Latest CVE Feed
-
7.5
HIGHCVE-2021-40325
Cobbler before 3.3.0 allows authorization bypass for modification of settings.... Read more
- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-40324
Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.... Read more
- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40323
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.... Read more
- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-40317
Piwigo 11.5.0 is affected by a SQL injection vulnerability via admin.php and the id parameter.... Read more
Affected Products : piwigo- Published: May. 26, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-40313
Piwigo v11.5 was discovered to contain a SQL injection vulnerability via the parameter pwg_token in /admin/batch_manager_global.php.... Read more
Affected Products : piwigo- Published: Dec. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-40310
OpenSIS Community Edition version 8.0 is affected by a cross-site scripting (XSS) vulnerability in the TakeAttendance.php via the cp_id_miss_attn parameter.... Read more
Affected Products : opensis- Published: Sep. 24, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-40309
A SQL injection vulnerability exists in the Take Attendance functionality of OS4Ed's OpenSIS 8.0. allows an attacker to inject their own SQL query. The cp_id_miss_attn parameter from TakeAttendance.php is vulnerable to SQL injection. An attacker can make ... Read more
Affected Products : opensis- Published: Sep. 24, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-40292
A Stored Cross Site Sripting (XSS) vulnerability exists in DzzOffice 2.02.1 via the settingnew parameter.... Read more
Affected Products : dzzoffice- Published: Oct. 12, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-40288
A denial-of-service attack in WPA2, and WPA3-SAE authentication methods in TP-Link AX10v1 before V1_211014, allows a remote unauthenticated attacker to disconnect an already connected wireless client via sending with a wireless adapter specific spoofed au... Read more
- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-40285
htmly v2.8.1 was discovered to contain an arbitrary file deletion vulnerability via the component \views\backup.html.php.... Read more
Affected Products : htmly- Published: Aug. 26, 2022
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-40284
D-Link DSL-3782 EU v1.01:EU v1.03 is affected by a buffer overflow which can cause a denial of service. This vulnerability exists in the web interface "/cgi-bin/New_GUI/Igmp.asp". Authenticated remote attackers can trigger this vulnerability by sending a ... Read more
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-40282
An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, abd 2021 in dl/dl_download.php. when registering ordinary users.... Read more
Affected Products : zzcms- Published: Dec. 09, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-40281
An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 in dl/dl_print.php when registering ordinary users.... Read more
Affected Products : zzcms- Published: Dec. 09, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-40280
An SQL Injection vulnerablitly exits in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/dl_sendmail.php.... Read more
Affected Products : zzcms- Published: Dec. 09, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-40279
An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/bad.php.... Read more
Affected Products : zzcms- Published: Dec. 09, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-40266
FreeImage before 1.18.0, ReadPalette function in PluginTIFF.cpp is vulnerabile to null pointer dereference.... Read more
Affected Products : freeimage- Published: Aug. 22, 2023
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-40265
A heap overflow bug exists FreeImage before 1.18.0 via ofLoad function in PluginJPEG.cpp.... Read more
Affected Products : freeimage- Published: Aug. 22, 2023
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-40264
NULL pointer dereference vulnerability in FreeImage before 1.18.0 via the FreeImage_CloneTag function inFreeImageTag.cpp.... Read more
Affected Products : freeimage- Published: Aug. 22, 2023
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-40263
A heap overflow vulnerability in FreeImage 1.18.0 via the ofLoad function in PluginTIFF.cpp.... Read more
Affected Products : freeimage- Published: Aug. 22, 2023
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-40262
A stack exhaustion issue was discovered in FreeImage before 1.18.0 via the Validate function in PluginRAW.cpp.... Read more
Affected Products : freeimage- Published: Aug. 22, 2023
- Modified: Nov. 21, 2024