Latest CVE Feed
-
10.0
HIGHCVE-2021-42872
TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code.... Read more
- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-42870
ACCEL-PPP 1.12.0 has an out-of-bounds read in post_msg when processing a call_clear_request.... Read more
Affected Products : accel-ppp- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-42869
A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 via the last_name parameter in the (1) patient/insert, (2) patient_report, (3) /appointment_report, (4) visit_report, and (5) /bill_detail_report pages.... Read more
Affected Products : patient_management_software- Published: Mar. 31, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-42868
A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 in the first_name parameter in (1) patient/insert, (2) patient_report, (3) appointment_report, (4) visit_report, and (5) bill_detail_report pages. .... Read more
Affected Products : patient_management_software- Published: Mar. 31, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-42867
A Cross Site Scripting (XSS) vulnerability exists in DanPros htmly 2.8.1 via the Description field in (1) admin/config, and (2) index.php pages.... Read more
Affected Products : htmly- Published: Mar. 31, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-42866
A Cross Site Scripting vulnerabilty exists in Pixelimity 1.0 via the Site Description field in pixelimity/admin/setting.php... Read more
Affected Products : pixelimity- Published: Mar. 31, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42863
A buffer overflow in ecma_builtin_typedarray_prototype_filter() in JerryScript version fe3a5c0 allows an attacker to construct a fake object or a fake arraybuffer with unlimited size.... Read more
Affected Products : jerryscript- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-42860
A stack buffer overflow exists in Mini-XML v3.2. When inputting an unformed XML string to the mxmlLoadString API, it will cause a stack-buffer-overflow in mxml_string_getc:2611. NOTE: it is unclear whether this input is allowed by the API specification... Read more
Affected Products : mini-xml- Published: May. 26, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-42859
A memory leak issue was discovered in Mini-XML v3.2 that could cause a denial of service. NOTE: testing reports are inconsistent, with some testers seeing the issue in both the 3.2 release and in the October 2021 development code, but others not seeing th... Read more
Affected Products : mini-xml- Published: May. 26, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-42857
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDaServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/da/pcf" API. The affected endpoint does not have any validation of the user's in... Read more
Affected Products : steelcentral_appinternals_dynamic_sampling_agent- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-42856
It was discovered that the /DsaDataTest endpoint is susceptible to Cross-site scripting (XSS) attack. It was noted that the Metric parameter does not have any input checks on the user input that allows an attacker to craft its own malicious payload to tri... Read more
Affected Products : steelcentral_appinternals_dynamic_sampling_agent- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42855
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) uses the ".debug_command.config" file to store a json string that contains a list of IDs and pre-configured commands. The config file is subsequently used by the "/api/appIn... Read more
Affected Products : steelcentral_appinternals_dynamic_sampling_agent- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42854
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) PluginServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/plugin/pmx" API. The affected endpoint does not have any input validation of the user's... Read more
Affected Products : steelcentral_appinternals_dynamic_sampling_agent- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42853
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDiagnosticServlet has directory traversal vulnerability at the "/api/appInternals/1.0/agent/diagnostic/logs" API. The affected endpoint does not have any input valida... Read more
Affected Products : steelcentral_appinternals_dynamic_sampling_agent- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2021-42852
A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execute operating system commands by sending a crafted packet to the device.... Read more
Affected Products : a1_firmware t1_firmware x1_firmware t2_firmware t2pro_firmware a1 t1 x1 t2 t2pro- Published: May. 18, 2022
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2021-42851
A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to create a standard user account.... Read more
Affected Products : a1_firmware t1_firmware x1_firmware t2_firmware t2pro_firmware a1 t1 x1 t2 t2pro- Published: May. 18, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-42850
A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access.... Read more
Affected Products : a1_firmware t1_firmware x1_firmware t2_firmware t2pro_firmware a1 t1 x1 t2 t2pro- Published: May. 18, 2022
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-42849
A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access.... Read more
Affected Products : a1_firmware t1_firmware x1_firmware t2_firmware t2pro_firmware a1 t1 x1 t2 t2pro- Published: May. 18, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-42848
An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrieve device and networking details.... Read more
Affected Products : a1_firmware t1_firmware x1_firmware t2_firmware t2pro_firmware a1 t1 x1 t2 t2pro- Published: May. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42847
Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files.... Read more
Affected Products : manageengine_adaudit_plus- Published: Nov. 11, 2021
- Modified: Nov. 21, 2024