Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2021-34270

    An integer overflow in the mintToken function of a smart contract implementation for Doftcoin Token, an Ethereum ERC20 token, allows the owner to cause unexpected financial losses.... Read more

    Affected Products : doftcoin
    • EPSS Score: %0.21
    • Published: Aug. 03, 2021
    • Modified: Nov. 21, 2024
  • 4.6

    MEDIUM
    CVE-2021-34268

    An issue in the USBH_ParseDevDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial of service (DOS) via a malformed USB device packet.... Read more

    Affected Products : stm32cube_middleware stm32h7b3
    • EPSS Score: %0.06
    • Published: Jul. 22, 2021
    • Modified: Nov. 21, 2024
  • 4.6

    MEDIUM
    CVE-2021-34267

    An in the USBH_MSC_InterfaceInit() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial of service (DOS) when the system tries to communicate with the connected endpoint.... Read more

    Affected Products : stm32cube_middleware stm32h7b3
    • EPSS Score: %0.06
    • Published: Jul. 22, 2021
    • Modified: Nov. 21, 2024
  • 6.8

    MEDIUM
    CVE-2021-34262

    A buffer overflow vulnerability in the USBH_ParseEPDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code.... Read more

    Affected Products : stm32cube_middleware stm32h7b3
    • EPSS Score: %0.08
    • Published: Jul. 22, 2021
    • Modified: Nov. 21, 2024
  • 4.6

    MEDIUM
    CVE-2021-34261

    An issue in USBH_ParseCfgDesc() of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial of service due to the system hanging when trying to set a remote wake-up feature.... Read more

    Affected Products : stm32cube_middleware stm32h7b3
    • EPSS Score: %0.06
    • Published: Jul. 22, 2021
    • Modified: Nov. 21, 2024
  • 6.8

    MEDIUM
    CVE-2021-34260

    A buffer overflow vulnerability in the USBH_ParseInterfaceDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code.... Read more

    Affected Products : stm32cube_middleware stm32h7b3
    • EPSS Score: %0.08
    • Published: Jul. 22, 2021
    • Modified: Nov. 21, 2024
  • 6.8

    MEDIUM
    CVE-2021-34259

    A buffer overflow vulnerability in the USBH_ParseCfgDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code.... Read more

    Affected Products : stm32cube_middleware stm32h7b3
    • EPSS Score: %0.08
    • Published: Jul. 22, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-34257

    Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload to (1) Dashboard's Avatar image, (2) Posts Folder image, (3) Pages Folder image and (4) Gallery Folder image.... Read more

    Affected Products : wpanel_cms
    • EPSS Score: %0.87
    • Published: Mar. 31, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-34254

    Umbraco CMS before 7.15.7 is vulnerable to Open Redirection due to insufficient url sanitization on booting.aspx.... Read more

    Affected Products : umbraco_cms
    • EPSS Score: %0.16
    • Published: Jun. 28, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-34244

    A cross site request forgery (CSRF) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to create new admin accounts or change users' passwords.... Read more

    Affected Products : icehrm
    • EPSS Score: %0.14
    • Published: Jun. 22, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-34243

    A stored cross site scripting (XSS) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to execute arbitrary web scripts or HTML via a crafted file uploaded into the Document Management tab. The exploit is triggered when a user visits... Read more

    Affected Products : icehrm
    • EPSS Score: %0.18
    • Published: Jun. 22, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-34236

    Buffer Overflow in Netgear R8000 Router with firmware v1.0.4.56 allows remote attackers to execute arbitrary code or cause a denial-of-service by sending a crafted POST to '/bd_genie_create_account.cgi' with a sufficiently long parameter 'register_country... Read more

    Affected Products : r8000_firmware r8000
    • EPSS Score: %2.13
    • Published: Sep. 08, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-34228

    Cross-site scripting in parent_control.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Description" field and "Service Name" field.... Read more

    Affected Products : a3002r_firmware a3002r
    • EPSS Score: %1.81
    • Published: Aug. 20, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-34223

    Cross-site scripting in urlfilter.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "URL Address" field.... Read more

    Affected Products : a3002r_firmware a3002r
    • EPSS Score: %0.19
    • Published: Aug. 20, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-34220

    Cross-site scripting in tr069config.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "User Name" field or "Password" field.... Read more

    Affected Products : a3002r_firmware a3002r
    • EPSS Score: %0.19
    • Published: Aug. 20, 2021
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-34218

    Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /add/ , /img/, /js/, and /mobile directories via GET Parameter.... Read more

    Affected Products : a3002r_firmware a3002r
    • EPSS Score: %0.21
    • Published: Aug. 20, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-34215

    Cross-site scripting in tcpipwan.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Service Name" field.... Read more

    Affected Products : a3002r_firmware a3002r
    • EPSS Score: %0.19
    • Published: Aug. 20, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-34207

    Cross-site scripting in ddns.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Domain Name" field, "Server Address" field, "User Name/Email", or "Password/Key" fie... Read more

    Affected Products : a3002r_firmware a3002r
    • EPSS Score: %0.21
    • Published: Aug. 20, 2021
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-34204

    D-Link DIR-2640-US 1.01B04 is affected by Insufficiently Protected Credentials. D-Link AC2600(DIR-2640) stores the device system account password in plain text. It does not use linux user management. In addition, the passwords of all devices are the same,... Read more

    Affected Products : dir-2640-us_firmware dir-2640-us
    • EPSS Score: %0.06
    • Published: Jun. 16, 2021
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2021-34203

    D-Link DIR-2640-US 1.01B04 is vulnerable to Incorrect Access Control. Router ac2600 (dir-2640-us), when setting PPPoE, will start quagga process in the way of whole network monitoring, and this function uses the original default password and port. An atta... Read more

    Affected Products : dir-2640-us_firmware dir-2640-us
    • EPSS Score: %0.07
    • Published: Jun. 16, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 291274 Results