Latest CVE Feed
-
9.8
CRITICALCVE-2021-44143
A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted mail message that lacks headers (i.e., one that starts with an empty line) to provoke a heap overflow, which... Read more
- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-44141
All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. SMB1 with unix extensions has to be ... Read more
- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-44140
Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http request on logout, given that those files are reachable to the user running the JSPWiki instance. Apache JSPWiki... Read more
Affected Products : jspwiki- Published: Nov. 24, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-44139
Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF).... Read more
Affected Products : sentinel- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-44138
There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ; in a pathname within an HTTP request.... Read more
Affected Products : resin- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-44135
pagekit all versions, as of 15-10-2021, is vulnerable to SQL Injection via Comment listing.... Read more
Affected Products : pagekit- Published: Apr. 01, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-44132
A command injection vulnerability in the function formImportOMCIShell of C-DATA ONU4FERW V2.1.13_X139 allows attackers to execute arbitrary commands via a crafted file.... Read more
- Published: Feb. 25, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-44127
In DLink DAP-1360 F1 firmware version <=v6.10 in the "webupg" binary, an attacker can use the "file" parameter to execute arbitrary system commands when the parameter is "name=deleteFile" after being authorized.... Read more
- Published: Mar. 27, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-44124
Hiby Music Hiby OS R3 Pro 1.5 and 1.6 is vulnerable to Directory Traversal. The HTTP Server does not have enough input data sanitization when shown data from SD Card, an attacker can navigate through the device's File System over HTTP.... Read more
- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-44123
SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it.... Read more
Affected Products : spip- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-44122
SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious website which redirects to... Read more
Affected Products : spip- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44120
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the editor has an article written and ava... Read more
Affected Products : spip- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44118
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side into ... Read more
Affected Products : spip- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-44117
A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4.... Read more
Affected Products : fuel_cms- Published: Jun. 10, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-44116
Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php. Attackers can use the posts column to upload the title and content containing malicious code to achieve the purpose of obtaining the administrator cookie, thereby achievin... Read more
Affected Products : anchor_cms- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-44114
Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Stock Management System in PHP/OOP 1.0, which allows remote malicious users to execute arbitrary remote code execution via create user function.... Read more
Affected Products : stock_management_system- Published: Jan. 31, 2022
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-44111
A Directory Traversal vulnerability exists in S-Cart 6.7 via download in sc-admin/backup.... Read more
Affected Products : s-cart- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-44109
A buffer overflow in lib/sbi/message.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request.... Read more
Affected Products : open5gs- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-44108
A null pointer dereference in src/amf/namf-handler.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request to amf.... Read more
Affected Products : open5gs- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44098
EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database.... Read more
Affected Products : expense_management_system- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024