Search Results (30280 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-46198 1 Courier Management System Project 1 Courier Management System 2024-11-21 9.8 Critical
An SQL Injection vulnerability exists in Sourceodester Courier Management System 1.0 via the email parameter in /cms/ajax.php app.
CVE-2021-46110 1 Phpgurukul 1 Online Shopping Portal 2024-11-21 9.8 Critical
Online Shopping Portal v3.1 was discovered to contain multiple time-based SQL injection vulnerabilities via the email and contactno parameters.
CVE-2021-46093 1 Elitecms 1 Elite Cms 2024-11-21 9.8 Critical
eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php.
CVE-2021-46089 1 Jeecg 1 Jeecg Boot 2024-11-21 9.8 Critical
In JeecgBoot 3.0, there is a SQL injection vulnerability that can operate the database with root privileges.
CVE-2021-46067 1 Vehicle Service Management System Project 1 Vehicle Service Management System 2024-11-21 9.8 Critical
In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.
CVE-2021-46063 1 Mingsoft 1 Mcms 2024-11-21 9.1 Critical
MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management module.
CVE-2021-46061 1 Computer And Mobile Repair Shop Management System Project 1 Computer And Mobile Repair Shop Management System 2024-11-21 9.8 Critical
An SQL Injection vulnerability exists in Sourcecodester Computer and Mobile Repair Shop Management system (RSMS) 1.0 via the code parameter in /rsms/ node app.
CVE-2021-46036 1 Mingsoft 1 Mcms 2024-11-21 9.8 Critical
An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code.
CVE-2021-46033 1 Forestblog Project 1 Forestblog 2024-11-21 9.8 Critical
In ForestBlog, as of 2021-12-28, File upload can bypass verification.
CVE-2021-46024 1 Projectworlds 1 Online-shopping-webvsite-in-php 2024-11-21 9.8 Critical
Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the "id" parameter in cart_add.php, No login is required.
CVE-2021-46013 1 Free School Management Software Project 1 Free School Management Software 2024-11-21 9.8 Critical
An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can leverage this vulnerability to enable remote code execution on the affected web server. Once a php webshell containing "<?php system($_GET["cmd"]); ?>" gets uploaded it is saved into /uploads/exam_question/ directory, and is accessible by all users.
CVE-2021-46009 1 Totolink 2 A3100r, A3100r Firmware 2024-11-21 9.8 Critical
In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.
CVE-2021-46007 1 Totolink 2 Ar3100r, Ar3100r Firmware 2024-11-21 9.8 Critical
totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command, and the input field does not adequately filter special symbols. This can lead to command injection attacks.
CVE-2021-45998 1 Dlink 2 Dir-882, Dir-882 Firmware 2024-11-21 9.8 Critical
D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the LocalIPAddress parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.
CVE-2021-45990 1 Tendacn 4 G1, G1 Firmware, G3 and 1 more 2024-11-21 9.8 Critical
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function uploadPicture. This vulnerability allows attackers to execute arbitrary commands via the pic_name parameter.
CVE-2021-45987 1 Tendacn 4 G1, G1 Firmware, G3 and 1 more 2024-11-21 9.8 Critical
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetNetCheckTools. This vulnerability allows attackers to execute arbitrary commands via the hostName parameter.
CVE-2021-45986 1 Tendacn 4 G1, G1 Firmware, G3 and 1 more 2024-11-21 9.8 Critical
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetUSBShareInfo. This vulnerability allows attackers to execute arbitrary commands via the usbOrdinaryUserName parameter.
CVE-2021-45983 1 Netscout 1 Ngeniusone 2024-11-21 9.8 Critical
NetScout nGeniusONE 6.3.2 allows Java RMI Code Execution.
CVE-2021-45981 1 Netscout 1 Ngeniusone 2024-11-21 9.8 Critical
NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack.
CVE-2021-45977 1 Jetbrains 7 Clion, Goland, Intellij Idea and 4 more 2024-11-21 9.8 Critical
JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm 2021.3.1 RC (used as Remote Development backend IDEs) bind to the 0.0.0.0 IP address. The fixed versions are: IntelliJ IDEA 2021.3.1, PyCharm Professional 2021.3.1, GoLand 2021.3.2, PhpStorm 2021.3.1 (213.6461.83), RubyMine 2021.3.1, CLion 2021.3.2, and WebStorm 2021.3.1.