Search Results (79588 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-43283 1 Govicture 2 Wr1200, Wr1200 Firmware 2024-11-21 8.8 High
An issue was discovered on Victure WR1200 devices through 1.0.3. A command injection vulnerability was found within the web interface of the device, allowing an attacker with valid credentials to inject arbitrary shell commands to be executed by the device with root privileges. This occurs in the ping and traceroute features. An attacker would thus be able to use this vulnerability to open a reverse shell on the device with root privileges.
CVE-2021-43281 1 Mybb 1 Mybb 2024-11-21 7.2 High
MyBB before 1.8.29 allows Remote Code Injection by an admin with the "Can manage settings?" permission. The Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of supported type "php" with PHP code, executed on Change Settings pages.
CVE-2021-43280 1 Opendesign 1 Drawings Software Development Kit 2024-11-21 7.8 High
A stack-based buffer overflow vulnerability exists in the DWF file reading procedure in Open Design Alliance Drawings SDK before 2022.8. The issue results from the lack of proper validation of the length of user-supplied data before copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
CVE-2021-43279 1 Opendesign 1 Oda Prc Software Development Kit 2024-11-21 7.8 High
An out-of-bounds write vulnerability exists in the U3D file reading procedure in Open Design Alliance PRC SDK before 2022.10. Crafted data in a U3D file can trigger a write past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.
CVE-2021-43278 1 Opendesign 1 Drawings Software Developemnt Kit 2024-11-21 7.8 High
An Out-of-bounds Read vulnerability exists in the OBJ file reading procedure in Open Design Alliance Drawings SDK before 2022.11. The lack of validating the input length can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
CVE-2021-43277 1 Opendesign 1 Oda Prc Software Development Kit 2024-11-21 7.8 High
An out-of-bounds read vulnerability exists in the U3D file reading procedure in Open Design Alliance PRC SDK before 2022.10. Crafted data in a U3D file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.
CVE-2021-43276 1 Opendesign 1 Oda Viewer 2024-11-21 7.8 High
An Out-of-bounds Read vulnerability exists in Open Design Alliance ODA Viewer before 2022.8. Crafted data in a DWF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process
CVE-2021-43275 1 Opendesign 1 Drawings Software Development Kit 2024-11-21 7.8 High
A Use After Free vulnerability exists in the DGN file reading procedure in Open Design Alliance Drawings SDK before 2022.8. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process.
CVE-2021-43274 1 Opendesign 1 Drawings Software Development Kit 2024-11-21 7.8 High
A Use After Free Vulnerability exists in the Open Design Alliance Drawings SDK before 2022.11. The specific flaw exists within the parsing of DWF files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.
CVE-2021-43270 1 Datalust 1 Seq.app.emailplus 2024-11-21 7.5 High
Datalust Seq.App.EmailPlus (aka seq-app-htmlemail) 3.1.0-dev-00148, 3.1.0-dev-00170, and 3.1.0-dev-00176 can use cleartext SMTP on port 25 in some cases where encryption on port 465 was intended.
CVE-2021-43269 1 Code42 1 Code42 2024-11-21 8.8 High
In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config (PAC) file, leading to arbitrary code execution. This affects Incydr Basic, Advanced, and Gov F1; CrashPlan Cloud; and CrashPlan for Small Business. (Incydr Professional and Enterprise are unaffected.)
CVE-2021-43266 1 Mahara 1 Mahara 2024-11-21 7.3 High
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exporting collections via PDF export could lead to code execution via shell metacharacters in a collection name. Additional, in Mahara before 20.10.4, 21.04.3, and 21.10.1, exporting collections via PDF export could cause code execution
CVE-2021-43257 1 Mantisbt 1 Mantisbt 2024-11-21 7.8 High
Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain access to information when a user opens the csv_export.php generated CSV file in Excel.
CVE-2021-43256 1 Microsoft 8 365 Apps, Excel, Excel Rt and 5 more 2024-11-21 7.8 High
Microsoft Excel Remote Code Execution Vulnerability
CVE-2021-43248 1 Microsoft 22 Windows 10, Windows 10 1507, Windows 10 1607 and 19 more 2024-11-21 7.8 High
Windows Digital Media Receiver Elevation of Privilege Vulnerability
CVE-2021-43247 1 Microsoft 14 Windows 10, Windows 10 1809, Windows 10 1909 and 11 more 2024-11-21 7.8 High
Windows TCP/IP Driver Elevation of Privilege Vulnerability
CVE-2021-43245 1 Microsoft 7 Windows 7, Windows 8.1, Windows Rt 8.1 and 4 more 2024-11-21 7.8 High
Windows Digital TV Tuner Elevation of Privilege Vulnerability
CVE-2021-43242 1 Microsoft 3 Sharepoint Enterprise Server, Sharepoint Foundation, Sharepoint Server 2024-11-21 7.6 High
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2021-43240 1 Microsoft 13 Windows 10, Windows 10 1809, Windows 10 1909 and 10 more 2024-11-21 7.8 High
NTFS Set Short Name Elevation of Privilege Vulnerability
CVE-2021-43239 1 Microsoft 12 Windows 10, Windows 10 1809, Windows 10 20h2 and 9 more 2024-11-21 7.1 High
Windows Recovery Environment Agent Elevation of Privilege Vulnerability