|
196351
|
8.8 |
HIGH
Adjacent
|
netop
|
vision_pro
|
Cleartext transmission of sensitive information in Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to gather credentials including Windows login usernames and pass…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2021-27194
|
2024-11-21 14:57 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196352
|
9.8 |
CRITICAL
Network
|
netop
|
vision_pro
|
Incorrect default permissions vulnerability in the API of Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to read and write files on the remote machine with system…
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-27193
|
2024-11-21 14:57 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196353
|
7.8 |
HIGH
Local
|
netop
|
vision_pro
|
Local privilege escalation vulnerability in Windows clients of Netop Vision Pro up to and including 9.7.1 allows a local user to gain administrator privileges whilst using the clients.
|
CWE-269
Improper Privilege Management
|
CVE-2021-27192
|
2024-11-21 14:57 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196354
|
7.5 |
HIGH
Network
|
doctor_appointment_system_project
|
doctor_appointment_system
|
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.
|
CWE-89
SQL Injection
|
CVE-2021-27320
|
2024-11-21 14:57 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196355
|
7.5 |
HIGH
Network
|
doctor_appointment_system_project
|
doctor_appointment_system
|
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email parameter.
|
CWE-89
SQL Injection
|
CVE-2021-27319
|
2024-11-21 14:57 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196356
|
7.5 |
HIGH
Network
|
doctor_appointment_system_project
|
doctor_appointment_system
|
Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname parameter.
|
CWE-89
SQL Injection
|
CVE-2021-27316
|
2024-11-21 14:57 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196357
|
7.5 |
HIGH
Network
|
doctor_appointment_system_project
|
doctor_appointment_system
|
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter.
|
CWE-89
SQL Injection
|
CVE-2021-27315
|
2024-11-21 14:57 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196358
|
6.1 |
MEDIUM
Network
|
csphere
|
clansphere
|
Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "language" parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27310
|
2024-11-21 14:57 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196359
|
6.1 |
MEDIUM
Network
|
csphere
|
clansphere
|
Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "module" parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27309
|
2024-11-21 14:57 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196360
|
4.8 |
MEDIUM
Network
|
4homepages
|
4images
|
A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to inject JavaScript via the "redirect" parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27308
|
2024-11-21 14:57 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|