Export limit exceeded: 372784 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (372784 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-45811 | 1 Enhancesoft | 1 Osticket | 2024-11-21 | 6.5 Medium |
| A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination. | ||||
| CVE-2021-45810 | 1 Globalprotect-openconnect Project | 1 Globalprotect-openconnect | 2024-11-21 | 7.5 High |
| GlobalProtect-openconnect versions prior to 2.0.0 (exclusive) are affected by incorrect access control in GPService through DBUS, GUI. The way GlobalProtect-Openconnect is set up enables arbitrary users to start a VPN connection to arbitrary servers. By hosting an openconnect compatible server, the attack can redirect the entire host's traffic via their own server. | ||||
| CVE-2021-45809 | 1 Globalprotect-openconnect Project | 1 Globalprotect-openconnect | 2024-11-21 | 9.8 Critical |
| GlobalProtect-openconnect versions prior to 1.4.3 are affected by incorrect access control in GPService through DBUS, GUI Application. The way GlobalProtect-Openconnect is set up enables arbitrary users to execute commands as root by submitting the `--script=<script>` parameter. | ||||
| CVE-2021-45808 | 1 Jpress | 1 Jpress | 2024-11-21 | 8.8 High |
| jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the server. | ||||
| CVE-2021-45807 | 1 Jpress | 1 Jpress | 2024-11-21 | 9.8 Critical |
| jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall. | ||||
| CVE-2021-45806 | 1 Jpress | 1 Jpress | 2024-11-21 | 8.8 High |
| jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code. | ||||
| CVE-2021-45803 | 1 Iresturant Project | 1 Iresturant | 2024-11-21 | 8.8 High |
| MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because this view parameter value is added to the SQL query without additional verification when viewing reservation. | ||||
| CVE-2021-45802 | 1 Iresturant Project | 1 Iresturant | 2024-11-21 | 9.8 Critical |
| MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter values are added to the SQL query without any verification at the time of membership registration. | ||||
| CVE-2021-45794 | 1 Slims | 1 Senayan Library Management System | 2024-11-21 | 7.5 High |
| Slims9 Bulian 9.4.2 is affected by SQL injection in /admin/modules/system/backup.php. User data can be obtained. | ||||
| CVE-2021-45793 | 1 Slims | 1 Senayan Library Management System | 2024-11-21 | 7.5 High |
| Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained. | ||||
| CVE-2021-45792 | 1 Slims | 1 Senayan Library Management System | 2024-11-21 | 4.8 Medium |
| Slims9 Bulian 9.4.2 is affected by Cross Site Scripting (XSS) in /admin/modules/system/custom_field.php. | ||||
| CVE-2021-45791 | 1 Slims | 1 Senayan Library Management System | 2024-11-21 | 8.8 High |
| Slims8 Akasia 8.3.1 is affected by SQL injection in /admin/modules/bibliography/index.php, /admin/modules/membership/member_type.php, /admin/modules/system/user_group.php, and /admin/modules/membership/index.php through the dir parameter. It can be used by remotely authenticated librarian users. | ||||
| CVE-2021-45790 | 1 Metersphere | 1 Metersphere | 2024-11-21 | 9.8 Critical |
| An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to arbitrary directory, where attackers can write a cron job to execute commands. | ||||
| CVE-2021-45789 | 1 Metersphere | 1 Metersphere | 2024-11-21 | 6.5 Medium |
| An arbitrary file read vulnerability was found in Metersphere v1.15.4, where authenticated users can read any file on the server via the file download function. | ||||
| CVE-2021-45788 | 1 Metersphere | 1 Metersphere | 2024-11-21 | 8.8 High |
| Time-based SQL Injection vulnerabilities were found in Metersphere v1.15.4 via the "orders" parameter. | ||||
| CVE-2021-45787 | 1 Maccms | 1 Maccms | 2024-11-21 | 5.4 Medium |
| There is a stored Cross Site Scripting (XSS) vulnerability in maccms v10 through adding videos. XSS code can be inserted at parameter positions including name and remarks. | ||||
| CVE-2021-45786 | 1 Maccms | 1 Maccms | 2024-11-21 | 9.8 Critical |
| In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges. | ||||
| CVE-2021-45785 | 1 Trudesk Project | 1 Trudesk | 2024-11-21 | 4.3 Medium |
| TruDesk Help Desk/Ticketing Solution v1.1.11 is vulnerable to a Cross-Site Request Forgery (CSRF) attack which would allow an attacker to restart the server, causing a DoS attack. The attacker must craft a webpage that would perform a GET request to the /api/v1/admin/restart endpoint, then the victim (who has sufficient privileges), would visit the page and the server restart would begin. The attacker must know the full URL that TruDesk is on in order to craft the webpage. | ||||
| CVE-2021-45783 | 1 Bookeen | 2 Notea, Notea Firmware | 2024-11-21 | 4.6 Medium |
| Bookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to obtain sensitive information. | ||||
| CVE-2021-45773 | 1 Mz-automation | 1 Lib60870 | 2024-11-21 | 7.5 High |
| A NULL pointer dereference in CS104_IPAddress_setFromString at src/iec60870/cs104/cs104_slave.c of lib60870 commit 0d5e76e can lead to a segmentation fault or application crash. | ||||