Search Results (359923 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-42279 1 Microsoft 14 Windows 10, Windows 10 1507, Windows 10 1607 and 11 more 2024-11-21 4.2 Medium
Chakra Scripting Engine Memory Corruption Vulnerability
CVE-2021-42277 1 Microsoft 17 Visual Studio, Visual Studio 2017, Visual Studio 2019 and 14 more 2024-11-21 5.5 Medium
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
CVE-2021-42276 1 Microsoft 14 Windows 10, Windows 10 1507, Windows 10 1607 and 11 more 2024-11-21 7.8 High
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2021-42275 1 Microsoft 21 Windows 10, Windows 10 1507, Windows 10 1607 and 18 more 2024-11-21 8.8 High
Microsoft COM for Windows Remote Code Execution Vulnerability
CVE-2021-42274 1 Microsoft 11 Windows 10, Windows 10 1607, Windows 10 1809 and 8 more 2024-11-21 6.8 Medium
Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability
CVE-2021-42262 1 Softing 3 Datafeed Opc Suite, Opc Ua C\+\+ Software Development Kit, Secure Integration Server 2024-11-21 6.5 Medium
An issue was discovered in Softing OPC UA C++ SDK before 5.70. An invalid XML element in the type dictionary makes the OPC/UA client crash due to an out-of-memory condition.
CVE-2021-42261 1 Revisorlab 1 Video Management System 2024-11-21 7.5 High
Revisor Video Management System (VMS) before 2.0.0 has a directory traversal vulnerability. Successful exploitation could allow an attacker to traverse the file system to access files or directories that are outside of restricted directory on the remote server. This could lead to the disclosure of sensitive data on the vulnerable server.
CVE-2021-42257 1 Check Smart Project 1 Check Smart 2024-11-21 7.1 High
check_smart before 6.9.1 allows unintended drive access by an unprivileged user because it only checks for a substring match of a device path (the /dev/bus substring and a number), aka an unanchored regular expression.
CVE-2021-42255 1 Blueplanet-works 1 Appguard 2024-11-21 7.8 High
AppGuard Enterprise before 6.7.100.1 creates a Temporary File in a Directory with Insecure Permissions. Local users can gain SYSTEM privileges because a repair operation relies on the %TEMP% directory of an unprivileged user.
CVE-2021-42254 1 Beyondtrust 1 Privilege Management For Windows 2024-11-21 7.8 High
BeyondTrust Privilege Management prior to version 21.6 creates a Temporary File in a Directory with Insecure Permissions.
CVE-2021-42252 2 Linux, Netapp 19 Linux Kernel, H300e, H300e Firmware and 16 more 2024-11-21 7.8 High
An issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6. Local attackers able to access the Aspeed LPC control interface could overwrite memory in the kernel and potentially execute privileges, aka CID-b49a0e69a7b1. This occurs because a certain comparison uses values that are not memory sizes.
CVE-2021-42250 1 Apache 1 Superset 2024-11-21 6.5 Medium
Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs.
CVE-2021-42245 1 Flatcore 1 Flatcore-cms 2024-11-21 6.1 Medium
FlatCore-CMS 2.0.9 has a cross-site scripting (XSS) vulnerability in pages.edit.php through meta tags and content sections.
CVE-2021-42244 1 Notimoo Project 1 Notimoo 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in PaquitoSoftware Notimoo v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted title or message in a notification.
CVE-2021-42242 1 Jflyfox 1 Jfinal Cms 2024-11-21 9.8 Critical
A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor.
CVE-2021-42235 1 Enhancesoft 1 Osticket 2024-11-21 9.8 Critical
SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality.
CVE-2021-42233 2 Simple Blog Project, Wondercms 2 Simple Blog, Wondercms 2024-11-21 5.4 Medium
The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability. When any user opens a particular blog hosted on an attackers' site, XSS may occur.
CVE-2021-42232 1 Tp-link 2 Archer A7, Archer A7 Firmware 2024-11-21 9.8 Critical
TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the program taking part of the received data packet as part of the command. This will cause an attacker to execute arbitrary commands on the router.
CVE-2021-42230 1 Seowonintech 2 130-slc, 130-slc Firmware 2024-11-21 9.8 Critical
Seowon 130-SLC router all versions as of 2021-09-15 is vulnerable to Remote Code Execution via the queriesCnt parameter.
CVE-2021-42228 1 Kindsoft 1 Kindeditor 2024-11-21 8.8 High
A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.html.