Latest CVE Feed
-
4.3
MEDIUMCVE-2021-38378
OX App Suite 7.10.5 allows Information Exposure because a caching mechanism can caused a Modified By response to show a person's name.... Read more
- EPSS Score: %0.25
- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38377
OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.... Read more
- EPSS Score: %0.30
- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-38376
OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.... Read more
- EPSS Score: %0.27
- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38375
OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message.... Read more
- EPSS Score: %0.34
- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38374
OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL.... Read more
- EPSS Score: %0.38
- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-38373
In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked.... Read more
Affected Products : kmail- EPSS Score: %0.16
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-38372
In KDE Trojita 0.7, man-in-the-middle attackers can create new folders because untagged responses from an IMAP server are accepted before STARTTLS.... Read more
- EPSS Score: %0.31
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38371
The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending.... Read more
Affected Products : exim- EPSS Score: %1.21
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-38370
In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS.... Read more
Affected Products : alpine- EPSS Score: %0.19
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-38366
Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code execution by visiting an uploaded .aspx file at an admin/Packages URL.... Read more
Affected Products : sitecore- EPSS Score: %2.79
- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-38365
Winner (aka ToneWinner) desktop speakers through 2021-08-09 allow remote attackers to recover speech signals from the power-indicator LED via a telescope and an electro-optical sensor, aka a "Glowworm" attack.... Read more
- EPSS Score: %0.44
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-38362
In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecure Direct Object Reference (IDOR) issue and retrieve sensitive data.... Read more
Affected Products : archer- EPSS Score: %0.27
- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38361
The .htaccess Redirect WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the link parameter found in the ~/htaccess-redirect.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.3.1.... Read more
Affected Products : htaccess-redirect- EPSS Score: %0.21
- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38360
The wp-publications WordPress plugin is vulnerable to restrictive local file inclusion via the Q_FILE parameter found in the ~/bibtexbrowser.php file which allows attackers to include local zip files and achieve remote code execution, in versions up to an... Read more
Affected Products : wp-publications- EPSS Score: %4.63
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38359
The WordPress InviteBox Plugin for viral Refer-a-Friend Promotions WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the message parameter found in the ~/admin/admin.php file which allows attackers to inject arbitrary web scripts, in ve... Read more
Affected Products : invitebox- EPSS Score: %0.21
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38358
The MoolaMojo WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the classes parameter found in the ~/views/button-generator.html.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.7.4.1.... Read more
Affected Products : moolamojo- EPSS Score: %0.21
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38357
The SMS OVH WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the position parameter found in the ~/sms-ovh-sent.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.1.... Read more
Affected Products : sms-ovh- EPSS Score: %0.21
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38356
The NextScripts: Social Networks Auto-Poster <= 4.3.20 WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $_REQUEST['page'] parameter which is echoed out on inc/nxs_class_snap.php by supplying the appropriate value 'nxssnap-post' to ... Read more
Affected Products : social_networks_auto_poster- EPSS Score: %0.21
- Published: Nov. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38355
The Bug Library WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the successimportcount parameter found in the ~/bug-library.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.3.... Read more
Affected Products : bug_library- EPSS Score: %0.21
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38354
The GNU-Mailman Integration WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the gm_error parameter found in the ~/includes/admin/mailing-lists-page.php file which allows attackers to inject arbitrary web scripts, in versions up to and... Read more
Affected Products : gnu-mailman_integration- EPSS Score: %0.21
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024