Latest CVE Feed
-
9.8
CRITICALCVE-2021-44349
SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameter in App\Manage\Controller\DownloadController.class.php.... Read more
- Published: Dec. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44348
SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameer in App\Manage\Controller\AdvertController.class.php.... Read more
- Published: Dec. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44347
SQL Injection vulnerability exists in TuziCMS v2.0.6 in App\Manage\Controller\GuestbookController.class.php.... Read more
- Published: Dec. 03, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-44345
Beijing Wisdom Vision Technology Industry Co., Ltd One Card Integrated Management System 3.0 is vulnerable to SQL Injection.... Read more
Affected Products : one_card_integrated_management_system- Published: Mar. 20, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-44343
David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurred in function ok_png_read_data() in "/ok_png.c".... Read more
Affected Products : ok-file-formats- Published: Mar. 03, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-44342
David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow via function ok_png_transform_scanline() in "/ok_png.c:494".... Read more
Affected Products : ok-file-formats- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-44340
David Brackeen ok-file-formats dev version is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurred in function ok_jpg_generate_huffman_table() in "/ok_jpg.c:403".... Read more
Affected Products : ok-file-formats- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-44339
David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurred in function ok_png_transform_scanline() in "/ok_png.c:712".... Read more
Affected Products : ok-file-formats- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-44335
David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurs in function ok_png_transform_scanline() in "/ok_png.c:533".... Read more
Affected Products : ok-file-formats- Published: Mar. 03, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-44334
David Brackeen ok-file-formats 97f78ca is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurs in function ok_jpg_convert_YCbCr_to_RGB() in "/ok_jpg.c:513" .... Read more
Affected Products : ok-file-formats- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-44331
ARM astcenc 3.2.0 is vulnerable to Buffer Overflow in function encode_ise().... Read more
Affected Products : adaptive_scalable_texture_compression_encoder- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
5.0
MEDIUMCVE-2021-44321
Mini-Inventory-and-Sales-Management-System is affected by Cross Site Request Forgery (CSRF), where an attacker can update/delete items in the inventory. The attacker must be logged into the application create a malicious file for updating the inventory de... Read more
Affected Products : mini-inventory-and-sales-management-system- Published: Mar. 04, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44317
In Bus Pass Management System v1.0, parameters 'pagedes' and `About Us` are affected with a Stored Cross-site scripting vulnerability.... Read more
- Published: Dec. 16, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-44315
In Bus Pass Management System v1.0, Directory Listing/Browsing is enabled on the web server which allows an attacker to view the sensitive files of the application, for example: Any file which contains sensitive information of the user or server.... Read more
- Published: Dec. 16, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-44312
An issue was discovered in Firmware Analysis and Comparison Tool v3.2. Logged in administrators could be targeted by a CSRF attack through visiting a crafted web page.... Read more
Affected Products : firmware_analysis_and_comparison_tool- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-44310
An issue was discovered in Firmware Analysis and Comparison Tool v3.2. With administrator privileges, the attacker could perform stored XSS attacks by inserting JavaScript and HTML code in user creation functionality.... Read more
Affected Products : firmware_analysis_and_comparison_tool- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-44302
BaiCloud-cms v2.5.7 was discovered to contain multiple SQL injection vulnerabilities via the tongji and baidu_map parameters in /user/ztconfig.php.... Read more
Affected Products : baicloud-cms- Published: Feb. 19, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44299
A reflected cross-site scripting (XSS) vulnerability in \lib\packages\themes\themes.php of Navigate CMS v2.9.4 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : navigate_cms- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44280
attendance management system 1.0 is affected by a SQL injection vulnerability in admin/incFunctions.php through the makeSafe function.... Read more
Affected Products : attendance_management_system- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-44279
Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/forms/poller-groups.inc.php.... Read more
Affected Products : librenms- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024