Latest CVE Feed
-
9.8
CRITICALCVE-2021-3304
Sagemcom F@ST 3686 v2 3.495 devices have a buffer overflow via a long sessionKey to the goform/login URI.... Read more
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-3298
Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit address1 parameter.... Read more
Affected Products : collabtive- Published: Jan. 29, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-3297
On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.... Read more
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-3294
CASAP Automated Enrollment System 1.0 is affected by cross-site scripting (XSS) in users.php. An attacker can steal a cookie to perform user redirection to a malicious website.... Read more
Affected Products : casap_automated_enrollment_system- Published: Feb. 09, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-3293
emlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webroot/file.... Read more
Affected Products : emlog- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-3291
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command.... Read more
Affected Products : zen_cart- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-3287
Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class.... Read more
Affected Products : manageengine_opmanager- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-3286
SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variation of the payload may be used. NOTE: this issue exists because of an incomplete fix for CVE-2020-35545.... Read more
Affected Products : spotweb- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-3285
jxbrowser in TI Code Composer Studio IDE 8.x through 10.x before 10.1.1 does not verify X.509 certificates for HTTPS.... Read more
Affected Products : code_composer_studio_intgrated_development_environment- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-3283
HashiCorp Nomad and Nomad Enterprise up to 0.12.9 exec and java task drivers can access processes associated with other tasks on the same node. Fixed in 0.12.10, and 1.0.3.... Read more
Affected Products : nomad- Published: Feb. 01, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-3282
HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secondaries without authentication. Fixed in 1.6.2.... Read more
Affected Products : vault- Published: Feb. 01, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-3281
In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "startproject --template") allows directory traversal via an archive with absolute paths or relative paths wit... Read more
- Published: Feb. 02, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-3279
sz.chat version 4 allows injection of web scripts and HTML in the message box.... Read more
Affected Products : szchat- Published: Jul. 19, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-3278
Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection . Using this vulnerability, an attacker can bypass the login page.... Read more
Affected Products : local_services_search_engine_management_system- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-3277
Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rename functionality in custom-includes component, which leads to remote code execution by uploading php files.... Read more
Affected Products : nagios_xi- Published: Jun. 07, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-3275
Unauthenticated stored cross-site scripting (XSS) exists in multiple TP-Link products including WIFI Routers (Wireless AC routers), Access Points, ADSL + DSL Gateways and Routers, which affects TD-W9977v1, TL-WA801NDv5, TL-WA801Nv6, TL-WA802Nv5, and Arche... Read more
- Published: Mar. 26, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-3273
Nagios XI below 5.7 is affected by code injection in the /nagiosxi/admin/graphtemplates.php component. To exploit this vulnerability, someone must have an admin user account in Nagios XI's web system.... Read more
Affected Products : nagios_xi- Published: Feb. 25, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-3272
jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between the number of channels and the number of image components.... Read more
- Published: Jan. 27, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-3271
PressBooks 5.17.3 contains a cross-site scripting (XSS). Stored XSS can be submitted via the Book Info's Long Description Body, and all actions to open or preview the books page will result in the triggering the stored XSS.... Read more
Affected Products : pressbooks- Published: Feb. 18, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-3264
SQL Injection vulnerability in cxuucms 3.1 ivia the pid parameter in public/admin.php.... Read more
Affected Products : cxuucms- Published: Aug. 27, 2021
- Modified: Nov. 21, 2024