Export limit exceeded: 366379 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (366379 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-41965 | 1 Churchcrm | 1 Churchcrm | 2024-11-21 | 8.8 High |
| A SQL injection vulnerability exists in ChurchCRM version 2.0.0 to 4.4.5 that allows an authenticated attacker to issue an arbitrary SQL command to the database through the unsanitized EN_tyid, theID and EID fields used when an Edit action on an existing record is being performed. | ||||
| CVE-2021-41962 | 1 Vehicle Service Management System Project | 1 Vehicle Service Management System | 2024-11-21 | 4.8 Medium |
| Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the Owner fullname parameter in a Send Service Request in vehicle_service. | ||||
| CVE-2021-41959 | 1 Jerryscript | 1 Jerryscript | 2024-11-21 | 7.5 High |
| JerryScript Git version 14ff5bf does not sufficiently track and release allocated memory via jerry-core/ecma/operations/ecma-regexp-object.c after RegExp, which causes a memory leak. | ||||
| CVE-2021-41952 | 1 Tribalsystems | 1 Zenario | 2024-11-21 | 4.8 Medium |
| Zenario CMS 9.0.54156 is vulnerable to Cross Site Scripting (XSS) via upload file to *.SVG. An attacker can send malicious files to victims and steals victim's cookie leads to account takeover. The person viewing the image of a contact can be victim of XSS. | ||||
| CVE-2021-41951 | 1 Montala | 1 Resourcespace | 2024-11-21 | 6.1 Medium |
| ResourceSpace before 9.6 rev 18290 is affected by a reflected Cross-Site Scripting vulnerability in plugins/wordpress_sso/pages/index.php via the wordpress_user parameter. If an attacker is able to persuade a victim to visit a crafted URL, malicious JavaScript content may be executed within the context of the victim's browser. | ||||
| CVE-2021-41950 | 1 Montala | 1 Resourcespace | 2024-11-21 | 9.1 Critical |
| A directory traversal issue in ResourceSpace 9.6 before 9.6 rev 18277 allows remote unauthenticated attackers to delete arbitrary files on the ResourceSpace server via the provider and variant parameters in pages/ajax/tiles.php. Attackers can delete configuration or source code files, causing the application to become unavailable to all users. | ||||
| CVE-2021-41948 | 1 Intelliants | 1 Subrion | 2024-11-21 | 5.4 Medium |
| A cross-site scripting (XSS) vulnerability exists in the "contact us" plugin for Subrion CMS <= 4.2.1 version via "List of subjects". | ||||
| CVE-2021-41947 | 1 Intelliants | 1 Subrion Cms | 2024-11-21 | 7.2 High |
| A SQL injection vulnerability exists in Subrion CMS v4.2.1 in the visual-mode. | ||||
| CVE-2021-41946 | 1 Fiberhome | 2 Hg150-ub, Hg150-ub Firmware | 2024-11-21 | 5.4 Medium |
| In FiberHome VDSL2 Modem HG150-Ub_V3.0, a stored cross-site scripting (XSS) vulnerability in Parental Control --> Access Time Restriction --> Username field, a user cannot delete the rule due to the XSS. | ||||
| CVE-2021-41945 | 1 Encode | 1 Httpx | 2024-11-21 | 9.1 Critical |
| Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`. | ||||
| CVE-2021-41942 | 1 Msvod | 1 Msvod Cms | 2024-11-21 | 7.5 High |
| The Magic CMS MSVOD v10 video system has a SQL injection vulnerability. Attackers can use vulnerabilities to obtain sensitive information in the database. | ||||
| CVE-2021-41938 | 1 Shopxo | 1 Shopxo | 2024-11-21 | 7.2 High |
| An issue was discovered in ShopXO CMS 2.2.0. After entering the management page, there is an arbitrary file upload vulnerability in three locations. | ||||
| CVE-2021-41932 | 1 Wolterskluwer | 1 Teammate\+ Audit | 2024-11-21 | 8.8 High |
| A blind SQL injection vulnerability in search form in TeamMate+ Audit version 28.0.19.0 allows any authenticated user to create malicious SQL injections, which can result in complete database compromise, gaining information about other users, unauthorized access to audit data etc. | ||||
| CVE-2021-41931 | 1 Recruitment Management System Project | 1 Recruitment Management System | 2024-11-21 | 9.8 Critical |
| The Company's Recruitment Management System in id=2 of the parameter from view_vacancy app on-page appears to be vulnerable to SQL injection. The payloads 19424269' or '1309'='1309 and 39476597' or '2917'='2923 were each submitted in the id parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way. | ||||
| CVE-2021-41930 | 1 Online Covid Vaccination Scheduler System Project | 1 Online Covid Vaccination Scheduler System | 2024-11-21 | 6.1 Medium |
| Cross site scripting (XSS) vulnerability in Sourcecodester Online Covid Vaccination Scheduler System v1 by oretnom23, allows attackers to execute arbitrary code via the lid parameter to /scheduler/addSchedule.php. | ||||
| CVE-2021-41929 | 1 The Electric Billing Management System Project | 1 The Electric Billing Management System | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting (XSS) in Sourcecodester The Electric Billing Management System 1.0 by oretnom23, allows attackers to execute arbitrary code via the about page. | ||||
| CVE-2021-41928 | 1 Try My Recipe Project | 1 Try My Recipe | 2024-11-21 | 9.8 Critical |
| SQL injection in Sourcecodester Try My Recipe (Recipe Sharing Website - CMS) 1.0 by oretnom23, allows attackers to execute arbitrary code via the rid parameter to the view_recipe page. | ||||
| CVE-2021-41924 | 1 Webkul | 1 Krayin | 2024-11-21 | 6.1 Medium |
| Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS). | ||||
| CVE-2021-41921 | 1 Xxyopen | 1 Novel-plus | 2024-11-21 | 9.8 Critical |
| novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution. | ||||
| CVE-2021-41920 | 1 Webtareas Project | 1 Webtareas | 2024-11-21 | 7.5 High |
| webTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/library.php, via the sor_cible, sor_champs, and sor_ordre HTTP POST parameters. This allows an attacker to access all the data in the database and obtain access to the webTareas application. | ||||