Latest CVE Feed
-
4.8
MEDIUMCVE-2021-36131
An XSS issue was discovered in the SportsTeams extension in MediaWiki through 1.36. Within several special pages, a privileged user could inject arbitrary HTML and JavaScript within various data fields. The attack could easily propagate across many pages ... Read more
Affected Products : mediawiki- EPSS Score: %0.25
- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-36130
An XSS issue was discovered in the SocialProfile extension in MediaWiki through 1.36. Within several gift-related special pages, a privileged user with the awardmanage right could inject arbitrary HTML and JavaScript within various gift-related data field... Read more
Affected Products : mediawiki- EPSS Score: %0.27
- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-36129
An issue was discovered in the Translate extension in MediaWiki through 1.36. The Aggregategroups Action API module does not validate the parameter for aggregategroup when action=remove is set, thus allowing users with the translate-manage right to silent... Read more
Affected Products : mediawiki- EPSS Score: %0.14
- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-36128
An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. Autoblocks for CentralAuth-issued suppression blocks are not properly implemented.... Read more
Affected Products : mediawiki- EPSS Score: %0.74
- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-36127
An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalUserRights page provided search results which, for a suppressed MediaWiki user, were different than for any other user, thus easily disclosing suppressed acc... Read more
Affected Products : mediawiki- EPSS Score: %0.15
- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-36126
An issue was discovered in the AbuseFilter extension in MediaWiki through 1.36. If the MediaWiki:Abusefilter-blocker message is invalid within the content language, the filter user falls back to the English version, but that English version could also be ... Read more
Affected Products : mediawiki- EPSS Score: %0.44
- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-36125
An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalRenameRequest page is vulnerable to infinite loops and denial of service attacks when a user's current username is beyond an arbitrary maximum configuration ... Read more
Affected Products : mediawiki- EPSS Score: %0.34
- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-36124
An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when accessing a subset of sensitive resources, leading to the ability for unauthenticated users to access pages that are vulnerable to attacks su... Read more
Affected Products : sharecare- EPSS Score: %0.54
- Published: Jul. 13, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-36123
An issue was discovered in Echo ShareCare 8.15.5. The TextReader feature in General/TextReader/TextReader.cfm is susceptible to a local file inclusion vulnerability when processing remote input in the textFile parameter from an authenticated user, leading... Read more
Affected Products : sharecare- EPSS Score: %0.18
- Published: Jul. 13, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-36122
An issue was discovered in Echo ShareCare 8.15.5. The UnzipFile feature in Access/EligFeedParse_Sup/UnzipFile_Upd.cfm is susceptible to a command argument injection vulnerability when processing remote input in the zippass parameter from an authenticated ... Read more
Affected Products : sharecare- EPSS Score: %0.53
- Published: Jul. 13, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-36121
An issue was discovered in Echo ShareCare 8.15.5. The file-upload feature in Access/DownloadFeed_Mnt/FileUpload_Upd.cfm is susceptible to an unrestricted upload vulnerability via the name1 parameter, when processing remote input from an authenticated user... Read more
Affected Products : sharecare- EPSS Score: %1.66
- Published: Jul. 13, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-36100
Specially crafted string in OTRS system configuration can allow the execution of any system command.... Read more
- EPSS Score: %0.94
- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-36097
Agents are able to lock the ticket without the "Owner" permission. Once the ticket is locked, it could be moved to the queue where the agent has "rw" permissions and gain a full control. This issue affects: OTRS AG OTRS 8.0.x version: 8.0.16 and prior ver... Read more
Affected Products : otrs- EPSS Score: %0.12
- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
5.2
MEDIUMCVE-2021-36096
Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions; 8.0.x v... Read more
Affected Products : otrs- EPSS Score: %0.14
- Published: Sep. 06, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-36095
Malicious attacker is able to find out valid user logins by using the "lost password" feature. This issue affects: OTRS AG ((OTRS)) Community Edition version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.... Read more
Affected Products : otrs- EPSS Score: %0.20
- Published: Sep. 06, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-36094
It's possible to craft a request for appointment edit screen, which could lead to the XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.... Read more
Affected Products : otrs- EPSS Score: %0.50
- Published: Sep. 06, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-36093
It's possible to create an email which can be stuck while being processed by PostMaster filters, causing DoS. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versio... Read more
Affected Products : otrs- EPSS Score: %0.38
- Published: Sep. 06, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-36092
It's possible to create an email which contains specially crafted link and it can be used to perform XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition:6.0.x version 6.0.1 and later versions. OTRS AG OTRS: 7.0.x version 7.0.27 and prior ve... Read more
Affected Products : otrs- EPSS Score: %0.41
- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-36091
Agents are able to list appointments in the calendars without required permissions. This issue affects: OTRS AG ((OTRS)) Community Edition: 6.0.x version 6.0.1 and later versions. OTRS AG OTRS: 7.0.x versions prior to 7.0.27.... Read more
Affected Products : otrs- EPSS Score: %0.15
- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-36090
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that us... Read more
Affected Products : active_iq_unified_manager peoplesoft_enterprise_peopletools oncommand_insight commerce_guided_search primavera_unifier communications_diameter_intelligence_hub communications_cloud_native_core_unified_data_repository flexcube_universal_banking banking_payments communications_billing_and_revenue_management +25 more products- EPSS Score: %0.28
- Published: Jul. 13, 2021
- Modified: Nov. 21, 2024