Unknown · CVSS Not scored
The dbName parameter in ajaxDbInstall.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a SQL injection and access sensitive database information.
Published Aug 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file.
Published Aug 17, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Request Forgery (CSRF) vulnerability in Express cart v1.1.16 allows attackers to add an administrator account, add discount code or other unspecified impacts.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.2 when adding a blog and then editing an image file.
Published Aug 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The gf_dash_segmenter_probe_input function in GPAC v0.8 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
Published Aug 4, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
CMS Made Simple (CMSMS) 2.2.14 allows stored XSS via the Extensions > Fie Picker..
Published Aug 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Rapid Software LLC Rapid SCADA 5.8.0 is affected by a local privilege escalation vulnerability in the ScadaAgentSvc.exe executable file. An attacker can obtain admin privileges by placing a malicious .exe file in the application and renaming it ScadaAgentSvc.exe, which would result in executing the binary as NT AUTHORITY\SYSTEM in a Windows operating system. For example, an attacker can plant a reverse shell from a low privileged user account and by restarting the computer, the malicious service will be started as NT AUTHORITY\SYSTEM by giving the attacker full system access to the remote PC.
Published Aug 14, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A File Upload Vulnerability in PNotes - Andrey Gruber PNotes.NET v3.8.1.2 allows a local attacker to execute arbitrary code via the Miscellaneous " External Programs by uploading the malicious .exe file to the external program.
Published Aug 14, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticated attackers to execute arbitrary code.
Published Aug 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A remote code execution (RCE) vulnerability in the \Playsong.php component of cscms v4.1 allows attackers to execute arbitrary commands.
Published Aug 30, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross-Site Scripting (XSS) vulnerability in Subrion 4.2.1 via the title when adding a page.
Published Aug 6, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information.
Published Aug 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
/graphStatus/displayServiceStatus.php in Centreon 19.10.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the RRDdatabase_path parameter.
Published Aug 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A SQL injection vulnerability in /oa.php?c=Staff&a=read of Find a Place LJCMS v 1.3 allows attackers to access sensitive database information via a crafted POST request.
Published Aug 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A stored cross site scripting (XSS) vulnerability in the web_attr_2 field of Eyoucms v1.4.1 allows authenticated attackers to execute arbitrary web scripts or HTML.
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap-use-after-free in the av_freep function in libavutil/mem.c of FFmpeg 4.2 allows attackers to execute arbitrary code.
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A global buffer overflow in the set_fill component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ge format.
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An arbitrary file upload in the <input type="file" name="user_image"> component of NewsOne CMS v1.1.0 allows attackers to webshell and execute arbitrary commands.
Published Aug 11, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A global buffer overflow in the set_color component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ge format.
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A stored cross site scripting (XSS) vulnerability in the web_copyright field of Eyoucms v1.4.1 allows authenticated attackers to execute arbitrary web scripts or HTML.
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ptk format.
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap-use-after-free in the mpeg_mux_write_packet function in libavformat/mpegenc.c of FFmpeg 4.2 allows to cause a denial of service (DOS) via a crafted avi file.
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap-based buffer overflow in the sixel_encoder_output_without_macro function in encoder.c of Libsixel 1.8.4 allows attackers to cause a denial of service (DOS) via converting a crafted PNG file into Sixel format.
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A global buffer overflow in the genmp_writefontmacro_latex component in genmp.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into mp format.
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A stack-based buffer overflow in the put_arrow() component in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pict2e format.
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A global buffer overflow in the shade_or_tint_name_after_declare_color in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pstricks format.
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code.
Published Aug 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pstricks format.
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A global buffer overflow in the put_font in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pict2e format.
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary files, enumerate folders and scan internal ports via crafted XML license file.
Published Aug 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Segmentation Fault issue discovered in in ieee_segment function in outieee.c in nasm 2.14.03 and 2.15 allows remote attackers to cause a denial of service via crafted assembly file.
Published Aug 22, 2023 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A cross site scripting (XSS) vulnerability in the background search function of Maccms10 allows attackers to execute arbitrary web scripts or HTML via the 'wd' parameter.
Published Aug 11, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in PostgreSQL 12.2 allows attackers to cause a denial of service via repeatedly sending SIGHUP signals. NOTE: this is disputed by the vendor because untrusted users cannot send SIGHUP signals; they can only be sent by a PostgreSQL superuser, a user with pg_reload_conf access, or a user with sufficient privileges at the OS level (the postgres account or the root account).
Published Aug 22, 2023 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A cross site request forgery (CSRF) in Wage-CMS 1.5.x-dev allows attackers to arbitrarily add users.
Published Aug 6, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a crafted html file running with the default configurations.
Published Aug 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An arbitrary file deletion vulnerability exists within Maccms10.
Published Aug 11, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execute arbitrary code via adding a character to the end of the uploaded file's name.
Published Aug 11, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A stored cross site scripting (XSS) vulnerability in /admin.php?mod=user&act=addnew of PopojiCMS 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the E-Mail field.
Published Aug 6, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Bento4 v1.5.1.0. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a denial of service (program crash), as demonstrated by mp42aac.
Published Aug 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A SQL injection in the /admin/?n=logs&c=index&a=dolist component of Metinfo 7.0 allows attackers to access sensitive database information.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An arbitrary file upload vulnerability in the move_uploaded_file() function of LJCMS v4.3 allows attackers to execute arbitrary code.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A cross site scripting (XSS) vulnerability in the /domains/cost-by-owner.php component of Domainmod 4.13 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "or Expiring Between" parameter.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A stored cross site scripting (XSS) vulnerability in /admin/snippets.php of GetSimple CMS 3.4.0a allows attackers to execute arbitrary web scripts or HTML via crafted payload in the Edit Snippets module.
Published Aug 6, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An information disclosure vulnerability in upload.php of PopojiCMS 1.2 leads to physical path disclosure of the host when 'name = "file" is deleted during file uploads.
Published Aug 6, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A stored cross site scripting (XSS) vulnerability in index.php/legend/6.html of UK CMS v1.1.10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Comments section.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ajax_policy_generator in admin/modules/cli-policy-generator/classes/class-policy-generator-ajax.php in GDPR Cookie Consent (cookie-law-info) 1.8.2 and below plugin for WordPress, allows authenticated stored XSS and privilege escalation.
Published Aug 21, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A cross site scripting (XSS) vulnerability in the /segments/edit.php component of Domainmod 4.13 allows attackers to execute arbitrary web scripts or HTML via the Segment Name parameter.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In \lib\admin\action\dataaction.class.php in Gxlcms v1.1, SQL Injection exists via the $filename parameter.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A cross-site request forgery (CSRF) in /admin/maintenance/ of Domainmod 4.13 allows attackers to arbitrarily delete logs.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) vulnerability exists in EyouCMS1.3.6 in the basic_information area.
Published Aug 19, 2021 · Updated Aug 4, 2024