4.8

CVSS4.0

CVE-2021-47817 - OpenEMR 5.0.2.1 - Remote Code Execution

OpenEMR 5.0.2.1 contains a cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript through user profile parameters. Attackers can exploit the vulnerability by crafting a malicious payload to download and execute a web shell, enabling remote command exec…

📅 Published: Jan. 21, 2026, 5:27 p.m. 🔄 Last Modified: March 5, 2026, 1:28 a.m.

8.7

CVSS4.0

CVE-2021-47802 - Tenda D151 & D301 - Configuration Download

Tenda D151 and D301 routers contain an unauthenticated configuration download vulnerability that allows remote attackers to retrieve router configuration files. Attackers can send a request to /goform/getimage endpoint to download configuration data including admin credentials without authenticatio…

📅 Published: Jan. 21, 2026, 5:27 p.m. 🔄 Last Modified: Feb. 2, 2026, 5:44 p.m.

8.6

CVSS4.0

CVE-2021-47770 - OpenPLC 3 - Remote Code Execution

OpenPLC v3 contains an authenticated remote code execution vulnerability that allows attackers with valid credentials to inject malicious code through the hardware configuration interface. Attackers can upload a custom hardware layer with embedded reverse shell code that establishes a network conne…

📅 Published: Jan. 21, 2026, 5:27 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2021-47748 - Hasura GraphQL 1.3.3 - Remote Code Execution

Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell commands through SQL query manipulation. Attackers can inject commands into the run_sql endpoint by crafting malicious GraphQL queries that execute system commands through PostgreSQL…

📅 Published: Jan. 21, 2026, 5:27 p.m. 🔄 Last Modified: Feb. 2, 2026, 6:11 p.m.

8.6

CVSS4.0

CVE-2021-47746 - NodeBB Plugin Emoji 3.2.1 - Arbitrary File Write

NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows administrative users to write files to arbitrary system locations through the emoji upload API. Attackers with admin access can craft file upload requests with directory traversal to overwrite system files by manip…

📅 Published: Jan. 21, 2026, 5:27 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS4.0

CVE-2026-0834 - Logic Vulnerability on TP-Link Archer C20 and Archer AX53

Logic vulnerability in TP-Link Archer C20 v6.0 and Archer AX53 v1.0 (TDDP module) allows unauthenticated adjacent attackers to execute administrative commands including factory reset and device reboot without credentials. Attackers on the adjacent network can remotely trigger factory resets and reb…

📅 Published: Jan. 21, 2026, 5:14 p.m. 🔄 Last Modified: April 22, 2026, 9:30 p.m.

8.2

CVSS3.1

CVE-2026-20045 - Cisco Unified Communications Products Remote Code Execution Vulnerability

A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Ins…

📅 Published: Jan. 21, 2026, 4:26 p.m. 🔄 Last Modified: April 22, 2026, midnight

4.8

CVSS3.1

CVE-2026-20109 - Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Cross-Site Scr…

Multiple vulnerabilities in the web-based management interface of Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-…

📅 Published: Jan. 21, 2026, 4:26 p.m. 🔄 Last Modified: April 18, 2026, 4:15 a.m.

5.3

CVSS3.1

CVE-2026-20080 - Cisco IEC6400 Edge Compute Appliance SSH Denial of Service Vulnerability

A vulnerability in the SSH service of Cisco IEC6400 Wireless Backhaul Edge Compute Software could allow an unauthenticated, remote attacker to cause the SSH service to stop responding. This vulnerability exists because the SSH service lacks effective flood protection. An attacker could exploit t…

📅 Published: Jan. 21, 2026, 4:26 p.m. 🔄 Last Modified: April 18, 2026, 4:15 a.m.

4.8

CVSS3.1

CVE-2026-20055 - Cisco Packaged Contact Center Enterprise & Cisco Unified Contact Center Enterprise Cross-Site Scrip…

Multiple vulnerabilities in the web-based management interface of Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-…

📅 Published: Jan. 21, 2026, 4:26 p.m. 🔄 Last Modified: April 18, 2026, 4:30 a.m.
Total resulsts: 346102
Page 1736 of 34,611
« previous page » next page
Filters