Medium · CVSS 6.4
An exploitable SQL injection vulnerability exists in ‘manageServiceStocks.jsp’ page of OpenClinic GA 5.173.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Published May 10, 2021 · Updated Aug 4, 2024
Medium · CVSS 6.4
An exploitable SQL injection vulnerability exists in ‘quickFile.jsp’ page of OpenClinic GA 5.173.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Published May 10, 2021 · Updated Aug 4, 2024
Medium · CVSS 6.4
A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findDistrict parameter in ‘‘patientslist.do’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Published May 10, 2021 · Updated Aug 4, 2024
Medium · CVSS 6.4
A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findPersonID parameter in ‘‘patientslist.do’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Published May 10, 2021 · Updated Aug 4, 2024
Medium · CVSS 6.4
A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findSector parameter in ‘‘patientslist.do’ page is vulnerable to authenticated SQL injection An attacker can make an authenticated HTTP request to trigger this vulnerability.
Published May 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The ECDSA operation of the micro-ecc library 1.0 is vulnerable to simple power analysis attacks which allows an adversary to extract the private ECC key.
Published May 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP) can be degraded from RDP level 2 (no access via debug interface) to level 1 (limited access via debug interface) by injecting a fault during the boot phase.
Published May 21, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.0.0 & Somu and the Nitrokey FIDO2 token. This allows an adversary to downgrade the RDP level and access secrets such as private ECC keys from SRAM via the debug interface.
Published May 21, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Nordic Semiconductor nRF52840 devices through 2020-10-19 have improper protection against physical side channels. The flash read-out protection (APPROTECT) can be bypassed by injecting a fault during the boot phase.
Published May 21, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration, and other sensitive data transmitted over Moxa Service.
Published May 14, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The NPort IA5000A Series devices use Telnet as one of the network device management services. Telnet does not support the encryption of client-server communications, making it vulnerable to Man-in-the-Middle attacks.
Published May 14, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In multiple versions of NPort IA5000A Series, the result of exporting a device’s configuration contains the passwords of all users on the system and other sensitive data in the original form if “Pre-shared key” doesn’t set.
Published May 14, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
By exploiting a vulnerability in NPort IA5150A/IA5250A Series before version 1.5, a user with “Read Only” privilege level can send requests via the web console to have the device’s configuration changed.
Published May 14, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password generation).
Published May 14, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability has been discovered in the login page of SeaCMS version 11 which allows an attacker to inject arbitrary web script or HTML.
Published May 28, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Cross Site Request Forgery (CSRF) vulnerability was discovered in iCMS 7.0.16 which can allow an attacker to execute arbitrary web scripts.
Published May 28, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on an insufficiently random AuthValue before the provisioning procedure times out, to complete authentication by leveraging Malleable Commitment.
Published May 24, 2021 · Updated Aug 4, 2024
High · CVSS 8.1
Dotmesh is a git-like command-line interface for capturing, organizing and sharing application states. In versions 0.8.1 and prior, the unsafe handling of symbolic links in an unpacking routine may
enable attackers to read and/or write to arbitrary locations outside the
designated target folder. The routine `untarFile` attempts to guard against creating symbolic links that point outside the directory a tar archive is extracted to. However, a malicious tarball first linking `subdir/parent` to `..` (allowed, because `subdir/..` falls within the archive root) and then linking `subdir/parent/escapes` to `..` results in a symbolic link pointing to the tarball’s parent directory, contrary to the routine’s goals. This issue may lead to arbitrary file write (with same permissions as the program running the unpack operation) if the attacker can control the archive file. Additionally, if the attacker has read access to the unpacked files, they may be able to read arbitrary system files the parent process has permissions to read. As of time of publication, no patch for this issue is available.
Published May 14, 2024 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the kernel in OpenBSD 6.6. The WEP, WPA, WPA2, and WPA3 implementations treat fragmented frames as full frames. An adversary can abuse this to inject arbitrary network packets, independent of the network configuration.
Published May 11, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Project Worlds Online Examination System 1.0 is affected by Cross Site Scripting (XSS) via account.php.
Published May 24, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability was found in the Linux Kernel where the function sunkbd_reinit having been scheduled by sunkbd_interrupt before sunkbd being freed. Though the dangling pointer is set to NULL in sunkbd_disconnect, there is still an alias in sunkbd_reinit causing Use After Free.
Published May 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op.
Published May 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A flaw was found in pki-core 10.9.0. A specially crafted POST request can be used to reflect a DOM-based cross-site scripting (XSS) attack to inject code into the search query form which can get automatically executed. The highest threat from this vulnerability is to data integrity.
Published May 28, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability.
Published May 28, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows an attacker to gain access to privileged information. The highest threat from this vulnerability is to confidentiality and integrity. Versions before resteasy 2.0.0.Alpha3 are affected.
Published May 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability was found in Linux kernel where non-blocking socket in llcp_sock_connect() leads to leak and eventually hanging-up the system.
Published May 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common.
Published May 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A privilege escalation flaw was found in the Xorg-x11-server due to a lack of authentication for X11 clients. This flaw allows an attacker to take control of an X application by impersonating the server it is expecting to connect to.
Published May 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an assertion failure. The highest threat from this vulnerability is to system availability.
Published May 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attacker to view sensitive information or modify service APIs. Versions before 3scale-2.10.0-ER1 are affected.
Published May 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability was found in Linux Kernel, where a refcount leak in llcp_sock_connect() causing use-after-free which might lead to privilege escalations.
Published May 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A memory leak vulnerability was found in Linux kernel in llcp_sock_connect
Published May 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability was found in Linux Kernel where refcount leak in llcp_sock_bind() causing use-after-free which might lead to privilege escalations.
Published May 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Projectworlds Online Examination System 1.0 is vulnerable to CSRF, which allows a remote attacker to delete the existing user.
Published May 24, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability has been identified in SIMATIC NET CP 343-1 Advanced (incl. SIPLUS variants) (All versions), SIMATIC NET CP 343-1 Lean (incl. SIPLUS variants) (All versions), SIMATIC NET CP 343-1 Standard (incl. SIPLUS variants) (All versions). Specially crafted packets sent to TCP port 102 could cause a Denial-of-Service condition on the affected devices. A cold restart might be necessary in order to recover.
Published May 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters.
Published May 24, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Cross-Site Request Forgery (CSRF) vulnerability exists in ProjectWorlds College Management System Php 1.0 that allows a remote attacker to modify, delete, or make a new entry of the student, faculty, teacher, subject, scores, location, and article data.
Published May 24, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when an administrator accesses the content management module.
Published May 17, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when visitors access the article module.
Published May 17, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=editpage
Published May 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Ubiquiti UniFi Video v3.10.13, when the executable starts, its first library validation is in the current directory. This allows the impersonation and modification of the library to execute code on the system. This was tested in (Windows 7 x64/Windows 10 x64).
Published May 17, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting to a network. Under the right circumstances, when another device sends fragmented frames encrypted using WEP, CCMP, or GCMP, this can be abused to inject arbitrary network packets and/or exfiltrate user data.
Published May 11, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP encryption key is periodically renewed.
Published May 11, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The USB firmware update script of homee Brain Cube v2 (2.28.2 and 2.28.4) devices allows an attacker with physical access to install compromised firmware. This occurs because of insufficient validation of the firmware image file and can lead to code execution on the device.
Published May 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
homee Brain Cube v2 (2.28.2 and 2.28.4) devices have sensitive SSH keys within downloadable and unencrypted firmware images. This allows remote attackers to use the support server as a SOCKS proxy.
Published May 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
TinyShop, a free and open source mall based on RageFrame2, has a stored XSS vulnerability that affects version 1.2.0. TinyShop allows XSS via the explain_first and again_explain parameters of the /evaluate/index.php page. The vulnerability may be exploited remotely, resulting in cross-site scripting (XSS) or information disclosure.
Published May 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect.
Published May 14, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A local file inclusion vulnerability in ILIAS before 5.3.19, 5.4.10 and 6.0 allows remote authenticated attackers to execute arbitrary code via the import of personal data.
Published May 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer Overflow vulnerability in FFMpeg 4.2.3 in dnn_execute_layer_pad in libavfilter/dnn/dnn_backend_native_layer_pad.c due to a call to memcpy without length checks, which could let a remote malicious user execute arbitrary code.
Published May 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Use-after-Free vulnerability in cflow 1.6 in the void call(char *name, int line) function at src/parser.c, which could cause a denial of service via the pointer variable caller->callee.
Published May 18, 2021 · Updated Aug 4, 2024