Latest CVE Feed
-
9.8
CRITICALCVE-2021-40960
Galera WebTemplate 1.0 is affected by a directory traversal vulnerability that could reveal information from /etc/passwd and /etc/shadow.... Read more
Affected Products : galera_webtemplate- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-40956
LaiKetui v3.5.0 has SQL injection in the background through the menu management function, and sensitive data can be obtained.... Read more
Affected Products : laiketui- Published: Jun. 23, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-40955
SQL injection exists in LaiKetui v3.5.0 the background administrator list.... Read more
Affected Products : laiketui- Published: Jun. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40954
Laiketui 3.5.0 is affected by an arbitrary file upload vulnerability that can allow an attacker to execute arbitrary code.... Read more
Affected Products : laiketui- Published: Jun. 23, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-40944
In GPAC MP4Box 1.1.0, there is a Null pointer reference in the function gf_filter_pid_get_packet function in src/filter_core/filter_pid.c:5394, as demonstrated by GPAC. This can cause a denial of service (DOS).... Read more
Affected Products : gpac- Published: Jun. 28, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-40943
In Bento4 1.6.0-638, there is a null pointer reference in the function AP4_DescriptorListInspector::Action function in Ap4Descriptor.h:124 , as demonstrated by GPAC. This can cause a denial of service (DOS).... Read more
Affected Products : bento4- Published: Jun. 28, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-40942
In GPAC MP4Box v1.1.0, there is a heap-buffer-overflow in the function filter_parse_dyn_args function in filter_core/filter.c:1454, as demonstrated by GPAC. This can cause a denial of service (DOS).... Read more
Affected Products : gpac- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-40941
In Bento4 1.6.0-638, there is an allocator is out of memory in the function AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity in Ap4Array.h:172, as demonstrated by GPAC. This can cause a denial of service (DOS).... Read more
Affected Products : bento4- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40940
Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.... Read more
Affected Products : monstra- Published: Jun. 15, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-40928
Cross-site scripting (XSS) vulnerability in index.php in FlexTV beta development version allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF parameter.... Read more
Affected Products : flextv- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-40927
Cross-site scripting (XSS) vulnerability in callback.php in Spotify-for-Alfred 0.13.9 and below allows remote attackers to inject arbitrary web script or HTML via the error parameter.... Read more
Affected Products : alfred_spotify_mini_player- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-40926
Cross-site scripting (XSS) vulnerability in demos/demo.mysqli.php in getID3 1.X and v2.0.0-beta allows remote attackers to inject arbitrary web script or HTML via the showtagfiles parameter.... Read more
Affected Products : getid3- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-40925
Cross-site scripting (XSS) vulnerability in dompdf/dompdf/www/demo.php infaveo-helpdesk v1.11.0 and below allow remote attackers to inject arbitrary web script or HTML via the $_SERVER["PHP_SELF"] parameter.... Read more
Affected Products : faveo- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-40924
Cross-site scripting (XSS) vulnerability in install/index.php in bugs 1.8 and below version allows remote attackers to inject arbitrary web script or HTML via the first_name parameter.... Read more
Affected Products : bugs- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-40923
Cross-site scripting (XSS) vulnerability in install/index.php in bugs 1.8 and below version allows remote attackers to inject arbitrary web script or HTML via the email parameter.... Read more
Affected Products : bugs- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-40922
Cross-site scripting (XSS) vulnerability in install/index.php in bugs 1.8 and below version allows remote attackers to inject arbitrary web script or HTML via the last_name parameter.... Read more
Affected Products : bugs- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-40921
Cross-site scripting (XSS) vulnerability in _contactform.inc.php in Detector 0.8.5 and below version allows remote attackers to inject arbitrary web script or HTML via the cid parameter.... Read more
Affected Products : detector- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-40910
There is a reflective cross-site scripting (XSS) vulnerability in the PHPCMS V9.6.3 management side.... Read more
Affected Products : phpcms- Published: Jun. 15, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-40909
Cross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using Ajax and DataTables Tutorial v1 by oretnom23, allows remote attackers to execute arbitrary code via the first_name, last_name, and email parameters to /ajax_c... Read more
Affected Products : php_crud_without_refresh\/reload_using_ajax_and_datatables_tutorial- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40908
SQL injection vulnerability in Login.php in Sourcecodester Purchase Order Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter.... Read more
Affected Products : purchase_order_management_system- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024