Click to open the Alert Filter

 
Year Month
Severity
Categories
Search by Alert Name
Page(s) : 1 ... 699 700 701 702 703 704 705 706 707 708 [709] 710 711 712 713 714 715 716 717 718 719 ... Result(s) : 43441

Alerts Feed Alerts

DATE NAME CATEGORIES DETAIL
9.8 2021-10-11 CVE-2021-40887 cve Projectsend version r1295 is affected by a directory traversal vulnerability. Because of lacking sanitization input for files[] parameter, an attacker can add ../ to move all PH...
9.1 2021-10-08 CVE-2021-41975 cve TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to delete arbitrary files in the system without logging in.
9.1 2021-10-08 CVE-2021-41974 cve Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view and modify arbitrary content of books without permission.
9.8 2021-10-08 CVE-2021-36767 cve In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making the protection ineffective. An attack...
9.8 2021-10-08 CVE-2021-35977 cve An issue was discovered in Digi RealPort for Windows through 4.8.488.0. A buffer overflow exists in the handling of ADDP discovery response messages. This could result in arbitr...
9.8 2021-10-08 CVE-2021-41566 cve The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of files and execute arbitrary code without logging in.
9.6 2021-10-08 CVE-2021-30633 cve Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escap...
9.8 2021-10-08 CVE-2020-22617 cve Ardour v5.12 contains a use-after-free vulnerability in the component ardour/libs/pbd/xml++.cc when using xmlFreeDoc and xmlXPathFreeContext.
9.8 2021-10-08 CVE-2021-42109 cve VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root.
9.6 2021-10-08 CVE-2021-37973 cve Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a...
9.8 2021-10-07 CVE-2020-21865 cve ThinkPHP50-CMS v1.0 contains a remote code execution (RCE) vulnerability in the component /public/?s=captcha.
9.8 2021-10-07 CVE-2021-42094 cve An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.
9.1 2021-10-07 CVE-2021-42091 cve An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration.
9.8 2021-10-07 CVE-2021-22958 cve A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the limitations in place for localhost al...
9.8 2021-10-07 CVE-2020-21726 cve OpenSNS v6.1.0 contains a blind SQL injection vulnerability in /Controller/ChinaCityController.class.php via the cid parameter.
9.8 2021-10-07 CVE-2021-3832 cve Integria IMS in its 5.0.92 version is vulnerable to a Remote Code Execution attack through file uploading. An unauthenticated attacker could abuse the AsyncUpload() function in ...
9.8 2021-10-07 CVE-2021-42090 cve An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.
9.8 2021-10-07 CVE-2021-22930 cve Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.
9.8 2021-10-07 CVE-2021-38298 cve Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.
9.8 2021-10-07 CVE-2020-21725 cve OpenSNS v6.1.0 contains a blind SQL injection vulnerability in /Controller/ChinaCityController.class.php via the pid parameter.
Page(s) : 1 ... 699 700 701 702 703 704 705 706 707 708 [709] 710 711 712 713 714 715 716 717 718 719 ... Result(s) : 43441