Search Results (360965 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-46042 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
A Pointer Dereference Vulnerability exists in GPAC 1.0.1 via the _fseeko function, which causes a Denial of Service.
CVE-2021-46041 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
A Segmentation Fault Vulnerability exists in GPAC 1.0.1 via the co64_box_new function, which causes a Denial of Service.
CVE-2021-46040 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
A Pointer Dereference Vulnerabilty exists in GPAC 1.0.1 via the finplace_shift_moov_meta_offsets function, which causes a Denial of Servie (context-dependent).
CVE-2021-46039 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
A Pointer Dereference Vulnerabilty exists in GPAC 1.0.1 via the shift_chunk_offsets.part function, which causes a Denial of Service (context-dependent).
CVE-2021-46038 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
A Pointer Dereference vulnerability exists in GPAC 1.0.1 in unlink_chunk.isra, which causes a Denial of Service (context-dependent).
CVE-2021-46037 1 Mingsoft 1 Mcms 2024-11-21 8.1 High
MCMS v5.2.4 was discovered to contain an arbitrary file deletion vulnerability via the component /template/unzip.do.
CVE-2021-46036 1 Mingsoft 1 Mcms 2024-11-21 9.8 Critical
An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code.
CVE-2021-46034 1 Forestblog Project 1 Forestblog 2024-11-21 6.1 Medium
A problem was found in ForestBlog, as of 2021-12-29, there is a XSS vulnerability that can be injected through the nickname input box.
CVE-2021-46033 1 Forestblog Project 1 Forestblog 2024-11-21 9.8 Critical
In ForestBlog, as of 2021-12-28, File upload can bypass verification.
CVE-2021-46030 1 Javaquarkbbs Project 1 Javaquarkbbs 2024-11-21 5.4 Medium
There is a Cross Site Scripting attack (XSS) vulnerability in JavaQuarkBBS <= v2. By entering specific statements into the background tag management module, the attack statement will be stored in the database, and the next victim will be attacked when he accesses the tag module.
CVE-2021-46028 1 Mblog Project 1 Mblog 2024-11-21 4.3 Medium
In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, the article will be deleted.
CVE-2021-46025 1 Oneblog Project 1 Oneblog 2024-11-21 5.4 Medium
A Cross SIte Scripting (XSS) vulnerability exists in OneBlog <= 2.2.8. via the add function in the operation tab list in the background.
CVE-2021-46024 1 Projectworlds 1 Online-shopping-webvsite-in-php 2024-11-21 9.8 Critical
Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the "id" parameter in cart_add.php, No login is required.
CVE-2021-46022 2 Fedoraproject, Gnu 2 Fedora, Recutils 2024-11-21 5.5 Medium
An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
CVE-2021-46021 2 Fedoraproject, Gnu 2 Fedora, Recutils 2024-11-21 5.5 Medium
An Use-After-Free vulnerability in rec_record_destroy() at rec-record.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
CVE-2021-46020 1 Mruby 1 Mruby 2024-11-21 7.5 High
An untrusted pointer dereference in mrb_vm_exec() of mruby v3.0.0 can lead to a segmentation fault or application crash.
CVE-2021-46019 2 Fedoraproject, Gnu 2 Fedora, Recutils 2024-11-21 5.5 Medium
An untrusted pointer dereference in rec_db_destroy() at rec-db.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
CVE-2021-46013 1 Free School Management Software Project 1 Free School Management Software 2024-11-21 9.8 Critical
An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can leverage this vulnerability to enable remote code execution on the affected web server. Once a php webshell containing "<?php system($_GET["cmd"]); ?>" gets uploaded it is saved into /uploads/exam_question/ directory, and is accessible by all users.
CVE-2021-46010 1 Totolink 2 A3100r, A3100r Firmware 2024-11-21 8.8 High
Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is predictable. An attacker can hijack a valid session and conduct further malicious operations.
CVE-2021-46009 1 Totolink 2 A3100r, A3100r Firmware 2024-11-21 9.8 Critical
In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.