Unknown · CVSS Not scored
An information disclosure vulnerability was discovered in alipay_function.php in the log file of Alibaba payment interface on PHPPYUN prior to version 5.0.1. If exploited, this vulnerability will allow attackers to obtain users' personally identifiable information including e-mail address and telephone numbers.
Published May 21, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An information disclosure vulnerability in ILIAS before 5.3.19, 5.4.12 and 6.0 allows remote authenticated attackers to get the upload data path via a workspace upload.
Published May 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap based buffer overflow vulnerability exists in ffjpeg through 2020-07-02 in the jfif_decode(void *ctxt, BMP *pb) function at ffjpeg/src/jfif.c (line 544 & line 545), which could cause a denial of service by submitting a malicious jpeg image.
Published May 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An arbitrary file deletion vulnerability was discovered on htmly v2.7.5 which allows remote attackers to use any absolute path to delete any file in the server should they gain Administrator privileges.
Published May 21, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0. If an attacker is able to gain Administrator rights they will be able to use unsafe plugins to upload a backup file and control the server.
Published May 21, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A stack-based buffer overflow vulnerability exists in ffjpeg through 2020-07-02 in the jfif_decode(void *ctxt, BMP *pb) function at ffjpeg/src/jfif.c:513:28, which could cause a denial of service by submitting a malicious jpeg image.
Published May 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap-based buffer overflow vulnerability exists in LibreDWG 0.10.1 via the read_system_page function at libredwg-0.10.1/src/decode_r2007.c:666:5, which causes a denial of service by submitting a dwg file.
Published May 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An Arbitrary File Upload vulnerability was discovered in the Golo Laravel theme v 1.1.5.
Published May 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In YFCMF v2.3.1, there is a stored XSS vulnerability in the comments section of the news page.
Published May 14, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
YFCMF v2.3.1 has a Remote Command Execution (RCE) vulnerability in the index.php.
Published May 14, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A directory traversal vulnerability exists in Kyocera Printer d-COPIA253MF plus. Successful exploitation of this vulnerability could allow an attacker to retrieve or view arbitrary files from the affected server.
Published May 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A reflected cross site scripting (XSS) vulnerability in Xtend Voice Logger 1.0 allows attackers to execute arbitrary web scripts or HTML, via the path of the error page.
Published May 2, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Java Remote Management Interface of all versions of Orlansoft ERP was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object.
Published May 2, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
NoneCMS v1.3 has a CSRF vulnerability in public/index.php/admin/nav/add.html, as demonstrated by adding a navigation column which can be injected with arbitrary web script or HTML via the name parameter to launch a stored XSS attack.
Published May 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCms v1.3.0 allows remote attackers to inject arbitrary web script or HTML via the movieName parameter.
Published May 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A cross site scripting (XSS) vulnerability in the error page of Totolink N200RE and N100RE Routers 2.0 allows attackers to execute arbitrary web scripts or HTML via SCRIPT element.
Published May 2, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In YzmCMS 5.6, XSS was discovered in member/member_content/init.html via the SRC attribute of an IFRAME element because of using UEditor 1.4.3.3.
Published May 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in admin/nav/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the name parameter.
Published May 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Java Remote Management Interface of all versions of SVI MS Management System was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object.
Published May 2, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in admin/article/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the name parameter.
Published May 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In YzmCMS 5.6, stored XSS exists via the common/static/plugin/ueditor/1.4.3.3/php/controller.php action parameter, which allows remote attackers to upload a swf file. The swf file can be injected with arbitrary web script or HTML.
Published May 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross-site request forgery (CSRF) in Fork-CMS before 5.8.2 allow remote attackers to hijack the authentication of logged administrators.
Published May 6, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Chamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege to create a new user then use the edit user function to change this new user to administrator privilege.
Published May 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Persistent Cross-site scripting vulnerability on Fork CMS version 5.8.2 allows remote attackers to inject arbitrary Javascript code via the "navigation_title" parameter and the "title" parameter in /private/en/pages/add.
Published May 6, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges by uploading a crafted file to the component "jeecgFormDemoController.do?commonUpload".
Published May 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user.
Published May 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Windscribe v1.83 Build 20, 'WindscribeService' has an Unquoted Service Path that facilitates privilege escalation.
Published May 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not filtered and can redirect user to any website.
Published May 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an admin) containing a JavaScript payload.
Published May 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap-based Buffer Overflow vulnerability exists in gaussian_blur at libavfilter/vf_edgedetect.c, which might lead to memory corruption and other potential consequences.
Published May 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/af_afade.c in crossfade_samples_fltp, which might lead to memory corruption and other potential consequences.
Published May 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap-based Buffer Overflow vulnerabililty exists in FFmpeg 4.2 in filter_frame at libavfilter/vf_bitplanenoise.c, which might lead to memory corruption and other potential consequences.
Published May 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/vf_w3fdif.c in filter16_complex_low, which might lead to memory corruption and other potential consequences.
Published May 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer Overflow vulnerability in FFmpeg 4.2 at the lagfun_frame16 function in libavfilter/vf_lagfun.c, which could let a remote malicious user cause Denial of Service.
Published May 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer Overflow vulnerability exists in FFmpeg 4.2 in the config_input function at libavfilter/af_tremolo.c, which could let a remote malicious user cause a Denial of Service.
Published May 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap-based Buffer Overflow vulnerability exits in FFmpeg 4.2 in deflate16 at libavfilter/vf_neighbor.c, which might lead to memory corruption and other potential consequences.
Published May 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/vf_colorconstancy.c: in slice_get_derivative, which crossfade_samples_fltp, which might lead to memory corruption and other potential consequences.
Published May 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap-based Buffer Overflow vulnerability exists FFmpeg 4.2 at libavfilter/vf_floodfill.c, which might lead to memory corruption and other potential consequences.
Published May 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap-based Buffer Overflow vulnerability exists FFmpeg 4.2 at libavfilter/vf_edgedetect.c in gaussian_blur, which might lead to memory corruption and other potential consequences.
Published May 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_vertically_8 at libavfilter/vf_avgblur.c, which could cause a remote Denial of Service.
Published May 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap-based Buffer Overflow Vulnerability exists FFmpeg 4.2 at libavfilter/vf_vmafmotion.c in convolution_y_8bit, which could let a remote malicious user cause a Denial of Service.
Published May 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
iWT Ltd FaceSentry Access Control System 6.4.8 suffers from an authenticated OS command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user via the 'strInIP' POST parameter in pingTest PHP script.
Published May 4, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at ff_fill_rectangle in libavfilter/drawutils.c, which might lead to memory corruption and other potential consequences.
Published May 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer Overflow vulnerability in FFmpeg 4.2 at filter_edges function in libavfilter/vf_yadif.c, which could let a remote malicious user cause a Denial of Service.
Published May 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer Overflow vulnerability in FFmpeg 4.2 in mov_write_video_tag due to the out of bounds in libavformat/movenc.c, which could let a remote malicious user obtain sensitive information, cause a Denial of Service, or execute arbitrary code.
Published May 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_frame at libavfilter/vf_fieldorder.c, which might lead to memory corruption and other potential consequences.
Published May 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer Overflow vulnerability in FFmpeg 4.2 in the build_diff_map function in libavfilter/vf_fieldmatch.c, which could let a remote malicious user cause a Denial of Service.
Published May 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer Overflow vulnerability in FFmpeg 4.2 at convolution_y_10bit in libavfilter/vf_vmafmotion.c, which could let a remote malicious user cause a Denial of Service.
Published May 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap-based Buffer Overflow vulnerability in FFmpeg 4.2 at libavcodec/get_bits.h when writing .mov files, which might lead to memory corruption and other potential consequences.
Published May 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Insecure permissions issue in zzcms 201910 via the reset any user password in /one/getpassword.php.
Published May 13, 2021 · Updated Aug 4, 2024