Latest CVE Feed
-
8.0
HIGHCVE-2021-41503
DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices command interface allows attack vectors that may compromise the cameras configuration and allow malicious users on th... Read more
- Published: Sep. 24, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-41502
An issue was discovered in Subrion CMS v4.2.1 There is a stored cross-site scripting (XSS) vulnerability that can execute malicious JavaScript code by modifying the name of the uploaded image, closing the html tag, or adding the onerror attribute.... Read more
- Published: Jun. 11, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41500
Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denial of Service attacks by construct f... Read more
- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41499
Buffer Overflow Vulnerability exists in ajaxsoundstudio.com n Pyo < 1.03 in the Server_debug function, which allows remote attackers to conduct DoS attacks by deliberately passing on an overlong audio file name.... Read more
Affected Products : pyo- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41498
Buffer overflow in ajaxsoundstudio.com Pyo < and 1.03 in the Server_jack_init function. which allows attackers to conduct Denial of Service attacks by arbitrary constructing a overlong server name.... Read more
Affected Products : pyo- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41497
Null pointer reference in CMS_Conservative_increment_obj in RaRe-Technologies bounter version 1.01 and 1.10, allows attackers to conduct Denial of Service attacks by inputting a huge width of hash bucket.... Read more
Affected Products : bounter- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-41496
Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19, which allows attackers to conduct a Denial of Service attacks by carefully constructing an array with negative values. NOTE: The vendor does not agree this is a vulnerabi... Read more
Affected Products : numpy- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-41495
Null Pointer Dereference vulnerability exists in numpy.sort in NumPy < and 1.19 in the PyArray_DescrNew function due to missing return-value validation, which allows attackers to conduct DoS attacks by repetitively creating sort arrays. NOTE: While corr... Read more
Affected Products : numpy- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41492
Multiple SQL Injection vulnerabilities exist in Sourcecodester Simple Cashiering System (POS) 1.0 via the (1) Product Code in the pos page in cashiering. (2) id parameter in manage_products and the (3) t paramater in actions.php.... Read more
Affected Products : simple_cashiering_system- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41490
Memory leaks in LazyPRM.cpp of OMPL v1.5.0 can cause unexpected behavior.... Read more
Affected Products : open_motion_planning_library- Published: Jun. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41487
NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.... Read more
Affected Products : vitalsuite- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41472
SQL injection vulnerability in Sourcecodester Simple Membership System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password parameters.... Read more
Affected Products : simple_membership_system_using_php_and_ajax- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41471
SQL injection vulnerability in Sourcecodester South Gate Inn Online Reservation System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the email and Password parameters.... Read more
Affected Products : south_gate_inn_online_reservation_system- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41467
Cross-site scripting (XSS) vulnerability in application/controllers/dropbox.php in JustWriting 1.0.0 and below allow remote attackers to inject arbitrary web script or HTML via the challenge parameter.... Read more
Affected Products : justwriting- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41465
Cross-site scripting (XSS) vulnerability in concrete/elements/collection_theme.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the rel parameter.... Read more
Affected Products : concrete5-legacy- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41464
Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the rel parameter.... Read more
Affected Products : concrete5-legacy- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41463
Cross-site scripting (XSS) vulnerability in toos/permissions/dialogs/access/entity/types/group_combination.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the cID parameter.... Read more
Affected Products : concrete5-legacy- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41462
Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the ctID parameter.... Read more
Affected Products : concrete5-legacy- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41461
Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the mode parameter.... Read more
Affected Products : concrete5-legacy- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41460
ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.... Read more
Affected Products : ecshop- Published: Jun. 28, 2022
- Modified: Nov. 21, 2024