Search Results (13922 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-26699 1 Open-xchange 1 Open-xchange Appsuite 2024-11-21 5.4 Medium
OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter component when the .png extension is used.
CVE-2021-26622 2 Genians, Microsoft 2 Genian Nac, Windows 2024-11-21 9.6 Critical
An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote attackers are able to execute arbitrary malicious code with SYSTEM privileges on all connected nodes in NAC through this vulnerability.
CVE-2021-26551 1 Smartfoxserver 1 Smartfoxserver 2024-11-21 8.8 High
An issue was discovered in SmartFoxServer 2.17.0. An attacker can execute arbitrary Python code, and bypass the javashell.py protection mechanism, by creating /config/ConsoleModuleUnlock.txt and editing /config/admin/admintool.xml to enable the Console module.
CVE-2021-26305 1 Cdr Project 1 Cdr 2024-11-21 9.8 Critical
An issue was discovered in Deserializer::read_vec in the cdr crate before 0.2.4 for Rust. A user-provided Read implementation can gain access to the old contents of newly allocated heap memory, violating soundness.
CVE-2021-26276 1 Godaddy 1 Node-config-shield 2024-11-21 5.3 Medium
scripts/cli.js in the GoDaddy node-config-shield (aka Config Shield) package before 0.2.2 for Node.js calls eval when processing a set command. NOTE: the vendor reportedly states that this is not a vulnerability. The set command was not intended for use with untrusted data
CVE-2021-26120 2 Debian, Smarty 2 Debian Linux, Smarty 2024-11-21 9.8 Critical
Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.
CVE-2021-26113 1 Fortinet 1 Fortiwan 2024-11-21 6.2 Medium
A use of a one-way hash with a predictable salt vulnerability [CWE-760] in FortiWAN before 4.5.9 may allow an attacker who has previously come in possession of the password file to potentially guess passwords therein stored.
CVE-2021-26072 1 Atlassian 2 Confluence Data Center, Confluence Server 2024-11-21 4.3 Medium
The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.
CVE-2021-25945 1 Js-extend Project 1 Js-extend 2024-11-21 9.8 Critical
Prototype pollution vulnerability in 'js-extend' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
CVE-2021-25939 1 Arangodb 1 Arangodb 2024-11-21 2.7 Low
In ArangoDB, versions v3.7.0 through v3.9.0-alpha.1 have a feature which allows downloading a Foxx service from a publicly available URL. This feature does not enforce proper filtering of requests performed internally, which can be abused by a highly-privileged attacker to perform blind SSRF and send internal requests to localhost.
CVE-2021-25905 1 Bra Project 1 Bra 2024-11-21 9.1 Critical
An issue was discovered in the bra crate before 0.1.1 for Rust. It lacks soundness because it can read uninitialized memory.
CVE-2021-25877 1 Youphptube 1 Youphptube 2024-11-21 7.2 High
AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write files on filesystem using flag and code variables in file save.php.
CVE-2021-25808 1 Bludit 1 Bludit 2024-11-21 7.8 High
A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file.
CVE-2021-25776 1 Jetbrains 1 Teamcity 2024-11-21 7.5 High
In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters.
CVE-2021-25770 1 Jetbrains 1 Youtrack 2024-11-21 9.8 Critical
In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution.
CVE-2021-25640 1 Apache 1 Dubbo 2024-11-21 6.1 Medium
In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or SSRF vulnerability.
CVE-2021-25527 1 Samsung 1 Pay 2024-11-21 3.8 Low
Improper export of Android application components vulnerability in Samsung Pay (India only) prior to version 4.1.77 allows attacker to access Bill Pay and Recharge menu without authentication.
CVE-2021-25526 1 Samsung 1 Blockchain Wallet 2024-11-21 4 Medium
Intent redirection vulnerability in Samsung Blockchain Wallet prior to version 1.3.02.8 allows attacker to execute privileged action.
CVE-2021-25524 1 Samsung 1 Contacts 2024-11-21 4 Medium
Insecure storage of device information in Contacts prior to version 12.7.05.24 allows attacker to get Samsung Account ID.
CVE-2021-25523 1 Samsung 1 Dialer 2024-11-21 4 Medium
Insecure storage of device information in Samsung Dialer prior to version 12.7.05.24 allows attacker to get Samsung Account ID.