Latest CVE Feed
-
8.2
HIGHCVE-2021-36823
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cusmin AGCA - Absolutely Glamorous Custom Admin (WordPress plugin) allows Stored XSS.This issue affects AGCA - Absolutely Glamorous Custom Admin (WordPre... Read more
Affected Products : absolutely_glamorous_custom_admin- EPSS Score: %0.21
- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-36821
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMU DEV Forminator allows Stored XSS.This issue affects Forminator: from n/a through 1.14.11.... Read more
Affected Products : forminator- EPSS Score: %0.07
- Published: Mar. 16, 2023
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-36809
A local attacker can overwrite arbitrary files on the system with VPN client logs using administrator privileges, potentially resulting in a denial of service and data loss, in all versions of Sophos SSL VPN client.... Read more
Affected Products : ssl_vpn_client- EPSS Score: %0.05
- Published: Mar. 08, 2022
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2021-36808
A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115.... Read more
Affected Products : sophos_secure_workspace- EPSS Score: %0.02
- Published: Oct. 30, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-36807
An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before version 9.708 MR8.... Read more
Affected Products : unified_threat_management_up2date- EPSS Score: %0.20
- Published: Nov. 26, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-36806
A reflected XSS vulnerability allows an open redirect when the victim clicks a malicious link to an error page on Sophos Email Appliance older than version 4.5.3.4. ... Read more
Affected Products : email_appliance- EPSS Score: %0.08
- Published: Nov. 30, 2023
- Modified: Nov. 21, 2024
-
5.2
MEDIUMCVE-2021-36805
Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in the sales invoice processing component of the application. This issue was fixed in version 2.1.13 of the product.... Read more
Affected Products : akaunting- EPSS Score: %0.30
- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-36804
Akaunting version 2.1.12 and earlier suffers from a password reset spoofing vulnerability, wherein an attacker can proxy password reset requests through a running Akaunting instance, if that attacker knows the target's e-mail address. This issue was fixed... Read more
Affected Products : akaunting- EPSS Score: %0.32
- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2021-36803
Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This issue was fixed in version 2.1.13 of the product.... Read more
Affected Products : akaunting- EPSS Score: %0.33
- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-36802
Akaunting version 2.1.12 and earlier suffers from a denial-of-service issue that is triggered by setting a malformed 'locale' variable and sending it in an otherwise normal HTTP POST request. This issue was fixed in version 2.1.13 of the product.... Read more
Affected Products : akaunting- EPSS Score: %0.36
- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-36801
Akaunting version 2.1.12 and earlier suffers from an authentication bypass issue in the user-controllable field, companies[0]. This issue was fixed in version 2.1.13 of the product.... Read more
Affected Products : akaunting- EPSS Score: %0.28
- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-36800
Akaunting version 2.1.12 and earlier suffers from a code injection issue in the Money.php component of the application. A POST sent to /{company_id}/sales/invoices/{invoice_id} with an items[0][price] that includes a PHP callable function is executed dire... Read more
Affected Products : akaunting- EPSS Score: %0.32
- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-36799
KNX ETS5 through 5.7.6 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information. NOTE: This vulnerability only affects products that are no longer supported by the maintainer... Read more
Affected Products : engineering_tool_software_5- EPSS Score: %0.13
- Published: Jul. 19, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-36798
A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3. It allows remote attackers to crash the C2 server thread and block beacons' communication with it.... Read more
Affected Products : cobalt_strike- EPSS Score: %27.68
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-36797
In Victron Energy Venus OS through 2.72, root access is granted by default to anyone with physical access to the device. NOTE: the vendor disagrees with the reporter's opinion about an alleged "security best practices" violation... Read more
Affected Products : venus_os- EPSS Score: %0.05
- Published: Jul. 19, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-36795
A permission issue in the Cohesity Linux agent may allow privilege escalation in version 6.5.1b to 6.5.1d-hotfix10, 6.6.0a to 6.6.0b-hotfix1. An underprivileged linux user, if certain environment criteria are met, can gain additional privileges.... Read more
Affected Products : linux_agent- EPSS Score: %0.05
- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-36794
In Siren Investigate before 11.1.4, when enabling the cluster feature of the Siren Alert application, TLS verifications are disabled globally in the Siren Investigate main process.... Read more
Affected Products : investigate- EPSS Score: %0.65
- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-36793
The routes (aka Extbase Yaml Routes) extension before 2.1.1 for TYPO3, when CsrfTokenViewHelper is used, allows Sensitive Information Disclosure because a session identifier is unsafely present in HTML output.... Read more
Affected Products : routes- EPSS Score: %0.25
- Published: Aug. 13, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-36792
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 has incorrect Access Control for confirming various applications.... Read more
Affected Products : dated_news- EPSS Score: %0.18
- Published: Aug. 13, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-36791
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows Information Disclosure of application registration data.... Read more
Affected Products : dated_news- EPSS Score: %0.19
- Published: Aug. 13, 2021
- Modified: Nov. 21, 2024