|
31
|
4.3 |
MEDIUM
Network
|
-
|
-
|
OpenCart 3.0.3.7 contains a cross-site request forgery vulnerability that allows attackers to change user passwords by sending crafted requests to the account/password endpoint. Attackers can trick a…
New
|
CWE-352
Origin Validation Error
|
CVE-2021-47953
|
2026-05-10 22:16 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
32
|
6.4 |
MEDIUM
Network
|
-
|
-
|
WordPress Picture Gallery 1.4.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Edit Content URL field in the Access C…
New
|
CWE-79
Cross-site Scripting
|
CVE-2021-47951
|
2026-05-10 22:16 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
33
|
6.4 |
MEDIUM
Network
|
-
|
-
|
Advanced Guestbook 2.4.4 contains a persistent cross-site scripting vulnerability in the smilies administration interface that allows authenticated attackers to inject malicious scripts by manipulati…
New
|
CWE-79
Cross-site Scripting
|
CVE-2021-47950
|
2026-05-10 22:16 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
34
|
8.8 |
HIGH
Network
|
-
|
-
|
CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files and execute remote code by exploiting symlink attacks through the filemanager con…
New
|
CWE-59
Link Following
|
CVE-2021-47949
|
2026-05-10 22:16 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
35
|
5.4 |
MEDIUM
Network
|
-
|
-
|
WordPress GetPaid Plugin 2.4.6 contains an HTML injection vulnerability that allows authenticated attackers to inject arbitrary HTML code by exploiting the Help Text field in payment forms. Attackers…
New
|
CWE-80
Basic XSS
|
CVE-2021-47948
|
2026-05-10 22:16 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
36
|
6.4 |
MEDIUM
Network
|
-
|
-
|
Projectsend r1295 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input in the 'name' parameter of files-edi…
New
|
CWE-79
Cross-site Scripting
|
CVE-2021-47947
|
2026-05-10 22:16 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
37
|
5.3 |
MEDIUM
Network
|
-
|
-
|
OpenCart 3.0.36 contains a cross-site request forgery vulnerability in the /account/edit endpoint that allows unauthenticated attackers to modify victim account details by tricking users into visitin…
New
|
CWE-352
Origin Validation Error
|
CVE-2021-47946
|
2026-05-10 22:16 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
38
|
7.8 |
HIGH
Local
|
-
|
-
|
Argus Surveillance DVR 4.0 contains an unquoted service path vulnerability in the DVRWatchdog service that allows local attackers to escalate privileges by exploiting the service binary path. Attacke…
New
|
CWE-428
Unquoted Search Path or Element
|
CVE-2021-47945
|
2026-05-10 22:16 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
39
|
7.5 |
HIGH
Network
|
-
|
-
|
memono Notepad 4.2 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character buffers into note fields. Attackers can generate a p…
New
|
CWE-789
Memory Allocation with Excessive Size Value
|
CVE-2021-47944
|
2026-05-10 22:16 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
40
|
8.8 |
HIGH
Network
|
-
|
-
|
TextPattern CMS 4.8.7 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by uploading malicious PHP files through the file upload functio…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-47943
|
2026-05-10 22:16 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|