Latest CVE Feed
-
6.5
MEDIUMCVE-2021-25214
In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when ... Read more
Affected Products : fedora debian_linux active_iq_unified_manager cloud_backup h300s_firmware h500s_firmware h700s_firmware h410s_firmware sinec_ins sinec_infrastructure_network_services +15 more products- EPSS Score: %0.48
- Published: Apr. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25213
SQL injection vulnerability in SourceCodester Travel Management System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the catid parameter to subcat.php.... Read more
Affected Products : travel_management_system- EPSS Score: %0.51
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25212
SQL injection vulnerability in SourceCodester Alumni Management System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to manage_event.php.... Read more
Affected Products : alumni_management_system- EPSS Score: %0.51
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25211
Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, via the file upload to ordering\admin\products\edit.php.... Read more
Affected Products : online_ordering_system- EPSS Score: %1.02
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25210
Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to manage_event.php.... Read more
Affected Products : alumni_management_system- EPSS Score: %0.94
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25209
SQL injection vulnerability in SourceCodester Theme Park Ticketing System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to view_user.php .... Read more
Affected Products : theme_park_ticketing_system- EPSS Score: %0.44
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25208
Arbitrary file upload vulnerability in SourceCodester Travel Management System v 1.0 allows attackers to execute arbitrary code via the file upload to updatepackage.php.... Read more
Affected Products : travel_management_system- EPSS Score: %1.02
- Published: Jul. 23, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25207
Arbitrary file upload vulnerability in SourceCodester E-Commerce Website v 1.0 allows attackers to execute arbitrary code via the file upload to prodViewUpdate.php.... Read more
Affected Products : e-commerce_website- EPSS Score: %1.02
- Published: Jul. 23, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25206
Arbitrary file upload vulnerability in SourceCodester Responsive Ordering System v 1.0 allows attackers to execute arbitrary code via the file upload to Product_model.php.... Read more
Affected Products : responsive_ordering_system- EPSS Score: %1.02
- Published: Jul. 23, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25205
SQL injection vulnerability in SourceCodester E-Commerce Website V 1.0 allows remote attackers to execute arbitrary SQL statements, via the update parameter to empViewUpdate.php .... Read more
Affected Products : e-commerce_website- EPSS Score: %0.49
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25204
Cross-site scripting (XSS) vulnerability in SourceCodester E-Commerce Website v 1.0 allows remote attackers to inject arbitrary web script or HTM via the subject field to feedback_process.php.... Read more
Affected Products : e-commerce_website- EPSS Score: %0.13
- Published: Jul. 23, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25203
Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload to \CMSsite-master\admin\includes\admin_add_post.php.... Read more
Affected Products : victor_cms- EPSS Score: %1.02
- Published: Jul. 23, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25202
SQL injection vulnerability in SourceCodester Sales and Inventory System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to \ahira\admin\inventory.php.... Read more
Affected Products : sales_and_inventory_system- EPSS Score: %0.51
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-25201
SQL injection vulnerability in Learning Management System v 1.0 allows remote attackers to execute arbitrary SQL statements through the id parameter to obtain sensitive database information.... Read more
Affected Products : learning_management_system- EPSS Score: %0.23
- Published: Jul. 23, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25200
Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to \lms\student_avatar.php.... Read more
Affected Products : learning_management_system- EPSS Score: %1.02
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25197
Cross-site scripting (XSS) vulnerability in SourceCodester Content Management System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter to content_management_system\admin\new_content.php... Read more
Affected Products : content_management_system- EPSS Score: %0.22
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-25195
Windows PKU2U Elevation of Privilege Vulnerability... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 +9 more products- EPSS Score: %0.15
- Published: Feb. 25, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25179
SolarWinds Serv-U before 15.2 is affected by Cross Site Scripting (XSS) via the HTTP Host header.... Read more
Affected Products : serv-u_file_server- EPSS Score: %1.84
- Published: May. 05, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-25178
An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A stack-based buffer overflow vulnerability exists when the recover operation is run with malformed .DXF and .DWG files. This can allow attackers to cause a crash potentially ena... Read more
- EPSS Score: %0.90
- Published: Jan. 18, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-25177
An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A Type Confusion issue exists when rendering malformed .DXF and .DWG files. This can allow attackers to cause a crash, potentially enabling a denial of service attack (Crash, Exi... Read more
- EPSS Score: %0.34
- Published: Jan. 18, 2021
- Modified: Nov. 21, 2024