Search Results (357832 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-46265 1 Tenda 2 Ac11, Ac11 Firmware 2024-11-21 9.8 Critical
Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the wanBasicCfg module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.
CVE-2021-46264 1 Tenda 2 Ac11, Ac11 Firmware 2024-11-21 9.8 Critical
Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the onlineList module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.
CVE-2021-46263 1 Tenda 2 Ac11, Ac11 Firmware 2024-11-21 9.8 Critical
Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the wifiTime module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.
CVE-2021-46262 1 Tenda 2 Ac11, Ac11 Firmware 2024-11-21 9.8 Critical
Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the PPPoE module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.
CVE-2021-46255 1 Eyoucms 1 Eyoucms 2024-11-21 8.1 High
eyouCMS V1.5.5-UTF8-SP3_1 suffers from Arbitrary file deletion due to insufficient filtering of the parameter filename.
CVE-2021-46253 1 Anchorcms 1 Anchor Cms 2024-11-21 5.4 Medium
A cross-site scripting (XSS) vulnerability in the Create Post function of Anchor CMS v0.12.7 allows attackers to execute arbitrary web scripts or HTML.
CVE-2021-46252 1 Scratch-wiki 1 Scratch Confirmaccount V3 2024-11-21 6.5 Medium
A Cross-Site Request Forgery (CSRF) in RequirementsBypassPage.php of Scratch Wiki scratch-confirmaccount-v3 allows attackers to modify account request requirement bypasses.
CVE-2021-46251 1 Scratchoauth2 Project 1 Scratchoauth2 2024-11-21 6.1 Medium
A reflected cross-site scripting (XSS) in ScratchOAuth2 before commit 1603f04e44ef67dde6ccffe866d2dca16defb293 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.
CVE-2021-46250 1 Scratchoauth2 Project 1 Scratchoauth2 2024-11-21 10 Critical
An issue in SOA2Login::commented of ScratchOAuth2 before commit a91879bd58fa83b09283c0708a1864cdf067c64a allows attackers to authenticate as other users on downstream components that rely on ScratchOAuth2.
CVE-2021-46249 1 Scratchoauth2 Project 1 Scratchoauth2 2024-11-21 6.5 Medium
An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd40775d6 allows app owners to set flags that indicate whether an app is verified on their own apps.
CVE-2021-46247 1 Asus 2 Cmax6000, Cmax6000 Firmware 2024-11-21 7.5 High
The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from ASUS CMAX6000 v1.02.00.
CVE-2021-46244 1 Hdfgroup 1 Hdf5 2024-11-21 6.5 Medium
A Divide By Zero vulnerability exists in HDF5 v1.13.1-1 vis the function H5T__complete_copy () at /hdf5/src/H5T.c. This vulnerability causes an aritmetic exception, leading to a Denial of Service (DoS).
CVE-2021-46243 1 Hdfgroup 1 Hdf5 2024-11-21 6.5 Medium
An untrusted pointer dereference vulnerability exists in HDF5 v1.13.1-1 via the function H5O__dtype_decode_helper () at hdf5/src/H5Odtype.c. This vulnerability can lead to a Denial of Service (DoS).
CVE-2021-46242 1 Hdfgroup 1 Hdf5 2024-11-21 8.8 High
HDF5 v1.13.1-1 was discovered to contain a heap-use-after free via the component H5AC_unpin_entry.
CVE-2021-46240 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_dump_vrml_sffield () at scene_manager/scene_dump.c. This vulnerability can lead to a Denial of Service (DoS).
CVE-2021-46239 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
The binary MP4Box in GPAC v1.1.0 was discovered to contain an invalid free vulnerability via the function gf_free () at utils/alloc.c. This vulnerability can lead to a Denial of Service (DoS).
CVE-2021-46238 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
GPAC v1.1.0 was discovered to contain a stack overflow via the function gf_node_get_name () at scenegraph/base_scenegraph.c. This vulnerability can lead to a program crash, causing a Denial of Service (DoS).
CVE-2021-46237 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
An untrusted pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_node_unregister () at scenegraph/base_scenegraph.c. This vulnerability can lead to a Denial of Service (DoS).
CVE-2021-46236 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_sg_vrml_field_pointer_del () at scenegraph/vrml_tools.c. This vulnerability can lead to a Denial of Service (DoS).
CVE-2021-46234 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_node_unregister () at scenegraph/base_scenegraph.c. This vulnerability can lead to a Denial of Service (DoS).