Search Results (84588 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-38653 1 Microsoft 2 365 Apps, Office 2024-11-21 7.8 High
Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2021-38619 1 Openbaraza 1 Openbaraza Human Capital Management 2024-11-21 6.1 Medium
openBaraza HCM 3.1.6 does not properly neutralize user-controllable input: an unauthenticated remote attacker can conduct a stored cross-site scripting (XSS) attack against an administrative user from hr/subscription.jsp and hr/application.jsp and and hr/index.jsp (with view=).
CVE-2021-38614 1 Polipo Project 1 Polipo 2024-11-21 7.5 High
Polipo through 1.1.1, when NDEBUG is used, allows a heap-based buffer overflow during parsing of a Range header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVE-2021-38611 1 Nascent 1 Remkon Device Manager 2024-11-21 9.8 Critical
A command-injection vulnerability in the Image Upload function of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to execute arbitrary commands, as root, via shell metacharacters in the filename parameter to assets/index.php.
CVE-2021-38607 1 Crocoblock 1 Jetengine 2024-11-21 5.4 Medium
Crocoblock JetEngine before 2.6.1 allows XSS by remote authenticated users via a custom form input.
CVE-2021-38603 1 Pluxml 1 Pluxml 2024-11-21 4.8 Medium
PluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field.
CVE-2021-38602 1 Pluxml 1 Pluxml 2024-11-21 4.8 Medium
PluXML 5.8.7 allows Article Editing stored XSS via Headline or Content.
CVE-2021-38599 1 Wal-g Project 1 Wal-g 2024-11-21 7.5 High
WAL-G before 1.1, when a non-libsodium build (e.g., one of the official binary releases published as GitHub Releases) is used, silently ignores the libsodium encryption key and uploads cleartext backups. This is arguably a Principle of Least Surprise violation because "the user likely wanted to encrypt all file activity."
CVE-2021-38593 3 Fedoraproject, Qt, Redhat 3 Fedora, Qt, Enterprise Linux 2024-11-21 7.5 High
Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).
CVE-2021-38592 1 Wasm3 Project 1 Wasm3 2024-11-21 7.5 High
Wasm3 0.5.0 has a heap-based buffer overflow in op_Const64 (called from EvaluateExpression and m3_LoadModule).
CVE-2021-38590 1 Cpanel 1 Cpanel 2024-11-21 5.5 Medium
In cPanel before 96.0.8, weak permissions on web stats can lead to information disclosure (SEC-584).
CVE-2021-38583 1 Openbaraza 1 Openbaraza Human Capital Management 2024-11-21 6.1 Medium
openBaraza HCM 3.1.6 does not properly neutralize user-controllable input, which allows reflected cross-site scripting (XSS) on multiple pages: hr/subscription.jsp and hr/application.jsp and and hr/index.jsp (with view= and data=).
CVE-2021-38568 1 Foxitsoftware 2 Foxit Reader, Phantompdf 2024-11-21 9.8 Critical
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows memory corruption during conversion of a PDF document to a different document format.
CVE-2021-38560 1 Ivanti 1 Service Manager 2024-11-21 6.1 Medium
Ivanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in RelocateAttachments.aspx.
CVE-2021-38559 1 Digitaldruid 1 Hoteldruid 2024-11-21 6.1 Medium
DigitalDruid HotelDruid 3.0.2 has an XSS vulnerability in prenota.php affecting the fineperiodo1 parameter.
CVE-2021-38557 1 Raspap 1 Raspap 2024-11-21 8.8 High
raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions. The www-data account can execute /etc/raspap/hostapd/enablelog.sh as root with no password; however, the www-data account can also overwrite /etc/raspap/hostapd/enablelog.sh with any executable content.
CVE-2021-38556 1 Raspap 1 Raspap 2024-11-21 8.8 High
includes/configure_client.php in RaspAP 2.6.6 allows attackers to execute commands via command injection.
CVE-2021-38542 1 Apache 1 James 2024-11-21 5.9 Medium
Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-middle command injection attacks, leading potentially to leakage of sensible information.
CVE-2021-38538 1 Netgear 30 D7800, D7800 Firmware, R7800 and 27 more 2024-11-21 6.3 Medium
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.68, R8900 before 1.0.4.26, R9000 before 1.0.4.26, RAX120 before 1.0.0.78, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and XR500 before 2.3.2.56.
CVE-2021-38537 1 Netgear 36 Ac2100, Ac2100 Firmware, Ac2400 and 33 more 2024-11-21 4.2 Medium
Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6120 before 1.0.0.66, R6260 before 1.1.0.78, R6700v2 before 1.2.0.76, R6800 before 1.2.0.76, R6900v2 before 1.2.0.76, R6850 before 1.1.0.78, R7200 before 1.2.0.76, R7350 before 1.2.0.76, R7400 before 1.2.0.76, R7450 before 1.2.0.76, AC2100 before 1.2.0.76, AC2400 before 1.2.0.76, AC2600 before 1.2.0.76, and RAX40 before 1.0.3.62.