Search Results (357170 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-46033 1 Forestblog Project 1 Forestblog 2024-11-21 9.8 Critical
In ForestBlog, as of 2021-12-28, File upload can bypass verification.
CVE-2021-46030 1 Javaquarkbbs Project 1 Javaquarkbbs 2024-11-21 5.4 Medium
There is a Cross Site Scripting attack (XSS) vulnerability in JavaQuarkBBS <= v2. By entering specific statements into the background tag management module, the attack statement will be stored in the database, and the next victim will be attacked when he accesses the tag module.
CVE-2021-46028 1 Mblog Project 1 Mblog 2024-11-21 4.3 Medium
In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, the article will be deleted.
CVE-2021-46025 1 Oneblog Project 1 Oneblog 2024-11-21 5.4 Medium
A Cross SIte Scripting (XSS) vulnerability exists in OneBlog <= 2.2.8. via the add function in the operation tab list in the background.
CVE-2021-46024 1 Projectworlds 1 Online-shopping-webvsite-in-php 2024-11-21 9.8 Critical
Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the "id" parameter in cart_add.php, No login is required.
CVE-2021-46022 2 Fedoraproject, Gnu 2 Fedora, Recutils 2024-11-21 5.5 Medium
An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
CVE-2021-46021 2 Fedoraproject, Gnu 2 Fedora, Recutils 2024-11-21 5.5 Medium
An Use-After-Free vulnerability in rec_record_destroy() at rec-record.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
CVE-2021-46020 1 Mruby 1 Mruby 2024-11-21 7.5 High
An untrusted pointer dereference in mrb_vm_exec() of mruby v3.0.0 can lead to a segmentation fault or application crash.
CVE-2021-46019 2 Fedoraproject, Gnu 2 Fedora, Recutils 2024-11-21 5.5 Medium
An untrusted pointer dereference in rec_db_destroy() at rec-db.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
CVE-2021-46013 1 Free School Management Software Project 1 Free School Management Software 2024-11-21 9.8 Critical
An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can leverage this vulnerability to enable remote code execution on the affected web server. Once a php webshell containing "<?php system($_GET["cmd"]); ?>" gets uploaded it is saved into /uploads/exam_question/ directory, and is accessible by all users.
CVE-2021-46010 1 Totolink 2 A3100r, A3100r Firmware 2024-11-21 8.8 High
Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is predictable. An attacker can hijack a valid session and conduct further malicious operations.
CVE-2021-46009 1 Totolink 2 A3100r, A3100r Firmware 2024-11-21 9.8 Critical
In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.
CVE-2021-46008 1 Totolink 2 A3100r, A3100r Firmware 2024-11-21 8.8 High
In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An attacker, who has connected to the Wi-Fi, can easily telnet into the target with root shell if the telnet is function turned on.
CVE-2021-46007 1 Totolink 2 Ar3100r, Ar3100r Firmware 2024-11-21 9.8 Critical
totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command, and the input field does not adequately filter special symbols. This can lead to command injection attacks.
CVE-2021-46006 1 Totolink 2 A3100r, A3100r Firmware 2024-11-21 6.5 Medium
In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function, an attacker can configure multiple settings without authentication.
CVE-2021-46005 1 Car Rental Management System Project 1 Car Rental Management System 2024-11-21 5.4 Medium
Sourcecodester Car Rental Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via vehicalorcview parameter.
CVE-2021-45998 1 Dlink 2 Dir-882, Dir-882 Firmware 2024-11-21 9.8 Critical
D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the LocalIPAddress parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.
CVE-2021-45997 1 Tendacn 4 G1, G1 Firmware, G3 and 1 more 2024-11-21 7.5 High
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetPortMapping. This vulnerability allows attackers to cause a Denial of Service (DoS) via the portMappingServer, portMappingProtocol, portMappingWan, porMappingtInternal, and portMappingExternal parameters.
CVE-2021-45996 1 Tendacn 4 G1, G1 Firmware, G3 and 1 more 2024-11-21 7.5 High
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetPortMapping. This vulnerability allows attackers to cause a Denial of Service (DoS) via the portMappingServer, portMappingProtocol, portMappingWan, porMappingtInternal, and portMappingExternal parameters.
CVE-2021-45995 1 Tendacn 4 G1, G1 Firmware, G3 and 1 more 2024-11-21 7.5 High
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetStaticRoute. This vulnerability allows attackers to cause a Denial of Service (DoS) via the staticRouteNet, staticRouteMask, and staticRouteGateway parameters.