Latest CVE Feed
-
5.4
MEDIUMCVE-2021-41918
webTareas version 2.4 and earlier allows an authenticated user to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack against the platform users and administrators. Th... Read more
Affected Products : webtareas- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-41917
webTareas version 2.4 and earlier allows an authenticated user to store arbitrary web script or HTML by creating or editing a client name in the clients section, due to incorrect sanitization of user-supplied data and achieve a Stored Cross-Site Scripting... Read more
Affected Products : webtareas- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-41916
A Cross-Site Request Forgery (CSRF) vulnerability in webTareas version 2.4 and earlier allows a remote attacker to create a new administrative profile and add a new user to the new profile. without the victim's knowledge, by enticing an authenticated admi... Read more
Affected Products : webtareas- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41878
A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console and it is possible to insert a vulnerable mal... Read more
Affected Products : i-panel_administration_system- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-41873
Penguin Aurora TV Box 41502 is a high-end network HD set-top box produced by Tencent Video and Skyworth Digital. An unauthorized access vulnerability exists in the Penguin Aurora Box. An attacker can use the vulnerability to gain unauthorized access to a ... Read more
- Published: Oct. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41872
Skyworth Digital Technology Penguin Aurora Box 41502 has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service.... Read more
- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-41871
An issue was discovered in Socomec REMOTE VIEW PRO 2.0.41.4. Improper validation of input into the username field makes it possible to place a stored XSS payload. This is executed if an administrator views the System Event Log.... Read more
- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-41870
An issue was discovered in the firmware update form in Socomec REMOTE VIEW PRO 2.0.41.4. An authenticated attacker can bypass a client-side file-type check and upload arbitrary .php files.... Read more
- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-41869
SuiteCRM 7.10.x before 7.10.33 and 7.11.x before 7.11.22 is vulnerable to privilege escalation.... Read more
Affected Products : suitecrm- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41868
OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to upload files on a non-public node when using the --receive functionality.... Read more
Affected Products : onionshare- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-41867
An information disclosure vulnerability in OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to retrieve the full list of participants of a non-public OnionShare node via the --chat feature.... Read more
Affected Products : onionshare- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-41866
MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not escaped properly.... Read more
Affected Products : mybb- Published: Oct. 26, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-41865
HashiCorp Nomad and Nomad Enterprise 1.1.1 through 1.1.5 allowed authenticated users with job submission capabilities to cause denial of service by submitting incomplete job specifications with a Consul mesh gateway and host networking mode. Fixed in 1.1.... Read more
Affected Products : nomad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-41864
prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write.... Read more
Affected Products : linux_kernel fedora debian_linux solidfire_baseboard_management_controller_firmware h410c_firmware cloud_backup hci_management_node solidfire h300s_firmware h500s_firmware +14 more products- Published: Oct. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41862
AviatorScript through 5.2.7 allows code execution via an expression that is encoded with Byte Code Engineering Library (BCEL).... Read more
Affected Products : aviatorscript- Published: Oct. 02, 2021
- Modified: Nov. 21, 2024
-
3.3
LOWCVE-2021-41861
The Telegram application 7.5.0 through 7.8.0 for Android does not properly implement image self-destruction, a different vulnerability than CVE-2019-16248. After approximately two to four uses of the self-destruct feature, there is a misleading UI indicat... Read more
Affected Products : telegram- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-41850
An issue was discovered in Luna Simo PPR1.180610.011/202001031830. A pre-installed app with a package name of com.skyroam.silverhelper writes three IMEI values to system properties at system startup. The system property values can be obtained via getprop ... Read more
Affected Products : g90_firmware g9_firmware tommy_3_firmware tommy_3_plus_firmware simo_firmware g90 g9 tommy_3 tommy_3_plus simo- Published: Mar. 11, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-41849
An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It sends the following Personally Identifiable Information (PII) in plaintext using HTTP to servers located in China: user's list of installed apps and device International Mobile Equipmen... Read more
Affected Products : g90_firmware g9_firmware tommy_3_firmware tommy_3_plus_firmware simo_firmware g90 g9 tommy_3 tommy_3_plus simo- Published: Mar. 11, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-41848
An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It mishandles software updates such that local third-party apps can provide a spoofed software update file that contains an arbitrary shell script and arbitrary ARM binary, where both will... Read more
Affected Products : g90_firmware g9_firmware tommy_3_firmware tommy_3_plus_firmware simo_firmware g90 g9 tommy_3 tommy_3_plus simo- Published: Mar. 11, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-41847
An issue was discovered in 3xLogic Infinias Access Control through 6.7.10708.0, affecting physical security. Users with login credentials assigned to a specific zone can send modified HTTP GET and POST requests, allowing them to view user data such as per... Read more
Affected Products : infinias_access_control- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024