Unknown · CVSS Not scored
SQL Injection in Wuzhi CMS v4.1.0 allows remote attackers to obtain sensitive information via the 'flag' parameter in the component '/coreframe/app/order/admin/index.php'.
Published Aug 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer Overflow vulnerability in one_one_mapping function in progs/dump_entry.c:1373 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Published Aug 22, 2023 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary code via line 54 of the component 'simiki/blob/master/simiki/generators.py'.
Published Aug 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Command Injection in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary system commands via line 64 of the component 'simiki/blob/master/simiki/config.py'.
Published Aug 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the contents of typename.inc are under an attacker's control.
Published Aug 24, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) in S-CMS v1.0 allows remote attackers to execute arbitrary code via the component '/admin/tpl.php?page='.
Published Aug 31, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) in Mezzanine v4.3.1 allows remote attackers to execute arbitrary code via the 'Description' field of the component 'admin/blog/blogpost/add/'. This issue is different than CVE-2018-16632.
Published Aug 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An invalid memory access in the decode function in iptc.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.
Published Aug 23, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file.
Published Aug 19, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Halo blog 1.2.0 allows users to submit comments on blog posts via /api/content/posts/comments. The javascript code supplied by the attacker will then execute in the victim user's browser.
Published Aug 26, 2020 · Updated Aug 4, 2024
Low · CVSS 3.3
A heap-based buffer overflow in the libexe_io_handle_read_coff_optional_header function of libyal libexe before 20181128. NOTE: the vendor has disputed this as described in libyal/libexe issue 1 on GitHub
Published Aug 19, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Published Aug 22, 2023 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bl-kereln/ajax/upload-logo.php'.
Published Aug 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
zrlog v2.1.0 has a vulnerability with the permission check. If admin account is logged in, other unauthorized users can download the database backup file directly.
Published Aug 25, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin/custom/blog-plugin/add'.
Published Aug 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer Overflow in Tcpreplay v4.3.2 allows attackers to cause a Denial of Service via the 'do_checksum' function in 'checksum.c'. It can be triggered by sending a crafted pcap file to the 'tcpreplay-edit' binary. This issue is different than CVE-2019-8381.
Published Aug 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin/submit-articles'.
Published Aug 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An use-after-free vulnerability in the libpff_item_tree_create_node function of libyal Libpff before 20180623 allows attackers to cause a denial of service (DOS) or execute arbitrary code via a crafted pff file.
Published Aug 19, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToenizer.cpp'.
Published Aug 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An information disclosure vulnerability exists in the EPA protocol of Dut Computer Control Engineering Co.'s PLC MAC1100.
Published Aug 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An arbitrary memory access vulnerability in the EPA protocol of Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to read the contents of any variable area.
Published Aug 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer Overflow in Netwide Assembler (NASM) v2.15.xx allows attackers to cause a denial of service via 'crc64i' in the component 'nasmlib/crc64'. This issue is different than CVE-2019-7147.
Published Aug 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) in Typora v0.9.65 allows attackers to execute arbitrary code via mathjax syntax due to a mathjax configuration error in the mathematical formula blocks. This is a different vulnerability from CVE-2020-18221.
Published Aug 19, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_p_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
Published Aug 23, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocity) files.
Published Aug 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_b_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
Published Aug 23, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Unrestricted File Upload in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the component 'admin/upload_file_do.php'.
Published Aug 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to cause persistent denial of service (DOS) via a crafted packet.
Published Aug 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An information disclosure vulnerability exists within Dut Computer Control Engineering Co.'s PLC MAC1100.
Published Aug 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap buffer overflow in /src/dds_stream.c of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.
Published Aug 23, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/cms/user.py'.
Published Aug 16, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the 'Username' parameter in the component 'quokka/admin/actions.py'.
Published Aug 16, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Unrestricted Upload of File with Dangerous Type in Django-Widgy v0.8.4 allows remote attackers to execute arbitrary code via the 'image' widget in the component 'Change Widgy Page'.
Published Aug 16, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/utils/atom.py'.
Published Aug 16, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to execute arbitrary code.
Published Aug 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A segmentation violation in the Iec104_Deal_FirmUpdate function of IEC104 v1.0 allows attackers to cause a denial of service (DOS).
Published Aug 23, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection in AiteCMS v1.0 allows remote attackers to execute arbitrary code via the component "aitecms/login/diy_list.php".
Published Aug 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A stack buffer overflow in /ddsi/q_bitset.h of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.
Published Aug 23, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to gain access to the system and escalate privileges via a crafted packet.
Published Aug 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/core/content/views.py'.
Published Aug 16, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A segmentation violation in the Iec104_Deal_I function of IEC104 v1.0 allows attackers to cause a denial of service (DOS).
Published Aug 23, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the application not invalidating a user's authentication token upon logout, which allows for replaying packets.
Published Aug 16, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) in Lin-CMS-Flask v0.1.1 allows remote attackers to execute arbitrary code by entering scripts in the the 'Username' parameter of the in component 'app/api/cms/user.py'.
Published Aug 16, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) in MineWebCMS v1.7.0 allows remote attackers to execute arbitrary code by injecting malicious code into the 'Title' field of the component '/admin/news'.
Published Aug 6, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) vulnerabilty exists in Hucart CMS 5.7.4 is via the mes_title field. The first user inserts a malicious script into the header field of the outbox and sends it to other users. When other users open the email, the malicious code will be executed.
Published Aug 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) vulnerability exists in DamiCMS v6.0.6 via the title parameter in the doadd function in LabelAction.class.php.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the upurl function in Page.php.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Stored cross-site scripting (XSS) vulnerability in the Name of application field found in the General Configuration page in Rukovoditel 2.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to rukovoditel_2.4.1/install/index.php.
Published Aug 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Request Forgery (CSRF) vulnerability exists in v2.0.0 in video_list.php, which can let a malicious user delete a video message.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Request Forgery (CSRF) vulnerability in bycms v1.3 via admin.php/systems/index/module_id/70/group_id/1.html.
Published Aug 12, 2021 · Updated Aug 4, 2024