Latest CVE Feed
-
9.8
CRITICALCVE-2021-40612
An issue was discovered in Opmantek Open-AudIT after 3.5.0. Without authentication, a vulnerability in code_igniter/application/controllers/util.php allows an attacker perform command execution without echoes.... Read more
Affected Products : open-audit- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-40610
Emlog Pro v 1.0.4 cross-site scripting (XSS) in Emlog Pro background management.... Read more
Affected Products : emlog_pro- Published: Jun. 09, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-40609
The GetHintFormat function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.... Read more
Affected Products : gpac- Published: Jun. 28, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-40608
The gf_hinter_track_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.... Read more
Affected Products : gpac- Published: Jun. 28, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-40607
The schm_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.... Read more
Affected Products : gpac- Published: Jun. 28, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-40606
The gf_bs_write_data function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.... Read more
Affected Products : gpac- Published: Jun. 28, 2022
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-40604
A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbitrary URLs or trigger deserialization via phar protocol when generating class names dynamically. In some cases an explo... Read more
Affected Products : ips_community_suite- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-40597
The firmware of EDIMAX IC-3140W Version 3.11 is hardcoded with Administrator username and password.... Read more
- Published: Jun. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40595
SQL injection vulnerability in Sourcecodester Online Leave Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter to /leave_system/classes/Login.php.... Read more
Affected Products : online_leave_management_system- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-40592
GPAC version before commit 71460d72ec07df766dab0a4d52687529f3efcf0a (version v1.0.1 onwards) contains loop with unreachable exit condition ('infinite loop') vulnerability in ISOBMFF reader filter, isoffin_read.c. Function isoffin_process() can result in D... Read more
Affected Products : gpac- Published: Jun. 08, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40589
ZAngband zangband-data 2.7.5 is affected by an integer underflow vulnerability in src/tk/plat.c through the variable fileheader.bfOffBits.... Read more
Affected Products : zangband-data- Published: Jun. 08, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-40579
https://www.sourcecodester.com/ Online Enrollment Management System in PHP and PayPal Free Source Code 1.0 is affected by: Incorrect Access Control. The impact is: gain privileges (remote).... Read more
Affected Products : online_enrollment_management_system- Published: Dec. 28, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-40578
Authenticated Blind & Error-based SQL injection vulnerability was discovered in Online Enrollment Management System in PHP and PayPal Free Source Code 1.0, that allows attackers to obtain sensitive information and execute arbitrary SQL commands via IDNO p... Read more
Affected Products : online_enrollment_management_system- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-40577
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP and PayPal Free Source Code 1.0 in the Add-Users page via the Name parameter.... Read more
Affected Products : online_enrollment_management_system- Published: Nov. 08, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-40576
The binary MP4Box in Gpac 1.0.1 has a null pointer dereference vulnerability in the gf_isom_get_payt_count function in hint_track.c, which allows attackers to cause a denial of service.... Read more
Affected Products : gpac- Published: Jan. 13, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-40575
The binary MP4Box in Gpac 1.0.1 has a null pointer dereference vulnerability in the mpgviddmx_process function in reframe_mpgvid.c, which allows attackers to cause a denial of service. This vulnerability is possibly due to an incomplete fix for CVE-2021-4... Read more
Affected Products : gpac- Published: Jan. 13, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-40573
The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the gf_list_del function in list.c, which allows attackers to cause a denial of service.... Read more
Affected Products : gpac- Published: Jan. 13, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-40572
The binary MP4Box in Gpac 1.0.1 has a double-free bug in the av1dmx_finalize function in reframe_av1.c, which allows attackers to cause a denial of service.... Read more
Affected Products : gpac- Published: Jan. 13, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-40571
The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the ilst_box_read function in box_code_apple.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.... Read more
Affected Products : gpac- Published: Jan. 13, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-40570
The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the avc_compute_poc function in av_parsers.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.... Read more
Affected Products : gpac- Published: Jan. 13, 2022
- Modified: Nov. 21, 2024