Latest CVE Feed
-
7.5
HIGHCVE-2021-45793
Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained.... Read more
Affected Products : senayan_library_management_system- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-45792
Slims9 Bulian 9.4.2 is affected by Cross Site Scripting (XSS) in /admin/modules/system/custom_field.php.... Read more
Affected Products : senayan_library_management_system- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-45791
Slims8 Akasia 8.3.1 is affected by SQL injection in /admin/modules/bibliography/index.php, /admin/modules/membership/member_type.php, /admin/modules/system/user_group.php, and /admin/modules/membership/index.php through the dir parameter. It can be used b... Read more
Affected Products : senayan_library_management_system- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45790
An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to arbitrary directory, where attackers can write a cron job to execute commands.... Read more
Affected Products : metersphere- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-45789
An arbitrary file read vulnerability was found in Metersphere v1.15.4, where authenticated users can read any file on the server via the file download function.... Read more
Affected Products : metersphere- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-45788
Time-based SQL Injection vulnerabilities were found in Metersphere v1.15.4 via the "orders" parameter.... Read more
Affected Products : metersphere- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-45787
There is a stored Cross Site Scripting (XSS) vulnerability in maccms v10 through adding videos. XSS code can be inserted at parameter positions including name and remarks.... Read more
Affected Products : maccms- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45786
In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.... Read more
Affected Products : maccms- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-45785
TruDesk Help Desk/Ticketing Solution v1.1.11 is vulnerable to a Cross-Site Request Forgery (CSRF) attack which would allow an attacker to restart the server, causing a DoS attack. The attacker must craft a webpage that would perform a GET request to the /... Read more
Affected Products : trudesk- Published: Jun. 24, 2024
- Modified: Nov. 21, 2024
-
4.6
MEDIUMCVE-2021-45783
Bookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to obtain sensitive information.... Read more
- Published: May. 05, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45773
A NULL pointer dereference in CS104_IPAddress_setFromString at src/iec60870/cs104/cs104_slave.c of lib60870 commit 0d5e76e can lead to a segmentation fault or application crash.... Read more
Affected Products : lib60870- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45769
A NULL pointer dereference in AcseConnection_parseMessage at src/mms/iso_acse/acse.c of libiec61850 v1.5.0 can lead to a segmentation fault or application crash.... Read more
Affected Products : libiec61850- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45767
GPAC 1.1.0 was discovered to contain an invalid memory address dereference via the function lsr_read_id(). This vulnerability can lead to a Denial of Service (DoS).... Read more
Affected Products : gpac- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45764
GPAC v1.1.0 was discovered to contain an invalid memory address dereference via the function shift_chunk_offsets.isra().... Read more
Affected Products : gpac- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45763
GPAC v1.1.0 was discovered to contain an invalid call in the function gf_node_changed(). This vulnerability can lead to a Denial of Service (DoS).... Read more
Affected Products : gpac- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45762
GPAC v1.1.0 was discovered to contain an invalid memory address dereference via the function gf_sg_vrml_mf_reset(). This vulnerability allows attackers to cause a Denial of Service (DoS).... Read more
Affected Products : gpac- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45761
ROPium v3.1 was discovered to contain an invalid memory address dereference via the find() function.... Read more
Affected Products : ropium- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45760
GPAC v1.1.0 was discovered to contain an invalid memory address dereference via the function gf_list_last(). This vulnerability allows attackers to cause a Denial of Service (DoS).... Read more
Affected Products : gpac- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-45757
ASUS AC68U <=3.0.0.4.385.20852 is affected by a buffer overflow in blocking.cgi, which may cause a denial of service (DoS).... Read more
- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45756
Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.cgi.... Read more
- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024