Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.8

    MEDIUM
    CVE-2021-36839

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Follow Buttons Bar plugin <= 4.73 at WordPress.... Read more

    Affected Products : social_media_follow_buttons_bar
    • EPSS Score: %0.14
    • Published: Sep. 30, 2022
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2021-36833

    Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ibericode's MC4WP plugin <= 4.8.6 at WordPress.... Read more

    Affected Products : mailchimp_for_wordpress
    • EPSS Score: %0.48
    • Published: May. 20, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-36832

    WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&message_data[16][headline]) input.... Read more

    Affected Products : icegram_engage
    • EPSS Score: %0.18
    • Published: Oct. 19, 2021
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2021-36830

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Comment Guestbook plugin <= 0.8.0 at WordPress.... Read more

    Affected Products : comment_guestbook
    • EPSS Score: %0.14
    • Published: Sep. 30, 2022
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2021-36829

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop Launcher: Coming Soon & Maintenance Mode plugin <= 1.0.11 at WordPress.... Read more

    Affected Products : launcher
    • EPSS Score: %0.18
    • Published: Sep. 06, 2022
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2021-36828

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) in WP Maintenance plugin <= 6.0.7 versions.... Read more

    Affected Products : wp_maintenance
    • EPSS Score: %0.32
    • Published: Apr. 15, 2022
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2021-36827

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saturday Drive's Ninja Forms Contact Form plugin <= 3.6.9 at WordPress via "label".... Read more

    Affected Products : ninja_forms
    • EPSS Score: %0.20
    • Published: Jun. 16, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-36826

    Authenticated (subscriber or higher user role if allowed to access projects) Stored Cross-Site Scripting (XSS) vulnerability in weDevs WP Project Manager plugin <= 2.4.13 versions.... Read more

    Affected Products : wp_project_manager
    • EPSS Score: %0.23
    • Published: Apr. 04, 2022
    • Modified: Nov. 21, 2024
  • 8.2

    HIGH
    CVE-2021-36823

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cusmin AGCA - Absolutely Glamorous Custom Admin (WordPress plugin) allows Stored XSS.This issue affects AGCA - Absolutely Glamorous Custom Admin (WordPre... Read more

    Affected Products : absolutely_glamorous_custom_admin
    • EPSS Score: %0.21
    • Published: Sep. 23, 2021
    • Modified: Nov. 21, 2024
  • 7.1

    HIGH
    CVE-2021-36821

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMU DEV Forminator allows Stored XSS.This issue affects Forminator: from n/a through 1.14.11.... Read more

    Affected Products : forminator
    • EPSS Score: %0.07
    • Published: Mar. 16, 2023
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-36809

    A local attacker can overwrite arbitrary files on the system with VPN client logs using administrator privileges, potentially resulting in a denial of service and data loss, in all versions of Sophos SSL VPN client.... Read more

    Affected Products : ssl_vpn_client
    • EPSS Score: %0.05
    • Published: Mar. 08, 2022
    • Modified: Nov. 21, 2024
  • 7.0

    HIGH
    CVE-2021-36808

    A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115.... Read more

    Affected Products : sophos_secure_workspace
    • EPSS Score: %0.02
    • Published: Oct. 30, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-36807

    An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before version 9.708 MR8.... Read more

    Affected Products : unified_threat_management_up2date
    • EPSS Score: %0.20
    • Published: Nov. 26, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-36806

    A reflected XSS vulnerability allows an open redirect when the victim clicks a malicious link to an error page on Sophos Email Appliance older than version 4.5.3.4. ... Read more

    Affected Products : email_appliance
    • EPSS Score: %0.08
    • Published: Nov. 30, 2023
    • Modified: Nov. 21, 2024
  • 5.2

    MEDIUM
    CVE-2021-36805

    Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in the sales invoice processing component of the application. This issue was fixed in version 2.1.13 of the product.... Read more

    Affected Products : akaunting
    • EPSS Score: %0.30
    • Published: Aug. 04, 2021
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2021-36804

    Akaunting version 2.1.12 and earlier suffers from a password reset spoofing vulnerability, wherein an attacker can proxy password reset requests through a running Akaunting instance, if that attacker knows the target's e-mail address. This issue was fixed... Read more

    Affected Products : akaunting
    • EPSS Score: %0.32
    • Published: Aug. 04, 2021
    • Modified: Nov. 21, 2024
  • 6.3

    MEDIUM
    CVE-2021-36803

    Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This issue was fixed in version 2.1.13 of the product.... Read more

    Affected Products : akaunting
    • EPSS Score: %0.33
    • Published: Aug. 04, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-36802

    Akaunting version 2.1.12 and earlier suffers from a denial-of-service issue that is triggered by setting a malformed 'locale' variable and sending it in an otherwise normal HTTP POST request. This issue was fixed in version 2.1.13 of the product.... Read more

    Affected Products : akaunting
    • EPSS Score: %0.36
    • Published: Aug. 04, 2021
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2021-36801

    Akaunting version 2.1.12 and earlier suffers from an authentication bypass issue in the user-controllable field, companies[0]. This issue was fixed in version 2.1.13 of the product.... Read more

    Affected Products : akaunting
    • EPSS Score: %0.28
    • Published: Aug. 04, 2021
    • Modified: Nov. 21, 2024
  • 9.1

    CRITICAL
    CVE-2021-36800

    Akaunting version 2.1.12 and earlier suffers from a code injection issue in the Money.php component of the application. A POST sent to /{company_id}/sales/invoices/{invoice_id} with an items[0][price] that includes a PHP callable function is executed dire... Read more

    Affected Products : akaunting
    • EPSS Score: %0.32
    • Published: Aug. 04, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 291573 Results