Search Results (84595 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-37402 1 Open-xchange 1 Open-xchange Appsuite 2024-11-21 6.1 Medium
OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the legacy dataretrieval endpoint has been enabled.
CVE-2021-37393 1 Rpcms 1 Rpcms 2024-11-21 5.4 Medium
In RPCMS v1.8 and below, the "nickname" variable is not properly sanitized before being displayed on page. Attacker can use "update password" function to inject XSS payloads into nickname variable, and achieve stored XSS. Users who view the articles published by the injected user will trigger the XSS.
CVE-2021-37392 1 Rpcms 1 Rpcms 2024-11-21 5.4 Medium
In RPCMS v1.8 and below, the "nickname" variable is not properly sanitized before being displayed on page. When the API functions are enabled, the attacker can use API to update user nickname with XSS payload and achieve stored XSS. Users who view the articles published by the injected user will trigger the XSS.
CVE-2021-37391 1 Chamilo 1 Chamilo Lms 2024-11-21 5.4 Medium
A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.php, main/inc/lib/social.lib.php and steal cookies or execute arbitrary code on the administration side via a stored XSS vulnerability via social network the send invitation feature.
CVE-2021-37390 1 Chamilo 1 Chamilo Lms 2024-11-21 6.1 Medium
A Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature).
CVE-2021-37389 1 Chamilo 1 Chamilo 2024-11-21 6.1 Medium
Chamilo 1.11.14 allows stored XSS via main/install/index.php and main/install/ajax.php through the port parameter.
CVE-2021-37386 1 Furukawa 8 423-41w\/ac, 423-41w\/ac Firmware, Ld420-10r and 5 more 2024-11-21 7.5 High
Furukawa Electric LatAm 423-41W/AC before v1.1.4 and LD421-21W before v1.3.3 were discovered to contain an HTML injection vulnerability via the serial number update function.
CVE-2021-37379 1 Teradek 2 Sphere, Sphere Firmware 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) vulnerability in Teradek Sphere all firmware versions allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue.
CVE-2021-37377 1 Teradek 2 Brik, Brik Firmware 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) vulnerability in Teradek Brik firmware version 7.2.x and earlier allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue.
CVE-2021-37376 1 Teradek 6 Bond, Bond 2, Bond 2 Firmware and 3 more 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) vulnerability in Teradek Bond, Bond 2 and Bond Pro firmware version 7.3.x and earlier allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue.
CVE-2021-37375 1 Teradek 4 Vidiu, Vidiu Firmware, Vidiu Mini and 1 more 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) vulnerability in Teradek VidiU / VidiU Mini firmware version 3.0.8 and earlier allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue.
CVE-2021-37365 1 Ctparental Project 1 Ctparental 2024-11-21 6.1 Medium
CTparental before 4.45.03 is vulnerable to cross-site scripting (XSS) in the CTparental admin panel. In bl_categires_help.php, the 'categories' variable is assigned with the content of the query string param 'cat' without sanitization or encoding, enabling an attacker to inject malicious code into the output webpage.
CVE-2021-37364 1 Openclinic Ga Project 1 Openclinic Ga 2024-11-21 7.8 High
OpenClinic GA 5.194.18 is affected by Insecure Permissions. By default the Authenticated Users group has the modify permission to openclinic folders/files. A low privilege account is able to rename mysqld.exe or tomcat8.exe files located in bin folders and replace with a malicious file that would connect back to an attacking computer giving system level privileges (nt authority\system) due to the service running as Local System. While a low privilege user is unable to restart the service through the application, a restart of the computer triggers the execution of the malicious file. The application also have unquoted service path issues.
CVE-2021-37354 1 Xerox 2 Phaser 4622, Phaser 4622 Firmware 2024-11-21 9.8 Critical
Xerox Phaser 4622 v35.013.01.000 was discovered to contain a buffer overflow in the function sub_3226AC via the TIMEZONE variable. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.
CVE-2021-37346 1 Nagios 1 Nagios Xi Watchguard Wizard 2024-11-21 9.8 Critical
Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation of special elements used in an OS Command (OS Command injection).
CVE-2021-37344 1 Nagios 1 Nagios Xi Switch Wizard 2024-11-21 9.8 Critical
Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS Command (OS Command injection).
CVE-2021-37330 1 Bookingcore 1 Booking Core 2024-11-21 5.4 Medium
Laravel Booking System Booking Core 2.0 is vulnerable to Cross Site Scripting (XSS). The Avatar upload in the My Profile section could be exploited to upload a malicious SVG file which contains Javascript. Now if another user/admin views the profile and clicks to view his avatar, an XSS will trigger.
CVE-2021-37271 1 Baidu 1 Ueditor 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) vulnerability exists in UEditor v1.4.3.3, which can be exploited by an attacker to obtain user cookie information.
CVE-2021-37267 1 Kindsoft 1 Kindeditor 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability exists in all versions of KindEditor, which can be exploited by an attacker to obtain user cookie information.
CVE-2021-37262 1 Jflyfox 1 Jfinal Cms 2024-11-21 7.5 High
JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service.