Search Results (Refine Search)

Search Parameters:
There are 155,605 matching records.
Displaying matches 101 through 120.
Vuln ID Summary CVSS Severity
CVE-2021-1524

A vulnerability in the API of Cisco Meeting Server could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because requests that are sent to the API are not properly validated. An attacker could exploit this vulnerability by sending a malicious request to the API. A successful exploit could allow the attacker to cause all participants on a call to be disconnected, resulting in a DoS condition.

Published: June 16, 2021; 2:15:08 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2021-1395

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.

Published: June 16, 2021; 2:15:07 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2020-22212

SQL Injection in 74cms 3.2.0 via the id parameter to wap/wap-company-show.php.

Published: June 16, 2021; 2:15:07 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2020-22211

SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.

Published: June 16, 2021; 2:15:07 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2020-22210

SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.

Published: June 16, 2021; 2:15:07 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2020-22209

SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php.

Published: June 16, 2021; 2:15:07 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2020-22208

SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.

Published: June 16, 2021; 2:15:07 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2020-22206

SQL Injection in ECShop 3.0 via the aid parameter to admin/affiliate_ck.php.

Published: June 16, 2021; 2:15:07 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2020-22205

SQL Injection in ECShop 3.0 via the id parameter to admin/shophelp.php.

Published: June 16, 2021; 2:15:07 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2020-22204

SQL Injection in ECShop 2.7.6 via the goods_number parameter to flow.php. .

Published: June 16, 2021; 2:15:07 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2020-22203

SQL Injection in phpCMS 2008 sp4 via the genre parameter to yp/job.php.

Published: June 16, 2021; 2:15:07 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2021-29702

Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200658.

Published: June 16, 2021; 1:15:07 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2021-20567

IBM Resilient SOAR V38.0 could allow a local privileged attacker to obtain sensitive information due to improper or nonexisting encryption.IBM X-Force ID: 199239.

Published: June 16, 2021; 1:15:07 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2021-20566

IBM Resilient SOAR V38.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 199238.

Published: June 16, 2021; 1:15:07 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2021-20488

IBM Security Identity Manager 6.0.2 could allow an authenticated malicious user to change the passwords of other users in the Windows AD environment when IBM Security Identity Manager Windows Password Synch Plug-in is deployed and configured. IBM X-Force ID: 197789.

Published: June 16, 2021; 1:15:07 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2021-20483

IBM Security Identity Manager 6.0.2 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 197591.

Published: June 16, 2021; 1:15:07 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2020-22201

phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/product.php.

Published: June 16, 2021; 1:15:07 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2020-22200

Directory Traversal vulnerability in phpCMS 9.1.13 via the q parameter to public_get_suggest_keyword.

Published: June 16, 2021; 1:15:07 PM -0400
V3.1: 5.3 MEDIUM
V2.0: 5.0 MEDIUM
CVE-2020-22199

SQL Injection vulnerability in phpCMS 2007 SP6 build 0805 via the digg_mod parameter to digg_add.php.

Published: June 16, 2021; 1:15:07 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2020-35762

bloofoxCMS 0.5.2.1 is infected with Path traversal in the 'fileurl' parameter that allows attackers to read local files.

Published: June 16, 2021; 12:15:08 PM -0400
V3.1: 2.7 LOW
V2.0: 4.0 MEDIUM