Latest CVE Feed
-
6.1
MEDIUMCVE-2021-42245
FlatCore-CMS 2.0.9 has a cross-site scripting (XSS) vulnerability in pages.edit.php through meta tags and content sections.... Read more
Affected Products : flatcore-cms- Published: Jun. 06, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-42244
A cross-site scripting (XSS) vulnerability in PaquitoSoftware Notimoo v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted title or message in a notification.... Read more
Affected Products : notimoo- Published: Feb. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42242
A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor.... Read more
Affected Products : jfinal_cms- Published: May. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42235
SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality.... Read more
Affected Products : osticket- Published: May. 04, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-42233
The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability. When any user opens a particular blog hosted on an attackers' site, XSS may occur.... Read more
- Published: May. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42232
TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the program taking part of the received data packet as part of the command. This will cause an attacker to execute ... Read more
- Published: Aug. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42230
Seowon 130-SLC router all versions as of 2021-09-15 is vulnerable to Remote Code Execution via the queriesCnt parameter.... Read more
- Published: Apr. 15, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-42228
A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.html.... Read more
- Published: Oct. 14, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-42227
Cross SIte Scripting (XSS) vulnerability exists in KindEditor 4.1.x via a Google search inurl:/examples/uploadbutton.html and then the .html file on the website that uses this editor (the file suffix is allowed).... Read more
- Published: Oct. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42224
SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php.... Read more
- Published: Oct. 13, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-42223
Cross Site Scripting (XSS).vulnerability exists in Online DJ Booking Management System 1.0 in view-booking-detail.php.... Read more
- Published: Oct. 13, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-42220
A Cross Site Scripting (XSS) vulnerability exists in Dolibarr before 14.0.3 via the ticket creation flow. Exploitation requires that an admin copies the payload into a box.... Read more
- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-42219
Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is caused by missing memory in the component /ethash/algorithm.go.... Read more
Affected Products : go_ethereum- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-42218
OMPL v1.5.2 contains a memory leak in VFRRT.cpp... Read more
Affected Products : open_motion_planning_library- Published: May. 03, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42216
A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.... Read more
Affected Products : anonaddy- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42204
An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetBits() located in rfxswf.c. It allows an attacker to cause code execution.... Read more
Affected Products : swftools- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42203
An issue was discovered in swftools through 20201222. A heap-use-after-free exists in the function swf_FontExtract_DefineTextCallback() located in swftext.c. It allows an attacker to cause code execution.... Read more
Affected Products : swftools- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-42202
An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function swf_DeleteFilter() located in swffilter.c. It allows an attacker to cause Denial of Service.... Read more
Affected Products : swftools- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42201
An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetD64() located in rfxswf.c. It allows an attacker to cause code execution.... Read more
Affected Products : swftools- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-42200
An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function main() located in swfdump.c. It allows an attacker to cause Denial of Service.... Read more
Affected Products : swftools- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024