Export limit exceeded: 385093 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (385093 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-46229 | 1 Dlink | 2 Di-7200gv2, Di-7200gv2 Firmware | 2024-11-21 | 9.8 Critical |
| D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function usb_paswd.asp. This vulnerability allows attackers to execute arbitrary commands via the name parameter. | ||||
| CVE-2021-46228 | 1 Dlink | 2 Di-7200gv2, Di-7200gv2 Firmware | 2024-11-21 | 9.8 Critical |
| D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function httpd_debug.asp. This vulnerability allows attackers to execute arbitrary commands via the time parameter. | ||||
| CVE-2021-46227 | 1 Dlink | 2 Di-7200gv2, Di-7200gv2 Firmware | 2024-11-21 | 9.8 Critical |
| D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function proxy_client.asp. This vulnerability allows attackers to execute arbitrary commands via the proxy_srv, proxy_srvport, proxy_lanip, proxy_lanport parameters. | ||||
| CVE-2021-46226 | 1 Dlink | 2 Di-7200gv2, Di-7200gv2 Firmware | 2024-11-21 | 9.8 Critical |
| D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function wget_test.asp. This vulnerability allows attackers to execute arbitrary commands via the url parameter. | ||||
| CVE-2021-46225 | 1 Libmeshb Project | 1 Libmeshb | 2024-11-21 | 6.5 Medium |
| A buffer overflow in the GmfOpenMesh() function of libMeshb v7.61 allows attackers to cause a Denial of Service (DoS) via a crafted MESH file. | ||||
| CVE-2021-46204 | 1 Taogogo | 1 Taocms | 2024-11-21 | 9.8 Critical |
| Taocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter. SQL injection vulnerability via taocms\include\Model\Article.php. | ||||
| CVE-2021-46203 | 1 Taogogo | 1 Taocms | 2024-11-21 | 6.5 Medium |
| Taocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter. | ||||
| CVE-2021-46201 | 1 Online Resort Management System Project | 1 Online Resort Management System | 2024-11-21 | 9.8 Critical |
| An SQL Injection vulnerability exists in Sourcecodester Online Resort Management System 1.0 via the id parameterv in /orms/ node. | ||||
| CVE-2021-46198 | 1 Courier Management System Project | 1 Courier Management System | 2024-11-21 | 9.8 Critical |
| An SQL Injection vulnerability exists in Sourceodester Courier Management System 1.0 via the email parameter in /cms/ajax.php app. | ||||
| CVE-2021-46195 | 2 Gnu, Redhat | 2 Gcc, Enterprise Linux | 2024-11-21 | 5.5 Medium |
| GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources. | ||||
| CVE-2021-46174 | 2 Binutils, Gnu | 2 Objdump, Binutils | 2024-11-21 | 7.5 High |
| Heap-based Buffer Overflow in function bfd_getl32 in Binutils objdump 3.37. | ||||
| CVE-2021-46171 | 1 Modex Project | 1 Modex | 2024-11-21 | 5.5 Medium |
| Modex v2.11 was discovered to contain a NULL pointer dereference in set_create_id() at xtract.c. | ||||
| CVE-2021-46170 | 1 Jerryscript | 1 Jerryscript | 2024-11-21 | 7.5 High |
| An issue was discovered in JerryScript commit a6ab5e9. There is an Use-After-Free in lexer_compare_identifier_to_string in js-lexer.c file. | ||||
| CVE-2021-46169 | 1 Modex Project | 1 Modex | 2024-11-21 | 5.5 Medium |
| Modex v2.11 was discovered to contain an Use-After-Free vulnerability via the component tcache. | ||||
| CVE-2021-46168 | 1 Spinroot | 1 Spin | 2024-11-21 | 5.5 Medium |
| Spin v6.5.1 was discovered to contain an out-of-bounds write in lex() at spinlex.c. | ||||
| CVE-2021-46167 | 1 Wizplat | 2 Pd065, Pd065 Firmware | 2024-11-21 | 7.8 High |
| An access control issue in the authentication module of wizplat PD065 v1.19 allows attackers to access sensitive data and cause a Denial of Service (DoS). | ||||
| CVE-2021-46166 | 1 Zohocorp | 1 Manageengine Desktop Central | 2024-11-21 | 6.5 Medium |
| Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Reports page. | ||||
| CVE-2021-46165 | 1 Zohocorp | 1 Manageengine Desktop Central | 2024-11-21 | 7.8 High |
| Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from the batch files, but this file's path might not be properly defined. | ||||
| CVE-2021-46164 | 1 Zohocorp | 1 Manageengine Desktop Central | 2024-11-21 | 8.8 High |
| Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated user who has complete access to the Reports module. | ||||
| CVE-2021-46162 | 1 Siemens | 1 Simcenter Femap | 2024-11-21 | 7.8 High |
| A vulnerability has been identified in Simcenter Femap (All versions < V2022.1.1). Affected application contains an out of bounds write past the end of an allocated structure while parsing specially crafted NEU files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-15048) | ||||