CVE-2016-20009
Last Modified: 21 Nov 2024A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVE-2021-28154
Last Modified: 21 Nov 2024Camunda Modeler (aka camunda-modeler) through 4.6.0 allows arbitrary file access. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which manipulates the readFile and writeFile APIs. NOTE: the vendor states "The way we secured the app is that it does not allow any remote scripts to be opened, no unsafe scripts to be evaluated, no remote sites to be browsed.
CVE-2020-24984
Last Modified: 21 Nov 2024An issue was discovered in Quadbase EspressReports ES 7 Update 9. It allows CSRF, whereby an attacker may be able to trick an authenticated admin level user into uploading malicious files to the web server.
CVE-2021-22709
Last Modified: 21 Nov 2024A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in loss of data or remote code execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
CVE-2021-22710
Last Modified: 21 Nov 2024A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could cause remote code execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
CVE-2021-22712
Last Modified: 21 Nov 2024A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in arbitrary read or write conditions when malicious CGF (Configuration Group File) file is imported to IGSS Definition due to an unchecked pointer address.
CVE-2020-36277
Last Modified: 21 Nov 2024Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixconv.c.
CVE-2021-22711
Last Modified: 21 Nov 2024A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in arbitrary read or write conditions when malicious CGF (Configuration Group File) file is imported to IGSS Definition due to missing validation of input data.
CVE-2021-22713
Last Modified: 29 May 2026A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION8650, ION8800, ION7650, ION7700/73xx, and ION83xx/84xx/85xx/8600 (see security notifcation for affected versions), which could cause the meter to reboot.
CVE-2021-22714
Last Modified: 21 Nov 2024A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION7400, PM8000 and ION9000 (All versions prior to V3.0.0), which could cause the meter to reboot or allow for remote code execution.
CVE-2020-29045
Last Modified: 21 Nov 2024The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php.
CVE-2020-14989
Last Modified: 21 Nov 2024An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows CSRF if the attacker uses GET where POST was intended.
CVE-2020-14988
Last Modified: 21 Nov 2024An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows XSS in the login page via the loginmessage parameter, the text editor via the src attribute of HTML elements, the translations menu via the foldername parameter, the author page via the link URL, or the upload image functionality via an SVG document containing JavaScript.
CVE-2020-14987
Last Modified: 21 Nov 2024An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to execute arbitrary code because there is a mishandling of the capability for administrators to write and run Groovy scripts within the updater editor. An attacker must use an AST transforming annotation such as @Grab.
CVE-2021-28141
Last Modified: 30 Jun 2025An issue was discovered in Progress Telerik UI for ASP.NET AJAX 2021.1.224. It allows unauthorized access to MicrosoftAjax.js through the Telerik.Web.UI.WebResource.axd file. This may allow the attacker to gain unauthorized access to the server and execute code. To exploit, one must use the parameter _TSM_HiddenField_ and inject a command at the end of the URI. NOTE: the vendor states that this is not a vulnerability. The request's output does not indicate that a "true" command was executed on the server, and the request's output does not leak any private source code or data from the server
CVE-2021-28088
Last Modified: 21 Nov 2024Cross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to inject arbitrary web script or HTML parameters through the "Display Name" field.
CVE-2021-27679
Last Modified: 21 Nov 2024Cross-site scripting (XSS) vulnerability in Navigation in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the field name.
CVE-2021-27678
Last Modified: 21 Nov 2024Cross-site scripting (XSS) vulnerability in Snippets in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the field name.
CVE-2021-27677
Last Modified: 21 Nov 2024Cross-site scripting (XSS) vulnerability in Galleries in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the field name.
CVE-2021-26776
Last Modified: 21 Nov 2024CSZ CMS 1.2.9 is affected by a cross-site scripting (XSS) vulnerability in multiple pages through the field name.
CVE-2021-28144
Last Modified: 21 Nov 2024prog.cgi on D-Link DIR-3060 devices before 1.11b04 HF2 allows remote authenticated users to inject arbitrary commands in an admin or root context because SetVirtualServerSettings calls CheckArpTables, which calls popen unsafely.
CVE-2021-27077
Last Modified: 19 Aug 2026Windows Win32k Elevation of Privilege Vulnerability
CVE-2021-27076
Last Modified: 19 Aug 2026Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2021-27075
Last Modified: 19 Aug 2026Azure Virtual Machine Information Disclosure Vulnerability
CVE-2021-27074
Last Modified: 19 Aug 2026Azure Sphere Unsigned Code Execution Vulnerability
CVE-2021-27070
Last Modified: 19 Aug 2026Windows 10 Update Assistant Elevation of Privilege Vulnerability
CVE-2021-27066
Last Modified: 19 Aug 2026Windows Admin Center Security Feature Bypass Vulnerability
CVE-2021-27063
Last Modified: 19 Aug 2026Windows DNS Server Denial of Service Vulnerability
CVE-2021-27062
Last Modified: 19 Aug 2026HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-27061
Last Modified: 19 Aug 2026HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-27060
Last Modified: 19 Aug 2026Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-27059
Last Modified: 19 Aug 2026Microsoft Office Remote Code Execution Vulnerability
CVE-2021-27058
Last Modified: 19 Aug 2026Microsoft Office ClickToRun Remote Code Execution Vulnerability
CVE-2021-27057
Last Modified: 19 Aug 2026Microsoft Office Remote Code Execution Vulnerability
CVE-2021-27056
Last Modified: 19 Aug 2026Microsoft PowerPoint Remote Code Execution Vulnerability
CVE-2021-27055
Last Modified: 19 Aug 2026Microsoft Visio Security Feature Bypass Vulnerability
CVE-2021-27080
Last Modified: 19 Aug 2026Azure Sphere Unsigned Code Execution Vulnerability
CVE-2021-27081
Last Modified: 19 Aug 2026Visual Studio Code ESLint Extension Remote Code Execution Vulnerability
CVE-2021-27082
Last Modified: 19 Aug 2026Quantum Development Kit for Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-27083
Last Modified: 19 Aug 2026Remote Development Extension for Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-27084
Last Modified: 19 Aug 2026Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability
CVE-2021-27085
Last Modified: 19 Aug 2026Internet Explorer Remote Code Execution Vulnerability
CVE-2021-27054
Last Modified: 19 Aug 2026Microsoft Excel Remote Code Execution Vulnerability
CVE-2021-27053
Last Modified: 19 Aug 2026Microsoft Excel Remote Code Execution Vulnerability
CVE-2021-27052
Last Modified: 19 Aug 2026Microsoft SharePoint Server Information Disclosure Vulnerability
CVE-2021-27051
Last Modified: 19 Aug 2026HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-27050
Last Modified: 19 Aug 2026HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-27049
Last Modified: 19 Aug 2026HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-27048
Last Modified: 19 Aug 2026HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-27047
Last Modified: 19 Aug 2026HEVC Video Extensions Remote Code Execution Vulnerability
