Unknown · CVSS Not scored
Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder variable to app/edit/folderdelete.php.
Published May 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) vulnerability in Halo 1.1.3 via post publish components in the manage panel, which lets a remote malicious user execute arbitrary code.
Published May 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.
Published May 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scriptiong (XSS) vulnerability exists in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script or HTML via an unsanitized "query_string" variable in app\devices\device_imports.php.
Published May 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script or HTML via an unsanitized "f" variable in app\vars\vars_textarea.php.
Published May 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer Overflow vulnerability exists in FFmpeg 4.1 via apng_do_inverse_blend in libavcodec/pngenc.c, which could let a remote malicious user cause a Denial of Service
Published May 24, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Directory Traversal vulnerability exists in FusionPBX 4.5.7, which allows a remote malicious user to create folders via the folder variale to app\edit\foldernew.php.
Published May 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.via the (1) folder, (2) filename, and (3) newfilename variables in app\edit\filerename.php.
Published May 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
MetInfo 7.0 beta is affected by a file modification vulnerability. Attackers can delete and modify ini files in app/system/language/admin/language_general.class.php and app/system/include/function/file.func.php.
Published May 24, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Denial of Service issue in FFmpeg 4.2 due to resource management errors via fftools/cmdutils.c.
Published May 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/aacpsy.c, which allows a remote malicious user to cause a Denial of Service.
Published May 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
FFmpeg 4.2 is affected by null pointer dereference passed as argument to libavformat/aviobuf.c, which could cause a Denial of Service.
Published May 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/aaccoder, which allows a remote malicious user to cause a Denial of Service
Published May 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/lpc.h, which allows a remote malicious user to cause a Denial of Service.
Published May 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
FFmpeg 4.1.3 is affected by a Divide By Zero issue via libavcodec/ratecontrol.c, which allows a remote malicious user to cause a Denial of Service.
Published May 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/dot1x process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
Published May 19, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type to image/jpeg and placing PHP code after the JPEG data, which could let a remote malicious user execute arbitrary PHP code.
Published May 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/traceroute process. An authenticated remote attacker can cause a Denial of Service due via the loop counter variable.
Published May 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
Published May 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Mikrotik RouterOs stable 6.46.3 suffers from a memory corruption vulnerability in the mactel process. An authenticated remote attacker can cause a Denial of Service due to improper memory access.
Published May 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Mikrotik RouterOs stable 6.47 suffers from a memory corruption vulnerability in the /nova/bin/diskd process. An authenticated remote attacker can cause a Denial of Service due to invalid memory access.
Published May 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /ram/pckg/wireless/nova/bin/wireless process. An authenticated remote attacker can cause a Denial of Service due via a crafted packet.
Published May 11, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Mikrotik RouterOs 6.44.6 (long-term tree) suffers from an assertion failure vulnerability in the btest process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.
Published May 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Ethereum 0xe933c0cd9784414d5f278c114904f5a84b396919#code.sol latest version is affected by a denial of service vulnerability in the affected payout function. Once the length of this array is too long, it will result in an exception. Attackers can make attacks by creating a series of account addresses.
Published May 24, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Mikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An authenticated remote attacker can cause a Denial of Service due to improper memory access.
Published May 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Mikrotik RouterOs before 6.47 (stable tree) suffers from a divison by zero vulnerability in the /nova/bin/lcdstat process. An authenticated remote attacker can cause a Denial of Service due to a divide by zero error.
Published May 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Mikrotik RouterOs stable 6.46.3 suffers from a memory corruption vulnerability in the log process. An authenticated remote attacker can cause a Denial of Service due to improper memory access.
Published May 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/resolver process. An authenticated remote attacker can cause a Denial of Service due to invalid memory access.
Published May 11, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Mikrotik RouterOs before 6.47 (stable tree) in the /ram/pckg/advanced-tools/nova/bin/netwatch process. An authenticated remote attacker can cause a Denial of Service due to a divide by zero error.
Published May 19, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Mikrotik RouterOs prior to stable 6.47 suffers from a memory corruption vulnerability in the /nova/bin/bfd process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
Published May 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Mikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An authenticated remote attacker can cause a Denial of Service due to improper memory access.
Published May 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Mikrotik RouterOs before 6.46.5 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/traceroute process. An authenticated remote attacker can cause a Denial of Service due via the loop counter variable.
Published May 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
Published May 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Boostnote 0.12.1, exporting to PDF contains opportunities for XSS attacks.
Published May 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An Information Disclosure vulnerability exists in dhcms 2017-09-18 when entering invalid characters after the normal interface, which causes an error that will leak the physical path.
Published May 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=group_perm.
Published May 6, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to book.php parameter, which could let a remote malicious user execute arbitrary code.
Published May 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via /admin/functions.php.
Published May 6, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Cross Site Request Forgery (CSRF) vulnerability exists in PHPOK 5.2.060 via admin.php?c=admin&f=save, which could let a remote malicious user execute arbitrary code.
Published May 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_edit.php, which could let a remote malicious user execute arbitrary code.
Published May 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Arbitrary File Upload vulnerability in Online Book Store v1.0 in admin_add.php, which may lead to remote code execution.
Published May 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_perm.
Published May 6, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection vulnerability in admin/group_list.php in piwigo v2.9.5, via the group parameter to delete.
Published May 6, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection vulnerability in admin/batch_manager.php in piwigo v2.9.5, via the filter_category parameter to admin.php?page=batch_manager.
Published May 6, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.
Published May 6, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Cross SIte Scripting (XSS) vulnerability exists in Dhcms 2017-09-18 in guestbook via the message board, which could let a remote malicious user execute arbitrary code.
Published May 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection vulnerability in Online Book Store v1.0 via the isbn parameter to edit_book.php, which could let a remote malicious user execute arbitrary code.
Published May 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Request Forgery (CSRF) vulnerability in puppyCMS v5.1 that can change the admin's password via /admin/settings.php.
Published May 6, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_delete.php, which could let a remote malicious user execute arbitrary code.
Published May 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection vulnerability in Online Book Store v1.0 via the pubid parameter to bookPerPub.php, which could let a remote malicious user execute arbitrary code.
Published May 5, 2021 · Updated Aug 4, 2024