Export limit exceeded: 373723 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (373723 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-38758 | 1 Online Catering Reservation System Project | 1 Online Catering Reservation System | 2024-11-21 | 7.5 High |
| Directory traversal vulnerability in Online Catering Reservation System 1.0 exists due to lack of validation in index.php. | ||||
| CVE-2021-38757 | 1 Hospital Management System Project | 1 Hospital Management System | 2024-11-21 | 6.1 Medium |
| Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php. | ||||
| CVE-2021-38756 | 1 Hospital Management System Project | 1 Hospital Management System | 2024-11-21 | 6.1 Medium |
| Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through prescribe.php. | ||||
| CVE-2021-38755 | 1 Hospital Management System Project | 1 Hospital Management System | 2024-11-21 | 5.3 Medium |
| Unauthenticated doctor entry deletion in Hospital Management System in admin-panel1.php. | ||||
| CVE-2021-38754 | 1 Hospital Management System Project | 1 Hospital Management System | 2024-11-21 | 9.8 Critical |
| SQL Injection vulnerability in Hospital Management System due to lack of input validation in messearch.php. | ||||
| CVE-2021-38753 | 1 Simple Image Gallery Web App Project | 1 Simple Image Gallery Web App | 2024-11-21 | 9.8 Critical |
| An unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain unauthorized access to the server hosting the web app. | ||||
| CVE-2021-38752 | 1 Online Catering Reservation System Project | 1 Online Catering Reservation System | 2024-11-21 | 5.4 Medium |
| A cross-site scripting (XSS) vulnerability in Online Catering Reservation System using PHP on Sourcecodester allows an attacker to arbitrarily inject code in the search bar. | ||||
| CVE-2021-38751 | 1 Exponentcms | 1 Exponentcms | 2024-11-21 | 4.3 Medium |
| A HTTP Host header attack exists in ExponentCMS 2.6 and below in /exponent_constants.php. A modified HTTP header can change links on the webpage to an arbitrary value, leading to a possible attack vector for MITM. | ||||
| CVE-2021-38745 | 1 Chamilo | 1 Chamilo | 2024-11-21 | 6.8 Medium |
| Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a crafted plugin. This vulnerability is triggered through user interaction with the attacker's profile page. | ||||
| CVE-2021-38727 | 1 Thedaylightstudio | 1 Fuel Cms | 2024-11-21 | 9.8 Critical |
| FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items | ||||
| CVE-2021-38725 | 1 Thedaylightstudio | 1 Fuel Cms | 2024-11-21 | 5.3 Medium |
| Fuel CMS 1.5.0 has a brute force vulnerability in fuel/modules/fuel/controllers/Login.php | ||||
| CVE-2021-38723 | 1 Thedaylightstudio | 1 Fuel Cms | 2024-11-21 | 8.8 High |
| FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/pages/items | ||||
| CVE-2021-38721 | 1 Thedaylightstudio | 1 Fuel Cms | 2024-11-21 | 6.5 Medium |
| FUEL CMS 1.5.0 login.php contains a cross-site request forgery (CSRF) vulnerability | ||||
| CVE-2021-38714 | 3 Debian, Fedoraproject, Plib Project | 4 Debian Linux, Extra Packages For Enterprise Linux, Fedora and 1 more | 2024-11-21 | 8.8 High |
| In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file. | ||||
| CVE-2021-38713 | 1 Imgurl Project | 1 Imgurl | 2024-11-21 | 5.4 Medium |
| imgURL 2.31 allows XSS via an X-Forwarded-For HTTP header. | ||||
| CVE-2021-38712 | 1 Onenav | 1 Onenav | 2024-11-21 | 7.5 High |
| OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to block the access via an NGINX configuration file. | ||||
| CVE-2021-38711 | 1 Gitit Project | 1 Gitit | 2024-11-21 | 7.5 High |
| In gitit before 0.15.0.0, the Export feature can be exploited to leak information from files. | ||||
| CVE-2021-38710 | 1 Yclas | 1 Yclas | 2024-11-21 | 6.1 Medium |
| Static (Persistent) XSS Vulnerability exists in version 4.3.0 of Yclas when using the install/view/form.php script. An attacker can store XSS in the database through the vulnerable SITE_NAME parameter. | ||||
| CVE-2021-38709 | 1 Compo | 1 Composr Cms | 2024-11-21 | 6.1 Medium |
| In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via the staff_messaging messaging system for XSS. | ||||
| CVE-2021-38708 | 1 Compo | 1 Composr Cms | 2024-11-21 | 5.4 Medium |
| In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via Comcode for XSS. | ||||