Latest CVE Feed
-
5.5
MEDIUMCVE-2021-45259
An Invalid pointer reference vulnerability exists in gpac 1.1.0 via the gf_svg_node_del function, which causes a segmentation fault and application crash.... Read more
Affected Products : gpac- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45258
A stack overflow vulnerability exists in gpac 1.1.0 via the gf_bifs_dec_proto_list function, which causes a segmentation fault and application crash.... Read more
Affected Products : gpac- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45257
An infinite loop vulnerability exists in nasm 2.16rc0 via the gpaste_tokens function.... Read more
- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45256
A Null Pointer Dereference vulnerability existfs in nasm 2.16rc0 via asm/preproc.c.... Read more
- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-45255
The email parameter from ajax.php of Video Sharing Website 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The... Read more
Affected Products : video_sharing_website- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45253
The id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an... Read more
- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45252
Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be retrieving all information from the database of this sy... Read more
Affected Products : simple_forum\/discussion_system- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45232
In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use ... Read more
Affected Products : apisix_dashboard- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-45231
A link following privilege escalation vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to create a specially crafted file with arbitrary content whic... Read more
Affected Products : windows apex_one worry-free_business_security worry-free_business_security_services- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-45230
In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on DAG Runs can create Dag Runs for dags that they don't have "edit" permissions for.... Read more
Affected Products : airflow- Published: Jan. 20, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-45229
It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. This issue affects Apache Airflow versions 2.2.3 and below.... Read more
Affected Products : airflow- Published: Feb. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-45228
An XSS issue was discovered in COINS Construction Cloud 11.12. Due to insufficient neutralization of user input in the description of a task, it is possible to store malicious JavaScript code in the task description. This is later executed when it is refl... Read more
Affected Products : coins_construction_cloud- Published: Apr. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-45227
An issue was discovered in COINS Construction Cloud 11.12. Due to an inappropriate use of HTML IFRAME elements, the file upload functionality is vulnerable to a persistent Cross-Site Scripting (XSS) attack.... Read more
Affected Products : coins_construction_cloud- Published: Apr. 14, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-45226
An issue was discovered in COINS Construction Cloud 11.12. Due to improper validation of user-controlled HTTP headers, attackers can cause it to send password-reset e-mails pointing to arbitrary websites.... Read more
Affected Products : coins_construction_cloud- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-45225
An issue was discovered in COINS Construction Cloud 11.12. Due to improper input neutralization, it is vulnerable to reflected cross-site scripting (XSS) via malicious links (affecting the search window and activity view window).... Read more
Affected Products : coins_construction_cloud- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-45224
An issue was discovered in COINS Construction Cloud 11.12. In several locations throughout the application, JavaScript code is passed as a URL parameter. Attackers can trivially alter this code to cause malicious behaviour. The application is therefore vu... Read more
Affected Products : coins_construction_cloud- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-45223
An issue was discovered in COINS Construction Cloud 11.12. Due to insufficient input neutralization, it is vulnerable to denial of service attacks via forced server crashes.... Read more
Affected Products : coins_construction_cloud- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-45222
An issue was discovered in COINS Construction Cloud 11.12. Due to logical flaws in the human ressources interface, it is vulnerable to privilege escalation by HR personnel.... Read more
Affected Products : coins_construction_cloud- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-45117
The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointer dereference.... Read more
- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45115
An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. UserAttributeSimilarityValidator incurred significant overhead in evaluating a submitted password that was artificially large in relation to the comparison value... Read more
- Published: Jan. 05, 2022
- Modified: Nov. 21, 2024