Export limit exceeded: 40503 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (40503 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-27099 | 1 Cncf | 1 Spire | 2024-11-21 | 6.8 Medium |
| In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided through the agent ID templating feature, which may allow the issuance of an arbitrary SPIFFE ID within the same trust domain, if the attacker controls the value of an EC2 tag prior to attestation, and the attestor is configured for agent ID templating where the tag value is the last element in the path. This issue has been fixed in SPIRE versions 0.11.3 and 0.12.1 | ||||
| CVE-2021-27086 | 1 Microsoft | 10 Windows 10, Windows 10 1803, Windows 10 1809 and 7 more | 2024-11-21 | 7.8 High |
| Windows Services and Controller App Elevation of Privilege Vulnerability | ||||
| CVE-2021-27038 | 1 Autodesk | 1 Design Review | 2024-11-21 | 7.8 High |
| A Type Confusion vulnerability in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can occur when processing a maliciously crafted PDF file. A malicious actor can leverage this to execute arbitrary code. | ||||
| CVE-2021-27021 | 1 Puppet | 3 Puppet, Puppet Enterprise, Puppetdb | 2024-11-21 | 8.8 High |
| A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query. | ||||
| CVE-2021-26990 | 1 Netapp | 1 Cloud Manager | 2024-11-21 | 9.1 Critical |
| Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability that could allow a remote attacker to overwrite arbitrary system files. | ||||
| CVE-2021-26988 | 1 Netapp | 1 Data Ontap | 2024-11-21 | 3.5 Low |
| Clustered Data ONTAP versions prior to 9.3P21, 9.5P16, 9.6P12, 9.7P8 and 9.8 are susceptible to a vulnerability which could allow unauthorized tenant users to discover information related to converting a 7-Mode directory to Cluster-mode such as Storage Virtual Machine (SVM) names, volume names, directory paths and Job IDs. | ||||
| CVE-2021-26966 | 1 Arubanetworks | 1 Airwave | 2024-11-21 | 6.5 Medium |
| A remote authenticated sql injection vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Multiple vulnerabilities in the API of AirWave could allow an authenticated remote attacker to conduct SQL injection attacks against the AirWave instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database. | ||||
| CVE-2021-26965 | 1 Arubanetworks | 1 Airwave | 2024-11-21 | 6.5 Medium |
| A remote authenticated sql injection vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Multiple vulnerabilities in the API of AirWave could allow an authenticated remote attacker to conduct SQL injection attacks against the AirWave instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database. | ||||
| CVE-2021-26964 | 1 Arubanetworks | 1 Airwave | 2024-11-21 | 7.1 High |
| A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an authenticated remote attacker to improperly access and modify devices and management user details. A successful exploit would consist of an attacker using a lower privileged account to change management user or device details. This could allow the attacker to escalate privileges and/or change network details that they should not have access to. | ||||
| CVE-2021-26935 | 1 Wowonder | 1 Wowonder | 2024-11-21 | 7.5 High |
| In WoWonder < 3.1, remote attackers can gain access to the database by exploiting a requests.php?f=search-my-followers SQL Injection vulnerability via the event_id parameter. | ||||
| CVE-2021-26904 | 1 Isida | 1 Retriever | 2024-11-21 | 9.8 Critical |
| LMA ISIDA Retriever 5.2 allows SQL Injection. | ||||
| CVE-2021-26845 | 1 Hitachienergy | 1 Esoms | 2024-11-21 | 7.5 High |
| Information Exposure vulnerability in Hitachi ABB Power Grids eSOMS allows unauthorized user to gain access to report data if the URL used to access the report is discovered. This issue affects: Hitachi ABB Power Grids eSOMS 6.0 versions prior to 6.0.4.2.2; 6.1 versions prior to 6.1.4; 6.3 versions prior to 6.3. | ||||
| CVE-2021-26837 | 1 Fortra | 1 Delivernow | 2024-11-21 | 9.8 Critical |
| SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute arbitrary code, escalate privileges, and gain sensitive information. | ||||
| CVE-2021-26830 | 1 Tribalsystems | 1 Zenario | 2024-11-21 | 9.1 Critical |
| SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin library - delete` module. | ||||
| CVE-2021-26822 | 1 Phpgurukul | 1 Teachers Record Management System | 2024-11-21 | 9.8 Critical |
| Teachers Record Management System 1.0 is affected by a SQL injection vulnerability in 'searchteacher' POST parameter in search-teacher.php. This vulnerability can be exploited by a remote unauthenticated attacker to leak sensitive information and perform code execution attacks. | ||||
| CVE-2021-26795 | 1 Talariax | 1 Sendquick Alert Plus Server Admin | 2024-11-21 | 8.8 High |
| A SQL Injection vulnerability in /appliance/shiftmgn.php in TalariaX sendQuick Alert Plus Server Admin 4.3 before 8HF11 allows attackers to obtain sensitive information via a Roster Time to Roster Management. | ||||
| CVE-2021-26765 | 1 Phpgurukul | 1 Student Record System | 2024-11-21 | 9.8 Critical |
| SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the sid parameter to edit-sub.php. | ||||
| CVE-2021-26764 | 1 Phpgurukul | 1 Student Record System | 2024-11-21 | 8.8 High |
| SQL injection vulnerability in PHPGurukul Student Record System v 4.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit-std.php. | ||||
| CVE-2021-26762 | 1 Phpgurukul | 1 Student Record System | 2024-11-21 | 8.8 High |
| SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the cid parameter to edit-course.php. | ||||
| CVE-2021-26754 | 1 Wpdatatables | 1 Wpdatatables | 2024-11-21 | 9.8 Critical |
| wpDataTables before 3.4.1 mishandles order direction for server-side tables, aka admin-ajax.php?action=get_wdtable order[0][dir] SQL injection. | ||||