Export limit exceeded: 357918 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (357918 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-38674 | 1 Qnap | 3 Qts, Quts Hero, Qutscloud | 2024-11-21 | 4.2 Medium |
| A cross-site scripting (XSS) vulnerability has been reported to affect QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QTS, QuTS hero and QuTScloud: QuTS hero h4.5.4.1771 build 20210825 and later QTS 4.5.4.1787 build 20210910 and later QuTScloud c4.5.7.1864 and later | ||||
| CVE-2021-38672 | 1 Microsoft | 3 Windows 11, Windows 11 21h2, Windows Server 2022 | 2024-11-21 | 8 High |
| Windows Hyper-V Remote Code Execution Vulnerability | ||||
| CVE-2021-38666 | 1 Microsoft | 22 Windows 10, Windows 10 1507, Windows 10 1607 and 19 more | 2024-11-21 | 8.8 High |
| Remote Desktop Client Remote Code Execution Vulnerability | ||||
| CVE-2021-38663 | 1 Microsoft | 23 Windows 10, Windows 10 1507, Windows 10 1607 and 20 more | 2024-11-21 | 5.5 Medium |
| Windows exFAT File System Information Disclosure Vulnerability | ||||
| CVE-2021-38662 | 1 Microsoft | 23 Windows 10, Windows 10 1507, Windows 10 1607 and 20 more | 2024-11-21 | 5.5 Medium |
| Windows Fast FAT File System Driver Information Disclosure Vulnerability | ||||
| CVE-2021-38631 | 1 Microsoft | 22 Windows 10, Windows 10 1507, Windows 10 1607 and 19 more | 2024-11-21 | 4.4 Medium |
| Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | ||||
| CVE-2021-38623 | 1 Deferred Image Processing Project | 1 Deferred Image Processing | 2024-11-21 | 7.5 High |
| The deferred_image_processing (aka Deferred image processing) extension before 1.0.2 for TYPO3 allows Denial of Service via the FAL API because of /var/transient disk consumption. | ||||
| CVE-2021-38621 | 1 Netless | 1 Flat Server | 2024-11-21 | 9.1 Critical |
| The remove API in v1/controller/cloudStorage/alibabaCloud/remove/index.ts in netless Agora Flat Server before 2021-07-30 mishandles file ownership. | ||||
| CVE-2021-38619 | 1 Openbaraza | 1 Openbaraza Human Capital Management | 2024-11-21 | 6.1 Medium |
| openBaraza HCM 3.1.6 does not properly neutralize user-controllable input: an unauthenticated remote attacker can conduct a stored cross-site scripting (XSS) attack against an administrative user from hr/subscription.jsp and hr/application.jsp and and hr/index.jsp (with view=). | ||||
| CVE-2021-38614 | 1 Polipo Project | 1 Polipo | 2024-11-21 | 7.5 High |
| Polipo through 1.1.1, when NDEBUG is used, allows a heap-based buffer overflow during parsing of a Range header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | ||||
| CVE-2021-38613 | 1 Nascent | 1 Remkon Device Manager | 2024-11-21 | 9.8 Critical |
| The assets/index.php Image Upload feature of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to upload any code to the target system and achieve remote code execution. | ||||
| CVE-2021-38612 | 1 Nascent | 1 Remkon Device Manager | 2024-11-21 | 7.5 High |
| In NASCENT RemKon Device Manager 4.0.0.0, a Directory Traversal vulnerability in a log-reading function in maintenance/readLog.php allows an attacker to read any file via a specialized URL. | ||||
| CVE-2021-38611 | 1 Nascent | 1 Remkon Device Manager | 2024-11-21 | 9.8 Critical |
| A command-injection vulnerability in the Image Upload function of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to execute arbitrary commands, as root, via shell metacharacters in the filename parameter to assets/index.php. | ||||
| CVE-2021-38608 | 1 Tranquil | 1 Wapt | 2024-11-21 | 7.8 High |
| Incorrect Access Control in Tranquil WAPT Enterprise - before 1.8.2.7373 and before 2.0.0.9450 allows guest OS users to escalate privileges via WAPT Agent. | ||||
| CVE-2021-38607 | 1 Crocoblock | 1 Jetengine | 2024-11-21 | 5.4 Medium |
| Crocoblock JetEngine before 2.6.1 allows XSS by remote authenticated users via a custom form input. | ||||
| CVE-2021-38606 | 1 Yogeshojha | 1 Rengine | 2024-11-21 | 9.8 Critical |
| reNgine through 0.5 relies on a predictable directory name. | ||||
| CVE-2021-38603 | 1 Pluxml | 1 Pluxml | 2024-11-21 | 4.8 Medium |
| PluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field. | ||||
| CVE-2021-38602 | 1 Pluxml | 1 Pluxml | 2024-11-21 | 4.8 Medium |
| PluXML 5.8.7 allows Article Editing stored XSS via Headline or Content. | ||||
| CVE-2021-38599 | 1 Wal-g Project | 1 Wal-g | 2024-11-21 | 7.5 High |
| WAL-G before 1.1, when a non-libsodium build (e.g., one of the official binary releases published as GitHub Releases) is used, silently ignores the libsodium encryption key and uploads cleartext backups. This is arguably a Principle of Least Surprise violation because "the user likely wanted to encrypt all file activity." | ||||
| CVE-2021-38598 | 1 Openstack | 1 Neutron | 2024-11-21 | 9.1 Critical |
| OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the hardware addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations. | ||||