Latest CVE Feed
-
7.5
HIGHCVE-2021-46385
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.FormDataAction#queryData. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql i... Read more
Affected Products : mcms- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-46384
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ¶¶ MCMS has a pre-auth RCE vulnerability through which allows u... Read more
Affected Products : mcms- Published: Mar. 04, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-46383
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.web.DictAction#list. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql inject... Read more
Affected Products : mcms- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-46382
Unauthenticated cross-site scripting (XSS) in Netgear WAC120 AC Access Point may lead to mulitple attacks like session hijacking even clipboard hijacking.... Read more
- Published: Mar. 04, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-46381
Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow].... Read more
- Published: Mar. 04, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-46379
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.... Read more
- Published: Mar. 04, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-46378
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote configuration download.... Read more
- Published: Mar. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-46377
There is a front-end sql injection vulnerability in cszcms 1.2.9 via cszcms/controllers/Member.php#viewUser... Read more
- Published: Jan. 27, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-46372
Scoold 1.47.2 is a Q&A/knowledge base platform written in Java. When writing a Q&A, the markdown editor is vulnerable to a XSS attack when using uppercase letters.... Read more
Affected Products : scoold- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-46371
antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the foreground leads to leakage of sensitive information.... Read more
Affected Products : antd-admin- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-46368
TRIGONE Remote System Monitor 3.61 is vulnerable to an unquoted path service allowing local users to launch processes with elevated privileges.... Read more
Affected Products : remote_system_monitor- Published: Feb. 17, 2022
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-46367
RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated attacker can upload a PHP file and bypass the .htacess configuration to deny execution of .php files in media and files directory by de... Read more
Affected Products : ritecms- Published: Apr. 08, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-46366
An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerability and Cross-Site Request Forgery (CSRF) in order to brute force and exfiltrate users' credentials.... Read more
Affected Products : magnolia_cms- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-46365
An issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute XML External Entity attacks via a crafted XLF file.... Read more
Affected Products : magnolia_cms- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-46364
A vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows attackers to execute arbitrary code via a crafted YAML file.... Read more
Affected Products : magnolia_cms- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-46363
An issue in the Export function of Magnolia v6.2.3 and below allows attackers to perform Formula Injection attacks via crafted CSV/XLS files. These formulas may result in arbitrary code execution on a victim's computer when opening the exported files with... Read more
Affected Products : magnolia_cms- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-46362
A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a crafted payload entered into the fullname parameter.... Read more
Affected Products : magnolia_cms- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-46361
An issue in the Freemark Filter of Magnolia CMS v6.2.11 and below allows attackers to bypass security restrictions and execute arbitrary code via a crafted FreeMarker payload.... Read more
Affected Products : magnolia_cms- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-46360
Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrary code via uploading a PHP shell through /adminzone/index.php?page=admin-commandr.... Read more
- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-46359
FISCO-BCOS release-3.0.0-rc2 contains a denial of service vulnerability. Some transactions may not be committed successfully, and malicious users may use this to achieve double-spending attacks.... Read more
Affected Products : fisco-bcos- Published: Feb. 07, 2022
- Modified: Nov. 21, 2024