Latest CVE Feed
-
8.8
HIGHCVE-2021-44302
BaiCloud-cms v2.5.7 was discovered to contain multiple SQL injection vulnerabilities via the tongji and baidu_map parameters in /user/ztconfig.php.... Read more
Affected Products : baicloud-cms- Published: Feb. 19, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44299
A reflected cross-site scripting (XSS) vulnerability in \lib\packages\themes\themes.php of Navigate CMS v2.9.4 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : navigate_cms- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44280
attendance management system 1.0 is affected by a SQL injection vulnerability in admin/incFunctions.php through the makeSafe function.... Read more
Affected Products : attendance_management_system- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-44279
Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/forms/poller-groups.inc.php.... Read more
Affected Products : librenms- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44278
Librenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php.... Read more
Affected Products : librenms- Published: Dec. 03, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-44277
Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/common/alert-log.inc.php.... Read more
Affected Products : librenms- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2021-44273
e2guardian v5.4.x <= v5.4.3r is affected by missing SSL certificate validation in the SSL MITM engine. In standalone mode (i.e., acting as a proxy or a transparent proxy), with SSL MITM enabled, e2guardian, if built with OpenSSL v1.1.x, did not validate h... Read more
Affected Products : e2guardian- Published: Dec. 23, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-44269
An out of bounds read was found in Wavpack 5.4.0 in processing *.WAV files. This issue triggered in function WavpackPackSamples of file src/pack_utils.c, tainted variable cnt is too large, that makes pointer sptr read beyond heap bound.... Read more
- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-44266
GUnet Open eClass (aka openeclass) before 3.12.2 allows XSS via the modules/auth/formuser.php auth parameter.... Read more
Affected Products : open_eclass_platform- Published: Jun. 11, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44263
Gurock TestRail before 7.2.4 mishandles HTML escaping.... Read more
Affected Products : testrail- Published: Dec. 20, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-44262
A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information for the device.... Read more
- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-44261
A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes firmware version information for the device.... Read more
Affected Products : r7800_firmware r6220_firmware r6900_firmware wac104_firmware r7450_firmware r6900 r6220 r7800 r7450 wac104- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-44260
A vulnerability is in the 'live_mfg.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information of the manager of... Read more
- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44259
A vulnerability is in the 'wx.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication. When an unauthorized user accesses this page directly, it connects to t... Read more
- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-44255
Authenticated remote code execution in MotionEye <= 0.42.1 and MotioneEyeOS <= 20200606 allows a remote attacker to upload a configuration backup file containing a malicious python pickle file which will execute arbitrary code on the server.... Read more
- Published: Jan. 31, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44249
Online Motorcycle (Bike) Rental System 1.0 is vulnerable to a Blind Time-Based SQL Injection attack within the login portal. This can lead attackers to remotely dump MySQL database credentials.... Read more
Affected Products : online_motorcycle_\(bike\)_rental_system- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44247
Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg. This vulnerability allows attackers to execute arbitrary... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-44246
Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain a stack overflow in the function setNoticeCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) ... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44245
An SQL Injection vulnerability exists in Courcecodester COVID 19 Testing Management System (CTMS) 1.0 via the (1) username and (2) contactno parameters.... Read more
Affected Products : covid_19_testing_management_system- Published: Jan. 20, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44244
An SQL Injection vulnerabiity exists in Sourcecodester Logistic Hub Parcel's Management System 1.0 via the username parameter in login.php.... Read more
Affected Products : sourcecodester_logistic_hub_parcel\'s_management_system- Published: Jan. 20, 2022
- Modified: Nov. 21, 2024