Latest CVE Feed
-
6.1
MEDIUMCVE-2021-43695
issabelPBX version 2.11 is affected by a Cross Site Scripting (XSS) vulnerability. In file page.backup_restore.php, the exit function will terminate the script and print the message to the user. The message will contain $_REQUEST without sanitization, the... Read more
Affected Products : pbx- Published: Nov. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43693
vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php.... Read more
Affected Products : vesta_control_panel- Published: Nov. 29, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-43692
youtube-php-mirroring (last update Jun 9, 2017) is affected by a Cross Site Scripting (XSS) vulnerability in file ytproxy/index.php.... Read more
Affected Products : youtube-php-mirroring- Published: Nov. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43691
tripexpress v1.1 is affected by a path manipulation vulnerability in file system/helpers/dompdf/load_font.php. The variable src is coming from $_SERVER["argv"] then there is a path manipulation vulnerability.... Read more
Affected Products : tripexpress- Published: Nov. 29, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-43690
YurunProxy v0.01 is affected by a Cross Site Scripting (XSS) vulnerability in src/Client.php. The exit function will terminate the script and print a message which have values from the socket_read.... Read more
Affected Products : yurunproxy- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-43689
manage (last update Oct 24, 2017) is affected by a Cross Site Scripting (XSS) vulnerability in Application/Home/Controller/GoodsController.class.php. The exit function will terminate the script and print a message which have values from $_POST.... Read more
Affected Products : manage- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-43687
chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an attacker passes a message hex2bin in the cookie.... Read more
- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-43686
nZEDb v0.4.20 is affected by a Cross Site Scripting (XSS) vulnerability in www/pages/api.php. The exit function will terminate the script and print the message which has the input $_GET['t'].... Read more
Affected Products : nzedb- Published: Dec. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43685
libretime hv3.0.0-alpha.10 is affected by a path manipulation vulnerability in /blob/master/legacy/application/modules/rest/controllers/ShowImageController.php through the rename function.... Read more
Affected Products : libretime_hv- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-43683
pictshare v1.5 is affected by a Cross Site Scripting (XSS) vulnerability in api/info.php. The exit function will terminate the script and print the message which has $_REQUEST['hash'].... Read more
Affected Products : pictshare- Published: Dec. 02, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-43682
thinkphp-bjyblog (last update Jun 4 2021) is affected by a Cross Site Scripting (XSS) vulnerability in AdminBaseController.class.php. The exit function terminates the script and prints a message to the user that contains $_SERVER['HTTP_HOST'].... Read more
Affected Products : thinkphp-bjyblog- Published: Dec. 02, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-43681
SakuraPanel v1.0.1.1 is affected by a Cross Site Scripting (XSS) vulnerability in /master/core/PostHandler.php. The exit function will terminate the script and print the message $data['proxy_name'].... Read more
Affected Products : sakurapanel- Published: Dec. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43679
ecshop v2.7.3 is affected by a SQL injection vulnerability in shopex\ecshop\upload\api\client\api.php.... Read more
Affected Products : ecshop- Published: Dec. 02, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-43678
Wechat-php-sdk v1.10.2 is affected by a Cross Site Scripting (XSS) vulnerability in Wechat.php.... Read more
Affected Products : wechat-php-sdk- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-43677
Fluxbb v1.4.12 is affected by a Cross Site Scripting (XSS) vulnerability.... Read more
Affected Products : fluxbb- Published: Jan. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43676
matyhtf framework v3.0.5 is affected by a path manipulation vulnerability in Smarty.class.php.... Read more
Affected Products : swoole_php_framework- Published: Dec. 03, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-43675
Lychee-v3 3.2.16 is affected by a Cross Site Scripting (XSS) vulnerability in php/Access/Guest.php. The function exit will terminate the script and print the message to the user. The message will contain albumID which is controlled by the user.... Read more
Affected Products : lychee- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43674
ThinkUp 2.0-beta.10 is affected by a path manipulation vulnerability in Smarty.class.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer... Read more
Affected Products : thinkup- Published: Dec. 03, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-43673
dzzoffice 2.02.1_SC_UTF8 is affected by a Cross Site Scripting (XSS) vulnerability in explorerfile.php. The output of the exit function is printed for the user via exit(json_encode($return)).... Read more
Affected Products : dzzoffice- Published: Dec. 03, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-43669
A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.0.1, v2.3.0. It can easily break down as many orderers as the attacker wants. This bug can be leveraged by constructing a message whose header is invalid to the interface Order. Th... Read more
- Published: Nov. 18, 2021
- Modified: Nov. 21, 2024