Latest CVE Feed
-
7.8
HIGHCVE-2021-45757
ASUS AC68U <=3.0.0.4.385.20852 is affected by a buffer overflow in blocking.cgi, which may cause a denial of service (DoS).... Read more
- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45756
Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.cgi.... Read more
- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45746
A Directory Traversal vulnerability exists in WeBankPartners wecube-platform 3.2.1 via the file variable in PluginPackageController.java.... Read more
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-45745
A Stored Cross Site Scripting (XSS) vulnerability exists in Bludit 3.13.1 via the About Plugin in login panel.... Read more
Affected Products : bludit- Published: Jan. 06, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-45744
A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel.... Read more
Affected Products : bludit- Published: Jan. 06, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-45742
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-45741
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setIpv6Cfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the relay6to4 parameters.... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45740
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the setWiFiWpsStart function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the pin parameter.... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-45739
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the Form_Login function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the flag parameter.... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-45738
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function UploadFirmwareFile. This vulnerability allows attackers to execute arbitrary commands via the parameter FileName.... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-45737
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the Form_Login function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the Host parameter.... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-45736
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setL2tpServerCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the eip, sip, server parameters.... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45735
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to use the HTTP protocol for authentication into the admin interface, allowing attackers to intercept user credentials via packet capture software.... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-45734
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setUrlFilterRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via the url parameter.... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-45733
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function NTPSyncWithHost. This vulnerability allows attackers to execute arbitrary commands via the parameter host_time.... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-45732
Netgear Nighthawk R6700 version 1.0.4.120 makes use of a hardcoded credential. It does not appear that normal users are intended to be able to manipulate configuration backups due to the fact that they are encrypted/obfuscated. By extracting the configura... Read more
- Published: Dec. 30, 2021
- Modified: Nov. 21, 2024
-
6.0
MEDIUMCVE-2021-45730
JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for Platform Administrators.... Read more
Affected Products : artifactory- Published: May. 19, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45729
The Privilege Escalation vulnerability discovered in the WP Google Map WordPress plugin (versions <= 1.8.0) allows authenticated low-role users to create, edit, and delete maps.... Read more
Affected Products : wp_google_map- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-45721
JFrog Artifactory prior to version 7.29.8 and 6.23.38 is vulnerable to Reflected Cross-Site Scripting (XSS) through one of the XHR parameters in Users REST API endpoint. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.36.1 ... Read more
Affected Products : artifactory- Published: Jul. 06, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45720
An issue was discovered in the lru crate before 0.7.1 for Rust. The iterators have a use-after-free, as demonstrated by an access after a pop operation.... Read more
Affected Products : lru- Published: Dec. 26, 2021
- Modified: Nov. 21, 2024