Search Results (349276 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-43697 1 Workerman-thinkphp-redis Project 1 Workerman-thinkphp-redis 2024-11-21 6.1 Medium
Workerman-ThinkPHP-Redis (last update Mar 16, 2018) is affected by a Cross Site Scripting (XSS) vulnerability. In file Controller.class.php, the exit function will terminate the script and print the message to the user. The message will contain $_GET{C('VAR_JSONP_HANDLER')] then there is a XSS vulnerability.
CVE-2021-43696 1 Twmap Project 1 Twmap 2024-11-21 6.1 Medium
twmap v2.91_v4.33 is affected by a Cross Site Scripting (XSS) vulnerability. In file list.php, the exit function will terminate the script and print the message to the user. The message will contain $_REQUEST then there is a XSS vulnerability.
CVE-2021-43695 1 Issabel 1 Pbx 2024-11-21 6.1 Medium
issabelPBX version 2.11 is affected by a Cross Site Scripting (XSS) vulnerability. In file page.backup_restore.php, the exit function will terminate the script and print the message to the user. The message will contain $_REQUEST without sanitization, then there is a XSS vulnerability.
CVE-2021-43693 1 Vestacp 1 Vesta Control Panel 2024-11-21 9.8 Critical
vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php.
CVE-2021-43692 1 Youtube-php-mirroring Project 1 Youtube-php-mirroring 2024-11-21 6.1 Medium
youtube-php-mirroring (last update Jun 9, 2017) is affected by a Cross Site Scripting (XSS) vulnerability in file ytproxy/index.php.
CVE-2021-43691 1 Tripexpress Project 1 Tripexpress 2024-11-21 9.8 Critical
tripexpress v1.1 is affected by a path manipulation vulnerability in file system/helpers/dompdf/load_font.php. The variable src is coming from $_SERVER["argv"] then there is a path manipulation vulnerability.
CVE-2021-43690 1 Yurunproxy Project 1 Yurunproxy 2024-11-21 6.1 Medium
YurunProxy v0.01 is affected by a Cross Site Scripting (XSS) vulnerability in src/Client.php. The exit function will terminate the script and print a message which have values from the socket_read.
CVE-2021-43689 1 Manage Project 1 Manage 2024-11-21 6.1 Medium
manage (last update Oct 24, 2017) is affected by a Cross Site Scripting (XSS) vulnerability in Application/Home/Controller/GoodsController.class.php. The exit function will terminate the script and print a message which have values from $_POST.
CVE-2021-43687 1 Chamilo 1 Chamilo 2024-11-21 6.1 Medium
chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an attacker passes a message hex2bin in the cookie.
CVE-2021-43686 1 Nzedb Project 1 Nzedb 2024-11-21 6.1 Medium
nZEDb v0.4.20 is affected by a Cross Site Scripting (XSS) vulnerability in www/pages/api.php. The exit function will terminate the script and print the message which has the input $_GET['t'].
CVE-2021-43685 1 Libretime 1 Libretime Hv 2024-11-21 9.8 Critical
libretime hv3.0.0-alpha.10 is affected by a path manipulation vulnerability in /blob/master/legacy/application/modules/rest/controllers/ShowImageController.php through the rename function.
CVE-2021-43683 1 Haschek 1 Pictshare 2024-11-21 6.1 Medium
pictshare v1.5 is affected by a Cross Site Scripting (XSS) vulnerability in api/info.php. The exit function will terminate the script and print the message which has $_REQUEST['hash'].
CVE-2021-43682 1 Thinkphp-bjyblog Project 1 Thinkphp-bjyblog 2024-11-21 6.1 Medium
thinkphp-bjyblog (last update Jun 4 2021) is affected by a Cross Site Scripting (XSS) vulnerability in AdminBaseController.class.php. The exit function terminates the script and prints a message to the user that contains $_SERVER['HTTP_HOST'].
CVE-2021-43681 1 Zerodream 1 Sakurapanel 2024-11-21 6.1 Medium
SakuraPanel v1.0.1.1 is affected by a Cross Site Scripting (XSS) vulnerability in /master/core/PostHandler.php. The exit function will terminate the script and print the message $data['proxy_name'].
CVE-2021-43679 1 Shopex 1 Ecshop 2024-11-21 9.8 Critical
ecshop v2.7.3 is affected by a SQL injection vulnerability in shopex\ecshop\upload\api\client\api.php.
CVE-2021-43678 1 Wechat-php-sdk Project 1 Wechat-php-sdk 2024-11-21 6.1 Medium
Wechat-php-sdk v1.10.2 is affected by a Cross Site Scripting (XSS) vulnerability in Wechat.php.
CVE-2021-43677 1 Fluxbb 1 Fluxbb 2024-11-21 6.1 Medium
Fluxbb v1.4.12 is affected by a Cross Site Scripting (XSS) vulnerability.
CVE-2021-43676 1 Swoole 1 Swoole Php Framework 2024-11-21 9.8 Critical
matyhtf framework v3.0.5 is affected by a path manipulation vulnerability in Smarty.class.php.
CVE-2021-43675 1 Lycheeorg 1 Lychee 2024-11-21 6.1 Medium
Lychee-v3 3.2.16 is affected by a Cross Site Scripting (XSS) vulnerability in php/Access/Guest.php. The function exit will terminate the script and print the message to the user. The message will contain albumID which is controlled by the user.
CVE-2021-43674 1 Thinkupapp 1 Thinkup 2024-11-21 9.8 Critical
ThinkUp 2.0-beta.10 is affected by a path manipulation vulnerability in Smarty.class.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer