8.5

CVSS4.0

CVE-2021-47762 - HTTPDebuggerPro 9.11 - Unquoted Service Path

HTTPDebuggerPro 9.11 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables and gain elevated acces…

πŸ“… Published: Jan. 15, 2026, 3:52 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:55 p.m.

8.5

CVSS4.0

CVE-2021-47761 - MilleGPG5 5.7.2 Luglio 2021 (x64) - Local Privilege Escalation

MilleGPG5 5.7.2 contains a local privilege escalation vulnerability that allows authenticated users to modify service executable files in the MariaDB bin directory. Attackers can replace the mysqld.exe with a malicious executable, which will execute with system privileges when the computer restarts.

πŸ“… Published: Jan. 15, 2026, 3:52 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:55 p.m.

0.0

CVE-2021-47760 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as a duplicate.

πŸ“… Published: Jan. 15, 2026, 3:52 p.m. πŸ”„ Last Modified: Jan. 22, 2026, 9:15 p.m.

6.8

CVSS4.0

CVE-2021-47759 - MTPutty 1.0.1.21 - SSH Password Disclosure

MTPutty 1.0.1.21 contains a sensitive information disclosure vulnerability that allows local attackers to view SSH connection passwords through Windows PowerShell process listing. Attackers can run a PowerShell command to retrieve the full command line of MTPutty processes, exposing plaintext SSH c…

πŸ“… Published: Jan. 15, 2026, 3:52 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:55 p.m.

8.7

CVSS4.0

CVE-2021-47758 - Chikitsa Patient Management System 2.0.2 - Remote Code Execution (RCE) (Authenticated)

Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious PHP plugins through the module upload functionality. Authenticated attackers can generate and upload a ZIP plugin with a PHP backdoor that enables arbitra…

πŸ“… Published: Jan. 15, 2026, 3:52 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:55 p.m.

8.7

CVSS4.0

CVE-2021-47757 - Chikitsa Patient Management System 2.0.2 - 'plugin' Remote Code Execution (RCE) (Authenticated)

Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability in the backup restoration functionality. Authenticated attackers can upload a modified backup zip file with a malicious PHP shell to execute arbitrary system commands on the server.

πŸ“… Published: Jan. 15, 2026, 3:52 p.m. πŸ”„ Last Modified: Jan. 23, 2026, 6:17 p.m.

8.7

CVSS4.0

CVE-2021-47755 - Oliver Library Server v5 - Arbitrary File Download

Oliver Library Server v5 contains a file download vulnerability that allows unauthenticated attackers to access arbitrary system files through unsanitized input in the FileServlet endpoint. Attackers can exploit the vulnerability by manipulating the 'fileName' parameter to download sensitive files …

πŸ“… Published: Jan. 15, 2026, 3:52 p.m. πŸ”„ Last Modified: Jan. 26, 2026, 4:15 p.m.

6.9

CVSS4.0

CVE-2021-47754 - Arunna 1.0.0 - 'Multiple' Cross-Site Request Forgery (CSRF)

Arunna 1.0.0 contains a cross-site request forgery vulnerability that allows attackers to manipulate user profile settings without authentication. Attackers can craft a malicious form to change user details, including passwords, email, and administrative privileges by tricking authenticated users i…

πŸ“… Published: Jan. 15, 2026, 3:52 p.m. πŸ”„ Last Modified: Jan. 26, 2026, 4:15 p.m.

9.3

CVSS4.0

CVE-2021-47753 - phpKF CMS 3.00 Beta y6 - Remote Code Execution (RCE) (Unauthenticated)

phpKF CMS 3.00 Beta y6 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary code by bypassing file extension checks. Attackers can upload a PHP file disguised as a PNG, rename it, and execute system commands through a crafted web shell parameter.

πŸ“… Published: Jan. 15, 2026, 3:52 p.m. πŸ”„ Last Modified: Jan. 23, 2026, 6:31 p.m.

8.7

CVSS4.0

CVE-2021-47752 - AWebServer GhostBuilding 18 - Denial of Service (DoS)

AWebServer GhostBuilding 18 contains a denial of service vulnerability that allows remote attackers to overwhelm the server by sending multiple concurrent HTTP requests. Attackers can generate high-volume requests to multiple endpoints including /mysqladmin to potentially crash or render the servic…

πŸ“… Published: Jan. 15, 2026, 3:52 p.m. πŸ”„ Last Modified: Jan. 23, 2026, 6:32 p.m.
Total resulsts: 330388
Page 250 of 33,039
Β« previous page Β» next page
Filters