Export limit exceeded: 380956 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (380956 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-26909 | 1 Automox | 1 Automox | 2024-11-21 | 3.7 Low |
| Automox Agent prior to version 31 uses an insufficiently protected S3 bucket endpoint for storing sensitive files, which could be brute-forced by an attacker to subvert an organization's security program. The issue has since been fixed in version 31 of the Automox Agent. | ||||
| CVE-2021-26908 | 1 Automox | 1 Automox | 2024-11-21 | 3.3 Low |
| Automox Agent prior to version 31 logs potentially sensitive information in local log files, which could be used by a locally-authenticated attacker to subvert an organization's security program. The issue has since been fixed in version 31 of the Automox Agent. | ||||
| CVE-2021-26906 | 1 Digium | 2 Asterisk, Certified Asterisk | 2024-11-21 | 5.9 Medium |
| An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.x through 18.2.0, and Certified Asterisk through 16.8-cert5. An SDP negotiation vulnerability in PJSIP allows a remote server to potentially crash Asterisk by sending specific SIP responses that cause an SDP negotiation failure. | ||||
| CVE-2021-26905 | 1 1password | 1 Scim Bridge | 2024-11-21 | 6.5 Medium |
| 1Password SCIM Bridge before 1.6.2 mishandles validation of authenticated requests for log files, leading to disclosure of a TLS private key. | ||||
| CVE-2021-26904 | 1 Isida | 1 Retriever | 2024-11-21 | 9.8 Critical |
| LMA ISIDA Retriever 5.2 allows SQL Injection. | ||||
| CVE-2021-26903 | 1 Isida | 1 Retriever | 2024-11-21 | 6.1 Medium |
| LMA ISIDA Retriever 5.2 is vulnerable to XSS via query['text']. | ||||
| CVE-2021-26845 | 1 Hitachienergy | 1 Esoms | 2024-11-21 | 7.5 High |
| Information Exposure vulnerability in Hitachi ABB Power Grids eSOMS allows unauthorized user to gain access to report data if the URL used to access the report is discovered. This issue affects: Hitachi ABB Power Grids eSOMS 6.0 versions prior to 6.0.4.2.2; 6.1 versions prior to 6.1.4; 6.3 versions prior to 6.3. | ||||
| CVE-2021-26844 | 1 Poweradmin | 1 Pa Server Monitor | 2024-11-21 | 5.4 Medium |
| A cross-site scripting (XSS) vulnerability in Power Admin PA Server Monitor 8.2.1.1 allows remote attackers to inject arbitrary web script or HTML via Console.exe. | ||||
| CVE-2021-26843 | 1 Sthttpd Project | 1 Sthttpd | 2024-11-21 | 7.5 High |
| An issue was discovered in sthttpd through 2.27.1. On systems where the strcpy function is implemented with memcpy, the de_dotdot function may cause a Denial-of-Service (daemon crash) due to overlapping memory ranges being passed to memcpy. This can triggered with an HTTP GET request for a crafted filename. NOTE: this is similar to CVE-2017-10671, but occurs in a different part of the de_dotdot function. | ||||
| CVE-2021-26837 | 1 Fortra | 1 Delivernow | 2024-11-21 | 9.8 Critical |
| SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute arbitrary code, escalate privileges, and gain sensitive information. | ||||
| CVE-2021-26835 | 1 Zettlr | 1 Zettlr | 2024-11-21 | 6.1 Medium |
| No filtering of cross-site scripting (XSS) payloads in the markdown-editor in Zettlr 1.8.7 allows attackers to perform remote code execution via a crafted file. | ||||
| CVE-2021-26834 | 1 Znote | 1 Znote | 2024-11-21 | 5.4 Medium |
| A cross-site scripting (XSS) vulnerability exists in Znote 0.5.2. An attacker can insert payloads, and the code execution will happen immediately on markdown view mode. | ||||
| CVE-2021-26833 | 1 Timelybills | 1 Timelybills | 2024-11-21 | 5.9 Medium |
| Cleartext Storage in a File or on Disk in TimelyBills <= 1.7.0 for iOS and versions <= 1.21.115 for Android allows attacker who can locally read user's files obtain JWT tokens for user's account due to insufficient cache clearing mechanisms. A threat actor can obtain sensitive user data by decoding the tokens as JWT is signed and encoded, not encrypted. | ||||
| CVE-2021-26832 | 1 Priority-software | 1 Priority Enterprise Management System | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting (XSS) in the "Reset Password" page form of Priority Enterprise Management System v8.00 allows attackers to execute javascript on behalf of the victim by sending a malicious URL or directing the victim to a malicious site. | ||||
| CVE-2021-26830 | 1 Tribalsystems | 1 Zenario | 2024-11-21 | 9.1 Critical |
| SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin library - delete` module. | ||||
| CVE-2021-26827 | 1 Tp-link | 2 Tl-wr2041\+, Tl-wr2041\+ Firmware | 2024-11-21 | 7.5 High |
| Buffer Overflow in TP-Link WR2041 v1 firmware for the TL-WR2041+ router allows remote attackers to cause a Denial-of-Service (DoS) by sending an HTTP request with a very long "ssid" parameter to the "/userRpm/popupSiteSurveyRpm.html" webpage, which crashes the router. | ||||
| CVE-2021-26826 | 1 Godotengine | 1 Godot Engine | 2024-11-21 | 7.8 High |
| A stack overflow issue exists in Godot Engine up to v3.2 and is caused by improper boundary checks when loading .TGA image files. Depending on the context of the application, attack vector can be local or remote, and can lead to code execution and/or system crash. | ||||
| CVE-2021-26825 | 1 Godotengine | 1 Godot Engine | 2024-11-21 | 7.8 High |
| An integer overflow issue exists in Godot Engine up to v3.2 that can be triggered when loading specially crafted.TGA image files. The vulnerability exists in ImageLoaderTGA::load_image() function at line: const size_t buffer_size = (tga_header.image_width * tga_header.image_height) * pixel_size; The bug leads to Dynamic stack buffer overflow. Depending on the context of the application, attack vector can be local or remote, and can lead to code execution and/or system crash. | ||||
| CVE-2021-26824 | 1 Dm Fingertool Project | 1 Dm Fingertool | 2024-11-21 | 7.1 High |
| DM FingerTool v1.19 in the DM PD065 Secure USB is susceptible to improper authentication by a replay attack, allowing local attackers to bypass user authentication and access all features and data on the USB. | ||||
| CVE-2021-26822 | 1 Phpgurukul | 1 Teachers Record Management System | 2024-11-21 | 9.8 Critical |
| Teachers Record Management System 1.0 is affected by a SQL injection vulnerability in 'searchteacher' POST parameter in search-teacher.php. This vulnerability can be exploited by a remote unauthenticated attacker to leak sensitive information and perform code execution attacks. | ||||