6.9

CVSS4.0

CVE-2021-47776 - Umbraco v8.14.1 - 'baseUrl' SSRF

Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that allows attackers to manipulate baseUrl parameters in multiple dashboard and help controller endpoints. Attackers can craft malicious requests to the GetContextHelpForPage, GetRemoteDashboardContent, and GetRemoteDashboard…

📅 Published: Jan. 15, 2026, 3:52 p.m. 🔄 Last Modified: Jan. 23, 2026, 6:06 p.m.

8.4

CVSS4.0

CVE-2021-47775 - YouTube Video Grabber 1.9.9.1 - Buffer Overflow (SEH)

YouTube Video Grabber, now referred to as YouTube Downloader, 1.9.9.1 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting the Structured Exception Handler. Attackers can craft a malicious payload of 712 bytes with SEH manipulation to trigger a bin…

📅 Published: Jan. 15, 2026, 3:52 p.m. 🔄 Last Modified: Jan. 16, 2026, 3:55 p.m.

8.4

CVSS4.0

CVE-2021-47774 - Kingdia CD Extractor 3.0.2 - Buffer Overflow (SEH)

Kingdia CD Extractor 3.0.2 contains a buffer overflow vulnerability in the registration name field that allows attackers to execute arbitrary code. Attackers can craft a malicious payload exceeding 256 bytes to overwrite Structured Exception Handler and gain remote code execution through a bind she…

📅 Published: Jan. 15, 2026, 3:52 p.m. 🔄 Last Modified: Jan. 16, 2026, 3:55 p.m.

8.5

CVSS4.0

CVE-2021-47773 - Dynojet Power Core 2.3.0 - Unquoted Service Path

Dynojet Power Core 2.3.0 contains an unquoted service path vulnerability in the DJ.UpdateService that allows local authenticated users to potentially execute code with elevated privileges. Attackers can exploit the unquoted binary path by placing malicious executables in the service's file path to …

📅 Published: Jan. 15, 2026, 3:52 p.m. 🔄 Last Modified: Jan. 23, 2026, 6:07 p.m.

8.4

CVSS4.0

CVE-2021-47772 - 10-Strike Network Inventory Explorer Pro 9.31 - Buffer Overflow (SEH)

10-Strike Network Inventory Explorer Pro 9.31 contains a buffer overflow vulnerability in the text file import functionality that allows remote code execution. Attackers can craft a malicious text file with carefully constructed payload to trigger a reverse shell and execute arbitrary code on the t…

📅 Published: Jan. 15, 2026, 3:52 p.m. 🔄 Last Modified: Jan. 23, 2026, 6:08 p.m.

6.8

CVSS4.0

CVE-2021-47771 - RDP Manager 4.9.9.3 - Denial-of-Service (PoC)

RDP Manager 4.9.9.3 contains a denial of service vulnerability in connection input fields that allows local attackers to crash the application. Attackers can add oversized entries in Verbindungsname and Server fields to permanently freeze and crash the software, potentially requiring full reinstall…

📅 Published: Jan. 15, 2026, 3:52 p.m. 🔄 Last Modified: Jan. 26, 2026, 4:15 p.m.

5.1

CVSS4.0

CVE-2021-47769 - Isshue Shopping Cart 3.5 - 'Title' Cross Site Scripting (XSS)

Isshue Shopping Cart 3.5 contains a persistent cross-site scripting vulnerability in title input fields across stock, customer, and invoice modules. Attackers with privileged user accounts can inject malicious scripts that execute on preview, potentially enabling session hijacking and persistent ph…

📅 Published: Jan. 15, 2026, 3:52 p.m. 🔄 Last Modified: Jan. 26, 2026, 4:15 p.m.

5.3

CVSS4.0

CVE-2021-47768 - ImportExportTools NG 10.0.4 - HTML Injection

ImportExportTools NG 10.0.4 contains a persistent HTML injection vulnerability in the email export module that allows remote attackers to inject malicious HTML payloads. Attackers can send emails with crafted HTML in the subject that execute during HTML export, potentially compromising user data or…

📅 Published: Jan. 15, 2026, 3:52 p.m. 🔄 Last Modified: Jan. 30, 2026, 8 p.m.

8.5

CVSS4.0

CVE-2021-47767 - 10-Strike Network Inventory Explorer Pro 9.31 - 'srvInventoryWebServer' Unquoted Service Path

10-Strike Network Inventory Explorer Pro 9.31 contains an unquoted service path vulnerability in the srvInventoryWebServer service running with LocalSystem privileges. Attackers can exploit the unquoted path by placing malicious executables in potential path segments to achieve privilege escalation…

📅 Published: Jan. 15, 2026, 3:52 p.m. 🔄 Last Modified: Jan. 30, 2026, 8 p.m.

7.1

CVSS4.0

CVE-2021-47766 - Kmaleon 1.1.0.205 - 'tipocomb' SQL Injection (Authenticated)

Kmaleon 1.1.0.205 contains an authenticated SQL injection vulnerability in the 'tipocomb' parameter of kmaleonW.php that allows attackers to manipulate database queries. Attackers can exploit this vulnerability using boolean-based, error-based, and time-based blind SQL injection techniques to poten…

📅 Published: Jan. 15, 2026, 3:52 p.m. 🔄 Last Modified: Jan. 16, 2026, 3:55 p.m.
Total resulsts: 330532
Page 263 of 33,054
« previous page » next page
Filters