|
193771
|
5.5 |
MEDIUM
Local
|
razer
|
synapse
|
Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the Razer Chroma SDK subkey. These privileged operations consist of fil…
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-30494
|
2024-11-21 15:04 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193772
|
5.5 |
MEDIUM
Local
|
razer
|
synapse
|
Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the ChromaBroadcast subkey. These privileged operations consist of file…
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-30493
|
2024-11-21 15:04 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193773
|
5.4 |
MEDIUM
Network
|
htmly
|
htmly
|
htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.
|
CWE-79
Cross-site Scripting
|
CVE-2021-30637
|
2024-11-21 15:04 |
2021-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193774
|
9.8 |
CRITICAL
Network
|
glsl_linting_project
|
glsl_linting
|
The unofficial GLSL Linting extension before 1.4.0 for Visual Studio Code allows remote code execution via a crafted glslangValidatorPath in the workspace configuration.
|
NVD-CWE-Other
|
CVE-2021-30503
|
2024-11-21 15:04 |
2021-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193775
|
6.5 |
MEDIUM
Network
|
ezxml_project debian
|
ezxml debian_linux
|
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd(), while parsing a crafted XML file, performs incorrect memory handling, leading to a NULL pointer dereference wh…
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-30485
|
2024-11-21 15:04 |
2021-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193776
|
9.0 |
CRITICAL
Network
|
valvesoftware
|
steam_client
|
Valve Steam through 2021-04-10, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because of a buffer overflow that occurs for a Steam invite after o…
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-30481
|
2024-11-21 15:04 |
2021-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193777
|
8.8 |
HIGH
Network
|
zoom
|
chat
|
Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interaction. An attacker must be within the same organization, o…
|
NVD-CWE-noinfo
|
CVE-2021-30480
|
2024-11-21 15:04 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193778
|
6.1 |
MEDIUM
Network
|
dzzoffice
|
dzzoffice
|
A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2021-30203
|
2024-11-21 15:03 |
2023-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193779
|
7.5 |
HIGH
Network
|
vsftpd_project
|
vsftpd
|
VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.
|
NVD-CWE-noinfo
|
CVE-2021-30047
|
2024-11-21 15:03 |
2023-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193780
|
5.3 |
MEDIUM
Network
|
dzzoffice
|
dzzoffice
|
Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenticated attackers to browse departments and usernames.
|
NVD-CWE-Other
|
CVE-2021-30205
|
2024-11-21 15:03 |
2023-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|