Latest CVE Feed
-
4.3
MEDIUMCVE-2021-44942
glFusion CMS 1.7.9 is affected by a Cross Site Request Forgery (CSRF) vulnerability in /public_html/admin/plugins/bad_behavior2/blacklist.php. Using the CSRF vulnerability to trick the administrator to click, an attacker can add a blacklist.... Read more
Affected Products : glfusion- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-44937
glFusion CMS v1.7.9 is affected by an arbitrary user registration vulnerability in /public_html/users.php. An attacker can register with the mailbox of any user. When users want to register, they will find that the mailbox has been occupied.... Read more
Affected Products : glfusion- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-44935
glFusion CMS v1.7.9 is affected by an arbitrary user impersonation vulnerability in /public_html/comment.php. The attacker can complete the attack remotely without interaction.... Read more
Affected Products : glfusion- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-44927
A null pointer dereference vulnerability exists in gpac 1.1.0 in the gf_sg_vrml_mf_append function, which causes a segmentation fault and application crash.... Read more
Affected Products : gpac- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-44926
A null pointer dereference vulnerability exists in gpac 1.1.0-DEV in the gf_node_get_tag function, which causes a segmentation fault and application crash.... Read more
Affected Products : gpac- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-44925
A null pointer dereference vulnerability exists in gpac 1.1.0 in the gf_svg_get_attribute_name function, which causes a segmentation fault and application crash.... Read more
Affected Products : gpac- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-44924
An infinite loop vulnerability exists in gpac 1.1.0 in the gf_log function, which causes a Denial of Service.... Read more
Affected Products : gpac- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-44922
A null pointer dereference vulnerability exists in gpac 1.1.0 in the BD_CheckSFTimeOffset function, which causes a segmentation fault and application crash.... Read more
Affected Products : gpac- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-44921
A null pointer dereference vulnerability exists in gpac 1.1.0 in the gf_isom_parse_movie_boxes_internal function, which causes a segmentation fault and application crash.... Read more
Affected Products : gpac- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-44920
An invalid memory address dereference vulnerability exists in gpac 1.1.0 in the dump_od_to_saf.isra function, which causes a segmentation fault and application crash.... Read more
Affected Products : gpac- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-44919
A Null Pointer Dereference vulnerability exists in the gf_sg_vrml_mf_alloc function in gpac 1.1.0-DEV, which causes a segmentation fault and application crash.... Read more
Affected Products : gpac- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-44918
A Null Pointer Dereference vulnerability exists in gpac 1.1.0 in the gf_node_get_field function, which can cause a segmentation fault and application crash.... Read more
Affected Products : gpac- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-44917
A Divide by Zero vulnerability exists in gnuplot 5.4 in the boundary3d function in graph3d.c, which could cause a Arithmetic exception and application crash.... Read more
- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-44916
Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad value is passed to the routine via a URL, malicious JavaScript code can be executed in the victim's browser.... Read more
Affected Products : open-audit- Published: Dec. 20, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-44915
Taocms 3.0.2 was discovered to contain a blind SQL injection vulnerability via the function Edit category.... Read more
Affected Products : taocms- Published: Jul. 05, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44912
In XE 1.116, when uploading the Normal button, there is no restriction on the file suffix, which leads to any file uploading to the files directory. Since .htaccess only restricts the PHP type, uploading HTML-type files leads to stored XSS vulnerabilities... Read more
Affected Products : xpressengine- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44911
XE before 1.11.6 is vulnerable to Unrestricted file upload via modules/menu/menu.admin.controller.php. When uploading the Mouse over button and When selected button, there is no restriction on the file suffix, which leads to any file uploading to the file... Read more
Affected Products : xpressengine- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44908
SailsJS Sails.js <=1.4.0 is vulnerable to Prototype Pollution via controller/load-action-modules.js, function loadActionModules().... Read more
Affected Products : sails- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44906
Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).... Read more
Affected Products : minimist- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2021-44905
Incorrect permissions in the Bluetooth Services in the Fortessa FTBTLD Smart Lock as of 12-13-2022 allows a remote attacker to disable the lock via an unauthenticated edit to the lock name.... Read more
- Published: Mar. 25, 2022
- Modified: Nov. 21, 2024