8.1

CVSS3.1

CVE-2025-66292 - DPanel has an arbitrary file deletion vulnerability in /api/common/attach/delete interface

DPanel is an open source server management panel written in Go. Prior to 1.9.2, DPanel has an arbitrary file deletion vulnerability in the /api/common/attach/delete interface. Authenticated users can delete arbitrary files on the server via path traversal. When a user logs into the administrative b…

πŸ“… Published: Jan. 15, 2026, 4:19 p.m. πŸ”„ Last Modified: March 12, 2026, 6:07 p.m.

7.5

CVSS3.1

CVE-2025-64516 - GLPI incorrectly authorizes access to documents

GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documents attached to any item (ticket, asset, ...). If the public FAQ is enabled, this unauthorized access can be performed by an anonymous user. This vulnerability is fixed i…

πŸ“… Published: Jan. 15, 2026, 4:01 p.m. πŸ”„ Last Modified: Jan. 21, 2026, 8:53 p.m.

5.1

CVSS4.0

CVE-2021-47843 - Tagstoo 2.0.1 - Stored XSS to RCE

Tagstoo 2.0.1 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious payloads through files or custom tags. Attackers can execute arbitrary JavaScript code to spawn system processes, access files, and perform remote code execution on the victim's computer.

πŸ“… Published: Jan. 15, 2026, 3:52 p.m. πŸ”„ Last Modified: March 5, 2026, 1:28 a.m.

9.3

CVSS4.0

CVE-2021-47819 - ProjeQtOr Project Management 9.1.4 - Remote Code Execution

ProjeQtOr Project Management 9.1.4 contains a file upload vulnerability that allows guest users to upload malicious PHP files with arbitrary code execution capabilities. Attackers can upload a PHP script through the profile attachment section and execute system commands by accessing the uploaded fi…

πŸ“… Published: Jan. 15, 2026, 3:52 p.m. πŸ”„ Last Modified: March 5, 2026, 1:28 a.m.

8.5

CVSS4.0

CVE-2021-47799 - Visual Tools DVR VX16 4.2.28 - Local Privilege Escalation

Visual Tools DVR VX16 version 4.2.28 contains a local privilege escalation vulnerability in its Sudo configuration that allows attackers to gain root access. Attackers can exploit the unsafe Sudo settings by using mount commands to bind a shell, enabling unauthorized system-level privileges.

πŸ“… Published: Jan. 15, 2026, 3:52 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:55 p.m.

6.7

CVSS4.0

CVE-2021-47784 - Cyberfox Web Browser 52.9.1 - Denial of Service (PoC)

Cyberfox Web Browser 52.9.1 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the search bar with excessive data. Attackers can generate a 9,000,000 byte payload and paste it into the search bar to trigger an application crash.

πŸ“… Published: Jan. 15, 2026, 3:52 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:55 p.m.

6.7

CVSS4.0

CVE-2021-47781 - Cmder Console Emulator 1.3.18 - 'Cmder.exe' Denial of Service (PoC)

Cmder Console Emulator 1.3.18 contains a buffer overflow vulnerability that allows attackers to trigger a denial of service condition through a maliciously crafted .cmd file. Attackers can create a specially constructed .cmd file with repeated characters to overwhelm the console emulator's buffer a…

πŸ“… Published: Jan. 15, 2026, 3:52 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:55 p.m.

8.8

CVSS4.0

CVE-2021-47777 - Build Smart ERP 21.0817 - 'eidValue' SQL Injection (Unauthenticated)

Build Smart ERP 21.0817 contains an unauthenticated SQL injection vulnerability in the 'eidValue' parameter of the login validation endpoint. Attackers can inject stacked SQL queries using payloads like ';WAITFOR DELAY '0:0:3'-- to manipulate database queries and potentially extract or modify datab…

πŸ“… Published: Jan. 15, 2026, 3:52 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:55 p.m.

6.9

CVSS4.0

CVE-2021-47776 - Umbraco v8.14.1 - 'baseUrl' SSRF

Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that allows attackers to manipulate baseUrl parameters in multiple dashboard and help controller endpoints. Attackers can craft malicious requests to the GetContextHelpForPage, GetRemoteDashboardContent, and GetRemoteDashboard…

πŸ“… Published: Jan. 15, 2026, 3:52 p.m. πŸ”„ Last Modified: March 5, 2026, 1:28 a.m.

8.4

CVSS4.0

CVE-2021-47775 - YouTube Video Grabber 1.9.9.1 - Buffer Overflow (SEH)

YouTube Video Grabber, now referred to as YouTube Downloader, 1.9.9.1 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting the Structured Exception Handler. Attackers can craft a malicious payload of 712 bytes with SEH manipulation to trigger a bin…

πŸ“… Published: Jan. 15, 2026, 3:52 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:55 p.m.
Total resulsts: 342292
Page 1428 of 34,230
Β« previous page Β» next page
Filters