βΌ CVE-2021-41647 βΌ
π Read
via "National Vulnerability Database".
An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Ordering Web App 1.0. An attacker can exploit the vulnerable "username" parameter in login.php and retrieve sensitive database information, as well as add an administrative user.π Read
via "National Vulnerability Database".
βΌ CVE-2021-41649 βΌ
π Read
via "National Vulnerability Database".
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.π Read
via "National Vulnerability Database".
βΌ CVE-2021-41648 βΌ
π Read
via "National Vulnerability Database".
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input.π Read
via "National Vulnerability Database".
βΌ CVE-2021-3825 βΌ
π Read
via "National Vulnerability Database".
On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials.π Read
via "National Vulnerability Database".
βΌ CVE-2021-29109 βΌ
π Read
via "National Vulnerability Database".
A reflected XSS vulnerability in Esri Portal for ArcGIS version 10.9 and below may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the userΓ’β¬β’s browser.π Read
via "National Vulnerability Database".
π Friday Five 10/1 π
π Read
via "".
Android scam apps, how insider threats can cause damage, and combating SIM swap attacks - catch up on the week's infosec news with the Friday Five!π Read
via "".
Digital Guardian
Friday Five 10/1
Android scam apps, how insider threats can cause damage, and combating SIM swap attacks - catch up on the week's infosec news with the Friday Five!
βΌ CVE-2021-41461 βΌ
π Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the mode parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2021-41462 βΌ
π Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the ctID parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2021-40921 βΌ
π Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in _contactform.inc.php in Detector 0.8.5 and below version allows remote attackers to inject arbitrary web script or HTML via the cid parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2021-40925 βΌ
π Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in dompdf/dompdf/www/demo.php infaveo-helpdesk v1.11.0 and below allow remote attackers to inject arbitrary web script or HTML via the $_SERVER["PHP_SELF"] parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2021-40968 βΌ
π Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the newpassword2 parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2021-40975 βΌ
π Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in application/modules/admin/views/ecommerce/products.php in Ecommerce-CodeIgniter-Bootstrap (Codeigniter 3.1.11, Bootstrap 3.3.7) allows remote attackers to inject arbitrary web script or HTML via the search_title parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2021-40970 βΌ
π Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the username parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2021-40973 βΌ
π Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the lastname parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2021-40971 βΌ
π Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the newpassword1 parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2021-40923 βΌ
π Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in install/index.php in bugs 1.8 and below version allows remote attackers to inject arbitrary web script or HTML via the email parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2021-40927 βΌ
π Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in callback.php in Spotify-for-Alfred 0.13.9 and below allows remote attackers to inject arbitrary web script or HTML via the error parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2021-40928 βΌ
π Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in index.php in FlexTV beta development version allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2021-40969 βΌ
π Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the firstname parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2021-40926 βΌ
π Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in demos/demo.mysqli.php in getID3 1.X and v2.0.0-beta allows remote attackers to inject arbitrary web script or HTML via the showtagfiles parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2021-40972 βΌ
π Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the mail parameter.π Read
via "National Vulnerability Database".