Latest CVE Feed
-
8.8
HIGHCVE-2021-44123
SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it.... Read more
Affected Products : spip- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-44122
SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious website which redirects to... Read more
Affected Products : spip- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44120
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the editor has an article written and ava... Read more
Affected Products : spip- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44118
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side into ... Read more
Affected Products : spip- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-44117
A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4.... Read more
Affected Products : fuel_cms- Published: Jun. 10, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-44116
Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php. Attackers can use the posts column to upload the title and content containing malicious code to achieve the purpose of obtaining the administrator cookie, thereby achievin... Read more
Affected Products : anchor_cms- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-44114
Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Stock Management System in PHP/OOP 1.0, which allows remote malicious users to execute arbitrary remote code execution via create user function.... Read more
Affected Products : stock_management_system- Published: Jan. 31, 2022
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-44111
A Directory Traversal vulnerability exists in S-Cart 6.7 via download in sc-admin/backup.... Read more
Affected Products : s-cart- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-44109
A buffer overflow in lib/sbi/message.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request.... Read more
Affected Products : open5gs- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-44108
A null pointer dereference in src/amf/namf-handler.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request to amf.... Read more
Affected Products : open5gs- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44098
EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database.... Read more
Affected Products : expense_management_system- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44097
EGavilan Media Contact-Form-With-Messages-Entry-Management 1.0 is vulnerable to SQL Injection via Addmessage.php. This allows a remote attacker to compromise Application SQL database.... Read more
Affected Products : contact-form-with-messages-entry-management- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44096
EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user. This allows a remote attacker to compromise Application SQL database.... Read more
Affected Products : user_registration_and_login_system_with_admin_panel- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44095
A SQL injection vulnerability exists in ProjectWorlds Hospital Management System in php 1.0 on login page that allows a remote attacker to compromise Application SQL database.... Read more
Affected Products : hospital_management_system- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-44094
ZrLog 2.2.2 has a remote command execution vulnerability at plugin download function, it could execute any JAR file... Read more
Affected Products : zrlog- Published: Nov. 28, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44093
A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit, upload the JSP file to get a WebShell... Read more
Affected Products : zrlog- Published: Nov. 28, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44091
A Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in register.php via the (1) fullname, (2) phone, and (3) address parameters.... Read more
Affected Products : multi_restaurant_table_reservation_system- Published: Jan. 20, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44090
An SQL Injection vulnerability exists in Sourcecodester Online Reviewer System 1.0 via the password parameter.... Read more
- Published: Jan. 20, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44088
An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters.... Read more
Affected Products : attendance_and_payroll_system- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44087
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an unauthenticated remote attacker to upload a maliciously crafted PHP via photo upload.... Read more
Affected Products : attendance_and_payroll_system- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024