6.8

CVSS4.0

CVE-2021-47786 - Redragon Gaming Mouse - 'REDRAGON_MOUSE.sys' Denial of Service (PoC)

Redragon Gaming Mouse driver contains a kernel-level vulnerability that allows attackers to trigger a denial of service by sending malformed IOCTL requests. Attackers can send a crafted 2000-byte buffer with specific byte patterns to the REDRAGON_MOUSE device to crash the kernel driver.

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 10:16 p.m.

7

CVSS4.0

CVE-2021-47785 - Ether_MP3_CD_Burner 1.3.8 - Buffer Overflow (SEH)

Ether MP3 CD Burner 1.3.8 contains a buffer overflow vulnerability in the registration name field that allows remote code execution. Attackers can craft a malicious payload to overwrite SEH handlers and execute a bind shell on port 3110 by exploiting improper input validation.

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 10:16 p.m.

5.3

CVSS4.0

CVE-2021-47783 - Phpwcms 1.9.30 - Arbitrary File Upload

Phpwcms 1.9.30 contains a file upload vulnerability that allows authenticated attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG payloads through the multiple file upload feature to potentially execute cross-site scripting attacks on the platform.

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 10:16 p.m.

7.1

CVSS4.0

CVE-2021-47782 - Odine Solutions GateKeeper 1.0 - 'trafficCycle' SQL Injection

Odine Solutions GateKeeper 1.0 contains a SQL injection vulnerability in the trafficCycle API endpoint that allows remote attackers to inject malicious database queries. Attackers can exploit the vulnerability by sending crafted payloads to the /rass/api/v1/trafficCycle/ endpoint to manipulate Post…

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 4:10 p.m.

8.5

CVSS4.0

CVE-2021-47780 - Macro Expert 4.7 - Unquoted Service Path

Macro Expert 4.7 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the improperly configured service path to inject malicious executables that will be run with LocalSystem permissions …

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 21, 2026, 10:24 p.m.

8.4

CVSS4.0

CVE-2021-47779 - Dolibarr ERP-CRM 14.0.2 - Stored Cross-Site Scripting (XSS) / Privilege Escalation

Dolibarr ERP-CRM 14.0.2 contains a stored cross-site scripting vulnerability in the ticket creation module that allows low-privilege users to inject malicious scripts. Attackers can craft a specially designed ticket message with embedded JavaScript that triggers when an administrator copies the tex…

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 4:13 p.m.

8.4

CVSS4.0

CVE-2021-47756 - Laravel Valet 2.0.3 - Local Privilege Escalation (macOS)

Laravel Valet versions 1.1.4 to 2.0.3 contain a local privilege escalation vulnerability that allows users to modify the valet command with root privileges. Attackers can edit the symlinked valet command to execute arbitrary code with root permissions without additional authentication.

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 4:15 p.m.

8.5

CVSS4.0

CVE-2020-36930 - SysGauge 7.9.18 - ' SysGauge Server' Unquoted Service Path

SysGauge Server 7.9.18 contains an unquoted service path vulnerability in its binary path configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\SysGauge Server\bin\sysgaus.exe' to inject malicious executables an…

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 10:16 p.m.

8.5

CVSS4.0

CVE-2020-36929 - Brother BRPrint Auditor 3.0.7 - 'Multiple' Unquoted Service Path

Brother BRPrint Auditor 3.0.7 contains an unquoted service path vulnerability in its Windows service configurations that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted file paths in BrAuSvc and BRPA_Agent services to inject malicious executables and…

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 5:15 p.m.

8.5

CVSS4.0

CVE-2020-36928 - Brother BRAgent 1.38 - 'WBA_Agent_Client' Unquoted Service Path

Brother BRAgent 1.38 contains an unquoted service path vulnerability in the WBA_Agent_Client service running with LocalSystem privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Brother\BRAgent\ to inject and execute malicious code with elevated system permissions.

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 5:15 p.m.
Total resulsts: 329511
Page 156 of 32,952
Β« previous page Β» next page
Filters