Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.3

    MEDIUM
    CVE-2021-36803

    Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This issue was fixed in version 2.1.13 of the product.... Read more

    Affected Products : akaunting
    • EPSS Score: %0.33
    • Published: Aug. 04, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-36802

    Akaunting version 2.1.12 and earlier suffers from a denial-of-service issue that is triggered by setting a malformed 'locale' variable and sending it in an otherwise normal HTTP POST request. This issue was fixed in version 2.1.13 of the product.... Read more

    Affected Products : akaunting
    • EPSS Score: %0.36
    • Published: Aug. 04, 2021
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2021-36801

    Akaunting version 2.1.12 and earlier suffers from an authentication bypass issue in the user-controllable field, companies[0]. This issue was fixed in version 2.1.13 of the product.... Read more

    Affected Products : akaunting
    • EPSS Score: %0.28
    • Published: Aug. 04, 2021
    • Modified: Nov. 21, 2024
  • 9.1

    CRITICAL
    CVE-2021-36800

    Akaunting version 2.1.12 and earlier suffers from a code injection issue in the Money.php component of the application. A POST sent to /{company_id}/sales/invoices/{invoice_id} with an items[0][price] that includes a PHP callable function is executed dire... Read more

    Affected Products : akaunting
    • EPSS Score: %0.32
    • Published: Aug. 04, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-36799

    KNX ETS5 through 5.7.6 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information. NOTE: This vulnerability only affects products that are no longer supported by the maintainer... Read more

    Affected Products : engineering_tool_software_5
    • EPSS Score: %0.13
    • Published: Jul. 19, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-36798

    A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3. It allows remote attackers to crash the C2 server thread and block beacons' communication with it.... Read more

    Affected Products : cobalt_strike
    • EPSS Score: %27.68
    • Published: Aug. 09, 2021
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-36797

    In Victron Energy Venus OS through 2.72, root access is granted by default to anyone with physical access to the device. NOTE: the vendor disagrees with the reporter's opinion about an alleged "security best practices" violation... Read more

    Affected Products : venus_os
    • EPSS Score: %0.05
    • Published: Jul. 19, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-36795

    A permission issue in the Cohesity Linux agent may allow privilege escalation in version 6.5.1b to 6.5.1d-hotfix10, 6.6.0a to 6.6.0b-hotfix1. An underprivileged linux user, if certain environment criteria are met, can gain additional privileges.... Read more

    Affected Products : linux_agent
    • EPSS Score: %0.05
    • Published: Aug. 06, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-36794

    In Siren Investigate before 11.1.4, when enabling the cluster feature of the Siren Alert application, TLS verifications are disabled globally in the Siren Investigate main process.... Read more

    Affected Products : investigate
    • EPSS Score: %0.65
    • Published: Nov. 02, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-36793

    The routes (aka Extbase Yaml Routes) extension before 2.1.1 for TYPO3, when CsrfTokenViewHelper is used, allows Sensitive Information Disclosure because a session identifier is unsafely present in HTML output.... Read more

    Affected Products : routes
    • EPSS Score: %0.25
    • Published: Aug. 13, 2021
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-36792

    The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 has incorrect Access Control for confirming various applications.... Read more

    Affected Products : dated_news
    • EPSS Score: %0.18
    • Published: Aug. 13, 2021
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-36791

    The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows Information Disclosure of application registration data.... Read more

    Affected Products : dated_news
    • EPSS Score: %0.19
    • Published: Aug. 13, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-36790

    The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows XSS.... Read more

    Affected Products : dated_news
    • EPSS Score: %0.28
    • Published: Aug. 13, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-36789

    The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection.... Read more

    Affected Products : dated_news
    • EPSS Score: %0.38
    • Published: Aug. 13, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-36788

    The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS.... Read more

    Affected Products : yoast_seo
    • EPSS Score: %0.26
    • Published: Aug. 13, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-36787

    The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document.... Read more

    Affected Products : femanager
    • EPSS Score: %0.69
    • Published: Aug. 13, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-36786

    The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows Sensitive Data Exposure of API credentials and private keys.... Read more

    Affected Products : saml
    • EPSS Score: %0.25
    • Published: Aug. 13, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-36785

    The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows XSS.... Read more

    Affected Products : saml
    • EPSS Score: %0.26
    • Published: Aug. 13, 2021
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-36784

    A Improper Privilege Management vulnerability in SUSE Rancher allows users with the restricted-admin role to escalate to full admin. This issue affects: SUSE Rancher Rancher versions prior to 2.5.13; Rancher versions prior to 2.6.4.... Read more

    Affected Products : rancher rancher
    • EPSS Score: %0.34
    • Published: May. 02, 2022
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2021-36783

    A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners and Project Members to read credentials, passwords and API tokens that have been stored in cleartext and exposed via ... Read more

    Affected Products : rancher rancher
    • EPSS Score: %0.28
    • Published: Sep. 07, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 291717 Results