Latest CVE Feed
-
6.1
MEDIUMCVE-2021-38756
Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through prescribe.php.... Read more
Affected Products : hospital_management_system- EPSS Score: %0.20
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-38755
Unauthenticated doctor entry deletion in Hospital Management System in admin-panel1.php.... Read more
Affected Products : hospital_management_system- EPSS Score: %0.20
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38754
SQL Injection vulnerability in Hospital Management System due to lack of input validation in messearch.php.... Read more
Affected Products : hospital_management_system- EPSS Score: %0.33
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38753
An unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain unauthorized access to the server hosting the web app.... Read more
Affected Products : simple_image_gallery_web_app- EPSS Score: %0.52
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38752
A cross-site scripting (XSS) vulnerability in Online Catering Reservation System using PHP on Sourcecodester allows an attacker to arbitrarily inject code in the search bar.... Read more
Affected Products : online_catering_reservation_system- EPSS Score: %0.21
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-38751
A HTTP Host header attack exists in ExponentCMS 2.6 and below in /exponent_constants.php. A modified HTTP header can change links on the webpage to an arbitrary value, leading to a possible attack vector for MITM.... Read more
- EPSS Score: %12.88
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-38745
Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a crafted plugin. This vulnerability is triggered through user interaction with the attacker's profile page.... Read more
- EPSS Score: %1.54
- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38727
FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items... Read more
Affected Products : fuel_cms- EPSS Score: %1.24
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-38725
Fuel CMS 1.5.0 has a brute force vulnerability in fuel/modules/fuel/controllers/Login.php... Read more
Affected Products : fuel_cms- EPSS Score: %0.17
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-38723
FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/pages/items... Read more
Affected Products : fuel_cms- EPSS Score: %0.24
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-38721
FUEL CMS 1.5.0 login.php contains a cross-site request forgery (CSRF) vulnerability... Read more
Affected Products : fuel_cms- EPSS Score: %0.19
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-38714
In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file.... Read more
- EPSS Score: %0.18
- Published: Aug. 24, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38713
imgURL 2.31 allows XSS via an X-Forwarded-For HTTP header.... Read more
Affected Products : imgurl- EPSS Score: %0.17
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38712
OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to block the access via an NGINX configuration file.... Read more
- EPSS Score: %0.24
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38711
In gitit before 0.15.0.0, the Export feature can be exploited to leak information from files.... Read more
Affected Products : gitit- EPSS Score: %0.32
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38710
Static (Persistent) XSS Vulnerability exists in version 4.3.0 of Yclas when using the install/view/form.php script. An attacker can store XSS in the database through the vulnerable SITE_NAME parameter.... Read more
Affected Products : yclas- EPSS Score: %0.24
- Published: Aug. 18, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38709
In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via the staff_messaging messaging system for XSS.... Read more
Affected Products : composr_cms- EPSS Score: %0.32
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38708
In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via Comcode for XSS.... Read more
Affected Products : composr_cms- EPSS Score: %0.30
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38707
Persistent cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow low-privileged attackers to introduce arbitrary JavaScript to account parameters. The XSS payloads will execute in the browser of any user who views the relevant content. Thi... Read more
Affected Products : cliniccases- EPSS Score: %0.21
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-38706
messages_load.php in ClinicCases 7.3.3 suffers from a blind SQL injection vulnerability, which allows low-privileged attackers to execute arbitrary SQL commands through a vulnerable parameter.... Read more
Affected Products : cliniccases- EPSS Score: %0.74
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024