Latest CVE Feed
-
8.8
HIGHCVE-2021-37366
CTparental before 4.45.03 is vulnerable to cross-site request forgery (CSRF) in the CTparental admin panel. By combining CSRF with XSS, an attacker can trick the administrator into clicking a link that cancels the filtering for all standard users.... Read more
Affected Products : ctparental- EPSS Score: %0.14
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-37365
CTparental before 4.45.03 is vulnerable to cross-site scripting (XSS) in the CTparental admin panel. In bl_categires_help.php, the 'categories' variable is assigned with the content of the query string param 'cat' without sanitization or encoding, enablin... Read more
Affected Products : ctparental- EPSS Score: %0.22
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-37364
OpenClinic GA 5.194.18 is affected by Insecure Permissions. By default the Authenticated Users group has the modify permission to openclinic folders/files. A low privilege account is able to rename mysqld.exe or tomcat8.exe files located in bin folders an... Read more
Affected Products : openclinic_ga- EPSS Score: %0.17
- Published: Oct. 26, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-37363
An Insecure Permissions issue exists in Gestionale Open 11.00.00. A low privilege account is able to rename the mysqld.exe file located in bin folder and replace with a malicious file that would connect back to an attacking computer giving system level pr... Read more
Affected Products : gestionale_open- EPSS Score: %0.20
- Published: Oct. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37358
SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checkrepeat&v_name=".... Read more
Affected Products : seacms- EPSS Score: %1.63
- Published: Aug. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37354
Xerox Phaser 4622 v35.013.01.000 was discovered to contain a buffer overflow in the function sub_3226AC via the TIMEZONE variable. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.... Read more
- EPSS Score: %0.47
- Published: Feb. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37353
Nagios XI Docker Wizard before version 1.1.3 is vulnerable to SSRF due to improper sanitation in table_population.php.... Read more
Affected Products : nagios_xi_docker_wizard- EPSS Score: %2.36
- Published: Aug. 13, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-37352
An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link.... Read more
Affected Products : nagios_xi- EPSS Score: %3.25
- Published: Aug. 13, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-37351
Nagios XI before version 5.8.5 is vulnerable to insecure permissions and allows unauthenticated users to access guarded pages through a crafted HTTP request to the server.... Read more
Affected Products : nagios_xi- EPSS Score: %0.58
- Published: Aug. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37350
Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper input sanitisation.... Read more
Affected Products : nagios_xi- EPSS Score: %47.52
- Published: Aug. 13, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-37349
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because cleaner.php does not sanitise input read from the database.... Read more
Affected Products : nagios_xi- EPSS Score: %0.16
- Published: Aug. 13, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-37348
Nagios XI before version 5.8.5 is vulnerable to local file inclusion through improper limitation of a pathname in index.php.... Read more
Affected Products : nagios_xi- EPSS Score: %11.69
- Published: Aug. 13, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-37347
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because getprofile.sh does not validate the directory name it receives as an argument.... Read more
Affected Products : nagios_xi- EPSS Score: %0.08
- Published: Aug. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37346
Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation of special elements used in an OS Command (OS Command injection).... Read more
Affected Products : nagios_xi_watchguard_wizard- EPSS Score: %51.15
- Published: Aug. 13, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-37345
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scripts with elevated permissions.... Read more
Affected Products : nagios_xi- EPSS Score: %0.08
- Published: Aug. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37344
Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS Command (OS Command injection).... Read more
Affected Products : nagios_xi_switch_wizard- EPSS Score: %53.60
- Published: Aug. 13, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-37343
A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post authenticated RCE under security context of the user running Nagios.... Read more
Affected Products : nagios_xi- EPSS Score: %80.42
- Published: Aug. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37334
Umbraco Forms version 4.0.0 up to and including 8.7.5 and below are vulnerable to a security flaw that could lead to a remote code execution attack and/or arbitrary file deletion. A vulnerability occurs because validation of the file extension is performe... Read more
- EPSS Score: %1.20
- Published: Aug. 25, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37333
Laravel Booking System Booking Core 2.0 is vulnerable to Session Management. A password change at sandbox.bookingcore.org/user/profile/change-password does not invalidate a session that is opened in a different browser.... Read more
Affected Products : booking_core- EPSS Score: %0.38
- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-37331
Laravel Booking System Booking Core 2.0 is vulnerable to Incorrect Access Control. On the Verifications page, after uploading an ID Card or Trade License and viewing it, ID Cards and Trade Licenses of other vendors/users can be viewed by changing the URL.... Read more
Affected Products : booking_core- EPSS Score: %0.21
- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024