Latest CVE Feed
-
7.5
HIGHCVE-2021-46149
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. A denial of service (resource consumption) can be accomplished by searching for a very long key in a Language Name Search.... Read more
Affected Products : mediawiki- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-46148
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. Some unprivileged users can view confidential information (e.g., IP addresses and User-Agent headers for election traffic) on a testwiki SecurePoll instanc... Read more
Affected Products : mediawiki- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-46147
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. MassEditRegex allows CSRF.... Read more
Affected Products : mediawiki- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-46146
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The WikibaseMediaInfo component is vulnerable to XSS via the caption fields for a given media file.... Read more
Affected Products : mediawiki- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-46145
The keyfob subsystem in Honda Civic 2012 vehicles allows a replay attack for unlocking. This is related to a non-expiring rolling code and counter resynchronization.... Read more
Affected Products : civic_2012- Published: Jan. 06, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-46144
Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences.... Read more
- Published: Jan. 06, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-46142
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.... Read more
Affected Products : fedora debian_linux leap backports extra_packages_for_enterprise_linux factory uriparser- Published: Jan. 06, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-46141
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.... Read more
Affected Products : fedora debian_linux leap backports extra_packages_for_enterprise_linux factory uriparser- Published: Jan. 06, 2022
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-46122
Tp-Link TL-WR840N (EU) v6.20 Firmware (0.9.1 4.17 v0001.0 Build 201124 Rel.64328n) is vulnerable to Buffer Overflow via the Password reset feature.... Read more
- Published: Apr. 18, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-46118
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.... Read more
Affected Products : jpress- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-46117
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.... Read more
Affected Products : jpress- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-46116
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall. The admin panel provides a function through which attackers can install templates and inject some malicious code.... Read more
Affected Products : jpress- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-46115
jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile. The admin panel provides a function through which attackers can upload templates and inject some malicious code.... Read more
Affected Products : jpress- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-46114
jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.... Read more
Affected Products : jpress- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-46113
In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP files using the file upload vulnerability in this service.... Read more
Affected Products : kea-hotel-erp- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-46110
Online Shopping Portal v3.1 was discovered to contain multiple time-based SQL injection vulnerabilities via the email and contactno parameters.... Read more
- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-46109
Invalid input sanitizing leads to reflected Cross Site Scripting (XSS) in ASUS RT-AC52U_B1 3.0.0.4.380.10931 can lead to a user session hijack.... Read more
Affected Products : rt-ac52u_b1_firmware- Published: Jan. 03, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-46108
D-Link DSL-2730E CT-20131125 devices allow XSS via the username parameter to the password page in the maintenance configuration.... Read more
- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-46107
Ligeo Archives Ligeo Basics as of 02_01-2022 is vulnerable to Server Side Request Forgery (SSRF) which allows an attacker to read any documents via the download features.... Read more
Affected Products : ligeo_basics- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-46104
An issue was discovered in webp_server_go 0.4.0. There is a directory traversal vulnerability that can read arbitrary file information on the server.... Read more
Affected Products : webp_server_go- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024