Latest CVE Feed
-
7.2
HIGHCVE-2021-37770
Nucleus CMS v3.71 is affected by a file upload vulnerability. In this vulnerability, we can use upload to change the upload path to the path without the Htaccess file. Upload an Htaccess file and write it to AddType application / x-httpd-php.jpg. In this ... Read more
Affected Products : nucleus_cms- EPSS Score: %1.02
- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-37764
Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /shop/admin/manufacturers.php.... Read more
Affected Products : xos_shop_system- EPSS Score: %0.13
- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37762
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution.... Read more
Affected Products : manageengine_admanager_plus- EPSS Score: %37.38
- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37761
Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution.... Read more
Affected Products : manageengine_admanager_plus- EPSS Score: %37.38
- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37760
A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).... Read more
Affected Products : graylog- EPSS Score: %0.50
- Published: Jul. 31, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37759
A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).... Read more
Affected Products : graylog- EPSS Score: %0.50
- Published: Jul. 31, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-37750
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/do_tgs_req.c via a FAST inner body that lacks a server field.... Read more
- EPSS Score: %0.45
- Published: Aug. 23, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-37749
MapService.svc in Hexagon GeoMedia WebMap 2020 before Update 2 (aka 16.6.2.66) allows blind SQL Injection via the Id (within sourceItems) parameter to the GetMap method.... Read more
Affected Products : geomedia_webmap- EPSS Score: %0.92
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-37748
Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authenticated users to execute arbitrary code as root via a crafted manage_if setting, thus bypassing the intended restr... Read more
- EPSS Score: %11.92
- Published: Oct. 28, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-37746
textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.... Read more
- EPSS Score: %0.40
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37743
app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON format.... Read more
Affected Products : misp- EPSS Score: %0.26
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37742
app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster relationships.... Read more
Affected Products : misp- EPSS Score: %0.26
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-37741
ManageEngine ADManager Plus before 7111 has Pre-authentication RCE vulnerabilities.... Read more
Affected Products : manageengine_admanager_plus- EPSS Score: %5.41
- Published: Sep. 21, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-37740
A denial of service vulnerability exists in MDT's firmware for the KNXnet/IP Secure router SCN-IP100.03 and KNX IP interface SCN-IP000.03 before v3.0.4, that allows a remote attacker to turn the device unresponsive to all requests on the KNXnet/IP Secure ... Read more
- EPSS Score: %13.06
- Published: Apr. 20, 2022
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-37739
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior ... Read more
Affected Products : clearpass_policy_manager- EPSS Score: %3.30
- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-37738
A remote disclosure of sensitive information vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.... Read more
Affected Products : clearpass_policy_manager- EPSS Score: %0.32
- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-37737
A remote SQL injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1. ... Read more
Affected Products : clearpass_policy_manager- EPSS Score: %0.61
- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37736
A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8... Read more
Affected Products : clearpass_policy_manager- EPSS Score: %0.69
- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-37735
A remote denial of service vulnerability was discovered in Aruba Instant version(s): Aruba Instant 6.5.x.x: 6.5.4.18 and below; Aruba Instant 8.5.x.x: 8.5.0.10 and below; Aruba Instant 8.6.x.x: 8.6.0.4 and below. Aruba has released patches for Aruba Insta... Read more
- EPSS Score: %0.54
- Published: Oct. 12, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-37734
A remote unauthorized read access to files vulnerability was discovered in Aruba Instant version(s): 6.4.x.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x.x: 6.5.4.19 and below; Aruba Instant 8.5.x.x: 8.5.0.12 and below; Aruba Instant 8.6.x.x: 8.6.0.11... Read more
- EPSS Score: %0.48
- Published: Oct. 12, 2021
- Modified: Nov. 21, 2024