Latest CVE Feed
-
8.8
HIGHCVE-2021-39376
Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the CorCad_F2/executaConsultaEspecifico IE_CORPO_ASSIST or CD_USUARIO_CONVENIO parameter.... Read more
Affected Products : tasy_electronic_medical_record- EPSS Score: %0.48
- Published: Aug. 24, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-39375
Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the WAdvancedFilter/getDimensionItemsByCode FilterValue parameter.... Read more
- EPSS Score: %0.32
- Published: Aug. 24, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-39373
Samsung Drive Manager 2.0.104 on Samsung H3 devices allows attackers to bypass intended access controls on disk management. WideCharToMultiByte, WideCharStr, and MultiByteStr can contribute to password exposure.... Read more
- EPSS Score: %0.05
- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-39371
An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server filesystem by assigning a path to the entity. OWSLib 0.24.1 may also be affected.... Read more
- EPSS Score: %0.45
- Published: Aug. 23, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-39368
Canon Oce Print Exec Workgroup 1.3.2 allows XSS via the lang parameter.... Read more
Affected Products : oce_print_exec_workgroup- EPSS Score: %0.24
- Published: Aug. 23, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-39367
Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection.... Read more
Affected Products : oce_print_exec_workgroup- EPSS Score: %0.24
- Published: Aug. 23, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-39365
In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.... Read more
- EPSS Score: %0.30
- Published: Aug. 22, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-39364
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP cache poisoning has been achieved.... Read more
- EPSS Score: %0.23
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-39363
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow a video replay attack after ARP cache poisoning has been achieved.... Read more
- EPSS Score: %1.36
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-39362
An XSS issue was discovered in ReCaptcha Solver 5.7. A response from Anti-Captcha.com, RuCaptcha.com, 2captcha.com, DEATHbyCAPTCHA.com, ImageTyperz.com, or BestCaptchaSolver.com in setCaptchaCode() is inserted into the DOM as HTML, resulting in full contr... Read more
Affected Products : recaptcha_solver- EPSS Score: %0.24
- Published: Aug. 22, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-39361
In GNOME evolution-rss through 0.3.96, network-soup.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.... Read more
Affected Products : evolution-rss- EPSS Score: %0.11
- Published: Aug. 22, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-39360
In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.... Read more
- EPSS Score: %0.40
- Published: Aug. 22, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-39359
In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.... Read more
- EPSS Score: %0.27
- Published: Aug. 22, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-39358
In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.... Read more
- EPSS Score: %0.22
- Published: Aug. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39357
The Leaky Paywall WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via the ~/class.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in vers... Read more
Affected Products : leaky_paywall- EPSS Score: %0.45
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39356
The Content Staging WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via several parameters that are echo'd out via the ~/templates/settings.php file which allowed attackers with administrativ... Read more
Affected Products : content_staging- EPSS Score: %0.57
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39355
The Indeed Job Importer WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/indeed-job-importer/trunk/indeed-job-importer.php file which allowed attacker... Read more
Affected Products : indeed-job-importer- EPSS Score: %0.57
- Published: Oct. 19, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-39353
The Easy Registration Forms WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the ajax_add_form function found in the ~/includes/class-form.php file which made it possible for attackers to inject arbitrary we... Read more
Affected Products : easy_registration_forms- EPSS Score: %0.11
- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-39352
The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemoImport.php file, in versions up to and including 1.7, due to insufficient file type validation. This makes... Read more
Affected Products : catch_themes_demo_import- EPSS Score: %77.76
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39349
The Author Bio Box WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/includes/admin/class-author-bio-box-admin.php file which allowed attackers with ad... Read more
Affected Products : author_bio_box- EPSS Score: %0.91
- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024