Latest CVE Feed
-
5.4
MEDIUMCVE-2021-44120
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the editor has an article written and ava... Read more
Affected Products : spip- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44118
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side into ... Read more
Affected Products : spip- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-44117
A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4.... Read more
Affected Products : fuel_cms- Published: Jun. 10, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-44116
Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php. Attackers can use the posts column to upload the title and content containing malicious code to achieve the purpose of obtaining the administrator cookie, thereby achievin... Read more
Affected Products : anchor_cms- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-44114
Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Stock Management System in PHP/OOP 1.0, which allows remote malicious users to execute arbitrary remote code execution via create user function.... Read more
Affected Products : stock_management_system- Published: Jan. 31, 2022
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-44111
A Directory Traversal vulnerability exists in S-Cart 6.7 via download in sc-admin/backup.... Read more
Affected Products : s-cart- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-44109
A buffer overflow in lib/sbi/message.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request.... Read more
Affected Products : open5gs- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-44108
A null pointer dereference in src/amf/namf-handler.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request to amf.... Read more
Affected Products : open5gs- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44098
EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database.... Read more
Affected Products : expense_management_system- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44097
EGavilan Media Contact-Form-With-Messages-Entry-Management 1.0 is vulnerable to SQL Injection via Addmessage.php. This allows a remote attacker to compromise Application SQL database.... Read more
Affected Products : contact-form-with-messages-entry-management- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44096
EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user. This allows a remote attacker to compromise Application SQL database.... Read more
Affected Products : user_registration_and_login_system_with_admin_panel- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44095
A SQL injection vulnerability exists in ProjectWorlds Hospital Management System in php 1.0 on login page that allows a remote attacker to compromise Application SQL database.... Read more
Affected Products : hospital_management_system- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-44094
ZrLog 2.2.2 has a remote command execution vulnerability at plugin download function, it could execute any JAR file... Read more
Affected Products : zrlog- Published: Nov. 28, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44093
A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit, upload the JSP file to get a WebShell... Read more
Affected Products : zrlog- Published: Nov. 28, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44091
A Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in register.php via the (1) fullname, (2) phone, and (3) address parameters.... Read more
Affected Products : multi_restaurant_table_reservation_system- Published: Jan. 20, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44090
An SQL Injection vulnerability exists in Sourcecodester Online Reviewer System 1.0 via the password parameter.... Read more
- Published: Jan. 20, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44088
An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters.... Read more
Affected Products : attendance_and_payroll_system- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44087
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an unauthenticated remote attacker to upload a maliciously crafted PHP via photo upload.... Read more
Affected Products : attendance_and_payroll_system- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
8.3
HIGHCVE-2021-44082
textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to trigger remote code execution by uploading a webshell. To do so they must first steal the CSRF token before... Read more
Affected Products : textpattern- Published: Mar. 29, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-44081
A buffer overflow vulnerability exists in the AMF of open5gs 2.1.4. When the length of MSIN in Supi exceeds 24 characters, it leads to AMF denial of service.... Read more
Affected Products : open5gs- Published: Mar. 29, 2022
- Modified: Nov. 21, 2024