Latest CVE Feed
-
9.8
CRITICALCVE-2021-43679
ecshop v2.7.3 is affected by a SQL injection vulnerability in shopex\ecshop\upload\api\client\api.php.... Read more
Affected Products : ecshop- Published: Dec. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43722
D-Link DIR-645 1.03 A1 is vulnerable to Buffer Overflow. The hnap_main function in the cgibin handler uses sprintf to format the soapaction header onto the stack and has no limit on the size.... Read more
- Published: Mar. 31, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43650
WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process.... Read more
Affected Products : webrun- Published: Mar. 22, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43700
An issue was discovered in ApiManager 1.1. there is sql injection vulnerability that can use in /index.php?act=api&tag=8.... Read more
Affected Products : apimanager- Published: Mar. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43691
tripexpress v1.1 is affected by a path manipulation vulnerability in file system/helpers/dompdf/load_font.php. The variable src is coming from $_SERVER["argv"] then there is a path manipulation vulnerability.... Read more
Affected Products : tripexpress- Published: Nov. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43572
The verify function in the Stark Bank Python ECDSA library (aka starkbank-escada or ecdsa-python) before 2.0.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.... Read more
Affected Products : ecdsa-python- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43628
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the email parameter in hms-staff.php.... Read more
Affected Products : hospital_management_system_in_php- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43629
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php.... Read more
Affected Products : hospital_management_system_in_php- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43527
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 a... Read more
Affected Products : cloud_backup communications_policy_management e-series_santricity_os_controller communications_cloud_native_core_network_slice_selection_function communications_cloud_native_core_network_repository_function communications_cloud_native_core_binding_support_function starwind_virtual_san nss starwind_san_\&_nas nss_esr- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43510
SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php.... Read more
Affected Products : simple_client_management_system- Published: Feb. 01, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43711
The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The parameter name can be constructed for unauthenticated command execution.... Read more
- Published: Jan. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43568
The verify function in the Stark Bank Elixir ECDSA library (ecdsa-elixir) 1.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.... Read more
Affected Products : elixir_ecdsa- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43466
In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution.... Read more
Affected Products : thymeleaf- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43608
Doctrine DBAL 3.x before 3.1.4 allows SQL Injection. The escaping of offset and length inputs to the generation of a LIMIT clause was not probably cast to an integer, allowing SQL injection to take place if application developers passed unescaped user inp... Read more
Affected Products : database_abstraction_layer- Published: Dec. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43569
The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.... Read more
Affected Products : ecdsa-dotnet- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43394
Unisys OS 2200 Messaging Integration Services (NTSI) 7R3B IC3 and IC4, 7R3C, and 7R3D has an Incorrect Implementation of an Authentication Algorithm. An LDAP password is not properly validated.... Read more
- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43703
An Incorrect Access Control vulnerability exists in zzcms less than or equal to 2019 via admin.php. After disabling JavaScript, you can directly access the administrator console.... Read more
Affected Products : zzcms- Published: Dec. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43570
The verify function in the Stark Bank Java ECDSA library (ecdsa-java) 1.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.... Read more
Affected Products : ecdsa-java- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43445
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An attacker can authenticate with the web socket service of the ONLYOFFICE document editor which is protected by JWT auth by using a default JWT signing key.... Read more
Affected Products : server- Published: Jan. 23, 2023
- Modified: Apr. 02, 2025
-
9.8
CRITICALCVE-2024-6980
A verbose error handling issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects GravityZone Console versions before 6.38.1-5 running only on premise.... Read more
- Published: Jul. 31, 2024
- Modified: Feb. 07, 2025