Export limit exceeded: 36264 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (36264 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-42773 1 Broadcom 1 Emulex Hba Manager 2024-11-21 7.5 High
Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, could allow a user to retrieve an arbitrary file from a remote host with the GetDumpFile command. In non-secure mode, the user is unauthenticated.
CVE-2021-42766 1 Proof-of-stake Ethereum Project 1 Proof-of-stake Ethereum 2024-11-21 9.1 Critical
The Proof-of-Stake (PoS) Ethereum consensus protocol through 2021-10-19 allows an adversary to cause a denial of service (long-range consensus chain reorganizations), even when this adversary has little stake and cannot influence network message propagation. This can cause a protocol stall, or an increase in the profits of individual validators.
CVE-2021-42765 1 Proof-of-stake Ethereum Project 1 Proof-of-stake Ethereum 2024-11-21 7.5 High
The Proof-of-Stake (PoS) Ethereum consensus protocol through 2021-10-19 allows an adversary to leverage network delay to cause a denial of service (indefinite stalling of consensus decisions).
CVE-2021-42764 1 Proof-of-stake Ethereum Project 1 Proof-of-stake Ethereum 2024-11-21 9.1 Critical
The Proof-of-Stake (PoS) Ethereum consensus protocol through 2021-10-19 allows an adversary to cause a denial of service (delayed consensus decisions), and also increase the profits of individual validators, via short-range reorganizations of the underlying consensus chain.
CVE-2021-42575 3 Oracle, Owasp, Redhat 4 Middleware Common Libraries And Tools, Primavera Unifier, Java Html Sanitizer and 1 more 2024-11-21 9.8 Critical
The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.
CVE-2021-42315 1 Microsoft 1 Defender For Iot 2024-11-21 8.8 High
Microsoft Defender for IoT Remote Code Execution Vulnerability
CVE-2021-42314 1 Microsoft 1 Defender For Iot 2024-11-21 8.8 High
Microsoft Defender for IoT Remote Code Execution Vulnerability
CVE-2021-42312 1 Microsoft 1 Defender For Iot 2024-11-21 7.8 High
Microsoft Defender for IoT Elevation of Privilege Vulnerability
CVE-2021-42310 1 Microsoft 1 Defender For Iot 2024-11-21 8.1 High
Microsoft Defender for IoT Remote Code Execution Vulnerability
CVE-2021-42299 1 Microsoft 2 Surface Pro 3, Surface Pro 3 Firmware 2024-11-21 5.6 Medium
Microsoft Surface Pro 3 Security Feature Bypass Vulnerability
CVE-2021-42294 1 Microsoft 3 Sharepoint Enterprise Server, Sharepoint Foundation, Sharepoint Server 2024-11-21 7.2 High
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2021-42252 2 Linux, Netapp 20 Linux Kernel, Cloud Backup, H300e and 17 more 2024-11-21 7.8 High
An issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6. Local attackers able to access the Aspeed LPC control interface could overwrite memory in the kernel and potentially execute privileges, aka CID-b49a0e69a7b1. This occurs because a certain comparison uses values that are not memory sizes.
CVE-2021-42242 1 Jflyfox 1 Jfinal Cms 2024-11-21 9.8 Critical
A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor.
CVE-2021-42230 1 Seowonintech 2 130-slc, 130-slc Firmware 2024-11-21 9.8 Critical
Seowon 130-SLC router all versions as of 2021-09-15 is vulnerable to Remote Code Execution via the queriesCnt parameter.
CVE-2021-42219 1 Ethereum 1 Go Ethereum 2024-11-21 7.5 High
Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is caused by missing memory in the component /ethash/algorithm.go.
CVE-2021-42095 1 Netsarang 1 Xshell 2024-11-21 7.5 High
Xshell before 7.0.0.76 allows attackers to cause a crash by triggering rapid changes to the title bar.
CVE-2021-42093 1 Zammad 1 Zammad 2024-11-21 7.2 High
An issue was discovered in Zammad before 4.1.1. An admin can execute code on the server via a crafted request that manipulates triggers.
CVE-2021-42087 1 Zammad 1 Zammad 2024-11-21 4.9 Medium
An issue was discovered in Zammad before 4.1.1. An admin can discover the application secret via the API.
CVE-2021-42086 1 Zammad 1 Zammad 2024-11-21 8.8 High
An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a crafted request.
CVE-2021-42067 1 Sap 2 Netweaver Abap, Netweaver Application Server Abap 2024-11-21 4.3 Medium
In SAP NetWeaver AS for ABAP and ABAP Platform - versions 701, 702, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 786, an attacker authenticated as a regular user can use the S/4 Hana dashboard to reveal systems and services which they would not normally be allowed to see. No information alteration or denial of service is possible.