Search Results (9564 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-34422 1 Keybase 1 Keybase 2024-11-21 7.2 High
The Keybase Client for Windows before version 5.7.0 contains a path traversal vulnerability when checking the name of a file uploaded to a team folder. A malicious user could upload a file to a shared folder with a specially crafted file name which could allow a user to execute an application which was not intended on their host machine. If a malicious user leveraged this issue with the public folder sharing feature of the Keybase client, this could lead to remote code execution.
CVE-2021-34371 1 Neo4j 1 Neo4j 2024-11-21 9.8 Critical
Neo4j through 3.4.18 (with the shell server enabled) exposes an RMI service that arbitrarily deserializes Java objects, e.g., through setSessionVariable. An attacker can abuse this for remote code execution because there are dependencies with exploitable gadget chains.
CVE-2021-34280 1 Polarisoffice 1 Polaris Office 2024-11-21 7.8 High
Polaris Office v9.103.83.44230 is affected by a Uninitialized Pointer Vulnerability in PolarisOffice.exe and EngineDLL.dll that may cause a Remote Code Execution. To exploit the vulnerability, someone must open a crafted PDF file.
CVE-2021-34257 1 Wpanel Cms Project 1 Wpanel Cms 2024-11-21 8.8 High
Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload to (1) Dashboard's Avatar image, (2) Posts Folder image, (3) Pages Folder image and (4) Gallery Folder image.
CVE-2021-34202 1 Dlink 2 Dir-2640-us, Dir-2640-us Firmware 2024-11-21 7.8 High
There are multiple out-of-bounds vulnerabilities in some processes of D-Link AC2600(DIR-2640) 1.01B04. Ordinary permissions can be elevated to administrator permissions, resulting in local arbitrary code execution. An attacker can combine other vulnerabilities to further achieve the purpose of remote code execution.
CVE-2021-33911 1 Zohocorp 1 Manageengine Admanager Plus 2024-11-21 9.8 Critical
Zoho ManageEngine ADManager Plus before 7110 allows remote code execution.
CVE-2021-33907 1 Zoom 1 Meetings 2024-11-21 9.8 Critical
The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files when performing an update of the client. This could lead to remote code execution in an elevated privileged context.
CVE-2021-33898 1 Invoiceninja 1 Invoice Ninja 2024-11-21 8.1 High
In Invoice Ninja before 4.4.0, there is an unsafe call to unserialize() in app/Ninja/Repositories/AccountRepository.php that may allow an attacker to deserialize arbitrary PHP classes. In certain contexts, this can result in remote code execution. The attacker's input must be hosted at http://www.geoplugin.net (cleartext HTTP), and thus a successful attack requires spoofing that site or obtaining control of it.
CVE-2021-33806 1 Bdew 1 Bdlib 2024-11-21 9.8 Critical
The BDew BdLib library before 1.16.1.7 for Minecraft allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of its use of Java serialization.
CVE-2021-33790 2 Minecraft, Techreborn 2 Minecraft, Reborncore 2024-11-21 9.8 Critical
The RebornCore library before 4.7.3 allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of reborncore.common.network.ExtendedPacketBuffer. An attacker can instantiate any class on the classpath with any data. A class usable for exploitation might or might not be present, depending on what Minecraft modifications are installed.
CVE-2021-33780 1 Microsoft 9 Windows Server 2004, Windows Server 2008, Windows Server 2008 R2 and 6 more 2024-11-21 8.8 High
Windows DNS Server Remote Code Execution Vulnerability
CVE-2021-33778 1 Microsoft 1 Hevc Video Extensions 2024-11-21 7.8 High
HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-33777 1 Microsoft 1 Hevc Video Extensions 2024-11-21 7.8 High
HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-33776 1 Microsoft 1 Hevc Video Extensions 2024-11-21 7.8 High
HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-33775 1 Microsoft 1 Hevc Video Extensions 2024-11-21 7.8 High
HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-33756 1 Microsoft 18 Windows 10, Windows 10 1507, Windows 10 1809 and 15 more 2024-11-21 8.8 High
Windows DNS Snap-in Remote Code Execution Vulnerability
CVE-2021-33754 1 Microsoft 9 Windows Server 2004, Windows Server 2008, Windows Server 2008 R2 and 6 more 2024-11-21 8 High
Windows DNS Server Remote Code Execution Vulnerability
CVE-2021-33752 1 Microsoft 18 Windows 10, Windows 10 1507, Windows 10 1809 and 15 more 2024-11-21 8.8 High
Windows DNS Snap-in Remote Code Execution Vulnerability
CVE-2021-33750 1 Microsoft 18 Windows 10, Windows 10 1507, Windows 10 1809 and 15 more 2024-11-21 8.8 High
Windows DNS Snap-in Remote Code Execution Vulnerability
CVE-2021-33749 1 Microsoft 18 Windows 10, Windows 10 1507, Windows 10 1809 and 15 more 2024-11-21 8.8 High
Windows DNS Snap-in Remote Code Execution Vulnerability