Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.1

    MEDIUM
    CVE-2021-40928

    Cross-site scripting (XSS) vulnerability in index.php in FlexTV beta development version allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF parameter.... Read more

    Affected Products : flextv
    • Published: Oct. 01, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-40927

    Cross-site scripting (XSS) vulnerability in callback.php in Spotify-for-Alfred 0.13.9 and below allows remote attackers to inject arbitrary web script or HTML via the error parameter.... Read more

    Affected Products : alfred_spotify_mini_player
    • Published: Oct. 01, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-40926

    Cross-site scripting (XSS) vulnerability in demos/demo.mysqli.php in getID3 1.X and v2.0.0-beta allows remote attackers to inject arbitrary web script or HTML via the showtagfiles parameter.... Read more

    Affected Products : getid3
    • Published: Oct. 01, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-40925

    Cross-site scripting (XSS) vulnerability in dompdf/dompdf/www/demo.php infaveo-helpdesk v1.11.0 and below allow remote attackers to inject arbitrary web script or HTML via the $_SERVER["PHP_SELF"] parameter.... Read more

    Affected Products : faveo
    • Published: Oct. 01, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-40924

    Cross-site scripting (XSS) vulnerability in install/index.php in bugs 1.8 and below version allows remote attackers to inject arbitrary web script or HTML via the first_name parameter.... Read more

    Affected Products : bugs
    • Published: Oct. 01, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-40923

    Cross-site scripting (XSS) vulnerability in install/index.php in bugs 1.8 and below version allows remote attackers to inject arbitrary web script or HTML via the email parameter.... Read more

    Affected Products : bugs
    • Published: Oct. 01, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-40922

    Cross-site scripting (XSS) vulnerability in install/index.php in bugs 1.8 and below version allows remote attackers to inject arbitrary web script or HTML via the last_name parameter.... Read more

    Affected Products : bugs
    • Published: Oct. 01, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-40921

    Cross-site scripting (XSS) vulnerability in _contactform.inc.php in Detector 0.8.5 and below version allows remote attackers to inject arbitrary web script or HTML via the cid parameter.... Read more

    Affected Products : detector
    • Published: Oct. 01, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-40910

    There is a reflective cross-site scripting (XSS) vulnerability in the PHPCMS V9.6.3 management side.... Read more

    Affected Products : phpcms
    • Published: Jun. 15, 2022
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2021-40909

    Cross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using Ajax and DataTables Tutorial v1 by oretnom23, allows remote attackers to execute arbitrary code via the first_name, last_name, and email parameters to /ajax_c... Read more

    • Published: Jan. 24, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-40908

    SQL injection vulnerability in Login.php in Sourcecodester Purchase Order Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter.... Read more

    Affected Products : purchase_order_management_system
    • Published: Jan. 24, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-40907

    SQL injection vulnerability in Sourcecodester Storage Unit Rental Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter to /storage/classes/Login.php.... Read more

    • Published: Jan. 24, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-40906

    CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device with HTML content and interpreted by t... Read more

    Affected Products : checkmk checkmk
    • Published: Mar. 25, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-40905

    The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making remote code execution possible. Successful exploitation requires access to ... Read more

    Affected Products : checkmk checkmk
    • Published: Mar. 25, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-40904

    The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code. As a result, remote code execution is achieved. Successful exploitation r... Read more

    Affected Products : checkmk checkmk
    • Published: Mar. 25, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-40903

    A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a predefined secret string, which would be randomly generated, however it is static.... Read more

    Affected Products : antminer_monitor
    • Published: Jun. 17, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-40902

    flatCore-CMS version 2.0.8 is affected by Cross Site Scripting (XSS) in the "Create New Page" option through the index page.... Read more

    Affected Products : flatcore-cms
    • Published: Jun. 13, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-40901

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scniro-validator v1.0.1 when validating crafted invalid emails.... Read more

    Affected Products : scniro-validator
    • Published: Jun. 27, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-40900

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in regexfn v1.0.5 when validating crafted invalid emails.... Read more

    Affected Products : regexfn
    • Published: Jun. 27, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-40899

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in repo-git-downloader v0.1.1 when downloading crafted invalid git repositories.... Read more

    Affected Products : repo-git-downloader
    • Published: Jun. 27, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 293344 Results