Latest CVE Feed
-
5.3
MEDIUMCVE-2021-45286
Directory Traversal vulnerability exists in ZZCMS 2021 via the skin parameter in 1) index.php, 2) bottom.php, and 3) top_index.php.... Read more
Affected Products : zzcms- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-45281
QuickBox Pro v2.4.8 contains a cross-site scripting (XSS) vulnerability at "adminuseredit.php?usertoedit=XSS", as the user supplied input for the value of this parameter is not properly sanitized.... Read more
Affected Products : quickbox- Published: Feb. 07, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-45268
A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading a maliciously add-on with crafted PHP file. NOTE: the vendor disputes t... Read more
- Published: Feb. 03, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45267
An invalid memory address dereference vulnerability exists in gpac 1.1.0 via the svg_node_start function, which causes a segmentation fault and application crash.... Read more
Affected Products : gpac- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45266
A null pointer dereference vulnerability exists in gpac 1.1.0 via the lsr_read_anim_values_ex function, which causes a segmentation fault and application crash.... Read more
Affected Products : gpac- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45263
An invalid free vulnerability exists in gpac 1.1.0 via the gf_svg_delete_attribute_value function, which causes a segmentation fault and application crash.... Read more
Affected Products : gpac- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45262
An invalid free vulnerability exists in gpac 1.1.0 via the gf_sg_command_del function, which causes a segmentation fault and application crash.... Read more
Affected Products : gpac- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45261
An Invalid Pointer vulnerability exists in GNU patch 2.7 via the another_hunk function, which causes a Denial of Service.... Read more
Affected Products : patch- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45260
A null pointer dereference vulnerability exists in gpac 1.1.0 in the lsr_read_id.part function, which causes a segmentation fault and application crash.... Read more
Affected Products : gpac- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45259
An Invalid pointer reference vulnerability exists in gpac 1.1.0 via the gf_svg_node_del function, which causes a segmentation fault and application crash.... Read more
Affected Products : gpac- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45258
A stack overflow vulnerability exists in gpac 1.1.0 via the gf_bifs_dec_proto_list function, which causes a segmentation fault and application crash.... Read more
Affected Products : gpac- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45257
An infinite loop vulnerability exists in nasm 2.16rc0 via the gpaste_tokens function.... Read more
- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45256
A Null Pointer Dereference vulnerability existfs in nasm 2.16rc0 via asm/preproc.c.... Read more
- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-45255
The email parameter from ajax.php of Video Sharing Website 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The... Read more
Affected Products : video_sharing_website- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45253
The id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an... Read more
- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45252
Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be retrieving all information from the database of this sy... Read more
Affected Products : simple_forum\/discussion_system- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45232
In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use ... Read more
Affected Products : apisix_dashboard- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-45231
A link following privilege escalation vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to create a specially crafted file with arbitrary content whic... Read more
Affected Products : windows apex_one worry-free_business_security worry-free_business_security_services- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-45230
In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on DAG Runs can create Dag Runs for dags that they don't have "edit" permissions for.... Read more
Affected Products : airflow- Published: Jan. 20, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-45229
It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. This issue affects Apache Airflow versions 2.2.3 and below.... Read more
Affected Products : airflow- Published: Feb. 25, 2022
- Modified: Nov. 21, 2024