Search Results (360227 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-43725 1 Spotweb Project 1 Spotweb 2024-11-21 6.1 Medium
There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remote attackers to inject arbitrary web script or HTML via the data[performredirect] parameter.
CVE-2021-43724 1 Intelliants 1 Subrion Cms 2024-11-21 4.8 Medium
A Cross Site Scripting (XSS) vulnerability exits in Subrion CMS through 4.2.1 in the Create Page functionality of the admin Account via a SGV file.
CVE-2021-43722 1 Dlink 2 Dir-645, Dir-645 Firmware 2024-11-21 9.8 Critical
D-Link DIR-645 1.03 A1 is vulnerable to Buffer Overflow. The hnap_main function in the cgibin handler uses sprintf to format the soapaction header onto the stack and has no limit on the size.
CVE-2021-43721 1 Leanote 1 Leanote 2024-11-21 6.1 Medium
Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note. This leads to remote code execution with payload : <video src=x onerror=(function(){require('child_process').exec('calc');})();>
CVE-2021-43712 1 Employee Daily Task Management System Project 1 Employee Daily Task Management System 2024-11-21 5.4 Medium
Stored XSS in Add New Employee Form in Sourcecodester Employee Daily Task Management System 1.0 Allows Remote Attacker to Inject/Store Arbitrary Code via the Name Field.
CVE-2021-43711 1 Totolink 2 Ex200, Ex200 Firmware 2024-11-21 9.8 Critical
The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The parameter name can be constructed for unauthenticated command execution.
CVE-2021-43708 1 Helpsystems 1 Titus Data Classification 2024-11-21 5.5 Medium
The Labeling tool in Titus Classification Suite 18.8.1910.140 allows users to avoid the generation of a classification label by using Excel's safe mode.
CVE-2021-43707 1 Maccms 1 Maccms 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter.
CVE-2021-43703 1 Zzcms 1 Zzcms 2024-11-21 9.8 Critical
An Incorrect Access Control vulnerability exists in zzcms less than or equal to 2019 via admin.php. After disabling JavaScript, you can directly access the administrator console.
CVE-2021-43702 1 Asus 186 4g-ac53u, 4g-ac53u Firmware, 4g-ac68u and 183 more 2024-11-21 9.0 Critical
ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device.
CVE-2021-43701 1 Cszcms 1 Csz Cms 2024-11-21 6.5 Medium
CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/article_db, via the fieldS[] and orderby parameters.
CVE-2021-43700 1 Apimanager Project 1 Apimanager 2024-11-21 9.8 Critical
An issue was discovered in ApiManager 1.1. there is sql injection vulnerability that can use in /index.php?act=api&tag=8.
CVE-2021-43698 1 Phpwhois Project 1 Phpwhois 2024-11-21 6.1 Medium
phpWhois (last update Jun 30 2021) is affected by a Cross Site Scripting (XSS) vulnerability. In file example.php, the exit function will terminate the script and print the message to the user. The message will contain $_GET['query'] then there is a XSS vulnerability.
CVE-2021-43697 1 Workerman-thinkphp-redis Project 1 Workerman-thinkphp-redis 2024-11-21 6.1 Medium
Workerman-ThinkPHP-Redis (last update Mar 16, 2018) is affected by a Cross Site Scripting (XSS) vulnerability. In file Controller.class.php, the exit function will terminate the script and print the message to the user. The message will contain $_GET{C('VAR_JSONP_HANDLER')] then there is a XSS vulnerability.
CVE-2021-43696 1 Twmap Project 1 Twmap 2024-11-21 6.1 Medium
twmap v2.91_v4.33 is affected by a Cross Site Scripting (XSS) vulnerability. In file list.php, the exit function will terminate the script and print the message to the user. The message will contain $_REQUEST then there is a XSS vulnerability.
CVE-2021-43695 1 Issabel 1 Pbx 2024-11-21 6.1 Medium
issabelPBX version 2.11 is affected by a Cross Site Scripting (XSS) vulnerability. In file page.backup_restore.php, the exit function will terminate the script and print the message to the user. The message will contain $_REQUEST without sanitization, then there is a XSS vulnerability.
CVE-2021-43693 1 Vestacp 1 Vesta Control Panel 2024-11-21 9.8 Critical
vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php.
CVE-2021-43692 1 Youtube-php-mirroring Project 1 Youtube-php-mirroring 2024-11-21 6.1 Medium
youtube-php-mirroring (last update Jun 9, 2017) is affected by a Cross Site Scripting (XSS) vulnerability in file ytproxy/index.php.
CVE-2021-43691 1 Tripexpress Project 1 Tripexpress 2024-11-21 9.8 Critical
tripexpress v1.1 is affected by a path manipulation vulnerability in file system/helpers/dompdf/load_font.php. The variable src is coming from $_SERVER["argv"] then there is a path manipulation vulnerability.
CVE-2021-43690 1 Yurunproxy Project 1 Yurunproxy 2024-11-21 6.1 Medium
YurunProxy v0.01 is affected by a Cross Site Scripting (XSS) vulnerability in src/Client.php. The exit function will terminate the script and print a message which have values from the socket_read.