Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-41694 1 Globaldatingsoftware 1 Premiumdatingscript 2021-12-14 5.0 MEDIUM 9.8 CRITICAL
An Incorrect Access Control vulnerability exists in Premiumdatingscript 4.2.7.7 via the password change procedure in requests\user.php.
CVE-2021-23561 1 C2fo 1 Comb 2021-12-14 7.5 HIGH 9.8 CRITICAL
All versions of package comb are vulnerable to Prototype Pollution via the deepMerge() function.
CVE-2021-41695 1 Globaldatingsoftware 1 Premiumdatingscript 2021-12-14 7.5 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Premiumdatingscript 4.2.7.7 via the ip parameter in connect.php. .
CVE-2021-41696 1 Globaldatingsoftware 1 Premiumdatingscript 2021-12-14 4.0 MEDIUM 6.5 MEDIUM
An authentication bypass (account takeover) vulnerability exists in Premiumdatingscript 4.2.7.7 due to a weak password reset mechanism in requests\user.php.
CVE-2021-41697 1 Globaldatingsoftware 1 Premiumdatingscript 2021-12-14 4.3 MEDIUM 6.1 MEDIUM
A reflected Cross Site Scripting (XSS) vulnerability exists in Premiumdatingscript 4.2.7.7 via the aerror_description parameter in assets/sources/instagram.php script.
CVE-2021-27983 1 Max-3000 1 Maxsite Cms 2021-12-14 7.5 HIGH 9.8 CRITICAL
Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page.
CVE-2021-27984 1 Pluck-cms 1 Pluck 2021-12-14 7.5 HIGH 8.1 HIGH
In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.
CVE-2021-38937 1 Ibm 1 Powervm Hypervisor 2021-12-14 6.8 MEDIUM 6.5 MEDIUM
IBM PowerVM Hypervisor FW940, FW950, and FW1010 could allow an authenticated user to cause the system to crash using a specially crafted IBMi Hypervisor call. IBM X-Force ID: 210894.
CVE-2021-38917 1 Ibm 1 Powervm Hypervisor 2021-12-14 9.4 HIGH 9.1 CRITICAL
IBM PowerVM Hypervisor FW860, FW940, and FW950 could allow an attacker that gains service access to the FSP can read and write arbitrary host system memory through a series of carefully crafted service procedures. IBM X-Force ID: 210018.
CVE-2021-43410 1 Apache 1 Airavata Django Portal 2021-12-14 5.0 MEDIUM 5.3 MEDIUM
Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some HTTP request parameters are logged without first being escaped. Versions affected: master branch before commit 3c5d8c7 [1] of airavata-django-portal [1] https://github.com/apache/airavata-django-portal/commit/3c5d8c72bfc3eb0af8693a655a5d60f9273f8170
CVE-2021-4092 1 Yetiforce 1 Yetiforce Customer Relationship Management 2021-12-13 4.3 MEDIUM 4.3 MEDIUM
yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3829 1 Openwhyd 1 Openwhyd 2021-12-13 5.8 MEDIUM 6.1 MEDIUM
openwhyd is vulnerable to URL Redirection to Untrusted Site
CVE-2021-36911 1 Comment Engine Pro Project 1 Comment Engine Pro 2021-12-13 3.5 LOW 5.4 MEDIUM
Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Comment Engine Pro plugin (versions <= 1.0), could be exploited by users with Editor or higher role.
CVE-2021-41246 1 Auth0 1 Express Openid Connect 2021-12-13 6.8 MEDIUM 8.8 HIGH
Express OpenID Connect is express JS middleware implementing sign on for Express web apps using OpenID Connect. Versions before and including `2.5.1` do not regenerate the session id and session cookie when user logs in. This behavior opens up the application to various session fixation vulnerabilities. Versions `2.5.2` contains a patch for this issue.
CVE-2021-37941 1 Elastic 1 Apm Agent 2021-12-13 4.4 MEDIUM 7.8 HIGH
A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious file to an application running with the APM Java agent. Using this vector, a malicious or compromised user account could use the agent to run commands at a higher level of permissions than they possess. This vulnerability affects users that have set up the agent via the attacher cli 3, the attach API 2, as well as users that have enabled the profiling_inferred_spans_enabled option
CVE-2021-41450 1 Tp-link 2 Archer Ax10 V1, Archer Ax10 V1 Firmware 2021-12-13 5.0 MEDIUM 7.5 HIGH
An HTTP request smuggling attack in TP-Link AX10v1 before v1_211117 allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.
CVE-2021-40282 1 Zzcms 1 Zzcms 2021-12-13 6.5 MEDIUM 8.8 HIGH
An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, abd 2021 in dl/dl_download.php. when registering ordinary users.
CVE-2021-40281 1 Zzcms 1 Zzcms 2021-12-13 6.5 MEDIUM 8.8 HIGH
An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 in dl/dl_print.php when registering ordinary users.
CVE-2021-40280 1 Zzcms 1 Zzcms 2021-12-13 6.5 MEDIUM 7.2 HIGH
An SQL Injection vulnerablitly exits in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/dl_sendmail.php.
CVE-2021-40279 1 Zzcms 1 Zzcms 2021-12-13 6.5 MEDIUM 7.2 HIGH
An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/bad.php.