7.8
    High

    CVE-2021-46363

    Last Modified: 21 Nov 2024

    An issue in the Export function of Magnolia v6.2.3 and below allows attackers to perform Formula Injection attacks via crafted CSV/XLS files. These formulas may result in arbitrary code execution on a victim's computer when opening the exported files with Microsoft Excel.

    Published:11 Feb 2022
    9.8
    Critical

    CVE-2021-46362

    Last Modified: 21 Nov 2024

    A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a crafted payload entered into the fullname parameter.

    Published:11 Feb 2022
    9.8
    Critical

    CVE-2021-46361

    Last Modified: 21 Nov 2024

    An issue in the Freemark Filter of Magnolia CMS v6.2.11 and below allows attackers to bypass security restrictions and execute arbitrary code via a crafted FreeMarker payload.

    Published:11 Feb 2022
    8.8
    High

    CVE-2021-46360

    Last Modified: 13 Jun 2023

    Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrary code via uploading a PHP shell through /adminzone/index.php?page=admin-commandr.

    Source:Sarang Tumne
    Published:9 Feb 2022
    7.5
    High

    CVE-2021-46354

    Last Modified: 21 Feb 2022

    Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Addr" in cmd site. The ability to send requests to other systems can allow the vulnerable server to filtrate the real IP of the web server or increase the attack surface.

    Source:Daniel Morales
    Published:9 Feb 2022
    8.1
    High

    CVE-2021-46143

    Last Modified: 5 May 2025

    In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize.

    Published:6 Jan 2022
    5.4
    Medium

    CVE-2021-46108

    Last Modified: 21 Nov 2024

    D-Link DSL-2730E CT-20131125 devices allow XSS via the username parameter to the password page in the maintenance configuration.

    Published:18 Feb 2022
    4.8
    Medium

    CVE-2021-46080

    Last Modified: 21 Nov 2024

    A Cross Site Request Forgery (CSRF) vulnerability exists in Vehicle Service Management System 1.0. An successful CSRF attacks leads to Stored Cross Site Scripting Vulnerability.

    Published:6 Jan 2022
    7.2
    High

    CVE-2021-46079

    Last Modified: 21 Nov 2024

    An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can upload malicious files leading to Html Injection.

    Published:6 Jan 2022
    4.8
    Medium

    CVE-2021-46078

    Last Modified: 21 Nov 2024

    An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can upload malicious files leading to a Stored Cross-Site Scripting vulnerability.

    Published:6 Jan 2022
    8.8
    High

    CVE-2021-46076

    Last Modified: 21 Nov 2024

    Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in multiple endpoints it leading to Code Execution.

    Published:6 Jan 2022
    7.2
    High

    CVE-2021-46075

    Last Modified: 21 Nov 2024

    A Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users can access the admin resources and perform CRUD Operations.

    Published:6 Jan 2022
    4.8
    Medium

    CVE-2021-46074

    Last Modified: 21 Nov 2024

    A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the Settings Section in login panel.

    Published:6 Jan 2022
    4.8
    Medium

    CVE-2021-46073

    Last Modified: 21 Nov 2024

    A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the User List Section in login panel.

    Published:6 Jan 2022
    4.8
    Medium

    CVE-2021-46072

    Last Modified: 21 Nov 2024

    A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service List Section in login panel.

    Published:6 Jan 2022
    4.8
    Medium

    CVE-2021-46071

    Last Modified: 21 Nov 2024

    A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Category List Section in login panel.

    Published:6 Jan 2022
    4.8
    Medium

    CVE-2021-46070

    Last Modified: 21 Nov 2024

    A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service Requests Section in login panel.

    Published:6 Jan 2022
    4.8
    Medium

    CVE-2021-46069

    Last Modified: 21 Nov 2024

    A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Mechanic List Section in login panel.

    Published:6 Jan 2022
    4.8
    Medium

    CVE-2021-46068

    Last Modified: 21 Nov 2024

    A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the My Account Section in login panel.

    Published:6 Jan 2022
    9.8
    Critical

    CVE-2021-46067

    Last Modified: 21 Nov 2024

    In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

    Published:6 Jan 2022
    5.4
    Medium

    CVE-2021-46005

    Last Modified: 21 Nov 2024

    Sourcecodester Car Rental Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via vehicalorcview parameter.

    Published:18 Jan 2022
    8.8
    High

    CVE-2021-45960

    Last Modified: 5 May 2025

    In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

    Published:1 Jan 2022
    5.3
    Medium

    CVE-2021-45901

    Last Modified: 16 Feb 2022

    The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists.

    Source:Victor Hanna
    Published:10 Feb 2022
    8.8
    High

    CVE-2021-45897

    Last Modified: 21 Nov 2024

    SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution.

    Published:28 Jan 2022
    9.8
    Critical

    CVE-2021-45814

    Last Modified: 5 Jan 2022

    Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel with an administrative account.

    Source:Momen Eldawakhly
    Published:28 Dec 2021
    4.6
    Medium

    CVE-2021-45783

    Last Modified: 4 Nov 2022

    Bookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to obtain sensitive information.

    Source:Clement MAILLIOUX
    Published:5 May 2022
    5.4
    Medium

    CVE-2021-45745

    Last Modified: 21 Nov 2024

    A Stored Cross Site Scripting (XSS) vulnerability exists in Bludit 3.13.1 via the About Plugin in login panel.

    Published:6 Jan 2022
    5.4
    Medium

    CVE-2021-45744

    Last Modified: 21 Nov 2024

    A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel.

    Published:6 Jan 2022
    7.5
    High

    CVE-2021-45485

    Last Modified: 21 Nov 2024

    In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.

    Published:31 May 2021
    9.8
    Critical

    CVE-2021-45468

    Last Modified: 21 Nov 2024

    Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encoding: gzip" to evade WAF security controls and send malicious HTTP POST requests to web servers behind the WAF.

    Published:14 Jan 2022
    9.8
    Critical

    CVE-2021-45428

    Last Modified: 11 May 2022

    TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HTML and CGI formats.

    Source:Ahmed Alroky
    Published:3 Jan 2022
    6.1
    Medium

    CVE-2021-45425

    Last Modified: 5 Jan 2022

    Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScript codes.

    Source:Momen Eldawakhly
    Published:28 Dec 2021
    6.1
    Medium

    CVE-2021-45416

    Last Modified: 21 Nov 2024

    Reflected Cross-site scripting (XSS) vulnerability in RosarioSIS 8.2.1 allows attackers to inject arbitrary HTML via the search_term parameter in the modules/Scheduling/Courses.php script.

    Published:1 Feb 2022
    9.8
    Critical

    CVE-2021-45232

    Last Modified: 21 Nov 2024

    In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use the interface of framework `gin` thus bypassing the authentication.

    Published:27 Dec 2021
    5.9
    Medium

    CVE-2021-45105

    Last Modified: 25 Aug 2026

    Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

    Published:18 Dec 2021
    9.8
    Critical

    CVE-2021-45092

    Last Modified: 21 Feb 2022

    Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.

    Source:Daniel Morales
    Published:16 Dec 2021
    5.5
    Medium

    CVE-2021-45067

    Last Modified: 21 Nov 2024

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an Access of Memory Location After End of Buffer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published:14 Jan 2022
    9
    Critical

    CVE-2021-45046

    Last Modified: 27 Oct 2025

    It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.

    Published:14 Dec 2021
    7.5
    High

    CVE-2021-45043

    Last Modified: 15 Dec 2021

    HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_Language parameter.

    Source:Momen Eldawakhly
    Published:15 Dec 2021
    8.8
    High

    CVE-2021-45041

    Last Modified: 21 Nov 2024

    SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date.

    Published:19 Dec 2021
    6.1
    Medium

    CVE-2021-45026

    Last Modified: 21 Nov 2024

    ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS).

    Published:17 Jun 2022
    8.8
    High

    CVE-2021-45010

    Last Modified: 16 Mar 2022

    A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to upload malicious PHP files to the webroot, leading to code execution.

    Source:FEBIN MON SAJI
    Published:15 Mar 2022
    8.8
    High

    CVE-2021-45008

    Last Modified: 21 Nov 2024

    Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users

    Published:21 Feb 2022
    6.5
    Medium

    CVE-2021-45007

    Last Modified: 21 Nov 2024

    Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. NOTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users

    Published:20 Feb 2022
    8.8
    High

    CVE-2021-44967

    Last Modified: 20 Feb 2025

    A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP code, and can only be installed by a superadmin, and therefore the security model is not violated by this finding.

    Published:22 Feb 2022
    6.1
    Medium

    CVE-2021-44916

    Last Modified: 10 Jan 2022

    Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad value is passed to the routine via a URL, malicious JavaScript code can be executed in the victim's browser.

    Source:Dominic Clark
    Published:20 Dec 2021
    Unknown

    CVE-2021-44910

    https://github.com/W000i/CVE-2021-44910_SpringBlade

    Unknown

    CVE-2021-44909

    https://github.com/g1thub3r1st4/CVE-2021-44909

    9.8
    Critical

    CVE-2021-44906

    Last Modified: 21 Nov 2024

    Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).

    Published:10 Mar 2022
    7.8
    High

    CVE-2021-44852

    Last Modified: 21 Nov 2024

    An issue was discovered in BS_RCIO64.sys in Biostar RACING GT Evo 2.1.1905.1700. A low-integrity process can open the driver's device object and issue IOCTLs to read or write to arbitrary physical memory locations (or call an arbitrary address), leading to execution of arbitrary code. This is associated with 0x226040, 0x226044, and 0x226000.

    Published:1 Jan 2022