Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
Angry Yack Logo
Total 34640 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-46423 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
Telesquare TLR-2005KSH 1.0.0 is affected by an unauthenticated file download vulnerability that allows a remote attacker to download a full configuration file.
CVE-2021-46361 1 Magnolia-cms 1 Magnolia Cms 2024-11-21 7.5 HIGH 9.8 CRITICAL
An issue in the Freemark Filter of Magnolia CMS v6.2.11 and below allows attackers to bypass security restrictions and execute arbitrary code via a crafted FreeMarker payload.
CVE-2021-46359 1 Fisco-bcos 1 Fisco-bcos 2024-11-21 5.0 MEDIUM 7.5 HIGH
FISCO-BCOS release-3.0.0-rc2 contains a denial of service vulnerability. Some transactions may not be committed successfully, and malicious users may use this to achieve double-spending attacks.
CVE-2021-46331 1 Moddable 1 Moddable Sdk 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via xs/sources/xsProxy.c in fxProxyGetPrototype.
CVE-2021-46330 1 Moddable 1 Moddable Sdk 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via xs/sources/xsDataView.c in fx_ArrayBuffer_prototype_concat.
CVE-2021-46329 1 Moddable 1 Moddable Sdk 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via the component _fini.
CVE-2021-46327 1 Moddable 1 Moddable Sdk 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via xs/sources/xsArray.c in fx_Array_prototype_sort.
CVE-2021-46323 1 Espruino 1 Espruino 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
Espruino 2v11.251 was discovered to contain a SEGV vulnerability via src/jsinteractive.c in jsiGetDeviceFromClass.
CVE-2021-46313 1 Gpac 1 Gpac 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
The binary MP4Box in GPAC v1.0.1 was discovered to contain a segmentation fault via the function __memmove_avx_unaligned_erms (). This vulnerability can lead to a Denial of Service (DoS).
CVE-2021-46255 1 Eyoucms 1 Eyoucms 2024-11-21 5.5 MEDIUM 8.1 HIGH
eyouCMS V1.5.5-UTF8-SP3_1 suffers from Arbitrary file deletion due to insufficient filtering of the parameter filename.
CVE-2021-46250 1 Scratchoauth2 Project 1 Scratchoauth2 2024-11-21 7.5 HIGH 10.0 CRITICAL
An issue in SOA2Login::commented of ScratchOAuth2 before commit a91879bd58fa83b09283c0708a1864cdf067c64a allows attackers to authenticate as other users on downstream components that rely on ScratchOAuth2.
CVE-2021-46165 1 Zohocorp 1 Manageengine Desktop Central 2024-11-21 4.6 MEDIUM 7.8 HIGH
Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from the batch files, but this file's path might not be properly defined.
CVE-2021-46164 1 Zohocorp 1 Manageengine Desktop Central 2024-11-21 6.5 MEDIUM 8.8 HIGH
Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated user who has complete access to the Reports module.
CVE-2021-46101 1 Gitforwindows 1 Git 2024-11-21 5.0 MEDIUM 7.5 HIGH
In Git for windows through 2.34.1 when using git pull to update the local warehouse, git.cmd can be run directly.
CVE-2021-46088 1 Zabbix 1 Zabbix 2024-11-21 6.5 MEDIUM 7.2 HIGH
Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run custom shell script on the application server in the context of the application user.
CVE-2021-46067 1 Vehicle Service Management System Project 1 Vehicle Service Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.
CVE-2021-46062 1 Mingsoft 1 Mcms 2024-11-21 5.8 MEDIUM 7.1 HIGH
MCMS v5.2.5 was discovered to contain an arbitrary file deletion vulnerability via the component oldFileName.
CVE-2021-46045 1 Gpac 1 Gpac 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
GPAC 1.0.1 is affected by: Abort failed. The impact is: cause a denial of service (context-dependent).
CVE-2021-46041 1 Gpac 1 Gpac 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
A Segmentation Fault Vulnerability exists in GPAC 1.0.1 via the co64_box_new function, which causes a Denial of Service.
CVE-2021-46037 1 Mingsoft 1 Mcms 2024-11-21 5.5 MEDIUM 8.1 HIGH
MCMS v5.2.4 was discovered to contain an arbitrary file deletion vulnerability via the component /template/unzip.do.
CVE-2021-45983 1 Netscout 1 Ngeniusone 2024-11-21 7.5 HIGH 9.8 CRITICAL
NetScout nGeniusONE 6.3.2 allows Java RMI Code Execution.
CVE-2021-45980 2 Apple, Foxit 3 Macos, Pdf Editor, Pdf Reader 2024-11-21 6.8 MEDIUM 7.8 HIGH
Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via getURL in the JavaScript API.
CVE-2021-45977 1 Jetbrains 7 Clion, Goland, Intellij Idea and 4 more 2024-11-21 7.5 HIGH 9.8 CRITICAL
JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm 2021.3.1 RC (used as Remote Development backend IDEs) bind to the 0.0.0.0 IP address. The fixed versions are: IntelliJ IDEA 2021.3.1, PyCharm Professional 2021.3.1, GoLand 2021.3.2, PhpStorm 2021.3.1 (213.6461.83), RubyMine 20 ...

Show More

CVE-2021-45915 1 Luxsoft 1 Luxcal 2024-11-21 7.5 HIGH 9.8 CRITICAL
In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a cookie value. This allows the attacker's session to be authenticated as any registered LuxCal user, including the site administrator.
CVE-2021-45914 1 Luxsoft 1 Luxcal 2024-11-21 7.5 HIGH 9.8 CRITICAL
In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a POST request. This allows the attacker's session to be authenticated as any registered LuxCal user, including the site administrator.
CVE-2021-45898 1 Salesagility 1 Suitecrm 2024-11-21 7.5 HIGH 9.8 CRITICAL
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.
CVE-2021-45897 1 Salesagility 1 Suitecrm 2024-11-21 6.5 MEDIUM 8.8 HIGH
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution.
CVE-2021-45842 1 Terra-master 3 F2-210, F4-210, Tos 2024-11-21 5.0 MEDIUM 7.5 HIGH
It is possible to obtain the first administrator's hash set up in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) on the system as well as other information such as MAC address, internal IP address etc. by performing a request to the /module/api.php?mobile/wapNasIPS endpoint.
CVE-2021-45840 1 Terra-master 3 F2-210, F4-210, Tos 2024-11-21 10.0 HIGH 9.8 CRITICAL
It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending specifically crafted input to /tos/index.php?app/app_start_stop.
CVE-2021-45839 1 Terra-master 3 F2-210, F4-210, Tos 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
It is possible to obtain the first administrator's hash set up on the system in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) as well as other information such as MAC address, internal IP address etc. by performing a request to the /module/api.php?mobile/webNasIPS endpoint.
CVE-2021-45837 1 Terra-master 3 F2-210, F4-210, Tos 2024-11-21 10.0 HIGH 9.8 CRITICAL
It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending a specifically crafted input to /tos/index.php?app/del.
CVE-2021-45836 1 Terra-master 3 F2-210, F4-210, Tos 2024-11-21 9.0 HIGH 8.8 HIGH
An authenticated attacker can execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by injecting a maliciously crafted input in the request through /tos/index.php?app/hand_app.
CVE-2021-45810 1 Globalprotect-openconnect Project 1 Globalprotect-openconnect 2024-11-21 5.0 MEDIUM 7.5 HIGH
GlobalProtect-openconnect versions prior to 2.0.0 (exclusive) are affected by incorrect access control in GPService through DBUS, GUI. The way GlobalProtect-Openconnect is set up enables arbitrary users to start a VPN connection to arbitrary servers. By hosting an openconnect compatible server, the attack can redirect the entire host's traffic via their own server.
CVE-2021-45809 1 Globalprotect-openconnect Project 1 Globalprotect-openconnect 2024-11-21 10.0 HIGH 9.8 CRITICAL
GlobalProtect-openconnect versions prior to 1.4.3 are affected by incorrect access control in GPService through DBUS, GUI Application. The way GlobalProtect-Openconnect is set up enables arbitrary users to execute commands as root by submitting the `--script=<script>` parameter.
CVE-2021-45807 1 Jpress 1 Jpress 2024-11-21 7.5 HIGH 9.8 CRITICAL
jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.
CVE-2021-45789 1 Metersphere 1 Metersphere 2024-11-21 N/A 6.5 MEDIUM
An arbitrary file read vulnerability was found in Metersphere v1.15.4, where authenticated users can read any file on the server via the file download function.
CVE-2021-45763 1 Gpac 1 Gpac 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
GPAC v1.1.0 was discovered to contain an invalid call in the function gf_node_changed(). This vulnerability can lead to a Denial of Service (DoS).
CVE-2021-45741 1 Totolink 2 X5000r, X5000r Firmware 2024-11-21 7.8 HIGH 7.5 HIGH
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setIpv6Cfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the relay6to4 parameters.
CVE-2021-45740 1 Totolink 2 A720r, A720r Firmware 2024-11-21 7.5 HIGH 9.8 CRITICAL
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the setWiFiWpsStart function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the pin parameter.
CVE-2021-45739 1 Totolink 2 A720r, A720r Firmware 2024-11-21 7.8 HIGH 7.5 HIGH
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the Form_Login function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the flag parameter.