Search Results (360137 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-41660 1 Patient Appointment Scheduler System Project 1 Patient Appointment Scheduler System 2024-11-21 9.8 Critical
SQL injection vulnerability in Sourcecodester Patient Appointment Scheduler System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password fields to login.php.
CVE-2021-41658 1 Student Quarterly Grading System Project 1 Student Quarterly Grading System 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) in Sourcecodester Student Quarterly Grading System by oretnom23, allows attackers to execute arbitrary code via the fullname and username parameters to the users page.
CVE-2021-41657 1 Smartbear 1 Collaborator 2024-11-21 6.1 Medium
SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clickjacking attack.
CVE-2021-41654 1 Wuzhicms 1 Wuzhicms 2024-11-21 9.8 Critical
SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php
CVE-2021-41653 1 Tp-link 2 Tl-wr840n, Tl-wr840n Firmware 2024-11-21 9.8 Critical
The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.
CVE-2021-41652 1 Batflat 1 Batflat 2024-11-21 7.5 High
Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database.
CVE-2021-41651 1 Hotel Management System Project 1 Hotel Management System 2024-11-21 7.5 High
A blind SQL injection vulnerability exists in the Raymart DG / Ahmed Helal Hotel-mgmt-system. A malicious attacker can retrieve sensitive database information and interact with the database using the vulnerable cid parameter in process_update_profile.php.
CVE-2021-41649 1 Online-shopping-system-advanced Project 1 Online-shopping-system-advanced 2024-11-21 9.8 Critical
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.
CVE-2021-41648 1 Online-shopping-system-advanced Project 1 Online-shopping-system-advanced 2024-11-21 7.5 High
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input.
CVE-2021-41647 1 Online Food Ordering Web App Project 1 Online Food Ordering Web App 2024-11-21 9.1 Critical
An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Ordering Web App 1.0. An attacker can exploit the vulnerable "username" parameter in login.php and retrieve sensitive database information, as well as add an administrative user.
CVE-2021-41645 1 Oretnom23 1 Budget And Expense Tracker System 2024-11-21 8.8 High
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Budget and Expense Tracker System 1.0 that allows a remote malicious user to inject arbitrary code via the image upload field. .
CVE-2021-41643 1 Church Management System Project 1 Church Management System 2024-11-21 9.8 Critical
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field.
CVE-2021-41641 1 Deno 1 Deno 2024-11-21 8.4 High
Deno <=1.14.0 file sandbox does not handle symbolic links correctly. When running Deno with specific write access, the Deno.symlink method can be used to gain access to any directory.
CVE-2021-41639 1 Melag 1 Ftp Server 2024-11-21 5.5 Medium
MELAG FTP Server 2.2.0.4 stores unencrpyted passwords of FTP users in a local configuration file.
CVE-2021-41638 1 Melag 1 Ftp Server 2024-11-21 7.5 High
The authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to access local files only by using a valid username.
CVE-2021-41637 1 Melag 1 Ftp Server 2024-11-21 7.1 High
Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which includes among other information the unencrypted passwords of all FTP users.
CVE-2021-41636 1 Melag 1 Ftp Server 2024-11-21 6.5 Medium
MELAG FTP Server 2.2.0.4 allows an attacker to use the CWD command to break out of the FTP servers root directory and operate on the entire operating system, while the access restrictions of the user running the FTP server apply.
CVE-2021-41635 2 Melag, Microsoft 2 Ftp Server, Windows 2024-11-21 8.8 High
When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse misconfigurations or vulnerabilities with administrative access over the entire host system.
CVE-2021-41634 1 Melag 1 Ftp Server 2024-11-21 5.3 Medium
A user enumeration vulnerability in MELAG FTP Server 2.2.0.4 allows an attacker to identify valid FTP usernames.
CVE-2021-41619 1 Gradle 1 Enterprise 2024-11-21 7.2 High
An issue was discovered in Gradle Enterprise before 2021.1.2. There is potential remote code execution via the application startup configuration. The installation configuration user interface (available to administrators) allows specifying arbitrary Java Virtual Machine startup options. Some of these options, such as -XX:OnOutOfMemoryError, allow specifying a command to be run on the host. This can be abused to run arbitrary commands on the host, should an attacker gain administrative access to the application.