Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2021-43136

    An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.... Read more

    Affected Products : formalms
    • Published: Nov. 10, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2021-43130

    An SQL Injection vulnerability exists in Sourcecodester Customer Relationship Management System (CRM) 1.0 via the username parameter in customer/login.php.... Read more

    • Published: Nov. 03, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-43129

    A bypass exists for Desire2Learn/D2L Brightspace’s “Disable Right Click” option in the quizzing feature, which allows a quiz-taker to access print and copy functionality via the browser’s right click menu even when “Disable Right Click” is enabled on the ... Read more

    Affected Products : brightspace
    • Published: Apr. 19, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-43118

    A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a crafted HTTP message containing malformed QUERY STRING in mainfunction.cgi, which could let a remote malicious ... Read more

    • Published: Mar. 29, 2022
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2021-43117

    fastadmin v1.2.1 is affected by a file upload vulnerability which allows arbitrary code execution through shell access.... Read more

    Affected Products : fastadmin
    • Published: Dec. 13, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-43116

    An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login.... Read more

    Affected Products : nacos
    • Published: Jul. 05, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-43114

    FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectively disabling Route Origin Validation.... Read more

    Affected Products : debian_linux fort_validator
    • Published: Nov. 09, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-43113

    iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.... Read more

    Affected Products : debian_linux itext
    • Published: Dec. 15, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-43110

    An Access Conrol vulnerability exists in PuneethReddyHC online-shopping-system as of 11/01/2021 in add_products.... Read more

    • Published: Mar. 29, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-43109

    An SQL Injection vulnerability exits in PuneethReddyHC online-shopping-system as of 11/01/2021 via the p parameter in product.php.... Read more

    • Published: Mar. 29, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-43106

    A Header Injection vulnerability exists in Compass Plus TranzWare Online FIMI Web Interface Tranzware Online (TWO) 5.3.33.3 F38 and FIMI 4.2.19.4 25.The HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any change... Read more

    • Published: Feb. 14, 2022
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2021-43105

    A vulnerability in the bailiwick checking function in Technitium DNS Server <= v7.0 exists that allows specific malicious users to inject `NS` records of any domain (even TLDs) into the cache and conduct a DNS cache poisoning attack.... Read more

    Affected Products : dns_server
    • Published: Mar. 28, 2022
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-43103

    A File Upload vulnerability exists in bbs 5.3 is via ForumManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.... Read more

    Affected Products : bbs
    • Published: Mar. 28, 2022
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-43102

    A File Upload vulnerability exists in bbs 5.3 is via HelpManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.... Read more

    Affected Products : bbs
    • Published: Mar. 28, 2022
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-43101

    A File Upload vulnerability exists in bbs 5.3 is via MembershipCardManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.... Read more

    Affected Products : bbs
    • Published: Mar. 28, 2022
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-43100

    A File Upload vulnerability exists in bbs 5.3 is via TopicManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.... Read more

    Affected Products : bbs
    • Published: Mar. 28, 2022
    • Modified: Nov. 21, 2024
  • 4.9

    MEDIUM
    CVE-2021-43099

    An Archive Extraction (AKA "Zip Slip) vulnerability exists in bbs 5.3 in the UpgradeNow function in UpgradeManageAction.java, which unzips the arbitrary upladed zip file without checking filenames. The vulnerability is exploited using a specially crafted ... Read more

    Affected Products : bbs
    • Published: Mar. 28, 2022
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-43098

    A File Upload vulnerability exists in bbs v5.3 via QuestionManageAction.java in a getType function.... Read more

    Affected Products : bbs
    • Published: Mar. 28, 2022
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-43097

    A Server-side Template Injection (SSTI) vulnerability exists in bbs 5.3 in TemplateManageAction.javawhich could let a malicoius user execute arbitrary code.... Read more

    Affected Products : bbs
    • Published: Mar. 28, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-43094

    An SQL Injection vulnerability exists in OpenMRS Reference Application Standalone Edition <=2.11 and Platform Standalone Edition <=2.4.0 via GET requests on arbitrary parameters in patient.page.... Read more

    Affected Products : reference_application openmrs
    • Published: May. 10, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 293594 Results