Search Results (357832 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-46233 1 Dlink 2 Di-7200gv2, Di-7200gv2 Firmware 2024-11-21 9.8 Critical
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function msp_info.htm. This vulnerability allows attackers to execute arbitrary commands via the cmd parameter.
CVE-2021-46232 1 Dlink 2 Di-7200gv2, Di-7200gv2 Firmware 2024-11-21 9.8 Critical
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function version_upgrade.asp. This vulnerability allows attackers to execute arbitrary commands via the path parameter.
CVE-2021-46231 1 Dlink 2 Di-7200gv2, Di-7200gv2 Firmware 2024-11-21 9.8 Critical
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function urlrd_opt.asp. This vulnerability allows attackers to execute arbitrary commands via the url_en parameter.
CVE-2021-46230 1 Dlink 2 Di-7200gv2, Di-7200gv2 Firmware 2024-11-21 9.8 Critical
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function upgrade_filter. This vulnerability allows attackers to execute arbitrary commands via the path and time parameters.
CVE-2021-46229 1 Dlink 2 Di-7200gv2, Di-7200gv2 Firmware 2024-11-21 9.8 Critical
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function usb_paswd.asp. This vulnerability allows attackers to execute arbitrary commands via the name parameter.
CVE-2021-46228 1 Dlink 2 Di-7200gv2, Di-7200gv2 Firmware 2024-11-21 9.8 Critical
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function httpd_debug.asp. This vulnerability allows attackers to execute arbitrary commands via the time parameter.
CVE-2021-46227 1 Dlink 2 Di-7200gv2, Di-7200gv2 Firmware 2024-11-21 9.8 Critical
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function proxy_client.asp. This vulnerability allows attackers to execute arbitrary commands via the proxy_srv, proxy_srvport, proxy_lanip, proxy_lanport parameters.
CVE-2021-46226 1 Dlink 2 Di-7200gv2, Di-7200gv2 Firmware 2024-11-21 9.8 Critical
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function wget_test.asp. This vulnerability allows attackers to execute arbitrary commands via the url parameter.
CVE-2021-46225 1 Libmeshb Project 1 Libmeshb 2024-11-21 6.5 Medium
A buffer overflow in the GmfOpenMesh() function of libMeshb v7.61 allows attackers to cause a Denial of Service (DoS) via a crafted MESH file.
CVE-2021-46204 1 Taogogo 1 Taocms 2024-11-21 9.8 Critical
Taocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter. SQL injection vulnerability via taocms\include\Model\Article.php.
CVE-2021-46203 1 Taogogo 1 Taocms 2024-11-21 6.5 Medium
Taocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter.
CVE-2021-46201 1 Online Resort Management System Project 1 Online Resort Management System 2024-11-21 9.8 Critical
An SQL Injection vulnerability exists in Sourcecodester Online Resort Management System 1.0 via the id parameterv in /orms/ node.
CVE-2021-46198 1 Courier Management System Project 1 Courier Management System 2024-11-21 9.8 Critical
An SQL Injection vulnerability exists in Sourceodester Courier Management System 1.0 via the email parameter in /cms/ajax.php app.
CVE-2021-46195 2 Gnu, Redhat 2 Gcc, Enterprise Linux 2024-11-21 5.5 Medium
GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources.
CVE-2021-46174 2 Binutils, Gnu 2 Objdump, Binutils 2024-11-21 7.5 High
Heap-based Buffer Overflow in function bfd_getl32 in Binutils objdump 3.37.
CVE-2021-46171 1 Modex Project 1 Modex 2024-11-21 5.5 Medium
Modex v2.11 was discovered to contain a NULL pointer dereference in set_create_id() at xtract.c.
CVE-2021-46170 1 Jerryscript 1 Jerryscript 2024-11-21 7.5 High
An issue was discovered in JerryScript commit a6ab5e9. There is an Use-After-Free in lexer_compare_identifier_to_string in js-lexer.c file.
CVE-2021-46169 1 Modex Project 1 Modex 2024-11-21 5.5 Medium
Modex v2.11 was discovered to contain an Use-After-Free vulnerability via the component tcache.
CVE-2021-46168 1 Spinroot 1 Spin 2024-11-21 5.5 Medium
Spin v6.5.1 was discovered to contain an out-of-bounds write in lex() at spinlex.c.
CVE-2021-46167 1 Wizplat 2 Pd065, Pd065 Firmware 2024-11-21 7.8 High
An access control issue in the authentication module of wizplat PD065 v1.19 allows attackers to access sensitive data and cause a Denial of Service (DoS).