Latest CVE Feed
-
6.1
MEDIUM- Published: Jan. 01, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-44892
A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obtain server control privileges.... Read more
Affected Products : thinkphp- Published: Feb. 10, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-44886
In Zammad 5.0.2, agents can configure "out of office" periods and substitute persons. If the substitute persons didn't have the same permissions as the original agent, they could receive ticket notifications for tickets that they have no access to.... Read more
Affected Products : zammad- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-44882
D-Link device DIR_878_FW1.30B08_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-44881
D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-44880
D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to execute arbitrary commands via a crafted... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-44879
In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference.... Read more
Affected Products : linux_kernel- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-44878
If an OpenID Connect provider supports the "none" algorithm (i.e., tokens with no signature), pac4j v5.3.0 (and prior) does not refuse it without an explicit configuration on its side or for the "idtoken" response type which is not secure and violates the... Read more
Affected Products : pac4j- Published: Jan. 06, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-44877
Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to Incorrect Access Control. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts... Read more
Affected Products : systeam_enterprise_resource_planning- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-44876
Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. This i... Read more
Affected Products : systeam_enterprise_resource_planning- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-44875
Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. This i... Read more
Affected Products : systeam_enterprise_resource_planning- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-44874
Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to Insecure design on report build via SQL query. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web app... Read more
Affected Products : systeam_enterprise_resource_planning- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44868
A problem was found in ming-soft MCMS v5.1. There is a sql injection vulnerability in /ms/cms/content/list.do... Read more
Affected Products : mcms- Published: Feb. 17, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-44866
An issue was discovered in Online-Movie-Ticket-Booking-System 1.0. The file about.php does not perform input validation on the 'id' paramter. An attacker can append SQL queries to the input to extract sensitive information from the database.... Read more
Affected Products : online_movie_ticket_booking_system- Published: Feb. 03, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-44864
TP-Link WR886N 3.0 1.0.1 Build 150127 Rel.34123n is vulnerable to Buffer Overflow. Authenticated attackers can crash router httpd services via /userRpm/PingIframeRpm.htm request which contains redundant & in parameter.... Read more
- Published: Feb. 08, 2022
- Modified: Nov. 21, 2024
-
8.4
HIGHCVE-2021-44862
Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information stored in NSClient logs which should be restricted. The vulnerability exists because the sensitive information is not masked/scrubbed befo... Read more
Affected Products : netskope- Published: Nov. 03, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-44860
An out-of-bounds read vulnerability exists when reading a TIF file using Open Design Alliance Drawings SDK before 2022.12. The specific issue exists after loading TIF files. An unchecked input data from a crafted TIF file leads to an out-of-bounds read. A... Read more
Affected Products : drawings_sdk- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-44859
An out-of-bounds read vulnerability exists when reading a TGA file using Open Design Alliance Drawings SDK before 2022.12. The specific issue exists after loading TGA files. An unchecked input data from a crafted TGA file leads to an out-of-bounds read. A... Read more
Affected Products : drawings_sdk- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-44858
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one page... Read more
Affected Products : mediawiki- Published: Dec. 20, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-44857
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=mcrundo followed by action=mcrrestore to replace the content of any arbitrary page (that the user doesn't have edit rights for... Read more
Affected Products : mediawiki- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024