A vulnerability marked as critical has been reported in Supsystic Pricing Table 1.8.6/1.8.7. Affected by this vulnerability is the function getListForTbl of the component GET Parameter Handler. This manipulation of the argument sidx causes sql injection.
This vulnerability is registered as CVE-2020-37243. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability labeled as problematic has been found in bloofoxCMS up to 0.5.2.1. Affected is an unknown function of the component Admin User Creation Endpoint. The manipulation results in cross-site request forgery.
This vulnerability is cataloged as CVE-2020-37241. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability identified as problematic has been detected in CMS Made Simple 2.2.15. This impacts an unknown function of the component SVG File Handler. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2020-37238. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability categorized as problematic has been discovered in Wplearnmanager WP Learn Manager 1.1.2. This affects the function jslm_fieldordering of the component Field Ordering Interface. Executing a manipulation of the argument ordering can lead to cross site scripting.
This vulnerability is tracked as CVE-2021-47975. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability was found in Supsystic Digital Publications 1.6.9. It has been rated as critical. The impacted element is an unknown function. Performing a manipulation results in path traversal.
This vulnerability is identified as CVE-2020-37245. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability was found in Getfuelcms Fuel CMS 1.4.13. It has been declared as critical. The affected element is an unknown function of the component Activity Log Interface. Such manipulation of the argument col leads to sql injection.
This vulnerability is referenced as CVE-2021-47980. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability was found in ProcessMaker up to 3.5.4. It has been classified as problematic. Impacted is an unknown function. This manipulation causes improper control of filename for include/require statement in php program ('php remote file inclusion').
The identification of this vulnerability is CVE-2021-47978. The attack can only be executed locally. Furthermore, there is an exploit available.
A vulnerability was found in Vxsearch VX Search 13.5.28 and classified as problematic. This issue affects some unknown processing of the component Search Enterprise Service. The manipulation results in unquoted search path.
This vulnerability was named CVE-2021-47974. The attack needs to be approached locally. In addition, an exploit is available.
A vulnerability has been found in Kite 4.2.0.1 U1 and classified as problematic. This vulnerability affects unknown code of the component KiteService Windows Service. The manipulation leads to unquoted search path.
This vulnerability is uniquely identified as CVE-2020-37247. Local access is required to approach this attack. Moreover, an exploit is present.
A vulnerability, which was classified as problematic, was found in Opensolution Quick.CMS 6.7. This affects an unknown part. Executing a manipulation of the argument sDescription can lead to cross site scripting.
This vulnerability is handled as CVE-2021-47981. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability, which was classified as problematic, has been found in MyBB Timeline Plugin 1.0. Affected by this issue is some unknown functionality of the file timeline.php of the component User Profile Handler. Performing a manipulation results in cross site scripting.
This vulnerability is known as CVE-2021-47934. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability classified as problematic was found in sticky-notes Sticky Notes Widget 3.0.6. Affected by this vulnerability is an unknown functionality. Such manipulation leads to uncontrolled memory allocation.
This vulnerability is traded as CVE-2021-47973. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability described as problematic has been identified in my-notes-safe My Notes Safe 5.3. This impacts an unknown function. The manipulation results in uncontrolled memory allocation.
This vulnerability is reported as CVE-2021-47971. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability labeled as problematic has been found in Codekernel Queue Management System 4.0.0. The impacted element is an unknown function. Executing a manipulation can lead to cross site scripting.
This vulnerability is registered as CVE-2020-37240. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability identified as problematic has been detected in color-notes Color Notes 1.4. The affected element is an unknown function. Performing a manipulation results in uncontrolled memory allocation.
This vulnerability is cataloged as CVE-2021-47969. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability categorized as critical has been discovered in Home-Assistant Home Assistant Community Store up to 1.9.x. Impacted is an unknown function of the file /hacsfiles/ of the component Refresh Token Handler. Such manipulation leads to path traversal.
This vulnerability is listed as CVE-2021-47942. The attack may be performed from remote. In addition, an exploit is available.
It is advisable to upgrade the affected component.