Latest CVE Feed
-
9.8
CRITICALCVE-2021-35066
An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.... Read more
Affected Products : automate- EPSS Score: %0.43
- Published: Jun. 21, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-35064
KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits running of multiple dangerous commands, including unzip, systemctl and dpkg.... Read more
Affected Products : viaware- EPSS Score: %79.05
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGH- EPSS Score: %0.90
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-35062
A Shell Metacharacter Injection vulnerability in result.php in DRK Odenwaldkreis Testerfassung March-2021 allow an attacker with a valid token of a COVID-19 test result to execute shell commands with the permissions of the web server.... Read more
- EPSS Score: %0.31
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-35061
Multiple cross-site scripting (XSS) vulnerabilities in DRK Odenwaldkreis Testerfassung March-2021 allow remote attackers to inject arbitrary web script or HTML via all parameters to HTML form fields in all components.... Read more
Affected Products : testerfassung- EPSS Score: %0.22
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-35060
/way4acs/enroll in OpenWay WAY4 ACS before 1.2.278-2693 allows unauthenticated attackers to leverage response differences to discover whether a specific payment card number is stored in the system.... Read more
Affected Products : way4- EPSS Score: %0.32
- Published: Oct. 11, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-35059
OpenWay WAY4 ACS before 1.2.278-2693 allows XSS via the /way4acs/enroll action parameter.... Read more
Affected Products : way4- EPSS Score: %0.45
- Published: Oct. 11, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-35056
Unisys Stealth 5.1 before 5.1.025.0 and 6.0 before 6.0.055.0 has an unquoted Windows search path for a scheduled task. An unintended executable might run.... Read more
Affected Products : stealth- EPSS Score: %0.06
- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-35055
MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. (Affected Chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software... Read more
Affected Products : mt7613_firmware mt7615_firmware mt7622_firmware mt7628_firmware mt7629_firmware mt7915_firmware mt7603e_firmware mt7612_firmware mt7620_firmware mt7610_firmware +10 more products- EPSS Score: %0.55
- Published: Dec. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-35054
Minecraft before 1.17.1, when online-mode=false is configured, allows path traversal for deletion of arbitrary JSON files.... Read more
Affected Products : minecraft- EPSS Score: %0.37
- Published: Jul. 20, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-35053
Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the system to make the system unbootable.... Read more
- EPSS Score: %1.28
- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-35052
A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High.... Read more
Affected Products : password_manager- EPSS Score: %0.06
- Published: Nov. 23, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-35050
User credentials stored in a recoverable format within Fidelis Network and Deception CommandPost. In the event that an attacker gains access to the CommandPost, these values could be decoded and used to login to the application. The vulnerability is prese... Read more
- EPSS Score: %0.31
- Published: Jun. 25, 2021
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2021-35049
Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could allow a specially crafted HTTP request to execute system commands on the CommandPost and return results i... Read more
- EPSS Score: %3.37
- Published: Jun. 25, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-35048
Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interface. The vulnerability could lead to exposure of authentication tokens in some versions of Fidelis software. The vulnerability is presen... Read more
- EPSS Score: %0.78
- Published: Jun. 25, 2021
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2021-35047
Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with user level access to the CLI to inject root level commands into the component and neighboring Fidelis components. The vulnerabilit... Read more
- EPSS Score: %0.89
- Published: Jun. 25, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-35046
A session fixation vulnerability was discovered in Ice Hrm 29.0.0 OS which allows an attacker to hijack a valid user session via a crafted session cookie.... Read more
Affected Products : icehrm- EPSS Score: %0.20
- Published: Jun. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-35045
Cross site scripting (XSS) vulnerability in Ice Hrm 29.0.0.OS, allows attackers to execute arbitrary code via the parameters to the /app/ endpoint.... Read more
Affected Products : icehrm- EPSS Score: %0.40
- Published: Jun. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-35043
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.... Read more
- EPSS Score: %0.33
- Published: Jul. 19, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-35042
Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.... Read more
- EPSS Score: %6.96
- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024