Show filters
71,380 Total Results
Displaying 521-530 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Low
CVE-2020-28872
Disclosure Date: April 12, 2021 (last updated January 27, 2024)
An authorization bypass vulnerability in Monitorr v1.7.6m in Monitorr/assets/config/_installation/_register.php allows an unauthorized person to create valid credentials.
1
Attacker Value
Very High
CVE-2021-20020
Disclosure Date: April 10, 2021 (last updated November 28, 2024)
A command execution vulnerability in SonicWall GMS 9.3 allows a remote unauthenticated attacker to locally escalate privilege to root.
1
Attacker Value
Very High
CVE-2021-24175
Disclosure Date: April 05, 2021 (last updated November 28, 2024)
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any user (including admin) by just providing the related username, as well as create accounts with arbitrary roles, such as admin. These issues can be exploited even if registration is disabled, and the Login widget is not active.
1
Attacker Value
Unknown
CVE-2021-1879
Disclosure Date: April 02, 2021 (last updated May 16, 2024)
This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. Processing maliciously crafted web content may lead to universal cross site scripting. Apple is aware of a report that this issue may have been actively exploited..
1
Attacker Value
Moderate
CVE-2021-26236
Disclosure Date: March 18, 2021 (last updated November 28, 2024)
FastStone Image Viewer v.<= 7.5 is affected by a Stack-based Buffer Overflow at 0x005BDF49, affecting the CUR file parsing functionality (BITMAPINFOHEADER Structure, 'BitCount' file format field), that will end up corrupting the Structure Exception Handler (SEH). Attackers could exploit this issue to achieve code execution when a user opens or views a malformed/specially crafted CUR file.
1
Attacker Value
Very High
CVE-2021-21166
Disclosure Date: March 09, 2021 (last updated November 08, 2023)
Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
1
Attacker Value
Very High
CVE-2020-29134
Disclosure Date: March 05, 2021 (last updated November 28, 2024)
The TOTVS Fluig platform allows path traversal through the parameter "file = .. /" encoded in base64. This affects all versions Fluig Lake 1.7.0, Fluig 1.6.5 and Fluig 1.6.4
1
Attacker Value
Very High
CVE-2021-21307
Disclosure Date: February 11, 2021 (last updated November 28, 2024)
Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.96 there is an unauthenticated remote code exploit. This is fixed in versions 5.3.7.47, 5.3.6.68 or 5.3.5.96. As a workaround, one can block access to the Lucee Administrator.
1
Attacker Value
Moderate
CVE-2020-14343
Disclosure Date: February 09, 2021 (last updated November 28, 2024)
A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. This flaw allows an attacker to execute arbitrary code on the system by abusing the python/object/new constructor. This flaw is due to an incomplete fix for CVE-2020-1747.
1
Attacker Value
High
CVE-2020-28653
Disclosure Date: February 03, 2021 (last updated November 28, 2024)
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet.
1