6.7

CVSS4.0

CVE-2021-47813 - Backup Key Recovery 2.2.7 - Denial of Service (PoC)

Backup Key Recovery 2.2.7 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the registration code input field. Attackers can paste a large buffer of 256 repeated characters into the registration key field to trigger application instability and …

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:55 p.m.

9.3

CVSS4.0

CVE-2021-47812 - GravCMS 1.10.7 - Arbitrary YAML Write/Update (Unauthenticated) (2)

GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configuration and execute PHP code through the scheduler endpoint. Attackers can exploit the admin-nonce parameter to inject base64-encoded payloads and create malicious custom jobs with sy…

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 10:16 p.m.

8.8

CVSS4.0

CVE-2021-47811 - Grocery crud 1.6.4 - 'order_by' SQL Injection

Grocery Crud 1.6.4 contains a SQL injection vulnerability in the order_by parameter that allows remote attackers to manipulate database queries. Attackers can inject malicious SQL code through the order_by[] parameter in POST requests to the ajax_list endpoint to potentially extract or modify datab…

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 10:16 p.m.

8.5

CVSS4.0

CVE-2021-47810 - WibuKey Runtime 6.51 - 'WkSvW32.exe' Unquoted Service Path

WibuKey Runtime 6.51 contains an unquoted service path vulnerability in the WkSvW32.exe service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\PROGRAM FILES (X86)\WIBUKEY\SERVER\WkSvW32.exe' to inject malicious executables and escal…

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 10:16 p.m.

8.5

CVSS4.0

CVE-2021-47809 - Disk Sorter Enterprise 13.6.12 - 'Disk Sorter Enterprise' Unquoted Service Path

Disk Sorter Enterprise 13.6.12 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Disk Sorter Enterprise\bin\disksrs.exe' to inject malic…

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 10:16 p.m.

5.1

CVSS4.0

CVE-2021-47808 - Cotonti Siena 0.9.19 - 'maintitle' Stored Cross-Site Scripting

Cotonti Siena 0.9.19 contains a stored cross-site scripting vulnerability in the admin configuration panel's site title parameter. Attackers can inject malicious JavaScript code through the 'maintitle' parameter to execute scripts when administrators view the page.

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 10:16 p.m.

8.5

CVSS4.0

CVE-2021-47807 - Sync Breeze 13.6.18 - 'Multiple' Unquoted Service Path

Sync Breeze 13.6.18 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in service binaries located in 'Program Files' directories to inject malicious executab…

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 10:16 p.m.

8.5

CVSS4.0

CVE-2021-47806 - Dup Scout 13.5.28 - 'Multiple' Unquoted Service Path

Dup Scout 13.5.28 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Dup Scout Server\bin\dupscts.exe' to inject malicious executables an…

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 10:16 p.m.

8.5

CVSS4.0

CVE-2021-47805 - Disk Savvy 13.6.14 - 'Multiple' Unquoted Service Path

Disk Savvy 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in service binaries to inject malicious executables that will be run with elevated Local…

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 21, 2026, 10:23 p.m.

8.5

CVSS4.0

CVE-2021-47804 - Wise Care 365 5.6.7.568 - 'WiseBootAssistant' Unquoted Service Path

Wise Care 365 5.6.7.568 contains an unquoted service path vulnerability in the WiseBootAssistant service running with LocalSystem privileges. Attackers can exploit this by inserting a malicious executable in the service path, which will execute with elevated system privileges when the service resta…

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:55 p.m.
Total resulsts: 329814
Page 181 of 32,982
Β« previous page Β» next page
Filters