|
196011
|
9.8 |
CRITICAL
Network
|
fantastic_blog_cms_project
|
fantastic_blog_cms
|
SQL injection vulnerability in SourceCodester Fantastic Blog CMS v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to category.php.
|
CWE-89
SQL Injection
|
CVE-2021-26231
|
2024-11-21 14:55 |
2021-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196012
|
6.1 |
MEDIUM
Network
|
casap_automated_enrollment_system_project
|
casap_automated_enrollment_system
|
Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the user information to save_user…
|
CWE-79
Cross-site Scripting
|
CVE-2021-26230
|
2024-11-21 14:55 |
2021-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196013
|
9.8 |
CRITICAL
Network
|
casap_automated_enrollment_system_project
|
casap_automated_enrollment_system
|
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_stud.php.
|
CWE-89
SQL Injection
|
CVE-2021-26229
|
2024-11-21 14:55 |
2021-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196014
|
9.8 |
CRITICAL
Network
|
casap_automated_enrollment_system_project
|
casap_automated_enrollment_system
|
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_class1.php.
|
CWE-89
SQL Injection
|
CVE-2021-26228
|
2024-11-21 14:55 |
2021-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196015
|
6.1 |
MEDIUM
Network
|
casap_automated_enrollment_system_project
|
casap_automated_enrollment_system
|
Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the student information parameter…
|
CWE-79
Cross-site Scripting
|
CVE-2021-26227
|
2024-11-21 14:55 |
2021-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196016
|
5.5 |
MEDIUM
Local
|
teradici
|
pcoip_client
|
The fUSBHub driver in the PCoIP Software Client prior to version 21.07.0 had an error in object management during the handling of a variety of IOCTLs, which allowed an attacker to cause a denial of s…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2021-25701
|
2024-11-21 14:55 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196017
|
7.8 |
HIGH
Local
|
teradici
|
pcoip_client
|
The OpenSSL component of the Teradici PCoIP Software Client prior to version 21.07.0 was compiled without the no-autoload-config option, which allowed an attacker to elevate to the privileges of the …
|
CWE-426
Untrusted Search Path
|
CVE-2021-25699
|
2024-11-21 14:55 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196018
|
7.8 |
HIGH
Local
|
teradici
|
pcoip_standard_agent
|
The OpenSSL component of the Teradici PCoIP Standard Agent prior to version 21.07.0 was compiled without the no-autoload-config option, which allowed an attacker to elevate to the privileges of the r…
|
CWE-426
Untrusted Search Path
|
CVE-2021-25698
|
2024-11-21 14:55 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196019
|
7.8 |
HIGH
Local
|
teradici
|
pcoip
|
The USB vHub in the Teradici PCOIP Software Agent prior to version 21.07.0 would accept commands from any program, which may allow an attacker to elevate privileges by changing the flow of program ex…
|
NVD-CWE-Other
|
CVE-2021-25695
|
2024-11-21 14:55 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196020
|
8.8 |
HIGH
Network
|
fortinet
|
fortimail
|
The combination of various cryptographic issues in the session management of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6, including the encryption construction of the session cookie, may al…
|
NVD-CWE-noinfo
|
CVE-2021-26095
|
2024-11-21 14:55 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|