Latest CVE Feed
-
9.8
CRITICALCVE-2021-45024
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).... Read more
Affected Products : ags-zena- Published: Jun. 17, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-45018
Cross Site Scripting (XSS) vulnerability exists in Catfish <=6.3.0 via a Google search in url:/catfishcms/index.php/admin/Index/addmenu.htmland then the .html file on the website that uses this editor (the file suffix is allowed).... Read more
- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-45017
Cross Site Request Forgery (CSRF) vulnerability exits in Catfish <=6.1.* when you upload an html file containing CSRF on the website that uses a google editor; you can specify the menu url address as your malicious url address in the Add Menu column.... Read more
- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-45015
taocms 3.0.2 is vulnerable to arbitrary file deletion via taocms\include\Model\file.php from line 60 to line 72.... Read more
Affected Products : taocms- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45014
There is an upload sql injection vulnerability in the background of taocms 3.0.2 in parameter id:action=cms&ctrl=update&id=26... Read more
Affected Products : taocms- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-45010
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to upload malicious PHP files to the webroot, leading to code execution.... Read more
Affected Products : tiny_file_manager- Published: Mar. 15, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-45008
Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users... Read more
Affected Products : plesk- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-45007
Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. NOTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users... Read more
Affected Products : plesk- Published: Feb. 20, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45005
Artifex MuJS v1.1.3 was discovered to contain a heap buffer overflow which is caused by conflicting JumpList of nested try/finally statements.... Read more
Affected Products : mujs- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-44994
There is an Assertion ''JERRY_CONTEXT (jmem_heap_allocated_size) == 0'' failed at /jerry-core/jmem/jmem-heap.c in Jerryscript 3.0.0.... Read more
Affected Products : jerryscript- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-44993
There is an Assertion ''ecma_is_value_boolean (base_value)'' failed at /jerry-core/ecma/operations/ecma-get-put-value.c in Jerryscript 3.0.0.... Read more
Affected Products : jerryscript- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-44992
There is an Assertion ''ecma_object_is_typedarray (obj_p)'' failed at /jerry-core/ecma/operations/ecma-typedarray-object.c in Jerryscript 3.0.0.... Read more
Affected Products : jerryscript- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-44988
Jerryscript v3.0.0 and below was discovered to contain a stack overflow via ecma_find_named_property in ecma-helpers.c.... Read more
Affected Products : jerryscript- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-44983
In taocms 3.0.1 after logging in to the background, there is an Arbitrary file download vulnerability at the File Management column.... Read more
Affected Products : taocms- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-44981
In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it into a shell_exec(''); function without properly sanitizing any shell arguments, therefore remote code execution is possible. Additionally... Read more
Affected Products : quickbox- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44978
iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution.... Read more
Affected Products : icms- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-44977
In iCMS <=8.0.0, a directory traversal vulnerability allows an attacker to read arbitrary files.... Read more
Affected Products : icms- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-44975
radareorg radare2 5.5.2 is vulnerable to Buffer Overflow via /libr/core/anal_objc.c mach-o parser.... Read more
Affected Products : radare2- Published: May. 24, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-44974
radareorg radare2 version 5.5.2 is vulnerable to NULL Pointer Dereference via libr/bin/p/bin_symbols.c binary symbol parser.... Read more
Affected Products : radare2- Published: May. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44971
Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticated command injectio... Read more
- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024