8.7

CVSS4.0

CVE-2021-47849 - Mini Mouse 9.3.0 - Local File inclusion / Path Traversal

Mini Mouse 9.3.0 contains a path traversal vulnerability that allows attackers to access sensitive system directories through the device information endpoint. Attackers can retrieve file lists from system directories like /usr, /etc, and /var by manipulating file path parameters in API requests.

📅 Published: Jan. 21, 2026, 5:27 p.m. 🔄 Last Modified: Feb. 2, 2026, 5:38 p.m.

8.8

CVSS4.0

CVE-2021-47848 - Blitar Tourism 1.0 - Authentication Bypass SQLi

Blitar Tourism 1.0 contains an authentication bypass vulnerability that allows attackers to bypass login by injecting SQL code through the username parameter. Attackers can manipulate the login request by sending a crafted username with SQL injection techniques to gain unauthorized administrative a…

📅 Published: Jan. 21, 2026, 5:27 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2021-47846 - Digital Crime Report Management System 1.0 - SQL Injection

Digital Crime Report Management System 1.0 contains a critical SQL injection vulnerability affecting multiple login pages that allows unauthenticated attackers to bypass authentication. Attackers can exploit the vulnerability by sending crafted SQL injection payloads in email and password parameter…

📅 Published: Jan. 21, 2026, 5:27 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2021-47830 - GetSimple CMS My SMTP Contact Plugin 1.1.1 - CSRF

GetSimple CMS My SMTP Contact Plugin 1.1.1 contains a cross-site request forgery (CSRF) vulnerability. Attackers can craft a malicious webpage that, when visited by an authenticated administrator, can change SMTP configuration settings in the plugin. This may allow unauthorized changes but does not…

📅 Published: Jan. 21, 2026, 5:27 p.m. 🔄 Last Modified: April 7, 2026, 2:06 p.m.

4.8

CVSS4.0

CVE-2021-47817 - OpenEMR 5.0.2.1 - Remote Code Execution

OpenEMR 5.0.2.1 contains a cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript through user profile parameters. Attackers can exploit the vulnerability by crafting a malicious payload to download and execute a web shell, enabling remote command exec…

📅 Published: Jan. 21, 2026, 5:27 p.m. 🔄 Last Modified: March 5, 2026, 1:28 a.m.

8.7

CVSS4.0

CVE-2021-47802 - Tenda D151 & D301 - Configuration Download

Tenda D151 and D301 routers contain an unauthenticated configuration download vulnerability that allows remote attackers to retrieve router configuration files. Attackers can send a request to /goform/getimage endpoint to download configuration data including admin credentials without authenticatio…

📅 Published: Jan. 21, 2026, 5:27 p.m. 🔄 Last Modified: Feb. 2, 2026, 5:44 p.m.

8.6

CVSS4.0

CVE-2021-47770 - OpenPLC 3 - Remote Code Execution

OpenPLC v3 contains an authenticated remote code execution vulnerability that allows attackers with valid credentials to inject malicious code through the hardware configuration interface. Attackers can upload a custom hardware layer with embedded reverse shell code that establishes a network conne…

📅 Published: Jan. 21, 2026, 5:27 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2021-47748 - Hasura GraphQL 1.3.3 - Remote Code Execution

Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell commands through SQL query manipulation. Attackers can inject commands into the run_sql endpoint by crafting malicious GraphQL queries that execute system commands through PostgreSQL…

📅 Published: Jan. 21, 2026, 5:27 p.m. 🔄 Last Modified: Feb. 2, 2026, 6:11 p.m.

8.6

CVSS4.0

CVE-2021-47746 - NodeBB Plugin Emoji 3.2.1 - Arbitrary File Write

NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows administrative users to write files to arbitrary system locations through the emoji upload API. Attackers with admin access can craft file upload requests with directory traversal to overwrite system files by manip…

📅 Published: Jan. 21, 2026, 5:27 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS4.0

CVE-2026-0834 - Logic Vulnerability on TP-Link Archer C20, Archer AX53 and TL-WR841N v13

Logic vulnerability in TP-Link Archer C20 v5, 6.0, Archer AX53 v1.0 and TL-WR841N v13 (TDDP module) allows unauthenticated adjacent attackers to execute administrative commands including factory reset and device reboot without credentials. Attackers on the adjacent network can remotely trigger fact…

📅 Published: Jan. 21, 2026, 5:14 p.m. 🔄 Last Modified: April 23, 2026, 6:16 p.m.
Total resulsts: 347742
Page 1899 of 34,775
« previous page » next page
Filters