Latest CVE Feed
-
4.3
MEDIUMCVE-2021-34682
Receita Federal IRPF 2021 1.7 allows a man-in-the-middle attack against the update feature.... Read more
Affected Products : imposto_de_renda_da_pessoa_fisica_2021- EPSS Score: %0.21
- Published: Jun. 12, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-34679
Thycotic Password Reset Server before 5.3.0 allows credential disclosure.... Read more
Affected Products : password_reset_server- EPSS Score: %0.24
- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-34676
Basix NEX-Forms through 7.8.7 allows authentication bypass for Excel report generation.... Read more
Affected Products : nex-forms- EPSS Score: %0.89
- Published: Jul. 19, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-34675
Basix NEX-Forms through 7.8.7 allows authentication bypass for stored PDF reports.... Read more
Affected Products : nex-forms- EPSS Score: %0.89
- Published: Jul. 19, 2021
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2021-34668
The WordPress Real Media Library WordPress plugin is vulnerable to Stored Cross-Site Scripting via the name parameter in the ~/inc/overrides/lite/rest/Folder.php file which allows author-level attackers to inject arbitrary web scripts in folder names, in ... Read more
Affected Products : wordpress_real_media_library- EPSS Score: %0.17
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34667
The Calendar_plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of `$_SERVER['PHP_SELF']` in the ~/calendar.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.... Read more
Affected Products : calendar_plugin- EPSS Score: %0.21
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34666
The Add Sidebar WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the add parameter in the ~/wp_sidebarMenu.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.0.... Read more
Affected Products : add_sidebar- EPSS Score: %0.21
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34665
The WP SEO Tags WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the saq_txt_the_filter parameter in the ~/wp-seo-tags.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.2.7.... Read more
Affected Products : wp_seo_tags- EPSS Score: %0.21
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34664
The Moova for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the lat parameter in the ~/Checkout/Checkout.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.5.... Read more
Affected Products : moova_for_woocommerce- EPSS Score: %0.21
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34663
The jQuery Tagline Rotator WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/jquery-tagline-rotator.php file which allows attackers to inject arbitrary web scripts, in versions up to and inclu... Read more
Affected Products : jquery_tagline_rotator- EPSS Score: %0.21
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34661
The WP Fusion Lite WordPress plugin is vulnerable to Cross-Site Request Forgery via the `show_logs_section` function found in the ~/includes/admin/logging/class-log-handler.php file which allows attackers to drop all logs for the plugin, in versions up to... Read more
Affected Products : wp_fusion- EPSS Score: %0.10
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34660
The WP Fusion Lite WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the startdate parameter found in the ~/includes/admin/logging/class-log-table-list.php file which allows attackers to inject arbitrary web scripts, in versions up to a... Read more
Affected Products : wp_fusion- EPSS Score: %0.21
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34659
The Plugmatter Pricing Table Lite WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `email` parameter in the ~/license.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.32.... Read more
Affected Products : plugmatter_pricing_table- EPSS Score: %0.21
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34658
The Simple Popup Newsletter WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/simple-popup-newsletter.php file which allows attackers to inject arbitrary web scripts, in versions up to and inc... Read more
Affected Products : simple_popup_newsletter- EPSS Score: %0.21
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34657
The 2TypoFR WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the text function found in the ~/vendor/Org_Heigl/Hyphenator/index.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.11.... Read more
Affected Products : typofr- EPSS Score: %0.21
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34656
The 2Way VideoCalls and Random Chat - HTML5 Webcam Videochat WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `vws_notice` function found in the ~/inc/requirements.php file which allows attackers to inject arbitrary web scripts, in... Read more
Affected Products : 2way_videocalls_and_random_chat- EPSS Score: %0.21
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34655
The WP Songbook WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the url parameter found in the ~/inc/class.ajax.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.11.... Read more
Affected Products : wp_songbook- EPSS Score: %0.21
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34654
The Custom Post Type Relations WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the cptr[name] parameter found in the ~/pages/admin-page.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1... Read more
Affected Products : custom_post_type_relations- EPSS Score: %0.21
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34653
The WP Fountain WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/wp-fountain.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.5.9.... Read more
Affected Products : wp_fountain- EPSS Score: %0.21
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34652
The Media Usage WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter in the ~/mmu_admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.0.4.... Read more
Affected Products : media_usage- EPSS Score: %0.21
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024