Show filters
12,170 Total Results
Displaying 41-50 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Very High
CVE-2021-41676
Disclosure Date: October 29, 2021 (last updated February 23, 2025)
An SQL Injection vulnerabilty exists in the oretnom23 Pharmacy Point of Sale System 1.0 in the login function in actions.php.
1
Attacker Value
Very High
CVE-2021-38757
Disclosure Date: August 16, 2021 (last updated February 23, 2025)
Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php.
1
Attacker Value
Moderate
CVE-2021-38699
Disclosure Date: August 15, 2021 (last updated February 23, 2025)
TastyIgniter 3.0.7 allows XSS via /account, /reservation, /admin/dashboard, and /admin/system_logs.
1
Attacker Value
High
CVE-2021-36798
Disclosure Date: August 09, 2021 (last updated February 23, 2025)
A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3. It allows remote attackers to crash the C2 server thread and block beacons' communication with it.
1
Attacker Value
Very High
CVE-2021-36624
Disclosure Date: July 30, 2021 (last updated February 23, 2025)
Sourcecodester Phone Shop Sales Managements System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
1
Attacker Value
Very High
CVE-2021-36621
Disclosure Date: July 30, 2021 (last updated February 23, 2025)
Sourcecodester Online Covid Vaccination Scheduler System 1.0 is vulnerable to SQL Injection. The username parameter is vulnerable to time-based SQL injection. Upon successful dumping the admin password hash, an attacker can decrypt and obtain the plain-text password. Hence, the attacker could authenticate as Administrator.
1
Attacker Value
Low
CVE-2021-35941
Disclosure Date: June 29, 2021 (last updated February 22, 2025)
Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory restore without authentication, as exploited in the wild in June 2021, a different vulnerability than CVE-2018-18472.
1
Attacker Value
Moderate
CVE-2021-26236
Disclosure Date: March 18, 2021 (last updated February 22, 2025)
FastStone Image Viewer v.<= 7.5 is affected by a Stack-based Buffer Overflow at 0x005BDF49, affecting the CUR file parsing functionality (BITMAPINFOHEADER Structure, 'BitCount' file format field), that will end up corrupting the Structure Exception Handler (SEH). Attackers could exploit this issue to achieve code execution when a user opens or views a malformed/specially crafted CUR file.
1
Attacker Value
Unknown
CVE-2020-15568
Disclosure Date: January 30, 2021 (last updated February 22, 2025)
TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parameter.
1
Attacker Value
High
CVE-2020-27955 — Git Large File Storage / Git LFS (git-lfs) - Remote Code Execu…
Disclosure Date: November 05, 2020 (last updated February 22, 2025)
Git LFS 2.12.0 allows Remote Code Execution.
1