Latest CVE Feed
-
7.5
HIGHCVE-2021-36723
Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predictable IDs an attacker can scrape all the files on the service.... Read more
Affected Products : emuse_-_eservices_\/_envoice- EPSS Score: %0.21
- Published: Dec. 29, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-36722
Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dumping the whole database to full RCE on the affected endpoints. The SQLi caused by CWE-209: Generation of Error Message Containig Senset... Read more
Affected Products : emuse_-_eservices_\/_envoice- EPSS Score: %0.19
- Published: Dec. 29, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-36721
Sysaid API User Enumeration - Attacker sending requests to specific api path without any authorization before 21.3.60 version could get users names from the LDAP server.... Read more
Affected Products : application_programming_interface- EPSS Score: %0.15
- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-36720
PineApp - Mail Secure - Attacker sending a request to :/blocking.php?url=<script>alert(1)</script> and stealing cookies .... Read more
Affected Products : mail_secure- EPSS Score: %0.24
- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-36719
PineApp - Mail Secure - The attacker must be logged in as a user to the Pineapp system. The attacker exploits the vulnerable nicUpload.php file to upload a malicious file,Thus taking over the server and running remote code.... Read more
- EPSS Score: %0.40
- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-36718
SYNEL - eharmonynew / Synel Reports - The attacker can log in to the system with default credentials and export a report of eharmony system with sensetive data (Employee name, Employee ID number, Working hours etc') The vulnerabilety has been addressed an... Read more
- EPSS Score: %0.18
- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-36717
Synerion TimeNet version 9.21 contains a directory traversal vulnerability where, on the "Name" parameter, the attacker can return to the root directory and open the host file. This might give the attacker the ability to view restricted files, which could... Read more
Affected Products : timenet- EPSS Score: %0.25
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-36716
A ReDoS (regular expression denial of service) flaw was found in the Segment is-email package before 1.0.1 for Node.js. An attacker that is able to provide crafted input to the isEmail(input) function may cause an application to consume an excessive amoun... Read more
Affected Products : is-email- EPSS Score: %0.47
- Published: Jul. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-36711
WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled.... Read more
Affected Products : octobot- EPSS Score: %49.54
- Published: Jul. 16, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-36710
ToaruOS 1.99.2 is affected by incorrect access control via the kernel. Improper MMU management and having a low GDT address allows it to be mapped in userland. A call gate can then be written to escalate to CPL 0.... Read more
Affected Products : toaruos- EPSS Score: %0.05
- Published: Jun. 08, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-36708
In ProLink PRC2402M V1.0.18 and older, the set_sys_init function in the login.cgi binary allows an attacker to reset the password to the administrative interface of the router.... Read more
- EPSS Score: %0.29
- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-36707
In ProLink PRC2402M V1.0.18 and older, the set_ledonoff function in the adm.cgi binary, accessible with a page parameter value of ledonoff contains a trivial command injection where the value of the led_cmd parameter is passed directly to do_system.... Read more
- EPSS Score: %11.79
- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-36706
In ProLink PRC2402M V1.0.18 and older, the set_sys_cmd function in the adm.cgi binary, accessible with a page parameter value of sysCMD contains a trivial command injection where the value of the command parameter is passed directly to system.... Read more
- EPSS Score: %11.79
- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-36705
In ProLink PRC2402M V1.0.18 and older, the set_TR069 function in the adm.cgi binary, accessible with a page parameter value of TR069 contains a trivial command injection where the value of the TR069_local_port parameter is passed directly to system.... Read more
- EPSS Score: %11.79
- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-36703
The "blog title" field in the "Settings" menu "config" page of "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerability. It allows remote attackers to send an authenticated post HTTP request to admin/config and inject arbitrary we... Read more
Affected Products : htmly- EPSS Score: %0.22
- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-36702
The "content" field in the "regular post" page of the "add content" menu under "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerability. It allows remote attackers to send authenticated post-http requests to add / content and inje... Read more
Affected Products : htmly- EPSS Score: %0.20
- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-36701
In htmly version 2.8.1, is vulnerable to an Arbitrary File Deletion on the local host when delete backup files. The vulnerability may allow a remote attacker to delete arbitrary know files on the host.... Read more
Affected Products : htmly- EPSS Score: %0.87
- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-36698
Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.... Read more
Affected Products : pandora_fms- EPSS Score: %0.63
- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-36697
With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file contains a Rewrite Rule with a type definition. A normal PHP file can be uploaded with this new "file type" an... Read more
Affected Products : pandora_fms- EPSS Score: %0.24
- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-36696
Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in social media links on a user profile due to lack of input validation.... Read more
Affected Products : deskpro- EPSS Score: %0.21
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024