Latest CVE Feed
-
7.5
HIGHCVE-2021-37819
PDF Labs pdftk-java v3.2.3 was discovered to contain an infinite loop via the component /text/pdf/PdfReader.java.... Read more
Affected Products : pdftk-java- EPSS Score: %0.11
- Published: Sep. 09, 2022
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-37808
SQL Injection vulnerabilities exist in https://phpgurukul.com News Portal Project 3.1 via the (1) category, (2) subcategory, (3) sucatdescription, and (4) username parameters, the server response is about (N) seconds delay respectively which mean it is vu... Read more
- EPSS Score: %0.40
- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-37807
An SQL Injection vulneraility exists in https://phpgurukul.com Online Shopping Portal 3.1 via the email parameter on the /check_availability.php endpoint that serves as a checker whether a new user's email is already exist within the database.... Read more
- EPSS Score: %0.25
- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-37806
An SQL Injection vulnerability exists in https://phpgurukul.com Vehicle Parking Management System affected version 1.0. The system is vulnerable to time-based SQL injection on multiple endpoints. Based on the SLEEP(N) function payload that will sleep for ... Read more
Affected Products : vehicle_parking_management_system- EPSS Score: %0.40
- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37805
A Stored Cross Site Scripting (XSS) vunerability exists in Sourcecodeste Vehicle Parking Management System affected version 1.0 is via the add-vehicle.php endpoint.... Read more
Affected Products : vehicle_parking_management_system- EPSS Score: %0.18
- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-37803
An SQL Injection vulnerability exists in Sourcecodester Online Covid Vaccination Scheduler System 1.0 via the username in lognin.php .... Read more
Affected Products : online_covid_vaccination_scheduler_system- EPSS Score: %0.32
- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37794
A stored cross-site scripting (XSS) vulnerability exists in FileBrowser < v2.16.0 that allows an authenticated user authorized to upload a malicious .svg file which acts as a stored XSS payload. If this stored XSS payload is triggered by an administrator ... Read more
Affected Products : filebrowser- EPSS Score: %0.28
- Published: Aug. 31, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-37791
MyAdmin v1.0 is affected by an incorrect access control vulnerability in viewing personal center in /api/user/userData?userCode=admin.... Read more
Affected Products : myadmin- EPSS Score: %0.36
- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37788
A vulnerability in the web UI of Gurock TestRail v5.3.0.3603 could allow an unauthenticated, remote attacker to affect the integrity of a device via a clickjacking attack. The vulnerability is due to insufficient input validation of iFrame data in HTTP re... Read more
Affected Products : testrail- EPSS Score: %0.24
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
4.6
MEDIUMCVE-2021-37786
Certain Federal Office of Information Technology Systems and Telecommunication FOITT products are affected by improper handling of exceptional conditions. This affects COVID Certificate App IOS 2.2.0 and below affected, patch in progress and COVID Certifi... Read more
Affected Products : covid_certificate- EPSS Score: %0.03
- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37778
There is a buffer overflow in gps-sdr-sim v1.0 when parsing long command line parameters, which can lead to DoS or code execution.... Read more
Affected Products : gps-sdr-sim- EPSS Score: %1.21
- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-37777
Gila CMS 2.2.0 is vulnerable to Insecure Direct Object Reference (IDOR). Thumbnails uploaded by one site owner are visible by another site owner just by knowing the other site name and fuzzing for picture names. This leads to sensitive information disclos... Read more
Affected Products : gila_cms- EPSS Score: %0.36
- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-37770
Nucleus CMS v3.71 is affected by a file upload vulnerability. In this vulnerability, we can use upload to change the upload path to the path without the Htaccess file. Upload an Htaccess file and write it to AddType application / x-httpd-php.jpg. In this ... Read more
Affected Products : nucleus_cms- EPSS Score: %1.02
- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-37764
Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /shop/admin/manufacturers.php.... Read more
Affected Products : xos_shop_system- EPSS Score: %0.13
- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37762
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution.... Read more
Affected Products : manageengine_admanager_plus- EPSS Score: %37.38
- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37761
Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution.... Read more
Affected Products : manageengine_admanager_plus- EPSS Score: %37.38
- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37760
A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).... Read more
Affected Products : graylog- EPSS Score: %0.50
- Published: Jul. 31, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37759
A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).... Read more
Affected Products : graylog- EPSS Score: %0.50
- Published: Jul. 31, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-37750
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/do_tgs_req.c via a FAST inner body that lacks a server field.... Read more
- EPSS Score: %0.45
- Published: Aug. 23, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-37749
MapService.svc in Hexagon GeoMedia WebMap 2020 before Update 2 (aka 16.6.2.66) allows blind SQL Injection via the Id (within sourceItems) parameter to the GetMap method.... Read more
Affected Products : geomedia_webmap- EPSS Score: %0.92
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024