Export limit exceeded: 46075 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (46075 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-42897 | 1 Feminer Wms Project | 1 Feminer Wms | 2024-11-21 | 9.8 Critical |
| A remote command execution (RCE) vulnerability was found in FeMiner wms V1.0 in /wms/src/system/datarec.php. The $_POST[r_name] is directly passed into the $mysqlstr and is executed by exec. | ||||
| CVE-2021-42870 | 1 Accel-ppp | 1 Accel-ppp | 2024-11-21 | 7.5 High |
| ACCEL-PPP 1.12.0 has an out-of-bounds read in post_msg when processing a call_clear_request. | ||||
| CVE-2021-42851 | 1 Lenovo | 10 A1, A1 Firmware, T1 and 7 more | 2024-11-21 | 6.3 Medium |
| A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to create a standard user account. | ||||
| CVE-2021-42848 | 1 Lenovo | 10 A1, A1 Firmware, T1 and 7 more | 2024-11-21 | 4.3 Medium |
| An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrieve device and networking details. | ||||
| CVE-2021-42811 | 1 Thalesgroup | 1 Safenet Keysecure | 2024-11-21 | 3.3 Low |
| Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SafeNet KeySecure allows an authenticated user to read arbitrary files from the underlying system on which the product is deployed. | ||||
| CVE-2021-42751 | 1 Thingsboard | 1 Thingsboard | 2024-11-21 | 4.8 Medium |
| A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the description of a rule node. | ||||
| CVE-2021-42750 | 1 Thingsboard | 1 Thingsboard | 2024-11-21 | 4.8 Medium |
| A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the title of a rule node. | ||||
| CVE-2021-42732 | 3 Adobe, Apple, Microsoft | 3 Indesign, Macos, Windows | 2024-11-21 | 7.8 High |
| Access of Memory Location After End of Buffer (CWE-788) | ||||
| CVE-2021-42675 | 1 Kreado | 1 Kreasfero | 2024-11-21 | 9.8 Critical |
| Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP file and obtain remote code execution. | ||||
| CVE-2021-42656 | 1 Sscms | 1 Siteserver Cms | 2024-11-21 | 5.4 Medium |
| SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability. | ||||
| CVE-2021-42655 | 1 Sscms | 1 Siteserver Cms | 2024-11-21 | 8.8 High |
| SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability. | ||||
| CVE-2021-42654 | 1 Sscms | 1 Siteserver Cms | 2024-11-21 | 9.8 Critical |
| SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code. | ||||
| CVE-2021-42644 | 1 Cmseasy | 1 Cmseasy | 2024-11-21 | 6.5 Medium |
| cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file information of the website such as the database configuration file (config / config_database) can be read through this vulnerability. | ||||
| CVE-2021-42643 | 1 Cmseasy | 1 Cmseasy | 2024-11-21 | 8.8 High |
| cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability. Through this vulnerability, a PHP script file is written to the website server, and accessing this file can lead to a code execution vulnerability. | ||||
| CVE-2021-42614 | 2 Fedoraproject, Halibut Project | 2 Fedora, Halibut | 2024-11-21 | 7.8 High |
| A use after free in info_width_internal in bk_info.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly have unspecified other impact via a crafted text document. | ||||
| CVE-2021-42613 | 2 Fedoraproject, Halibut Project | 2 Fedora, Halibut | 2024-11-21 | 7.8 High |
| A double free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a denial of service or possibly have other unspecified impact via a crafted text document. | ||||
| CVE-2021-42612 | 2 Fedoraproject, Halibut Project | 2 Fedora, Halibut | 2024-11-21 | 7.8 High |
| A use after free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly have other unspecified impact via a crafted text document. | ||||
| CVE-2021-42586 | 1 Gnu | 1 Libredwg | 2024-11-21 | 8.8 High |
| A heap buffer overflow was discovered in copy_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file. | ||||
| CVE-2021-42585 | 1 Gnu | 1 Libredwg | 2024-11-21 | 8.8 High |
| A heap buffer overflow was discovered in copy_compressed_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file. | ||||
| CVE-2021-42552 | 1 Archivista | 1 Archivistabox | 2024-11-21 | 6.1 Medium |
| Cross-site Scripting (XSS) vulnerability in ArchivistaBox webclient allows an attacker to craft a malicious link, executing JavaScript in the context of a victim's browser. This issue affects all ArchivistaBox versions prior to 2022/I. | ||||