Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2021-38713

    imgURL 2.31 allows XSS via an X-Forwarded-For HTTP header.... Read more

    Affected Products : imgurl
    • EPSS Score: %0.17
    • Published: Aug. 16, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-38712

    OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to block the access via an NGINX configuration file.... Read more

    Affected Products : onenav onenav
    • EPSS Score: %0.24
    • Published: Aug. 16, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-38711

    In gitit before 0.15.0.0, the Export feature can be exploited to leak information from files.... Read more

    Affected Products : gitit
    • EPSS Score: %0.32
    • Published: Aug. 16, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-38710

    Static (Persistent) XSS Vulnerability exists in version 4.3.0 of Yclas when using the install/view/form.php script. An attacker can store XSS in the database through the vulnerable SITE_NAME parameter.... Read more

    Affected Products : yclas
    • EPSS Score: %0.24
    • Published: Aug. 18, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-38709

    In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via the staff_messaging messaging system for XSS.... Read more

    Affected Products : composr_cms
    • EPSS Score: %0.32
    • Published: Aug. 16, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-38708

    In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via Comcode for XSS.... Read more

    Affected Products : composr_cms
    • EPSS Score: %0.30
    • Published: Aug. 16, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-38707

    Persistent cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow low-privileged attackers to introduce arbitrary JavaScript to account parameters. The XSS payloads will execute in the browser of any user who views the relevant content. Thi... Read more

    Affected Products : cliniccases
    • EPSS Score: %0.21
    • Published: Sep. 07, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-38706

    messages_load.php in ClinicCases 7.3.3 suffers from a blind SQL injection vulnerability, which allows low-privileged attackers to execute arbitrary SQL commands through a vulnerable parameter.... Read more

    Affected Products : cliniccases
    • EPSS Score: %0.74
    • Published: Sep. 07, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-38705

    ClinicCases 7.3.3 is affected by Cross-Site Request Forgery (CSRF). A successful attack would consist of an authenticated user following a malicious link, resulting in arbitrary actions being carried out with the privilege level of the targeted user. This... Read more

    Affected Products : cliniccases
    • EPSS Score: %0.72
    • Published: Sep. 07, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-38704

    Multiple reflected cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow unauthenticated attackers to introduce arbitrary JavaScript by crafting a malicious URL. This can result in account takeover via session token theft.... Read more

    Affected Products : cliniccases
    • EPSS Score: %9.96
    • Published: Sep. 07, 2021
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2021-38703

    Wireless devices running certain Arcadyan-derived firmware (such as KPN Experia WiFi 1.00.15) do not properly sanitise user input to the syslog configuration form. An authenticated remote attacker could leverage this to alter the device configuration and ... Read more

    Affected Products : experia_wifi_firmware experia_wifi
    • EPSS Score: %8.25
    • Published: Sep. 01, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-38702

    Cyberoam NetGenie C0101B1-20141120-NG11VO devices through 2021-08-14 allow tweb/ft.php?u=[XSS] attacks.... Read more

    • EPSS Score: %46.90
    • Published: Aug. 17, 2021
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2021-38701

    Certain Motorola Solutions Avigilon devices allow XSS in the administrative UI. This affects T200/201 before 4.10.0.68; T290 before 4.4.0.80; T008 before 2.2.0.86; T205 before 4.12.0.62; T204 before 3.28.0.166; and T100, T101, T102, and T103 before 2.6.0.... Read more

    • EPSS Score: %0.40
    • Published: Dec. 15, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-38699

    TastyIgniter 3.0.7 allows XSS via /account, /reservation, /admin/dashboard, and /admin/system_logs.... Read more

    Affected Products : tastyigniter
    • EPSS Score: %4.64
    • Published: Aug. 15, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-38698

    HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. Fixed in 1.8.15, 1.9.9 and 1.10.2.... Read more

    Affected Products : consul
    • EPSS Score: %0.55
    • Published: Sep. 07, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-38697

    SoftVibe SARABAN for INFOMA 1.1 allows Unauthenticated unrestricted File Upload, that allows attackers to upload files with any file extension which can lead to arbitrary code execution.... Read more

    Affected Products : saraban
    • EPSS Score: %2.10
    • Published: Jan. 18, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-38696

    SoftVibe SARABAN for INFOMA 1.1 has Incorrect Access Control vulnerability, that allows attackers to access signature files on the application without any authentication.... Read more

    Affected Products : saraban
    • EPSS Score: %0.35
    • Published: Jan. 18, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-38695

    SoftVibe SARABAN for INFOMA 1.1 is vulnerable to stored cross-site scripting (XSS) that allows users to store scripts in certain fields (e.g. subject, description) of the document form.... Read more

    Affected Products : saraban
    • EPSS Score: %0.26
    • Published: Jan. 18, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-38694

    SoftVibe SARABAN for INFOMA 1.1 allows SQL Injection.... Read more

    Affected Products : saraban
    • EPSS Score: %0.28
    • Published: Jan. 18, 2022
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-38693

    A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, QTS, QVR Pro Appliance. If exploited, this vulnerability allows attackers to read the contents of unexpected files and expose sensitive data. We have alre... Read more

    Affected Products : quts_hero qts qutscloud
    • EPSS Score: %0.27
    • Published: May. 05, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 291814 Results