Search Results (84663 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-41464 1 Concrete5-legacy Project 1 Concrete5-legacy 2024-11-21 6.1 Medium
Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the rel parameter.
CVE-2021-41463 1 Concrete5-legacy Project 1 Concrete5-legacy 2024-11-21 6.1 Medium
Cross-site scripting (XSS) vulnerability in toos/permissions/dialogs/access/entity/types/group_combination.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the cID parameter.
CVE-2021-41462 1 Concrete5-legacy Project 1 Concrete5-legacy 2024-11-21 6.1 Medium
Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the ctID parameter.
CVE-2021-41461 1 Concrete5-legacy Project 1 Concrete5-legacy 2024-11-21 6.1 Medium
Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the mode parameter.
CVE-2021-41459 1 Gpac 1 Mp4box 2024-11-21 7.5 High
There is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1008 in the nhmldmx_send_sample() function szXmlFrom parameter which leads to a denial of service vulnerability.
CVE-2021-41458 1 Gpac 1 Mp4box 2024-11-21 5.5 Medium
In GPAC MP4Box v1.1.0, there is a stack buffer overflow at src/utils/error.c:1769 which leads to a denial of service vulnerability.
CVE-2021-41457 1 Gpac 1 Mp4box 2024-11-21 7.5 High
There is a stack buffer overflow in MP4Box 1.1.0 at src/filters/dmx_nhml.c in nhmldmx_init_parsing which leads to a denial of service vulnerability.
CVE-2021-41456 1 Gpac 1 Mp4box 2024-11-21 7.5 High
There is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1004 in the nhmldmx_send_sample() function szXmlTo parameter which leads to a denial of service vulnerability.
CVE-2021-41445 1 Dlink 2 Dir-x1860, Dir-x1860 Firmware 2024-11-21 6.1 Medium
A reflected cross-site-scripting attack in web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to execute code in the device of the victim via sending a specific URL to the unauthenticated victim.
CVE-2021-41432 1 Flatpress 1 Flatpress 2024-11-21 5.4 Medium
A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands through blog content.
CVE-2021-41427 1 Beeline 2 Smart Box, Smart Box Firmware 2024-11-21 6.1 Medium
Beeline Smart Box 2.0.38 is vulnerable to Cross Site Scripting (XSS) via the choose_mac parameter to setup.cgi.
CVE-2021-41421 1 Maianmedia 1 Maianaffiliate 2024-11-21 4.8 Medium
A PHP code injection vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker to gain RCE through the MaianAffiliate admin panel.
CVE-2021-41420 1 Maianmedia 1 Maianaffiliate 2024-11-21 5.4 Medium
A stored XSS vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker for arbitrary JavaScript code execution in the context of authenticated and unauthenticated users through the MaianAffiliate admin panel.
CVE-2021-41415 1 Subscription-manager Project 1 Subscription-manager 2024-11-21 6.1 Medium
Subscription-Manager v1.0 /main.js has a cross-site scripting (XSS) vulnerability in the machineDetail parameter.
CVE-2021-41396 1 Live555 1 Live555 2024-11-21 7.5 High
Live555 through 1.08 does not handle socket connections properly. A huge number of incoming socket connections in a short time invokes the error-handling module, in which a heap-based buffer overflow happens. An attacker can leverage this to launch a DoS attack.
CVE-2021-41392 1 Boostnote 1 Boostnote 2024-11-21 9.8 Critical
static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal Electron API.
CVE-2021-41391 1 Ericsson 1 Enterprise Content Management 2024-11-21 5.4 Medium
In Ericsson ECM before 18.0, it was observed that Security Management Endpoint in User Profile Management Section is vulnerable to stored XSS via a name, leading to session hijacking and full account takeover.
CVE-2021-41390 1 Ericsson 1 Enterprise Content Management 2024-11-21 8.0 High
In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injection.
CVE-2021-41383 1 Netgear 2 R6020, R6020 Firmware 2024-11-21 7.2 High
setup.cgi on NETGEAR R6020 1.0.0.48 devices allows an admin to execute arbitrary shell commands via shell metacharacters in the ntp_server field.
CVE-2021-41354 1 Microsoft 1 Dynamics 365 2024-11-21 5.4 Medium
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability