Unknown · CVSS Not scored
Denial-of-service (DoS) vulnerability in the Multi-Factor Authentication module in Liferay DXP 7.3 before fix pack 1 allows remote authenticated attackers to prevent any user from authenticating by (1) enabling Time-based One-time password (TOTP) on behalf of the other user or (2) modifying the other user's TOTP shared secret.
Published May 16, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 20 and 7.2 before fix pack 10 may provide overly verbose error messages, which allows remote attackers to use the contents of error messages to help launch another, more focused attacks via crafted inputs.
Published May 16, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in the Asset module's categories administration page in Liferay Portal 7.3.4 allows remote attackers to inject arbitrary web script or HTML via the site name.
Published May 16, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file on the server.
Published Oct 11, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Insecure permission of chmod command on rConfig server 3.9.6 exists. After installing rConfig apache user may execute chmod as root without password which may let an attacker with low privilege to gain root access on server.
Published Oct 11, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
rConfig 3.9.6 is affected by SQL Injection. A user must be authenticated to exploit the vulnerability. If --secure-file-priv in MySQL server is not set and the Mysql server is the same as rConfig, an attacker may successfully upload a webshell to the server and access it remotely.
Published Oct 11, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Plixer Scrutinizer 19.0.2 is affected by: SQL Injection. The impact is: obtain sensitive information (remote).
Published Jun 30, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked.
Published Jun 16, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
The /password.html page of the Web management interface of the Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) contains the administrator account password in plaintext. The page can be intercepted on HTTP.
Published Mar 29, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
The Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) Web management administrator password can be changed by sending a specially crafted HTTP GET request. The administrator username has to be known (default:admin) whereas no previous authentication is required.
Published Mar 29, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
The text-to-speech engine in libretro RetroArch for Windows 1.9.0 passes unsanitized input to PowerShell through platform_win32.c via the accessibility_speak_windows function, which allows attackers who have write access on filesystems that are used by RetroArch to execute code via command injection using specially a crafted file and directory names.
Published Apr 7, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at risk causing a potential denial of service (DoS).
Published May 3, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.
Published Apr 4, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the framework is exposed with layouts, menus and functionalities.
Published Apr 14, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
The Web Interface for OpenWRT LuCI version 19.07 and lower has been discovered to have a cross-site scripting vulnerability.
Published May 25, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue was discovered in MoFi Network MOFI4500-4GXeLTE-V2 3.5.6-xnet-5052 allows attackers to bypass the authentication and execute arbitrary code via crafted HTTP request.
Published Sep 8, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via any "Add" sections, such as Add Card Building & Floor, or others in the Name and Code Parameters.
Published Mar 15, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Centreon version 20.10.2 is affected by a cross-site scripting (XSS) vulnerability. The dep_description (Dependency Description) and dep_name (Dependency Name) parameters are vulnerable to stored XSS. A user has to log in and go to the Configuration > Notifications > Hosts page.
Published May 26, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the class_name parameter to update_class.php.
Published Jul 22, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Yeastar NeoGate TG400 91.3.0.3 devices are affected by Directory Traversal. An authenticated user can decrypt firmware and can read sensitive information, such as a password or decryption key.
Published Feb 19, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.
Published Feb 27, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A cross site scripting (XSS) vulnerability in Genesys Workforce Management 8.5.214.20 can occur (during record deletion) via the Time-off parameter.
Published Dec 15, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditFolder.php.
Published Mar 18, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditDocument.php.
Published Mar 18, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
AVideo/YouPHPTube 10.0 and prior is affected by multiple reflected Cross Script Scripting vulnerabilities via the videoName parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.
Published Nov 1, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write files on filesystem using flag and code variables in file save.php.
Published Nov 1, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the u parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.
Published Nov 1, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the searchPhrase parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.
Published Nov 1, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve databases information such as application passwords hashes.
Published Nov 1, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
AdTran Personal Phone Manager 10.8.1 software is vulnerable to an issue that allows for exfiltration of data over DNS. This could allow for exposed AdTran Personal Phone Manager web servers to be used as DNS redirectors to tunnel arbitrary data over DNS. NOTE: The affected appliances NetVanta 7060 and NetVanta 7100 are considered End of Life and as such this issue will not be patched.
Published Apr 20, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. These issues impact at minimum versions 10.8.1 and below but potentially impact later versions as well since they have not previously been disclosed. Only version 10.8.1 was able to be confirmed during primary research. NOTE: The affected appliances NetVanta 7060 and NetVanta 7100 are considered End of Life and as such this issue will not be patched.
Published Apr 20, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
The AdTran Personal Phone Manager software is vulnerable to an authenticated stored cross-site scripting (XSS) issues. These issues impact at minimum versions 10.8.1 and below but potentially impact later versions as well since they have not previously been disclosed. Only version 10.8.1 was able to be confirmed during primary research. NOTE: The affected appliances NetVanta 7060 and NetVanta 7100 are considered End of Life and as such this issue will not be patched.
Published Apr 20, 2021 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal his/her session cookies or it can be chained with the previous bugs to get one-click remote command execution (RCE) on the Nagios XI server.
Published Feb 15, 2021 · Updated Jul 9, 2026
High · CVSS 8.8 · CISA KEV
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.
Published Feb 15, 2021 · Updated Jul 9, 2026
High · CVSS 8.8 · CISA KEV
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.
Published Feb 15, 2021 · Updated Jul 9, 2026
High · CVSS 8.8 · CISA KEV
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.
Published Feb 15, 2021 · Updated Jul 9, 2026
Medium · CVSS 4.3
In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.
Published Apr 2, 2021 · Updated Jul 7, 2026
Medium · CVSS 6.1
nopCommerce 4.40.3 is vulnerable to XSS in the Product Name at /Admin/Product/Edit/[id]. Each time a user views the product in the shop, the XSS payload fires.
Published Oct 3, 2025 · Updated Jul 5, 2026
Unknown · CVSS Not scored
An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.
Published Apr 11, 2022 · Updated Jul 5, 2026
Unknown · CVSS Not scored
An Access Control vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 due to an undocumented backdoor account. A malicious user can log in using the backdor account with admin highest privileges and obtain system control.
Published Apr 11, 2022 · Updated Jul 5, 2026
Unknown · CVSS Not scored
A Directory Traversal vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 via the page GET parameter in index.php.
Published Apr 11, 2022 · Updated Jul 5, 2026
Unknown · CVSS Not scored
Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the magick binary.
Published Oct 5, 2021 · Updated Jul 4, 2026
Unknown · CVSS Not scored
Afian FileRun 2021.03.26 allows XSS when an administrator encounters a crafted document during use of the HTML Editor for a preview or edit action.
Published Oct 5, 2021 · Updated Jul 4, 2026
Unknown · CVSS Not scored
Winner (aka ToneWinner) desktop speakers through 2021-08-09 allow remote attackers to recover speech signals from the power-indicator LED via a telescope and an electro-optical sensor, aka a "Glowworm" attack.
Published Aug 10, 2021 · Updated Jul 4, 2026
Unknown · CVSS Not scored
Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the ffmpeg binary.
Published Oct 5, 2021 · Updated Jul 4, 2026
Unknown · CVSS Not scored
Afian FileRun 2021.03.26 allows stored XSS via an HTTP X-Forwarded-For header that is mishandled when rendering Activity Logs.
Published Oct 5, 2021 · Updated Jul 4, 2026
Unknown · CVSS Not scored
In Eclipse Mosquitto versions 2.0.7 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0.
Published Jul 27, 2021 · Updated Jul 2, 2026
Medium · CVSS 5.3
A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1 and older that could expose files or directory content when access from an attacker is not restricted or incorrectly restricted.
Published Jun 11, 2021 · Updated Jun 29, 2026
High · CVSS 7.7
Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the official repository pointing to an unreviewed personal fork of a contributor with write access. No releases were published with these tags; a project was exposed only if it defined a git-based dependency referencing one of the affected tags (for example, parse-server#4.9.3). The code behind the tags was not reviewed or approved, and although no malicious code was identified, the introduction of security vulnerabilities could not be ruled out.
Published Jun 25, 2026 · Updated Jun 26, 2026
High · CVSS 7.7
Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attackers could exploit this by specifying affected version tags in dependency declarations to execute unreviewed and potentially malicious code.
Published Jun 25, 2026 · Updated Jun 26, 2026