Search

Search Results (374604 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-43691 1 Tripexpress Project 1 Tripexpress 2024-11-21 9.8 Critical
tripexpress v1.1 is affected by a path manipulation vulnerability in file system/helpers/dompdf/load_font.php. The variable src is coming from $_SERVER["argv"] then there is a path manipulation vulnerability.
CVE-2021-43690 1 Yurunproxy Project 1 Yurunproxy 2024-11-21 6.1 Medium
YurunProxy v0.01 is affected by a Cross Site Scripting (XSS) vulnerability in src/Client.php. The exit function will terminate the script and print a message which have values from the socket_read.
CVE-2021-43689 1 Manage Project 1 Manage 2024-11-21 6.1 Medium
manage (last update Oct 24, 2017) is affected by a Cross Site Scripting (XSS) vulnerability in Application/Home/Controller/GoodsController.class.php. The exit function will terminate the script and print a message which have values from $_POST.
CVE-2021-43687 1 Chamilo 1 Chamilo 2024-11-21 6.1 Medium
chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an attacker passes a message hex2bin in the cookie.
CVE-2021-43686 1 Nzedb Project 1 Nzedb 2024-11-21 6.1 Medium
nZEDb v0.4.20 is affected by a Cross Site Scripting (XSS) vulnerability in www/pages/api.php. The exit function will terminate the script and print the message which has the input $_GET['t'].
CVE-2021-43685 1 Libretime 1 Libretime Hv 2024-11-21 9.8 Critical
libretime hv3.0.0-alpha.10 is affected by a path manipulation vulnerability in /blob/master/legacy/application/modules/rest/controllers/ShowImageController.php through the rename function.
CVE-2021-43683 1 Haschek 1 Pictshare 2024-11-21 6.1 Medium
pictshare v1.5 is affected by a Cross Site Scripting (XSS) vulnerability in api/info.php. The exit function will terminate the script and print the message which has $_REQUEST['hash'].
CVE-2021-43682 1 Thinkphp-bjyblog Project 1 Thinkphp-bjyblog 2024-11-21 6.1 Medium
thinkphp-bjyblog (last update Jun 4 2021) is affected by a Cross Site Scripting (XSS) vulnerability in AdminBaseController.class.php. The exit function terminates the script and prints a message to the user that contains $_SERVER['HTTP_HOST'].
CVE-2021-43681 1 Zerodream 1 Sakurapanel 2024-11-21 6.1 Medium
SakuraPanel v1.0.1.1 is affected by a Cross Site Scripting (XSS) vulnerability in /master/core/PostHandler.php. The exit function will terminate the script and print the message $data['proxy_name'].
CVE-2021-43679 1 Shopex 1 Ecshop 2024-11-21 9.8 Critical
ecshop v2.7.3 is affected by a SQL injection vulnerability in shopex\ecshop\upload\api\client\api.php.
CVE-2021-43678 1 Wechat-php-sdk Project 1 Wechat-php-sdk 2024-11-21 6.1 Medium
Wechat-php-sdk v1.10.2 is affected by a Cross Site Scripting (XSS) vulnerability in Wechat.php.
CVE-2021-43677 1 Fluxbb 1 Fluxbb 2024-11-21 6.1 Medium
Fluxbb v1.4.12 is affected by a Cross Site Scripting (XSS) vulnerability.
CVE-2021-43676 1 Swoole 1 Swoole Php Framework 2024-11-21 9.8 Critical
matyhtf framework v3.0.5 is affected by a path manipulation vulnerability in Smarty.class.php.
CVE-2021-43675 1 Lycheeorg 1 Lychee 2024-11-21 6.1 Medium
Lychee-v3 3.2.16 is affected by a Cross Site Scripting (XSS) vulnerability in php/Access/Guest.php. The function exit will terminate the script and print the message to the user. The message will contain albumID which is controlled by the user.
CVE-2021-43674 1 Thinkupapp 1 Thinkup 2024-11-21 9.8 Critical
ThinkUp 2.0-beta.10 is affected by a path manipulation vulnerability in Smarty.class.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVE-2021-43673 1 Dzzoffice 1 Dzzoffice 2024-11-21 6.1 Medium
dzzoffice 2.02.1_SC_UTF8 is affected by a Cross Site Scripting (XSS) vulnerability in explorerfile.php. The output of the exit function is printed for the user via exit(json_encode($return)).
CVE-2021-43669 1 Linuxfoundation 1 Fabric 2024-11-21 7.5 High
A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.0.1, v2.3.0. It can easily break down as many orderers as the attacker wants. This bug can be leveraged by constructing a message whose header is invalid to the interface Order. This bug has been admitted and fixed by the developers of Fabric.
CVE-2021-43668 1 Ethereum 1 Go Ethereum 2024-11-21 5.5 Medium
Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They will crash with "runtime error: invalid memory address or nil pointer dereference" and arise a SEGV signal.
CVE-2021-43667 1 Linuxfoundation 1 Fabric 2024-11-21 7.5 High
A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.1.0. This bug can be leveraged by constructing a message whose payload is nil and sending this message with the method 'forwardToLeader'. This bug has been admitted and fixed by the developers of Fabric. If leveraged, any leader node will crash.
CVE-2021-43664 1 Totolink 2 Ex300 V2, Ex300 V2 Firmware 2024-11-21 8.1 High
totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component process forceugpo.