Search Results (322553 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-42242 1 Jflyfox 1 Jfinal Cms 2024-11-21 9.8 Critical
A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor.
CVE-2021-42235 1 Enhancesoft 1 Osticket 2024-11-21 9.8 Critical
SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality.
CVE-2021-42233 2 Simple Blog Project, Wondercms 2 Simple Blog, Wondercms 2024-11-21 5.4 Medium
The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability. When any user opens a particular blog hosted on an attackers' site, XSS may occur.
CVE-2021-42232 1 Tp-link 2 Archer A7, Archer A7 Firmware 2024-11-21 9.8 Critical
TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the program taking part of the received data packet as part of the command. This will cause an attacker to execute arbitrary commands on the router.
CVE-2021-42230 1 Seowonintech 2 130-slc, 130-slc Firmware 2024-11-21 9.8 Critical
Seowon 130-SLC router all versions as of 2021-09-15 is vulnerable to Remote Code Execution via the queriesCnt parameter.
CVE-2021-42228 1 Kindsoft 1 Kindeditor 2024-11-21 8.8 High
A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.html.
CVE-2021-42227 1 Kindsoft 1 Kindeditor 2024-11-21 6.1 Medium
Cross SIte Scripting (XSS) vulnerability exists in KindEditor 4.1.x via a Google search inurl:/examples/uploadbutton.html and then the .html file on the website that uses this editor (the file suffix is allowed).
CVE-2021-42224 1 Phpgurukul 1 Ifsc Code Finder 2024-11-21 9.8 Critical
SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php.
CVE-2021-42223 1 Phpgurukul 1 Online Dj Booking Management System 2024-11-21 6.1 Medium
Cross Site Scripting (XSS).vulnerability exists in Online DJ Booking Management System 1.0 in view-booking-detail.php.
CVE-2021-42220 1 Dolibarr 1 Dolibarr 2024-11-21 5.4 Medium
A Cross Site Scripting (XSS) vulnerability exists in Dolibarr before 14.0.3 via the ticket creation flow. Exploitation requires that an admin copies the payload into a box.
CVE-2021-42219 1 Ethereum 1 Go Ethereum 2024-11-21 7.5 High
Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is caused by missing memory in the component /ethash/algorithm.go.
CVE-2021-42218 1 Rice 1 Open Motion Planning Library 2024-11-21 7.5 High
OMPL v1.5.2 contains a memory leak in VFRRT.cpp
CVE-2021-42216 1 Anonaddy 1 Anonaddy 2024-11-21 9.8 Critical
A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.
CVE-2021-42204 1 Swftools 1 Swftools 2024-11-21 7.8 High
An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetBits() located in rfxswf.c. It allows an attacker to cause code execution.
CVE-2021-42203 1 Swftools 1 Swftools 2024-11-21 7.8 High
An issue was discovered in swftools through 20201222. A heap-use-after-free exists in the function swf_FontExtract_DefineTextCallback() located in swftext.c. It allows an attacker to cause code execution.
CVE-2021-42202 1 Swftools 1 Swftools 2024-11-21 5.5 Medium
An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function swf_DeleteFilter() located in swffilter.c. It allows an attacker to cause Denial of Service.
CVE-2021-42201 1 Swftools 1 Swftools 2024-11-21 7.8 High
An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetD64() located in rfxswf.c. It allows an attacker to cause code execution.
CVE-2021-42200 1 Swftools 1 Swftools 2024-11-21 5.5 Medium
An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function main() located in swfdump.c. It allows an attacker to cause Denial of Service.
CVE-2021-42199 1 Swftools 1 Swftools 2024-11-21 7.8 High
An issue was discovered in swftools through 20201222. A heap buffer overflow exists in the function swf_FontExtract_DefineTextCallback() located in swftext.c. It allows an attacker to cause code execution.
CVE-2021-42198 1 Swftools 1 Swftools 2024-11-21 5.5 Medium
An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function swf_GetBits() located in rfxswf.c. It allows an attacker to cause Denial of Service.