Latest CVE Feed
-
7.5
HIGHCVE-2021-37517
An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application allows email addresses as usernames, which can cause a Denial of Service.... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %0.34
- Published: Mar. 31, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-37504
A cross-site scripting (XSS) vulnerability in the fileNameStr parameter of jQuery-Upload-File v4.0.11 allows attackers to execute arbitrary web scripts or HTML via a crafted file with a Javascript payload in the file name.... Read more
Affected Products : jquery_upload_file- EPSS Score: %0.72
- Published: Feb. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37478
In NavigateCMS version 2.9.4 and below, function `block` is vulnerable to sql injection on parameter `block-order`, which results in arbitrary sql query execution in the backend database.... Read more
- EPSS Score: %0.68
- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37477
In NavigateCMS version 2.9.4 and below, function in `structure.php` is vulnerable to sql injection on parameter `children_order`, which results in arbitrary sql query execution in the backend database.... Read more
- EPSS Score: %0.68
- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37476
In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `id` through a post request, which results in arbitrary sql query execution in the backend database.... Read more
- EPSS Score: %0.68
- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37475
In NavigateCMS version 2.9.4 and below, function in `templates.php` is vulnerable to sql injection on parameter `template-properties-order`, which results in arbitrary sql query execution in the backend database.... Read more
- EPSS Score: %0.68
- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37473
In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `products-order` through a post request, which results in arbitrary sql query execution in the backend database.... Read more
- EPSS Score: %0.68
- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-37471
Cradlepoint IBR900-600 devices running versions < 7.21.10 are vulnerable to a restricted shell escape sequence that provides an attacker the capability to simultaneously deny availability to the device's NetCloud Manager console, local console and SSH com... Read more
- EPSS Score: %0.37
- Published: Nov. 07, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37470
In NCH WebDictate v2.13, persistent Cross Site Scripting (XSS) exists in the Recipient Name field. An authenticated user can add or modify the affected field to inject arbitrary JavaScript.... Read more
Affected Products : webdictate- EPSS Score: %0.16
- Published: Jul. 25, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-37469
In NCH WebDictate v2.13 and earlier, authenticated users can abuse logprop?file=/.. path traversal to read files on the filesystem.... Read more
Affected Products : webdictate- EPSS Score: %0.27
- Published: Jul. 25, 2021
- Modified: Nov. 21, 2024
-
3.3
LOWCVE-2021-37468
NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration files.... Read more
Affected Products : reflect_customer_relationship_management- EPSS Score: %0.02
- Published: Jul. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37467
In NCH Quorum v2.03 and earlier, XSS exists via /conferencebrowseuploadfile?confid= (reflected).... Read more
Affected Products : quorum- EPSS Score: %0.21
- Published: Jul. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37466
In NCH Quorum v2.03 and earlier, XSS exists via /conference?id= (reflected).... Read more
Affected Products : quorum- EPSS Score: %0.21
- Published: Jul. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37465
In NCH Quorum v2.03 and earlier, XSS exists via /uploaddoc?id= (reflected).... Read more
Affected Products : quorum- EPSS Score: %0.21
- Published: Jul. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37464
In NCH Quorum v2.03 and earlier, XSS exists via Conference Description (stored).... Read more
Affected Products : quorum- EPSS Score: %0.21
- Published: Jul. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37463
In NCH Quorum v2.03 and earlier, XSS exists via User Display Name (stored).... Read more
Affected Products : quorum- EPSS Score: %0.21
- Published: Jul. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37462
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /ipblacklist?errorip= (reflected).... Read more
Affected Products : axon_pbx- EPSS Score: %0.18
- Published: Jul. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37461
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /extensionsinstruction?id= (reflected).... Read more
Affected Products : axon_pbx- EPSS Score: %0.18
- Published: Jul. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37460
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /planprop?id= (reflected).... Read more
Affected Products : axon_pbx- EPSS Score: %0.21
- Published: Jul. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37459
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored).... Read more
Affected Products : axon_pbx- EPSS Score: %0.21
- Published: Jul. 25, 2021
- Modified: Nov. 21, 2024