5.1

CVSS4.0

CVE-2021-47857 - Moodle 3.10.3 - 'label' Persistent Cross Site Scripting

Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code when users view the eve…

πŸ“… Published: Jan. 21, 2026, 5:27 p.m. πŸ”„ Last Modified: March 5, 2026, 7:45 p.m.

5.1

CVSS4.0

CVE-2021-47855 - Openlitespeed 1.7.9 - 'Notes' Stored Cross-Site Scripting

Openlitespeed 1.7.9 contains a stored cross-site scripting vulnerability in the dashboard's Notes parameter that allows administrators to inject malicious scripts. Attackers can craft a payload in the Notes field during listener configuration that will execute when an administrator clicks on the De…

πŸ“… Published: Jan. 21, 2026, 5:27 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2021-47854 - DD-WRT 45723 - UPNP Buffer Overflow

DD-WRT version 45723 contains a buffer overflow vulnerability in the UPNP network discovery service that allows remote attackers to potentially execute arbitrary code. Attackers can send crafted M-SEARCH packets with oversized UUID payloads to trigger buffer overflow conditions on the target device.

πŸ“… Published: Jan. 21, 2026, 5:27 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2021-47853 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Jan. 21, 2026, 5:27 p.m. πŸ”„ Last Modified: Feb. 1, 2026, 12:15 p.m.

8.5

CVSS4.0

CVE-2021-47852 - Rockstar Service - Insecure File Permissions

Rockstar Games Launcher 1.0.37.349 contains a privilege escalation vulnerability that allows authenticated users to modify the service executable with weak permissions. Attackers can replace the RockstarService.exe with a malicious binary to create a new administrator user and gain elevated system …

πŸ“… Published: Jan. 21, 2026, 5:27 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2021-47851 - Mini Mouse 9.2.0 - Remote Code Execution

Mini Mouse 9.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands through an unauthenticated HTTP endpoint. Attackers can leverage the /op=command endpoint to download and execute payloads by sending crafted JSON requests with malicious script comma…

πŸ“… Published: Jan. 21, 2026, 5:27 p.m. πŸ”„ Last Modified: Feb. 2, 2026, 5:29 p.m.

8.7

CVSS4.0

CVE-2021-47850 - Mini Mouse 9.2.0 - Path Traversal

Mini Mouse 9.2.0 contains a path traversal vulnerability that allows remote attackers to access arbitrary system files and directories through crafted HTTP requests. Attackers can retrieve sensitive files like win.ini and list contents of system directories such as C:\Users\Public by manipulating f…

πŸ“… Published: Jan. 21, 2026, 5:27 p.m. πŸ”„ Last Modified: Feb. 2, 2026, 5:30 p.m.

8.7

CVSS4.0

CVE-2021-47849 - Mini Mouse 9.3.0 - Local File inclusion / Path Traversal

Mini Mouse 9.3.0 contains a path traversal vulnerability that allows attackers to access sensitive system directories through the device information endpoint. Attackers can retrieve file lists from system directories like /usr, /etc, and /var by manipulating file path parameters in API requests.

πŸ“… Published: Jan. 21, 2026, 5:27 p.m. πŸ”„ Last Modified: Feb. 2, 2026, 5:38 p.m.

8.8

CVSS4.0

CVE-2021-47848 - Blitar Tourism 1.0 - Authentication Bypass SQLi

Blitar Tourism 1.0 contains an authentication bypass vulnerability that allows attackers to bypass login by injecting SQL code through the username parameter. Attackers can manipulate the login request by sending a crafted username with SQL injection techniques to gain unauthorized administrative a…

πŸ“… Published: Jan. 21, 2026, 5:27 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2021-47846 - Digital Crime Report Management System 1.0 - SQL Injection

Digital Crime Report Management System 1.0 contains a critical SQL injection vulnerability affecting multiple login pages that allows unauthenticated attackers to bypass authentication. Attackers can exploit the vulnerability by sending crafted SQL injection payloads in email and password parameter…

πŸ“… Published: Jan. 21, 2026, 5:27 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346103
Page 1735 of 34,611
Β« previous page Β» next page
Filters