Latest CVE Feed
-
6.1
MEDIUMCVE-2021-26247
As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" to successfully execute the JavaScript payload present in the "ref" URL parameter.... Read more
Affected Products : cacti- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26237
FastStone Image Viewer <= 7.5 is affected by a user mode write access violation at 0x00402d7d, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Service (DoS) o... Read more
Affected Products : image_viewer- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26236
FastStone Image Viewer v.<= 7.5 is affected by a Stack-based Buffer Overflow at 0x005BDF49, affecting the CUR file parsing functionality (BITMAPINFOHEADER Structure, 'BitCount' file format field), that will end up corrupting the Structure Exception Handle... Read more
Affected Products : image_viewer- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26235
FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfc9, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Servi... Read more
Affected Products : image_viewer- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26234
FastStone Image Viewer <= 7.5 is affected by a user mode write access violation at 0x00402d8a, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Service (DoS) o... Read more
Affected Products : image_viewer- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26233
FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfcb, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Servi... Read more
Affected Products : image_viewer- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26232
SQL injection vulnerability in SourceCodester Simple College Website v 1.0 allows remote attackers to execute arbitrary SQL statements via the id parameter to news.php.... Read more
Affected Products : simple_college_website- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26231
SQL injection vulnerability in SourceCodester Fantastic Blog CMS v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to category.php.... Read more
Affected Products : fantastic_blog_cms- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26230
Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the user information to save_user.php.... Read more
Affected Products : casap_automated_enrollment_system- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26229
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_stud.php.... Read more
Affected Products : casap_automated_enrollment_system- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26228
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_class1.php.... Read more
Affected Products : casap_automated_enrollment_system- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26227
Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the student information parameters to edit_stud.php.... Read more
Affected Products : casap_automated_enrollment_system- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26226
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_user.php.... Read more
Affected Products : casap_automated_enrollment_system- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26224
Cross-site scripting (XSS) vulnerability in SourceCodester Fantastic-Blog-CMS V 1.0 allows remote attackers to inject arbitrary web script or HTML via the search field to search.php.... Read more
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26223
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to view_pay.php.... Read more
Affected Products : casap_automated_enrollment_system- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-26222
The ezxml_new function in ezXML 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool.... Read more
Affected Products : ezxml- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-26221
The ezxml_new function in ezXML 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool.... Read more
Affected Products : ezxml- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-26220
The ezxml_toxml function in ezxml 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool.... Read more
Affected Products : ezxml- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-26216
SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditFolder.php.... Read more
Affected Products : seeddms- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-26215
SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditDocument.php.... Read more
Affected Products : seeddms- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024