Search Results (372511 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-44118 1 Spip 1 Spip 2024-11-21 5.4 Medium
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side into web pages visited by other users (stored XSS).
CVE-2021-44117 1 Thedaylightstudio 1 Fuel Cms 2024-11-21 8.8 High
A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4.
CVE-2021-44116 1 Anchorcms 1 Anchor Cms 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php. Attackers can use the posts column to upload the title and content containing malicious code to achieve the purpose of obtaining the administrator cookie, thereby achieving other malicious operations.
CVE-2021-44114 1 Stock Management System Project 1 Stock Management System 2024-11-21 4.8 Medium
Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Stock Management System in PHP/OOP 1.0, which allows remote malicious users to execute arbitrary remote code execution via create user function.
CVE-2021-44111 1 S-cart 1 S-cart 2024-11-21 4.4 Medium
A Directory Traversal vulnerability exists in S-Cart 6.7 via download in sc-admin/backup.
CVE-2021-44109 1 Open5gs 1 Open5gs 2024-11-21 7.5 High
A buffer overflow in lib/sbi/message.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request.
CVE-2021-44108 1 Open5gs 1 Open5gs 2024-11-21 7.5 High
A null pointer dereference in src/amf/namf-handler.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request to amf.
CVE-2021-44098 1 Egavilanmedia 1 Expense Management System 2024-11-21 9.8 Critical
EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database.
CVE-2021-44097 1 Contact-form-with-messages-entry-management Project 1 Contact-form-with-messages-entry-management 2024-11-21 9.8 Critical
EGavilan Media Contact-Form-With-Messages-Entry-Management 1.0 is vulnerable to SQL Injection via Addmessage.php. This allows a remote attacker to compromise Application SQL database.
CVE-2021-44096 1 Egavilanmedia 1 User Registration And Login System With Admin Panel 2024-11-21 9.8 Critical
EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user. This allows a remote attacker to compromise Application SQL database.
CVE-2021-44095 1 Hospital Management System Project 1 Hospital Management System 2024-11-21 9.8 Critical
A SQL injection vulnerability exists in ProjectWorlds Hospital Management System in php 1.0 on login page that allows a remote attacker to compromise Application SQL database.
CVE-2021-44094 1 Zrlog 1 Zrlog 2024-11-21 7.8 High
ZrLog 2.2.2 has a remote command execution vulnerability at plugin download function, it could execute any JAR file
CVE-2021-44093 1 Zrlog 1 Zrlog 2024-11-21 9.8 Critical
A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit, upload the JSP file to get a WebShell
CVE-2021-44091 1 Multi Restaurant Table Reservation System Project 1 Multi Restaurant Table Reservation System 2024-11-21 5.4 Medium
A Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in register.php via the (1) fullname, (2) phone, and (3) address parameters.
CVE-2021-44090 1 Sourcecodester Online Reviewer System Project 1 Sourcecodester Online Reviewer System 2024-11-21 9.8 Critical
An SQL Injection vulnerability exists in Sourcecodester Online Reviewer System 1.0 via the password parameter.
CVE-2021-44088 1 Attendance And Payroll System Project 1 Attendance And Payroll System 2024-11-21 9.8 Critical
An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters.
CVE-2021-44087 1 Attendance And Payroll System Project 1 Attendance And Payroll System 2024-11-21 9.8 Critical
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an unauthenticated remote attacker to upload a maliciously crafted PHP via photo upload.
CVE-2021-44082 1 Textpattern 1 Textpattern 2024-11-21 8.3 High
textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to trigger remote code execution by uploading a webshell. To do so they must first steal the CSRF token before submitting a file upload request.
CVE-2021-44081 1 Open5gs 1 Open5gs 2024-11-21 7.5 High
A buffer overflow vulnerability exists in the AMF of open5gs 2.1.4. When the length of MSIN in Supi exceeds 24 characters, it leads to AMF denial of service.
CVE-2021-44080 1 Sercomm 2 H500s, H500s Firmware 2024-11-21 7.2 High
A Command Injection vulnerability in httpd web server (setup.cgi) in SerComm h500s, FW: lowi-h500s-v3.4.22 allows logged in administrators to arbitrary OS commands as root in the device via the connection_type parameter of the statussupport_diagnostic_tracing.json endpoint.