Latest CVE Feed
-
4.8
MEDIUMCVE-2021-36839
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Follow Buttons Bar plugin <= 4.73 at WordPress.... Read more
Affected Products : social_media_follow_buttons_bar- EPSS Score: %0.14
- Published: Sep. 30, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-36833
Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ibericode's MC4WP plugin <= 4.8.6 at WordPress.... Read more
Affected Products : mailchimp_for_wordpress- EPSS Score: %0.48
- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-36832
WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&message_data[16][headline]) input.... Read more
Affected Products : icegram_engage- EPSS Score: %0.18
- Published: Oct. 19, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-36830
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Comment Guestbook plugin <= 0.8.0 at WordPress.... Read more
Affected Products : comment_guestbook- EPSS Score: %0.14
- Published: Sep. 30, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-36829
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop Launcher: Coming Soon & Maintenance Mode plugin <= 1.0.11 at WordPress.... Read more
Affected Products : launcher- EPSS Score: %0.18
- Published: Sep. 06, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-36828
Authenticated (admin+) Stored Cross-Site Scripting (XSS) in WP Maintenance plugin <= 6.0.7 versions.... Read more
Affected Products : wp_maintenance- EPSS Score: %0.32
- Published: Apr. 15, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-36827
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saturday Drive's Ninja Forms Contact Form plugin <= 3.6.9 at WordPress via "label".... Read more
Affected Products : ninja_forms- EPSS Score: %0.20
- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-36826
Authenticated (subscriber or higher user role if allowed to access projects) Stored Cross-Site Scripting (XSS) vulnerability in weDevs WP Project Manager plugin <= 2.4.13 versions.... Read more
Affected Products : wp_project_manager- EPSS Score: %0.23
- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2021-36823
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cusmin AGCA - Absolutely Glamorous Custom Admin (WordPress plugin) allows Stored XSS.This issue affects AGCA - Absolutely Glamorous Custom Admin (WordPre... Read more
Affected Products : absolutely_glamorous_custom_admin- EPSS Score: %0.21
- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-36821
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMU DEV Forminator allows Stored XSS.This issue affects Forminator: from n/a through 1.14.11.... Read more
Affected Products : forminator- EPSS Score: %0.07
- Published: Mar. 16, 2023
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-36809
A local attacker can overwrite arbitrary files on the system with VPN client logs using administrator privileges, potentially resulting in a denial of service and data loss, in all versions of Sophos SSL VPN client.... Read more
Affected Products : ssl_vpn_client- EPSS Score: %0.05
- Published: Mar. 08, 2022
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2021-36808
A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115.... Read more
Affected Products : sophos_secure_workspace- EPSS Score: %0.02
- Published: Oct. 30, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-36807
An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before version 9.708 MR8.... Read more
Affected Products : unified_threat_management_up2date- EPSS Score: %0.20
- Published: Nov. 26, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-36806
A reflected XSS vulnerability allows an open redirect when the victim clicks a malicious link to an error page on Sophos Email Appliance older than version 4.5.3.4. ... Read more
Affected Products : email_appliance- EPSS Score: %0.08
- Published: Nov. 30, 2023
- Modified: Nov. 21, 2024
-
5.2
MEDIUMCVE-2021-36805
Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in the sales invoice processing component of the application. This issue was fixed in version 2.1.13 of the product.... Read more
Affected Products : akaunting- EPSS Score: %0.30
- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-36804
Akaunting version 2.1.12 and earlier suffers from a password reset spoofing vulnerability, wherein an attacker can proxy password reset requests through a running Akaunting instance, if that attacker knows the target's e-mail address. This issue was fixed... Read more
Affected Products : akaunting- EPSS Score: %0.32
- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2021-36803
Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This issue was fixed in version 2.1.13 of the product.... Read more
Affected Products : akaunting- EPSS Score: %0.33
- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-36802
Akaunting version 2.1.12 and earlier suffers from a denial-of-service issue that is triggered by setting a malformed 'locale' variable and sending it in an otherwise normal HTTP POST request. This issue was fixed in version 2.1.13 of the product.... Read more
Affected Products : akaunting- EPSS Score: %0.36
- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-36801
Akaunting version 2.1.12 and earlier suffers from an authentication bypass issue in the user-controllable field, companies[0]. This issue was fixed in version 2.1.13 of the product.... Read more
Affected Products : akaunting- EPSS Score: %0.28
- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-36800
Akaunting version 2.1.12 and earlier suffers from a code injection issue in the Money.php component of the application. A POST sent to /{company_id}/sales/invoices/{invoice_id} with an items[0][price] that includes a PHP callable function is executed dire... Read more
Affected Products : akaunting- EPSS Score: %0.32
- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024