Latest CVE Feed
-
7.8
HIGHCVE-2021-45912
An unauthenticated Named Pipe channel in Controlup Real-Time Agent (cuAgent.exe) before 8.5 potentially allows an attacker to run OS commands via the ProcessActionRequest WCF method.... Read more
Affected Products : real-time_agent- Published: Jan. 04, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-45911
An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow in the main function. It allows an attacker to write 2 bytes outside the boundaries of the buffer.... Read more
- Published: Dec. 28, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-45910
An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow within the main function. It allows an attacker to write data outside of the allocated buffer. The attacker has control over a part of the address that data is written to, cont... Read more
- Published: Dec. 28, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-45909
An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow vulnerability in the DecodeLZW function. It allows an attacker to write a large amount of arbitrary data outside the boundaries of a buffer.... Read more
- Published: Dec. 28, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-45908
An issue was discovered in gif2apng 1.9. There is a stack-based buffer overflow involving a while loop. An attacker has little influence over the data written to the stack, making it unlikely that the flow of control can be subverted.... Read more
Affected Products : gif2apng- Published: Dec. 28, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-45907
An issue was discovered in gif2apng 1.9. There is a stack-based buffer overflow involving a for loop. An attacker has little influence over the data written to the stack, making it unlikely that the flow of control can be subverted.... Read more
Affected Products : gif2apng- Published: Dec. 28, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-45906
OpenWrt 21.02.1 allows XSS via the NAT Rules Name screen.... Read more
Affected Products : openwrt- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-45905
OpenWrt 21.02.1 allows XSS via the Traffic Rules Name screen.... Read more
Affected Products : openwrt- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-45904
OpenWrt 21.02.1 allows XSS via the Port Forwards Add Name screen.... Read more
Affected Products : openwrt- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-45903
A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a different vulnerability than CVE-2021-... Read more
Affected Products : suitecrm- Published: Dec. 28, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-45901
The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists.... Read more
Affected Products : servicenow- Published: Feb. 10, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-45900
Vivoh Webinar Manager before 3.6.3.0 has improper API authentication. When a user logs in to the administration configuration web portlet, a VIVOH_AUTH cookie is assigned so that they can be uniquely identified. Certain APIs can be successfully executed w... Read more
Affected Products : webinar_manager- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45899
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.... Read more
Affected Products : suitecrm- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45898
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.... Read more
Affected Products : suitecrm- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-45897
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution.... Read more
Affected Products : suitecrm- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-45896
Nokia FastMile 3TG00118ABAD52 devices allow privilege escalation by an authenticated user via is_ctc_admin=1 to login_web_app.cgi and use of Import Config File.... Read more
- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-45895
Netgen Tags Bundle 3.4.x before 3.4.11 and 4.0.x before 4.0.15 allows XSS in the Tags Admin interface.... Read more
Affected Products : tags_bundle- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-45894
An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is Cleartext Transmission of Sensitive Information.... Read more
Affected Products : arc- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45893
An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is Improper Handling of Case Sensitivity, which makes password guessing easier.... Read more
Affected Products : arc- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-45892
An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is storage of Passwords in a Recoverable Format.... Read more
Affected Products : arc- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024