Search

Search Results (37079 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-40464 1 Microsoft 13 Windows 10, Windows 10 1809, Windows 10 1909 and 10 more 2024-11-21 8 High
Windows Nearby Sharing Elevation of Privilege Vulnerability
CVE-2021-40463 1 Microsoft 18 Windows 10, Windows 10 1507, Windows 10 1607 and 15 more 2024-11-21 7.7 High
Windows Network Address Translation (NAT) Denial of Service Vulnerability
CVE-2021-40462 1 Microsoft 14 Windows 10, Windows 10 1809, Windows 10 1909 and 11 more 2024-11-21 7.8 High
Windows Media Foundation Dolby Digital Atmos Decoders Remote Code Execution Vulnerability
CVE-2021-40461 1 Microsoft 12 Windows 10, Windows 10 1809, Windows 10 1909 and 9 more 2024-11-21 8 High
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2021-40460 1 Microsoft 22 Windows 10, Windows 10 1507, Windows 10 1607 and 19 more 2024-11-21 6.5 Medium
Windows Remote Procedure Call Runtime Security Feature Bypass Vulnerability
CVE-2021-40457 1 Microsoft 1 Dynamics 365 2024-11-21 7.4 High
Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability
CVE-2021-40456 1 Microsoft 5 Windows Server, Windows Server 2004, Windows Server 2019 and 2 more 2024-11-21 5.3 Medium
Windows AD FS Security Feature Bypass Vulnerability
CVE-2021-40455 1 Microsoft 23 Windows 10, Windows 10 1507, Windows 10 1607 and 20 more 2024-11-21 5.5 Medium
Windows Installer Spoofing Vulnerability
CVE-2021-40454 1 Microsoft 22 365 Apps, Office, Office Long Term Servicing Channel and 19 more 2024-11-21 5.5 Medium
Rich Text Edit Control Information Disclosure Vulnerability
CVE-2021-40443 1 Microsoft 23 Windows 10, Windows 10 1507, Windows 10 1607 and 20 more 2024-11-21 7.8 High
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-40347 1 Postorius Project 1 Postorius 2024-11-21 5.4 Medium
An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a mailing list, also revealing whether that address was subscribed in the first place.
CVE-2021-40326 2 Foxit, Microsoft 4 Pdf Editor, Pdf Reader, Phantompdf and 1 more 2024-11-21 5.5 Medium
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental data in signed documents. An attacker can write to an arbitrary file, and display controlled contents, during signature verification.
CVE-2021-40292 1 Dzzoffice 1 Dzzoffice 2024-11-21 5.4 Medium
A Stored Cross Site Sripting (XSS) vulnerability exists in DzzOffice 2.02.1 via the settingnew parameter.
CVE-2021-40285 1 Htmly 1 Htmly 2024-11-21 8.1 High
htmly v2.8.1 was discovered to contain an arbitrary file deletion vulnerability via the component \views\backup.html.php.
CVE-2021-40239 1 Miniftpd Project 1 Miniftpd 2024-11-21 9.8 Critical
A Buffer Overflow vulnerability exists in the latest version of Miniftpd in the do_retr function in ftpproto.c
CVE-2021-40191 1 Dzzoffice 1 Dzzoffice 2024-11-21 5.4 Medium
Dzzoffice Version 2.02.1 is affected by cross-site scripting (XSS) due to a lack of sanitization of input data at all upload functions in webroot/dzz/attach/Uploader.class.php and return a wrong response in content-type of output data in webroot/dzz/attach/controller.php.
CVE-2021-40189 1 Php-fusion 1 Phpfusion 2024-11-21 7.2 High
PHPFusion 9.03.110 is affected by a remote code execution vulnerability. The theme function will extract a file to "webroot/themes/{Theme Folder], where an attacker can access and execute arbitrary code.
CVE-2021-40188 1 Php-fusion 1 Phpfusion 2024-11-21 7.2 High
PHPFusion 9.03.110 is affected by an arbitrary file upload vulnerability. The File Manager function in admin panel does not filter all PHP extensions such as ".php, .php7, .phtml, .php5, ...". An attacker can upload a malicious file and execute code on the server.
CVE-2021-40166 1 Autodesk 19 Autocad, Autocad Advance Steel, Autocad Architecture and 16 more 2024-11-21 7.8 High
A maliciously crafted PNG file in Autodesk Image Processing component may be used to attempt to free an object that has already been freed while parsing them. This vulnerability may be exploited by attackers to execute arbitrary code.
CVE-2021-40165 1 Autodesk 19 Autocad, Autocad Advance Steel, Autocad Architecture and 16 more 2024-11-21 7.8 High
A maliciously crafted TIFF, PICT, TGA, or RLC file in Autodesk Image Processing component may be used to write beyond the allocated buffer while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.