Vulnerabilities
2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-42675 | Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP file and obtain remote code execution. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2021-44581 | An SQL Injection vulnerabilty exists in Kreado Kreasfero 1.5 via the id parameter. An SQL Injection vulnerabilty exists in Kreado Kreasfero 1.5 via the id parameter. NVD description · AI analysis pending | 7.5 | 1% |
| — |