Latest CVE Feed
-
9.6
CRITICALCVE-2020-26574
Leostream Connection Broker 8.2.x is affected by stored XSS. An unauthenticated attacker can inject arbitrary JavaScript code via the webquery.pl User-Agent HTTP header. It is rendered by the admins the next time they log in. The JavaScript injected can b... Read more
Affected Products : connection_broker- Published: Oct. 06, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-26904
Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.10.11, RBR850 before 3.2.10.11, and RBS850 b... Read more
Affected Products : rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware cbr40_firmware rbk752 rbr750 rbs750 +4 more products- Published: Oct. 09, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2019-6159
A stored cross-site scripting (XSS) vulnerability exists in various firmware versions of the legacy IBM System x IMM (IMM v1) embedded Baseboard Management Controller (BMC). This vulnerability could allow an unauthenticated user to cause JavaScript code t... Read more
Affected Products : bladecenter_hs22_firmware bladecenter_hs22v_firmware bladecenter_hx5_firmware system_x_idataplex_dx360_m2_firmware system_x_idataplex_dx360_m3_firmware system_x3400_m3_firmware system_x3500_m2_firmware system_x3500_m3_firmware system_x3550_m3_firmware system_x3560_m2_firmware +20 more products- Published: Aug. 19, 2019
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-14430
Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK842 before 3.2.15.25, RBR840 be... Read more
Affected Products : rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware rbk842_firmware rbr840_firmware rbs840_firmware rbk753_firmware +14 more products- Published: Jun. 18, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-14439
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK842 before 3.2.15.25, R... Read more
Affected Products : rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware rbk842_firmware rbr840_firmware rbs840_firmware rbk753_firmware +14 more products- Published: Jun. 18, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-29459
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible to persistently inject scripts in XWiki versions prior to 12.6.3 and 12.8. Unregistred users can fill simple text fields. Registered us... Read more
Affected Products : xwiki- Published: Apr. 20, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-22114
In Teedy, versions v1.5 through v1.9 are vulnerable to Reflected Cross-Site Scripting (XSS). The “search term" search functionality is not sufficiently sanitized while displaying the results of the search, which can be leveraged to inject arbitrary script... Read more
Affected Products : teedy- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-29082
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects RBW30 before 2.6.1.4, RBS40V before 2.6.1.4, RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBK754 before 3.2.15.25, RBR750 before 3.2.1... Read more
Affected Products : rbs40v_firmware rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware rbw30_firmware rbk753_firmware rbk753s_firmware +16 more products- Published: Mar. 23, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-3825
On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials.... Read more
Affected Products : liderahenk- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-40190
SAUTER Controls moduWeb firmware version 2.7.1 is vulnerable to reflective cross-site scripting (XSS). The web application does not adequately sanitize request strings of malicious JavaScript. An attacker utilizing XSS could then execute malicious code in... Read more
Affected Products : moduweb_firmware- Published: Oct. 31, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-21596
Dell OpenManage Enterprise versions 3.4 through 3.6.1 and Dell OpenManage Enterprise Modular versions 1.20.00 through 1.30.00, contain a remote code execution vulnerability. A malicious attacker with access to the immediate subnet may potentially exploit ... Read more
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-21801
This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.... Read more
Affected Products : r-seenet- Published: Jul. 16, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-4354
A vulnerability was found in LinZhaoguan pb-cms 2.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /blog/comment of the component Message Board. The manipulation leads to cross site scripting. The attack ma... Read more
Affected Products : pb-cms- Published: Dec. 08, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-2221
Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Client). The supported version that is affected is 5.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protoc... Read more
Affected Products : secure_global_desktop- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-43505
A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in SMB shares. This could allow an attacker to access files that the user should not have access to.... Read more
Affected Products : comos- Published: Nov. 14, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-26928
Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.10.11, RBR850 before 3.2.10.11, and RBS850 before 3.2.10.11.... Read more
Affected Products : rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware cbr40_firmware rbk752 rbr750 rbs750 +4 more products- Published: Oct. 09, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-27176
Mutation XSS exists in Mark Text through 0.16.2 that leads to Remote Code Execution. NOTE: this might be considered a duplicate of CVE-2020-26870; however, it can also be considered an issue in the design of the "source code mode" feature, which parses HT... Read more
Affected Products : marktext- Published: Oct. 16, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-4695
Use of Predictable Algorithm in Random Number Generator in GitHub repository pkp/pkp-lib prior to 3.3.0-16.... Read more
- Published: Sep. 01, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-30429
Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar. This issue affects Apache Pulsar: before 2.10.4, and 2.11.0. When a client connects to the Pulsar Function Worker via the Pulsar Proxy where the Pulsar Proxy uses mTLS au... Read more
Affected Products : pulsar- Published: Jul. 12, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-52139
Misskey is an open source, decentralized social media platform. Third-party applications may be able to access some endpoints or Websocket APIs that are incorrectly specified as [kind](https://github.com/misskey-dev/misskey/blob/406b4bdbe79b5b0b68fcdcb3c4... Read more
Affected Products : misskey- Published: Dec. 29, 2023
- Modified: Nov. 21, 2024