Latest CVE Feed
-
9.8
CRITICALCVE-2021-46110
Online Shopping Portal v3.1 was discovered to contain multiple time-based SQL injection vulnerabilities via the email and contactno parameters.... Read more
- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-46093
eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php.... Read more
Affected Products : elite_cms- Published: Feb. 01, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-46067
In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.... Read more
Affected Products : vehicle_service_management_system- Published: Jan. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-46264
Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the onlineList module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.... Read more
- Published: Feb. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45983
NetScout nGeniusONE 6.3.2 allows Java RMI Code Execution.... Read more
Affected Products : ngeniusone- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-46033
In ForestBlog, as of 2021-12-28, File upload can bypass verification.... Read more
Affected Products : forestblog- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45956
Dnsmasq 2.86 has a heap-based buffer overflow in print_mac (called from log_packet and dhcp_reply). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.... Read more
Affected Products : dnsmasq- Published: Jan. 01, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45899
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.... Read more
Affected Products : suitecrm- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45898
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.... Read more
Affected Products : suitecrm- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45890
basic/BasicAuthProvider.java in AuthGuard before 0.9.0 allows authentication via an inactive identifier.... Read more
Affected Products : authguard- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45990
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function uploadPicture. This vulnerability allows attackers to execute arbitrary commands via the pic_name parameter.... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45955
Dnsmasq 2.86 has a heap-based buffer overflow in resize_packet (called from FuzzResizePacket and fuzz_rfc1035.c) because of the lack of a proper bounds check upon pseudo header re-insertion. NOTE: the vendor's position is that CVE-2021-45951 through CVE-2... Read more
Affected Products : dnsmasq- Published: Jan. 01, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45865
A File Upload vulnerability exists in Sourcecodester Student Attendance Manageent System 1.0 via the file upload functionality.... Read more
Affected Products : student_attendance_management_system- Published: Mar. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45998
D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the LocalIPAddress parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45977
JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Pre... Read more
- Published: Feb. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45957
Dnsmasq 2.86 has a heap-based buffer overflow in answer_request (called from FuzzAnswerTheRequest and fuzz_rfc1035.c). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our kno... Read more
Affected Products : dnsmasq- Published: Jan. 01, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45987
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetNetCheckTools. This vulnerability allows attackers to execute arbitrary commands via the hostName parameter.... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45914
In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a POST request. This allows the attacker's session to be authenticated as any registered LuxCal user, including the site administrator.... Read more
Affected Products : luxcal- Published: May. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45877
Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credentials. A hardcoded credential exist in /etc/tomcat8/tomcat-user.xml, which allows attackers to gain authorized access and control the tomcat completely on port 8000 in the tomc... Read more
Affected Products : wallbox_glb_firmware wallbox_gtb_firmware wallbox_gtc_firmware wallbox_gtb wallbox_gtc wallbox_glb- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45835
The Online Admission System 1.0 allows an unauthenticated attacker to upload or transfer files of dangerous types to the application through documents.php, which may be used to execute malicious code or lead to code execution.... Read more
Affected Products : online_admissions_system- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024