Latest CVE Feed
-
9.8
CRITICALCVE-2021-41492
Multiple SQL Injection vulnerabilities exist in Sourcecodester Simple Cashiering System (POS) 1.0 via the (1) Product Code in the pos page in cashiering. (2) id parameter in manage_products and the (3) t paramater in actions.php.... Read more
Affected Products : simple_cashiering_system- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41490
Memory leaks in LazyPRM.cpp of OMPL v1.5.0 can cause unexpected behavior.... Read more
Affected Products : open_motion_planning_library- Published: Jun. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41487
NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.... Read more
Affected Products : vitalsuite- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41472
SQL injection vulnerability in Sourcecodester Simple Membership System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password parameters.... Read more
Affected Products : simple_membership_system_using_php_and_ajax- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41471
SQL injection vulnerability in Sourcecodester South Gate Inn Online Reservation System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the email and Password parameters.... Read more
Affected Products : south_gate_inn_online_reservation_system- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41467
Cross-site scripting (XSS) vulnerability in application/controllers/dropbox.php in JustWriting 1.0.0 and below allow remote attackers to inject arbitrary web script or HTML via the challenge parameter.... Read more
Affected Products : justwriting- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41465
Cross-site scripting (XSS) vulnerability in concrete/elements/collection_theme.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the rel parameter.... Read more
Affected Products : concrete5-legacy- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41464
Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the rel parameter.... Read more
Affected Products : concrete5-legacy- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41463
Cross-site scripting (XSS) vulnerability in toos/permissions/dialogs/access/entity/types/group_combination.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the cID parameter.... Read more
Affected Products : concrete5-legacy- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41462
Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the ctID parameter.... Read more
Affected Products : concrete5-legacy- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41461
Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the mode parameter.... Read more
Affected Products : concrete5-legacy- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41460
ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.... Read more
Affected Products : ecshop- Published: Jun. 28, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41459
There is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1008 in the nhmldmx_send_sample() function szXmlFrom parameter which leads to a denial of service vulnerability.... Read more
Affected Products : mp4box- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-41458
In GPAC MP4Box v1.1.0, there is a stack buffer overflow at src/utils/error.c:1769 which leads to a denial of service vulnerability.... Read more
Affected Products : mp4box- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41457
There is a stack buffer overflow in MP4Box 1.1.0 at src/filters/dmx_nhml.c in nhmldmx_init_parsing which leads to a denial of service vulnerability.... Read more
Affected Products : mp4box- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41456
There is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1004 in the nhmldmx_send_sample() function szXmlTo parameter which leads to a denial of service vulnerability.... Read more
Affected Products : mp4box- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41451
A misconfiguration in HTTP/1.0 and HTTP/1.1 of the web interface in TP-Link AX10v1 before V1_211117 allows a remote unauthenticated attacker to send a specially crafted HTTP request and receive a misconfigured HTTP/0.9 response, potentially leading into a... Read more
- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41450
An HTTP request smuggling attack in TP-Link AX10v1 before v1_211117 allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.... Read more
- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-41449
A path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote unauthenticated attacker to gain access to sensitive restricted information, such as forbidden files of the web application, via sendin... Read more
- Published: Dec. 09, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41445
A reflected cross-site-scripting attack in web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to execute code in the device of the victim via sending a specific URL to the unauthenticated victim.... Read more
- Published: Feb. 10, 2022
- Modified: Nov. 21, 2024