Show filters
204 topics marked with the following tags:
Displaying 181-190 of 204
Sort by:
Attacker Value
Very High

CVE-2021-26857

Disclosure Date: March 03, 2021 (last updated July 26, 2024)
Microsoft Exchange Server Remote Code Execution Vulnerability
Attacker Value
High

CVE-2021-42321

Disclosure Date: November 10, 2021 (last updated January 18, 2024)
Microsoft Exchange Server Remote Code Execution Vulnerability
Attacker Value
High

CVE-2022-21882

Disclosure Date: January 11, 2022 (last updated November 16, 2024)
Win32k Elevation of Privilege Vulnerability
Attacker Value
Moderate

CVE-2024-24725

Disclosure Date: March 23, 2024 (last updated April 02, 2024)
Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the modules/System%20Admin/import_run.php&type=externalAssessment&step=4 URI.
2
Attacker Value
Very High
The Online-Catering-Reservation-DT Food-Catering(by: oretnom23)v1.0 is vulnerable in the application /catering/classes/Login.php which is redirected from /catering/dist/js/script.js app. The SQL injection can be deployed by using the username vulnerable parameter on /catering/admin/login.php. The parameter is not protected correctly, and there is no security escaping correctly to the MySQL query on /catering/classes/Login.php when the user is sending fake information or malicious query payload to the database.
1
Attacker Value
Very High

CVE-2021-20022

Disclosure Date: April 09, 2021 (last updated October 07, 2023)
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
Attacker Value
Moderate

CVE-2018-13383

Disclosure Date: May 29, 2019 (last updated October 24, 2024)
A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users due to a failure to properly handle javascript href data when proxying webpages.
Attacker Value
High

CVE-2019-1458

Disclosure Date: December 10, 2019 (last updated October 06, 2023)
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
Attacker Value
Moderate

CVE-2020-17144

Disclosure Date: December 10, 2020 (last updated December 30, 2023)
Microsoft Exchange Remote Code Execution Vulnerability
Attacker Value
High

CVE-2021-1732

Disclosure Date: February 25, 2021 (last updated July 26, 2024)
Windows Win32k Elevation of Privilege Vulnerability