Search

Search Results (362568 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-26474 1 Vembu 2 Bdr Suite, Offsite Dr 2024-11-21 8.6 High
Various Vembu products allow an attacker to execute a (non-blind) http-only Cross Site Request Forgery (Other products or versions of products in this family may be affected too.)
CVE-2021-26473 1 Vembu 2 Bdr Suite, Offsite Dr 2024-11-21 9.8 Critical
In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 the http API located at /sgwebservice_o.php action logFilePath allows an attacker to write arbitrary files in the context of the web server process. These files can then be executed remotely by calling the file via the web server.
CVE-2021-26472 2 Microsoft, Vembu 3 Windows, Bdr Suite, Offsite Dr 2024-11-21 10 Critical
In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 installed on Windows, the http API located at /consumerweb/secure/download.php. Using this command argument an unauthenticated attacker can execute arbitrary OS commands with SYSTEM privileges.
CVE-2021-26471 1 Vembu 2 Bdr Suite, Offsite Dr 2024-11-21 9.8 Critical
In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1, the http API located at /sgwebservice_o.php accepts a command argument. Using this command argument an unauthenticated attacker can execute arbitrary shell commands.
CVE-2021-26461 1 Apache 1 Nuttx 2024-11-21 9.8 Critical
Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
CVE-2021-26442 1 Microsoft 22 Windows 10, Windows 10 1507, Windows 10 1607 and 19 more 2024-11-21 7 High
Windows HTTP.sys Elevation of Privilege Vulnerability
CVE-2021-26441 1 Microsoft 19 Windows 10, Windows 10 1507, Windows 10 1607 and 16 more 2024-11-21 7.8 High
Storage Spaces Controller Elevation of Privilege Vulnerability
CVE-2021-26427 1 Microsoft 1 Exchange Server 2024-11-21 9 Critical
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26422 1 Microsoft 2 Lync Server, Skype For Business Server 2024-11-21 7.2 High
Skype for Business and Lync Remote Code Execution Vulnerability
CVE-2021-26421 1 Microsoft 2 Lync Server, Skype For Business Server 2024-11-21 6.5 Medium
Skype for Business and Lync Spoofing Vulnerability
CVE-2021-26420 1 Microsoft 3 Sharepoint Enterprise Server, Sharepoint Foundation, Sharepoint Server 2024-11-21 7.1 High
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2021-26419 1 Microsoft 9 Internet Explorer, Windows 10, Windows 7 and 6 more 2024-11-21 7.5 High
Scripting Engine Memory Corruption Vulnerability
CVE-2021-26417 1 Microsoft 9 Windows 10, Windows 10 1809, Windows 10 1909 and 6 more 2024-11-21 5.5 Medium
Windows Overlay Filter Information Disclosure Vulnerability
CVE-2021-26416 1 Microsoft 9 Windows 10, Windows 10 1607, Windows 10 1809 and 6 more 2024-11-21 7.7 High
Windows Hyper-V Denial of Service Vulnerability
CVE-2021-26415 1 Microsoft 20 Windows 10, Windows 10 1507, Windows 10 1607 and 17 more 2024-11-21 7.8 High
Windows Installer Elevation of Privilege Vulnerability
CVE-2021-26414 1 Microsoft 21 Windows 10, Windows 10 1507, Windows 10 1607 and 18 more 2024-11-21 4.8 Medium
Windows DCOM Server Security Feature Bypass
CVE-2021-26413 1 Microsoft 20 Windows 10, Windows 10 1507, Windows 10 1607 and 17 more 2024-11-21 6.2 Medium
Windows Installer Spoofing Vulnerability
CVE-2021-26408 1 Amd 76 Epyc 7001, Epyc 7001 Firmware, Epyc 7002 and 73 more 2024-11-21 7.1 High
Insufficient validation of elliptic curve points in SEV-legacy firmware may compromise SEV-legacy guest migration potentially resulting in loss of guest's integrity or confidentiality.
CVE-2021-26401 2 Amd, Redhat 255 A10-9600p, A10-9600p Firmware, A10-9630p and 252 more 2024-11-21 5.6 Medium
LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.
CVE-2021-26400 1 Amd 1 Cpu 2024-11-21 4.0 Medium
AMD processors may speculatively re-order load instructions which can result in stale data being observed when multiple processors are operating on shared memory, resulting in potential data leakage.