Latest CVE Feed
-
7.5
HIGHCVE-2021-43172
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating ... Read more
Affected Products : routinator- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-43171
Improper verification of applications' cryptographic signatures in the /e/OS app store client App Lounge before 0.19q allows attackers in control of the application server to install malicious applications on user's systems by altering the server's API re... Read more
Affected Products : app_lounge- Published: Aug. 22, 2023
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-43164
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless.... Read more
- Published: May. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43163
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the checkNet function in /cgi-bin/luci/api/auth.... Read more
- Published: May. 04, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-43162
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the runPackDiagnose function in /cgi-bin/luci/api/diagnose.... Read more
- Published: May. 04, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-43161
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the doSwitchApi function in /cgi-bin/luci/api/switch.... Read more
- Published: May. 04, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-43160
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the switchFastDhcp function in /cgi-bin/luci/api/diagnose.... Read more
- Published: May. 04, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-43159
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the setSessionTime function in /cgi-bin/luci/api/common..... Read more
- Published: May. 04, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-43158
In ProjectWorlds Online Shopping System PHP 1.0, a CSRF vulnerability in cart_remove.php allows a remote attacker to remove any product in the customer's cart.... Read more
Affected Products : online_shopping_system_in_php- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43157
Projectsworlds Online Shopping System PHP 1.0 is vulnerable to SQL injection via the id parameter in cart_remove.php.... Read more
Affected Products : online_shopping_system_in_php- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-43156
In ProjectWorlds Online Book Store PHP 1.0 a CSRF vulnerability in admin_delete.php allows a remote attacker to delete any book.... Read more
Affected Products : online_book_store_project_in_php- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43155
Projectsworlds Online Book Store PHP v1.0 is vulnerable to SQL injection via the "bookisbn" parameter in cart.php.... Read more
Affected Products : online_book_store_project_in_php- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-43154
Cross Site Scripting (XSS) vulnerability exists in CMS Made Simple 2.2.15 via the Name field in an Add Category action in moduleinterface.php.... Read more
Affected Products : cms_made_simple- Published: Apr. 13, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-43145
With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user accounts.... Read more
Affected Products : zammad- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43142
An XML External Entity (XXE) vulnerability exists in wuta jox 1.16 in the readObject method in JOXSAXBeanInput.... Read more
Affected Products : jox- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-43138
In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution.... Read more
- Published: Apr. 06, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-43137
Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover.... Read more
Affected Products : hostel_management_system- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43136
An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.... Read more
Affected Products : formalms- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-43130
An SQL Injection vulnerability exists in Sourcecodester Customer Relationship Management System (CRM) 1.0 via the username parameter in customer/login.php.... Read more
Affected Products : customer_relationship_management_system- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-43129
A bypass exists for Desire2Learn/D2L Brightspace’s “Disable Right Click” option in the quizzing feature, which allows a quiz-taker to access print and copy functionality via the browser’s right click menu even when “Disable Right Click” is enabled on the ... Read more
Affected Products : brightspace- Published: Apr. 19, 2022
- Modified: Nov. 21, 2024