL 0x80002044 and execute the executable memory using this hook with IOCTL 0x80002014 or 0x80002018, this exposes ring 0 code execution in the context of the driver allowing the non-privileged process to elevate privileges.
CVE-2021-31727 1 Malwarefox 1 Antimalware 2024-11-21 7.8 High
Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 where IOCTL's 0x80002014, 0x80002018 expose unrestricted disk read/write capabilities respectively. A non-privileged process can open a handle to \.\ZemanaAntiMalware, register with the driver using IOCTL 0x80002010 and send these IOCTL's to escalate privileges by overwriting the boot sector or overwriting critical code in the pagefile.
CVE-2021-31726 1 Akuvox 2 C315, C315 Firmware 2024-11-21 9.8 Critical
Akuvox C315 115.116.2613 allows remote command Injection via the cfgd_server service. The attack vector is sending a payload to port 189 (default root 0.0.0.0).
CVE-2021-31721 1 Chevereto 1 Chevereto 2024-11-21 6.1 Medium
Chevereto before 3.17.1 allows Cross Site Scripting (XSS) via an image title at the image upload stage.
CVE-2021-31718 1 Npupnp Project 1 Npupnp 2024-11-21 8.8 High
The server in npupnp before 4.1.4 is affected by DNS rebinding in the embedded web server (including UPnP SOAP and GENA endpoints), leading to remote code execution.
CVE-2021-31712 1 React Draft Wysiwyg Project 1 React Draft Wysiwyg 2024-11-21 5.4 Medium
react-draft-wysiwyg (aka React Draft Wysiwyg) before 1.14.6 allows a javascript: URi in a Link Target of the link decorator in decorators/Link/index.js when a draft is shared across users, leading to XSS.
CVE-2021-31703 1 Frontiersoftware 1 Ichris 2024-11-21 9.8 Critical
Frontier ichris through 5.18 allows users to upload malicious executable files that might later be downloaded and run by any client user.
CVE-2021-31702 1 Frontiersoftware 1 Ichris 2024-11-21 7.5 High
Frontier ichris through 5.18 mishandles making a DNS request for the hostname in the HTTP Host header, as demonstrated by submitting 127.0.0.1 multiple times for DoS.