Show filters
71,380 Total Results
Displaying 491-500 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Very High
CVE-2021-41647
Disclosure Date: October 01, 2021 (last updated November 28, 2024)
An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Ordering Web App 1.0. An attacker can exploit the vulnerable "username" parameter in login.php and retrieve sensitive database information, as well as add an administrative user.
1
Attacker Value
Moderate
CVE-2021-22947
Disclosure Date: September 29, 2021 (last updated March 28, 2024)
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got *before* the TLS handshake as if they were authenticated.Using this flaw, it allows a Man-In-The-Middle attacker to first inject the fake responses, then pass-through the TLS traffic from the legitimate server and trick curl into sending data back to the user thinking the attacker's injected data comes from the TLS-protected server.
1
Attacker Value
Unknown
CVE-2021-40684
Disclosure Date: September 22, 2021 (last updated November 28, 2024)
Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint which allows remote access to the JMX of the runtime container, which would allow an attacker the ability to read or modify the container or software running in the container.
1
Attacker Value
Very High
CVE-2021-33045
Disclosure Date: September 15, 2021 (last updated August 22, 2024)
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
1
Attacker Value
Unknown
CVE-2021-33044
Disclosure Date: September 15, 2021 (last updated August 22, 2024)
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
1
Attacker Value
Low
CVE-2021-39211
Disclosure Date: September 15, 2021 (last updated November 28, 2024)
GLPI is a free Asset and IT management software package. Starting in version 9.2 and prior to version 9.5.6, the telemetry endpoint discloses GLPI and server information. This issue is fixed in version 9.5.6. As a workaround, remove the file `ajax/telemetry.php`, which is not needed for usual functions of GLPI.
1
Attacker Value
Very High
CVE-2021-41054
Disclosure Date: September 13, 2021 (last updated November 28, 2024)
tftpd_file.c in atftp through 0.7.4 has a buffer overflow because buffer-size handling does not properly consider the combination of data, OACK, and other options.
1
Attacker Value
Unknown
CVE-2021-30761
Disclosure Date: September 08, 2021 (last updated May 16, 2024)
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
1
Attacker Value
High
CVE-2021-30762
Disclosure Date: September 08, 2021 (last updated May 16, 2024)
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
1
Attacker Value
Unknown
CVE-2021-30617
Disclosure Date: September 03, 2021 (last updated November 08, 2023)
Chromium: CVE-2021-30617 Policy bypass in Blink
1