Latest CVE Feed
-
7.8
HIGHCVE-2021-38608
Incorrect Access Control in Tranquil WAPT Enterprise - before 1.8.2.7373 and before 2.0.0.9450 allows guest OS users to escalate privileges via WAPT Agent.... Read more
Affected Products : wapt- EPSS Score: %0.04
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38607
Crocoblock JetEngine before 2.6.1 allows XSS by remote authenticated users via a custom form input.... Read more
Affected Products : jetengine- EPSS Score: %0.21
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38606
reNgine through 0.5 relies on a predictable directory name.... Read more
- EPSS Score: %0.43
- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-38603
PluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field.... Read more
Affected Products : pluxml- EPSS Score: %0.76
- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-38602
PluXML 5.8.7 allows Article Editing stored XSS via Headline or Content.... Read more
Affected Products : pluxml- EPSS Score: %0.52
- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38599
WAL-G before 1.1, when a non-libsodium build (e.g., one of the official binary releases published as GitHub Releases) is used, silently ignores the libsodium encryption key and uploads cleartext backups. This is arguably a Principle of Least Surprise viol... Read more
Affected Products : wal-g- EPSS Score: %0.17
- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-38598
OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. By sending carefully crafted packets, anyone in control of a server ... Read more
- EPSS Score: %0.04
- Published: Aug. 23, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-38597
wolfSSL before 4.8.1 incorrectly skips OCSP verification in certain situations of irrelevant response data that contains the NoCheck extension.... Read more
Affected Products : wolfssl- EPSS Score: %0.18
- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38593
Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).... Read more
- EPSS Score: %0.94
- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38592
Wasm3 0.5.0 has a heap-based buffer overflow in op_Const64 (called from EvaluateExpression and m3_LoadModule).... Read more
Affected Products : wasm3- EPSS Score: %0.30
- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
3.3
LOWCVE-2021-38591
An issue was discovered on LG mobile devices with Android OS P and Q software for mt6762/mt6765/mt6883. Attackers can change some of the NvRAM content by leveraging the misconfiguration of a debug command. The LG ID is LVE-SMP-210005 (August 2021).... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-38590
In cPanel before 96.0.8, weak permissions on web stats can lead to information disclosure (SEC-584).... Read more
Affected Products : cpanel- EPSS Score: %0.04
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-38589
In cPanel before 96.0.13, scripts/fix-cpanel-perl does not properly restrict the overwriting of files (SEC-588).... Read more
Affected Products : cpanel- EPSS Score: %0.37
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-38588
In cPanel before 96.0.13, fix_cpanel_perl lacks verification of the integrity of downloads (SEC-587).... Read more
Affected Products : cpanel- EPSS Score: %0.19
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38587
In cPanel before 96.0.13, scripts/fix-cpanel-perl mishandles the creation of temporary files (SEC-586).... Read more
Affected Products : cpanel- EPSS Score: %0.17
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-38586
In cPanel before 98.0.1, /scripts/cpan_config performs unsafe operations on files (SEC-589).... Read more
Affected Products : cpanel- EPSS Score: %0.07
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-38585
The WHM Locale Upload feature in cPanel before 98.0.1 allows unserialization attacks (SEC-585).... Read more
Affected Products : cpanel- EPSS Score: %1.26
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-38584
The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585).... Read more
Affected Products : cpanel- EPSS Score: %0.40
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38583
openBaraza HCM 3.1.6 does not properly neutralize user-controllable input, which allows reflected cross-site scripting (XSS) on multiple pages: hr/subscription.jsp and hr/application.jsp and and hr/index.jsp (with view= and data=).... Read more
Affected Products : openbaraza_human_capital_management- EPSS Score: %1.09
- Published: Aug. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38578
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.... Read more
- EPSS Score: %0.06
- Published: Mar. 03, 2022
- Modified: Nov. 21, 2024