Search Results (96033 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-40143 1 Sonatype 1 Nexus Repository Manager 3 2024-11-21 8.2 High
Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vulnerable instance.
CVE-2021-40142 2 Opcfoundation, Siemens 8 Local Discover Server, Simatic Net Pc, Simatic Process Historian Opc Ua Server and 5 more 2024-11-21 7.5 High
In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefully crafted messages that lead to Access of a Memory Location After the End of a Buffer.
CVE-2021-40110 1 Apache 1 James 2024-11-21 7.5 High
In Apache James, using Jazzer fuzzer, we identified that an IMAP user can craft IMAP LIST commands to orchestrate a Denial Of Service using a vulnerable Regular expression. This affected Apache James prior to 3.6.1 We recommend upgrading to Apache James 3.6.1 or higher , which enforce the use of RE2J regular expression engine to execute regex in linear time without back-tracking.
CVE-2021-40108 1 Concretecms 1 Concrete Cms 2024-11-21 8.8 High
An issue was discovered in Concrete CMS through 8.5.5. The Calendar is vulnerable to CSRF. ccm_token is not verified on the ccm/calendar/dialogs/event/add/save endpoint.
CVE-2021-40104 1 Concretecms 1 Concrete Cms 2024-11-21 7.5 High
An issue was discovered in Concrete CMS through 8.5.5. There is an SVG sanitizer bypass.
CVE-2021-40103 1 Concretecms 1 Concrete Cms 2024-11-21 7.5 High
An issue was discovered in Concrete CMS through 8.5.5. Path Traversal can lead to Arbitrary File Reading and SSRF.
CVE-2021-40101 1 Concretecms 1 Concrete Cms 2024-11-21 7.2 High
An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.
CVE-2021-40099 1 Concretecms 1 Concrete Cms 2024-11-21 7.2 High
An issue was discovered in Concrete CMS through 8.5.5. Fetching the update json scheme over HTTP leads to remote code execution.
CVE-2021-40097 1 Concretecms 1 Concrete Cms 2024-11-21 8.8 High
An issue was discovered in Concrete CMS through 8.5.5. Authenticated path traversal leads to to remote code execution via uploaded PHP code, related to the bFilename parameter.
CVE-2021-40083 1 Nic 1 Knot Resolver 2024-11-21 7.5 High
Knot Resolver before 5.3.2 is prone to an assertion failure, triggerable by a remote attacker in an edge case (NSEC3 with too many iterations used for a positive wildcard proof).
CVE-2021-40065 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
The communication module has a service logic error vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2021-40064 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
There is a heap-based buffer overflow vulnerability in system components. Successful exploitation of this vulnerability may affect system stability.
CVE-2021-40063 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
There is an improper access control vulnerability in the video module. Successful exploitation of this vulnerability may affect confidentiality.
CVE-2021-40062 1 Huawei 2 Emui, Magic Ui 2024-11-21 7.5 High
There is a vulnerability of copying input buffer without checking its size in the video framework. Successful exploitation of this vulnerability may affect availability.
CVE-2021-40061 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
There is a vulnerability of accessing resources using an incompatible type (type confusion) in the Bastet module. Successful exploitation of this vulnerability may affect integrity.
CVE-2021-40060 1 Huawei 2 Emui, Magic Ui 2024-11-21 7.5 High
There is a heap-based buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability may affect availability.
CVE-2021-40058 1 Huawei 2 Emui, Magic Ui 2024-11-21 7.5 High
There is a heap-based buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability may affect availability.
CVE-2021-40057 1 Huawei 2 Emui, Magic Ui 2024-11-21 7.5 High
There is a heap-based and stack-based buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability may affect availability.
CVE-2021-40056 1 Huawei 2 Emui, Magic Ui 2024-11-21 7.5 High
There is a vulnerability of copying input buffer without checking its size in the video framework. Successful exploitation of this vulnerability may affect availability.
CVE-2021-40054 1 Huawei 2 Emui, Magic Ui 2024-11-21 7.5 High
There is an integer underflow vulnerability in the atcmdserver module. Successful exploitation of this vulnerability may affect integrity.