Latest CVE Feed
-
6.1
MEDIUMCVE-2021-43154
Cross Site Scripting (XSS) vulnerability exists in CMS Made Simple 2.2.15 via the Name field in an Add Category action in moduleinterface.php.... Read more
Affected Products : cms_made_simple- Published: Apr. 13, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-43145
With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user accounts.... Read more
Affected Products : zammad- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43142
An XML External Entity (XXE) vulnerability exists in wuta jox 1.16 in the readObject method in JOXSAXBeanInput.... Read more
Affected Products : jox- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-43138
In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution.... Read more
- Published: Apr. 06, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-43137
Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover.... Read more
Affected Products : hostel_management_system- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43136
An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.... Read more
Affected Products : formalms- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-43130
An SQL Injection vulnerability exists in Sourcecodester Customer Relationship Management System (CRM) 1.0 via the username parameter in customer/login.php.... Read more
Affected Products : customer_relationship_management_system- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-43129
A bypass exists for Desire2Learn/D2L Brightspace’s “Disable Right Click” option in the quizzing feature, which allows a quiz-taker to access print and copy functionality via the browser’s right click menu even when “Disable Right Click” is enabled on the ... Read more
Affected Products : brightspace- Published: Apr. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43118
A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a crafted HTTP message containing malformed QUERY STRING in mainfunction.cgi, which could let a remote malicious ... Read more
Affected Products : vigor2960_firmware vigor300b_firmware vigor3900_firmware vigor2960 vigor300b vigor3900- Published: Mar. 29, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-43117
fastadmin v1.2.1 is affected by a file upload vulnerability which allows arbitrary code execution through shell access.... Read more
Affected Products : fastadmin- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-43116
An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login.... Read more
Affected Products : nacos- Published: Jul. 05, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-43114
FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectively disabling Route Origin Validation.... Read more
- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43113
iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.... Read more
- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43110
An Access Conrol vulnerability exists in PuneethReddyHC online-shopping-system as of 11/01/2021 in add_products.... Read more
Affected Products : puneethreddyhc_online-shopping-system- Published: Mar. 29, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-43109
An SQL Injection vulnerability exits in PuneethReddyHC online-shopping-system as of 11/01/2021 via the p parameter in product.php.... Read more
Affected Products : puneethreddyhc_online-shopping-system- Published: Mar. 29, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-43106
A Header Injection vulnerability exists in Compass Plus TranzWare Online FIMI Web Interface Tranzware Online (TWO) 5.3.33.3 F38 and FIMI 4.2.19.4 25.The HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any change... Read more
- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-43105
A vulnerability in the bailiwick checking function in Technitium DNS Server <= v7.0 exists that allows specific malicious users to inject `NS` records of any domain (even TLDs) into the cache and conduct a DNS cache poisoning attack.... Read more
Affected Products : dns_server- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-43103
A File Upload vulnerability exists in bbs 5.3 is via ForumManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.... Read more
Affected Products : bbs- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-43102
A File Upload vulnerability exists in bbs 5.3 is via HelpManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.... Read more
Affected Products : bbs- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-43101
A File Upload vulnerability exists in bbs 5.3 is via MembershipCardManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.... Read more
Affected Products : bbs- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024