Search Results (359884 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-40643 1 Eyesofnetwork 1 Eyesofnetwork 2024-11-21 9.8 Critical
EyesOfNetwork before 07-07-2021 has a Remote Code Execution vulnerability on the mail options configuration page. In the location of the "sendmail" application in the "cacti" configuration page (by default/usr/sbin/sendmail) it is possible to execute any command, which will be executed when we make a test of the configuration ("send test mail").
CVE-2021-40642 1 Textpattern 1 Textpattern 2024-11-21 4.3 Medium
Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php. The secure flag is not set for txp_login session cookie in the application. If the secure flag is not set, then the cookie will be transmitted in clear-text if the user visits any HTTP URLs within the cookie's scope. An attacker may be able to induce this event by feeding a user suitable links, either directly or via another web site.
CVE-2021-40639 1 Jflyfox 1 Jfinal Cms 2024-11-21 7.5 High
Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.
CVE-2021-40637 1 Os4ed 1 Opensis 2024-11-21 6.1 Medium
OS4ED openSIS 8.0 is affected by cross-site scripting (XSS) in EmailCheckOthers.php. An attacker can inject JavaScript code to get the user's cookie and take over the working session of user.
CVE-2021-40636 1 Os4ed 1 Opensis 2024-11-21 7.5 High
OS4ED openSIS 8.0 is affected by SQL Injection in CheckDuplicateName.php, which can extract information from the database.
CVE-2021-40635 1 Os4ed 1 Opensis 2024-11-21 7.5 High
OS4ED openSIS 8.0 is affected by SQL injection in ChooseCpSearch.php, ChooseRequestSearch.php. An attacker can inject a SQL query to extract information from the database.
CVE-2021-40633 1 Giflib Project 1 Giflib 2024-11-21 8.8 High
A memory leak (out-of-memory) in gif2rgb in util/gif2rgb.c in giflib 5.1.4 allows remote attackers trigger an out of memory exception or denial of service via a gif format file.
CVE-2021-40618 1 Os4ed 1 Opensis 2024-11-21 9.8 Critical
An SQL Injection vulnerability exists in openSIS Classic 8.0 via the 1) ADDR_CONT_USRN, 2) ADDR_CONT_PSWD, 3) SECN_CONT_USRN or 4) SECN_CONT_PSWD parameters in HoldAddressFields.php.
CVE-2021-40616 1 Thinkcmf 1 Thinkcmf 2024-11-21 6.5 Medium
thinkcmf v5.1.7 has an unauthorized vulnerability. The attacker can modify the password of the administrator account with id 1 through the background user management group permissions. The use condition is that the background user management group authority is required.
CVE-2021-40612 1 Opmantek 1 Open-audit 2024-11-21 9.8 Critical
An issue was discovered in Opmantek Open-AudIT after 3.5.0. Without authentication, a vulnerability in code_igniter/application/controllers/util.php allows an attacker perform command execution without echoes.
CVE-2021-40610 1 Emlog Pro Project 1 Emlog Pro 2024-11-21 5.4 Medium
Emlog Pro v 1.0.4 cross-site scripting (XSS) in Emlog Pro background management.
CVE-2021-40609 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
The GetHintFormat function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.
CVE-2021-40608 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
The gf_hinter_track_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.
CVE-2021-40607 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
The schm_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.
CVE-2021-40606 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
The gf_bs_write_data function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.
CVE-2021-40604 1 Invisioncommunity 1 Ips Community Suite 2024-11-21 9.1 Critical
A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbitrary URLs or trigger deserialization via phar protocol when generating class names dynamically. In some cases an exploitation is possible by an unauthenticated user.
CVE-2021-40597 1 Edimax 2 Ic-3140w, Ic-3140w Firmware 2024-11-21 9.8 Critical
The firmware of EDIMAX IC-3140W Version 3.11 is hardcoded with Administrator username and password.
CVE-2021-40595 1 Online Leave Management System Project 1 Online Leave Management System 2024-11-21 9.8 Critical
SQL injection vulnerability in Sourcecodester Online Leave Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter to /leave_system/classes/Login.php.
CVE-2021-40592 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
GPAC version before commit 71460d72ec07df766dab0a4d52687529f3efcf0a (version v1.0.1 onwards) contains loop with unreachable exit condition ('infinite loop') vulnerability in ISOBMFF reader filter, isoffin_read.c. Function isoffin_process() can result in DoS by infinite loop. To exploit, the victim must open a specially crafted mp4 file.
CVE-2021-40589 1 Zangband-data Project 1 Zangband-data 2024-11-21 9.8 Critical
ZAngband zangband-data 2.7.5 is affected by an integer underflow vulnerability in src/tk/plat.c through the variable fileheader.bfOffBits.