5.1

CVSS4.0

CVE-2021-47892 - PEEL Shopping 9.3.0 - 'Comments/Special Instructions' Stored Cross-Site Scripting

PEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the 'Comments / Special Instructions' parameter of the purchase page. Attackers can inject malicious JavaScript payloads that will execute when the page is refreshed, potentially allowing client-side script execution.

πŸ“… Published: Jan. 23, 2026, 4:47 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2021-47891 - Unified Remote 3.9.0.2463 - Remote Code Execution

Unified Remote 3.9.0.2463 contains a remote code execution vulnerability that allows attackers to send crafted network packets to execute arbitrary commands. Attackers can exploit the service by connecting to port 9512 and sending specially crafted packets to open a command prompt and download and …

πŸ“… Published: Jan. 23, 2026, 4:47 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2021-47890 - LogonExpert 8.1 - 'LogonExpertSvc' Unquoted Service Path

LogonExpert 8.1 contains an unquoted service path vulnerability in the LogonExpertSvc service running with LocalSystem privileges. Attackers can exploit the unquoted path to place malicious executables in intermediate directories, potentially gaining elevated system access during service startup.

πŸ“… Published: Jan. 23, 2026, 4:47 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2021-47889 - Softros LAN Messenger 9.6.4 - 'SoftrosSpellChecker' Unquoted Service Path

Softros LAN Messenger 9.6.4 contains an unquoted service path vulnerability in the SoftrosSpellChecker service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Softros Systems\Softros Messenger\Spell Checker\' to i…

πŸ“… Published: Jan. 23, 2026, 4:47 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2021-47888 - Textpattern 4.8.3 - Remote code execution

Textpattern versions prior to 4.8.3 contain an authenticated remote code execution vulnerability that allows logged-in users to upload malicious PHP files. Attackers can upload a PHP file with a shell command execution payload and execute arbitrary commands by accessing the uploaded file through a …

πŸ“… Published: Jan. 23, 2026, 4:47 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.7

CVSS4.0

CVE-2021-47881 - dataSIMS Avionics ARINC 664-1 - Local Buffer Overflow

dataSIMS Avionics ARINC 664-1 version 4.5.3 contains a local buffer overflow vulnerability that allows attackers to overwrite memory by manipulating the milstd1553result.txt file. Attackers can craft a malicious file with carefully constructed payload and alignment sections to potentially execute a…

πŸ“… Published: Jan. 23, 2026, 4:47 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2018-25132 - MyBB Trending Widget Plugin 1.2 - Cross-Site Scripting

MyBB Trending Widget Plugin 1.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through thread titles. Attackers can modify thread titles with script payloads that will execute when other users view the trending widget.

πŸ“… Published: Jan. 23, 2026, 4:47 p.m. πŸ”„ Last Modified: April 9, 2026, 2:08 p.m.

5.1

CVSS4.0

CVE-2018-25116 - MyBB Thread Redirect Plugin 0.2.1 - Cross-Site Scripting

MyBB Thread Redirect Plugin 0.2.1 contains a cross-site scripting vulnerability in the custom text input field for thread redirects. Attackers can inject malicious SVG scripts that will execute when other users view the thread, allowing arbitrary script execution.

πŸ“… Published: Jan. 23, 2026, 4:47 p.m. πŸ”„ Last Modified: April 9, 2026, 2:12 p.m.

5.1

CVSS4.0

CVE-2025-71177 - LavaLite CMS <= 10.1.0 Stored XSS via Package Creation and Search

LavaLite CMS versions up to and including 10.1.0 contain a stored cross-site scripting vulnerability in the package creation and search functionality. Authenticated users can supply crafted HTML or JavaScript in the package Name or Description fields that is stored and later rendered without proper…

πŸ“… Published: Jan. 23, 2026, 4:40 p.m. πŸ”„ Last Modified: March 5, 2026, 1:29 a.m.

6

CVSS4.0

CVE-2026-1299 - email BytesGenerator header injection due to unquoted newlines

The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized. This is only applicable if using "LiteralHeader" writing headers that don't respect email foldi…

πŸ“… Published: Jan. 23, 2026, 4:27 p.m. πŸ”„ Last Modified: April 16, 2026, 5:45 p.m.
Total resulsts: 349182
Page 1965 of 34,919
Β« previous page Β» next page
Filters