Latest CVE Feed
-
9.8
CRITICALCVE-2021-41472
SQL injection vulnerability in Sourcecodester Simple Membership System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password parameters.... Read more
Affected Products : simple_membership_system_using_php_and_ajax- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41471
SQL injection vulnerability in Sourcecodester South Gate Inn Online Reservation System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the email and Password parameters.... Read more
Affected Products : south_gate_inn_online_reservation_system- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41467
Cross-site scripting (XSS) vulnerability in application/controllers/dropbox.php in JustWriting 1.0.0 and below allow remote attackers to inject arbitrary web script or HTML via the challenge parameter.... Read more
Affected Products : justwriting- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41465
Cross-site scripting (XSS) vulnerability in concrete/elements/collection_theme.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the rel parameter.... Read more
Affected Products : concrete5-legacy- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41464
Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the rel parameter.... Read more
Affected Products : concrete5-legacy- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41463
Cross-site scripting (XSS) vulnerability in toos/permissions/dialogs/access/entity/types/group_combination.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the cID parameter.... Read more
Affected Products : concrete5-legacy- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41462
Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the ctID parameter.... Read more
Affected Products : concrete5-legacy- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41461
Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the mode parameter.... Read more
Affected Products : concrete5-legacy- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41460
ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.... Read more
Affected Products : ecshop- Published: Jun. 28, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41459
There is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1008 in the nhmldmx_send_sample() function szXmlFrom parameter which leads to a denial of service vulnerability.... Read more
Affected Products : mp4box- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-41458
In GPAC MP4Box v1.1.0, there is a stack buffer overflow at src/utils/error.c:1769 which leads to a denial of service vulnerability.... Read more
Affected Products : mp4box- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41457
There is a stack buffer overflow in MP4Box 1.1.0 at src/filters/dmx_nhml.c in nhmldmx_init_parsing which leads to a denial of service vulnerability.... Read more
Affected Products : mp4box- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41456
There is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1004 in the nhmldmx_send_sample() function szXmlTo parameter which leads to a denial of service vulnerability.... Read more
Affected Products : mp4box- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41451
A misconfiguration in HTTP/1.0 and HTTP/1.1 of the web interface in TP-Link AX10v1 before V1_211117 allows a remote unauthenticated attacker to send a specially crafted HTTP request and receive a misconfigured HTTP/0.9 response, potentially leading into a... Read more
- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41450
An HTTP request smuggling attack in TP-Link AX10v1 before v1_211117 allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.... Read more
- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-41449
A path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote unauthenticated attacker to gain access to sensitive restricted information, such as forbidden files of the web application, via sendin... Read more
- Published: Dec. 09, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41445
A reflected cross-site-scripting attack in web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to execute code in the device of the victim via sending a specific URL to the unauthenticated victim.... Read more
- Published: Feb. 10, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41442
An HTTP smuggling attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.... Read more
- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2021-41441
A DoS attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to reboot the router via sending a specially crafted URL to an authenticated victim. The authenticated victim need to visit this URL, f... Read more
- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-41436
An HTTP request smuggling in web application in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gamin... Read more
Affected Products : rt-ax82u_firmware rt-ax55_firmware rt-ax56u_v2_firmware rt-ax88u_firmware zenwifi_ax_\(xt8\)_firmware rt-ax3000_firmware rt-ax56u_firmware rt-ax58u_firmware rt-ax68u_firmware rt-ax86u_firmware +26 more products- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024