Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2021-03-24 CVE-2021-27315 SQL Injection vulnerability in Doctor Appointment System Project Doctor Appointment System 1.0
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter.
network
low complexity
doctor-appointment-system-project CWE-89
5.0
2021-03-24 CVE-2021-29033 Cross-site Scripting vulnerability in Bitweaver 3.1.0
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/edit_group.php URI.
network
bitweaver CWE-79
3.5
2021-03-24 CVE-2021-29032 Cross-site Scripting vulnerability in Bitweaver 3.1.0
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/preferences.php URI.
network
bitweaver CWE-79
3.5
2021-03-24 CVE-2021-29031 Cross-site Scripting vulnerability in Bitweaver 3.1.0
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/users_import.php URI.
network
bitweaver CWE-79
3.5
2021-03-24 CVE-2021-29030 Cross-site Scripting vulnerability in Bitweaver 3.1.0
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/index.php URI.
network
bitweaver CWE-79
3.5
2021-03-24 CVE-2021-29029 Cross-site Scripting vulnerability in Bitweaver 3.1.0
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/edit_personal_page.php URI.
network
bitweaver CWE-79
3.5
2021-03-24 CVE-2021-29028 Cross-site Scripting vulnerability in Bitweaver 3.1.0
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/user_activity.php URI.
network
bitweaver CWE-79
3.5
2021-03-24 CVE-2021-29027 Cross-site Scripting vulnerability in Bitweaver 3.1.0
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/index.php URI.
network
bitweaver CWE-79
3.5
2021-03-24 CVE-2021-29026 Cross-site Scripting vulnerability in Bitweaver 3.1.0
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/permissions.php URI.
network
bitweaver CWE-79
3.5
2021-03-24 CVE-2021-29025 Cross-site Scripting vulnerability in Bitweaver 3.1.0
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/my_images.php URI.
network
bitweaver CWE-79
3.5