Latest CVE Feed
-
7.2
HIGHCVE-2021-37289
Insecure Permissions in administration interface in Planex MZK-DP150N 1.42 and 1.43 allows attackers to execute system command as root via etc_ro/web/syscmd.asp.... Read more
- EPSS Score: %0.46
- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-37274
Kingdee KIS Professional Edition has a privilege escalation vulnerability. Attackers can use the vulnerability to gain computer administrator rights via unspecified loopholes.... Read more
Affected Products : kis_cloud- EPSS Score: %0.33
- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-37273
A Denial of Service issue exists in China Telecom Corporation EPON Tianyi Gateway ZXHN F450(EPON ONU) 3.0. Tianyi Gateway is a hardware terminal of "Optical Modem Smart Router." Attackers can use this vulnerability to restart the device multiple times.... Read more
- EPSS Score: %0.30
- Published: Sep. 28, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37271
Cross Site Scripting (XSS) vulnerability exists in UEditor v1.4.3.3, which can be exploited by an attacker to obtain user cookie information.... Read more
Affected Products : ueditor- EPSS Score: %0.21
- Published: Sep. 28, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-37270
There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0. Attackers can use this vulnerability to directly access the specified background path without logging in to the background to obtain the background admini... Read more
Affected Products : cms_enterprise_website_construction_system- EPSS Score: %0.26
- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-37267
Cross Site Scripting (XSS) vulnerability exists in all versions of KindEditor, which can be exploited by an attacker to obtain user cookie information.... Read more
Affected Products : kindeditor- EPSS Score: %0.24
- Published: Sep. 28, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-37262
JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service.... Read more
Affected Products : jfinal_cms- EPSS Score: %0.37
- Published: Dec. 16, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-37254
In M-Files Web product with versions before 20.10.9524.1 and 20.10.9445.0, a remote attacker could use a flaw to obtain unauthenticated access to 3rd party component license key information on server.... Read more
- EPSS Score: %0.32
- Published: Oct. 28, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-37253
M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range or Request-Range headers). NOTE: this is disputed because the range behavior is the responsibility of the web server, not the responsibi... Read more
- EPSS Score: %3.12
- Published: Dec. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37232
A stack overflow vulnerability occurs in Atomicparsley 20210124.204813.840499f through APar_read64() in src/util.cpp due to the lack of buffer size of uint32_buffer while reading more bytes in APar_read64.... Read more
Affected Products : atomicparsley- EPSS Score: %0.59
- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-37231
A stack-buffer-overflow occurs in Atomicparsley 20210124.204813.840499f through APar_readX() in src/util.cpp while parsing a crafted mp4 file because of the missing boundary check.... Read more
Affected Products : atomicparsley- EPSS Score: %0.34
- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-37223
Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. Any authenticated user can create scheduled reports containing PDF screenshots of any view in the NagiosXI application. Due to lack of ... Read more
Affected Products : nagios_xi- EPSS Score: %0.68
- Published: Oct. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37222
Parsers in the open source project RCDCAP before 1.0.5 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via specially crafted packets.... Read more
Affected Products : rcdcap- EPSS Score: %0.88
- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-37221
A file upload vulnerability exists in Sourcecodester Customer Relationship Management System 1.0 via the account update option & customer create option, which could let a remote malicious user upload an arbitrary php file. .... Read more
Affected Products : customer_relationship_management_system- EPSS Score: %0.40
- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-37220
MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.... Read more
- EPSS Score: %0.12
- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-37219
HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.8.15, 1.9.9 and 1.10.2.... Read more
Affected Products : consul- EPSS Score: %1.72
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-37218
HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.0.10 and 1.1.4.... Read more
Affected Products : nomad- EPSS Score: %0.17
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-37216
QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript without logging in and launch reflected XSS attacks to access and modify specific data.... Read more
- EPSS Score: %4.04
- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-37215
The employee management page of Flygo contains an Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attacker can manipulate the user data and then over-write another employee’s user data by specifyi... Read more
Affected Products : flygo- EPSS Score: %0.11
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-37214
The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID in specific parameters to arbitrary access employee's data, ... Read more
Affected Products : flygo- EPSS Score: %0.57
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024