Latest CVE Feed
-
9.8
CRITICALCVE-2021-42185
wdja v2.1 is affected by a SQL injection vulnerability in the foreground search function.... Read more
Affected Products : wdja- EPSS Score: %0.23
- Published: May. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42258
BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) pa... Read more
Affected Products : billquick_web_suite- Actively Exploited
- EPSS Score: %93.83
- Published: Oct. 22, 2021
- Modified: Mar. 19, 2025
-
9.8
CRITICALCVE-2021-42127
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via Data Repository Service.... Read more
Affected Products : avalanche- EPSS Score: %53.97
- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42377
An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare... Read more
Affected Products : fedora cloud_backup hci_management_node solidfire h300s_firmware h500s_firmware h700s_firmware h410s_firmware busybox h300s +9 more products- EPSS Score: %1.86
- Published: Nov. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42142
An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers mishandle the early use of a large epoch number. This vulnerability allows remote attackers to cause a denial of service and false-positive packet drops.... Read more
Affected Products : tinydtls- EPSS Score: %1.06
- Published: Jan. 23, 2024
- Modified: Jun. 11, 2025
-
9.8
CRITICALCVE-2021-42224
SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php.... Read more
- EPSS Score: %0.38
- Published: Oct. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41931
The Company's Recruitment Management System in id=2 of the parameter from view_vacancy app on-page appears to be vulnerable to SQL injection. The payloads 19424269' or '1309'='1309 and 39476597' or '2917'='2923 were each submitted in the id parameter. The... Read more
Affected Products : recruitment_management_system- EPSS Score: %0.26
- Published: Nov. 17, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42230
Seowon 130-SLC router all versions as of 2021-09-15 is vulnerable to Remote Code Execution via the queriesCnt parameter.... Read more
- EPSS Score: %20.83
- Published: Apr. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41862
AviatorScript through 5.2.7 allows code execution via an expression that is encoded with Byte Code Engineering Library (BCEL).... Read more
Affected Products : aviatorscript- EPSS Score: %0.40
- Published: Oct. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41833
Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.... Read more
Affected Products : manageengine_patch_connect_plus- EPSS Score: %27.31
- Published: Nov. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41921
novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution.... Read more
Affected Products : novel-plus- EPSS Score: %0.81
- Published: Apr. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41752
Stack overflow vulnerability in Jerryscript before commit e1ce7dd7271288be8c0c8136eea9107df73a8ce2 on Oct 20, 2021 due to an unbounded recursive call to the new opt() function.... Read more
Affected Products : jerryscript- EPSS Score: %0.36
- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41691
A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" parameters in POST request sent to /TransferredOutModal.php.... Read more
Affected Products : opensis- Published: Jun. 24, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2021-42013
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directori... Read more
Affected Products : fedora cloud_backup http_server jd_edwards_enterpriseone_tools secure_backup instantis_enterprisetrack- Actively Exploited
- EPSS Score: %94.43
- Published: Oct. 07, 2021
- Modified: Mar. 21, 2025
-
9.8
CRITICALCVE-2021-41694
An Incorrect Access Control vulnerability exists in Premiumdatingscript 4.2.7.7 via the password change procedure in requests\user.php.... Read more
Affected Products : premiumdatingscript- EPSS Score: %0.35
- Published: Dec. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41674
An SQL Injection vulnerability exists in Sourcecodester E-Negosyo System 1.0 via the user_email parameter in /admin/login.php.... Read more
Affected Products : e-negosyo_system- EPSS Score: %0.38
- Published: Oct. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41745
ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions.... Read more
Affected Products : showdoc- EPSS Score: %0.33
- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41660
SQL injection vulnerability in Sourcecodester Patient Appointment Scheduler System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password fields to login.php.... Read more
Affected Products : patient_appointment_scheduler_system- EPSS Score: %0.26
- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41643
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field.... Read more
Affected Products : church_management_system- EPSS Score: %10.73
- Published: Oct. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41661
Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on the web server by uploading a PHP web... Read more
Affected Products : church_management_system- EPSS Score: %0.49
- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024