Latest CVE Feed
-
5.4
MEDIUMCVE-2021-41432
A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands through blog content.... Read more
Affected Products : flatpress- Published: Jun. 23, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41427
Beeline Smart Box 2.0.38 is vulnerable to Cross Site Scripting (XSS) via the choose_mac parameter to setup.cgi.... Read more
- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-41426
Beeline Smart box 2.0.38 is vulnerable to Cross Site Request Forgery (CSRF) via mgt_end_user.htm.... Read more
- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-41421
A PHP code injection vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker to gain RCE through the MaianAffiliate admin panel.... Read more
Affected Products : maianaffiliate- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-41420
A stored XSS vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker for arbitrary JavaScript code execution in the context of authenticated and unauthenticated users through the MaianAffiliate admin panel.... Read more
Affected Products : maianaffiliate- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41419
QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization.... Read more
- Published: Jul. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41418
AriaNg v0.1.0~v1.2.2 is affected by an incorrect access control vulnerability through not authenticating visitors' access rights.... Read more
Affected Products : ariang- Published: Jun. 15, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41415
Subscription-Manager v1.0 /main.js has a cross-site scripting (XSS) vulnerability in the machineDetail parameter.... Read more
Affected Products : subscription-manager- Published: Jun. 15, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-41413
ok-file-formats master 2021-9-12 is affected by a buffer overflow in ok_jpg_convert_data_unit_grayscale and ok_jpg_convert_YCbCr_to_RGB.... Read more
Affected Products : ok-file-formats- Published: Jun. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41411
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.... Read more
Affected Products : drools- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41408
VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter.... Read more
Affected Products : voipmonitor- Published: Jun. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41403
flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities.... Read more
Affected Products : flatcore-cms- Published: Jun. 15, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-41402
flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP code.... Read more
Affected Products : flatcore-cms- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41396
Live555 through 1.08 does not handle socket connections properly. A huge number of incoming socket connections in a short time invokes the error-handling module, in which a heap-based buffer overflow happens. An attacker can leverage this to launch a DoS ... Read more
Affected Products : live555- Published: Jul. 12, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-41395
Teleport before 6.2.12 and 7.x before 7.1.1 allows attackers to control a database connection string, in some situations, via a crafted database name or username.... Read more
Affected Products : teleport- Published: Sep. 18, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-41394
Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows alteration of build artifacts in some situations.... Read more
Affected Products : teleport- Published: Sep. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41393
Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows forgery of SSH host certificates in some situations.... Read more
Affected Products : teleport- Published: Sep. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41392
static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal Electron API.... Read more
Affected Products : boostnote- Published: Sep. 17, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-41391
In Ericsson ECM before 18.0, it was observed that Security Management Endpoint in User Profile Management Section is vulnerable to stored XSS via a name, leading to session hijacking and full account takeover.... Read more
Affected Products : enterprise_content_management- Published: Sep. 17, 2021
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2021-41390
In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injection.... Read more
Affected Products : enterprise_content_management- Published: Sep. 17, 2021
- Modified: Nov. 21, 2024