Latest CVE Feed
-
6.1
MEDIUMCVE-2021-43681
SakuraPanel v1.0.1.1 is affected by a Cross Site Scripting (XSS) vulnerability in /master/core/PostHandler.php. The exit function will terminate the script and print the message $data['proxy_name'].... Read more
Affected Products : sakurapanel- Published: Dec. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43679
ecshop v2.7.3 is affected by a SQL injection vulnerability in shopex\ecshop\upload\api\client\api.php.... Read more
Affected Products : ecshop- Published: Dec. 02, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-43678
Wechat-php-sdk v1.10.2 is affected by a Cross Site Scripting (XSS) vulnerability in Wechat.php.... Read more
Affected Products : wechat-php-sdk- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-43677
Fluxbb v1.4.12 is affected by a Cross Site Scripting (XSS) vulnerability.... Read more
Affected Products : fluxbb- Published: Jan. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43676
matyhtf framework v3.0.5 is affected by a path manipulation vulnerability in Smarty.class.php.... Read more
Affected Products : swoole_php_framework- Published: Dec. 03, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-43675
Lychee-v3 3.2.16 is affected by a Cross Site Scripting (XSS) vulnerability in php/Access/Guest.php. The function exit will terminate the script and print the message to the user. The message will contain albumID which is controlled by the user.... Read more
Affected Products : lychee- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43674
ThinkUp 2.0-beta.10 is affected by a path manipulation vulnerability in Smarty.class.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer... Read more
Affected Products : thinkup- Published: Dec. 03, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-43673
dzzoffice 2.02.1_SC_UTF8 is affected by a Cross Site Scripting (XSS) vulnerability in explorerfile.php. The output of the exit function is printed for the user via exit(json_encode($return)).... Read more
Affected Products : dzzoffice- Published: Dec. 03, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-43669
A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.0.1, v2.3.0. It can easily break down as many orderers as the attacker wants. This bug can be leveraged by constructing a message whose header is invalid to the interface Order. Th... Read more
- Published: Nov. 18, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-43668
Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They will crash with "runtime error: invalid memory address or nil pointer dereference" and arise a SEGV signal.... Read more
Affected Products : go_ethereum- Published: Nov. 18, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-43667
A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.1.0. This bug can be leveraged by constructing a message whose payload is nil and sending this message with the method 'forwardToLeader'. This bug has been admitted and fixed by th... Read more
- Published: Nov. 18, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-43666
A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0.... Read more
- Published: Mar. 24, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-43664
totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component process forceugpo.... Read more
- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
7.9
HIGHCVE-2021-43663
totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component cloudupdate_check.... Read more
- Published: Mar. 31, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-43662
totolink EX300_v2, ver V4.0.3c.140_B20210429 and A720R ,ver V4.1.5cu.470_B20200911 have an issue which causes uncontrolled resource consumption.... Read more
- Published: Mar. 31, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-43661
totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /home.asp.... Read more
- Published: Mar. 31, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-43659
In halo 1.4.14, the function point of uploading the avatar, any file can be uploaded, such as uploading an HTML file, which will cause a stored XSS vulnerability.... Read more
Affected Products : halo- Published: Mar. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43650
WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process.... Read more
Affected Products : webrun- Published: Mar. 22, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-43638
Amazon Amazon WorkSpaces agent is affected by Integer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS c... Read more
Affected Products : workspaces- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-43637
Amazon WorkSpaces agent is affected by Buffer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) vi... Read more
Affected Products : workspaces- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024