Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2021-09-07 CVE-2021-32800 Unspecified vulnerability in Nextcloud Server
Nextcloud server is an open source, self hosted personal cloud.
network
low complexity
nextcloud
8.1
2021-09-07 CVE-2021-37628 Authorization Bypass Through User-Controlled Key vulnerability in Nextcloud Richdocuments
Nextcloud Richdocuments is an open source collaborative office suite.
network
low complexity
nextcloud CWE-639
7.5
2021-09-07 CVE-2021-39500 Path Traversal vulnerability in Eyoucms 1.5.4
Eyoucms 1.5.4 is vulnerable to Directory Traversal.
network
low complexity
eyoucms CWE-22
7.5
2021-09-07 CVE-2020-19750 Out-of-bounds Read vulnerability in Gpac 0.8.0
An issue was discovered in gpac 0.8.0.
network
low complexity
gpac CWE-125
7.5
2021-09-07 CVE-2020-19752 NULL Pointer Dereference vulnerability in multiple products
The find_color_or_error function in gifsicle 1.92 contains a NULL pointer dereference.
network
low complexity
lcdf fedoraproject CWE-476
7.5
2021-09-07 CVE-2021-38705 Cross-Site Request Forgery (CSRF) vulnerability in Cliniccases 7.3.3
ClinicCases 7.3.3 is affected by Cross-Site Request Forgery (CSRF).
network
low complexity
cliniccases CWE-352
8.8
2021-09-07 CVE-2021-38706 SQL Injection vulnerability in Cliniccases 7.3.3
messages_load.php in ClinicCases 7.3.3 suffers from a blind SQL injection vulnerability, which allows low-privileged attackers to execute arbitrary SQL commands through a vulnerable parameter.
network
low complexity
cliniccases CWE-89
8.8
2021-09-07 CVE-2021-39503 Code Injection vulnerability in PHPmywind 5.6
PHPMyWind 5.6 is vulnerable to Remote Code Execution.
network
low complexity
phpmywind CWE-94
7.2
2021-09-07 CVE-2021-40143 Injection vulnerability in Sonatype Nexus Repository Manager 3
Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection.
network
low complexity
sonatype CWE-74
8.2
2021-09-07 CVE-2021-38142 Cleartext Transmission of Sensitive Information vulnerability in Barco Mirrorop Windows Sender
Barco MirrorOp Windows Sender before 2.5.3.65 uses cleartext HTTP and thus allows rogue software upgrades.
local
low complexity
barco CWE-319
8.8