Latest CVE Feed
-
7.5
HIGHCVE-2021-34270
An integer overflow in the mintToken function of a smart contract implementation for Doftcoin Token, an Ethereum ERC20 token, allows the owner to cause unexpected financial losses.... Read more
Affected Products : doftcoin- EPSS Score: %0.21
- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024
-
4.6
MEDIUMCVE-2021-34268
An issue in the USBH_ParseDevDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial of service (DOS) via a malformed USB device packet.... Read more
- EPSS Score: %0.06
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
4.6
MEDIUMCVE-2021-34267
An in the USBH_MSC_InterfaceInit() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial of service (DOS) when the system tries to communicate with the connected endpoint.... Read more
- EPSS Score: %0.06
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-34262
A buffer overflow vulnerability in the USBH_ParseEPDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code.... Read more
- EPSS Score: %0.08
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
4.6
MEDIUMCVE-2021-34261
An issue in USBH_ParseCfgDesc() of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial of service due to the system hanging when trying to set a remote wake-up feature.... Read more
- EPSS Score: %0.06
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-34260
A buffer overflow vulnerability in the USBH_ParseInterfaceDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code.... Read more
- EPSS Score: %0.08
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-34259
A buffer overflow vulnerability in the USBH_ParseCfgDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code.... Read more
- EPSS Score: %0.08
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-34257
Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload to (1) Dashboard's Avatar image, (2) Posts Folder image, (3) Pages Folder image and (4) Gallery Folder image.... Read more
Affected Products : wpanel_cms- EPSS Score: %0.87
- Published: Mar. 31, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34254
Umbraco CMS before 7.15.7 is vulnerable to Open Redirection due to insufficient url sanitization on booting.aspx.... Read more
Affected Products : umbraco_cms- EPSS Score: %0.16
- Published: Jun. 28, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-34244
A cross site request forgery (CSRF) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to create new admin accounts or change users' passwords.... Read more
Affected Products : icehrm- EPSS Score: %0.14
- Published: Jun. 22, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-34243
A stored cross site scripting (XSS) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to execute arbitrary web scripts or HTML via a crafted file uploaded into the Document Management tab. The exploit is triggered when a user visits... Read more
Affected Products : icehrm- EPSS Score: %0.18
- Published: Jun. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-34236
Buffer Overflow in Netgear R8000 Router with firmware v1.0.4.56 allows remote attackers to execute arbitrary code or cause a denial-of-service by sending a crafted POST to '/bd_genie_create_account.cgi' with a sufficiently long parameter 'register_country... Read more
- EPSS Score: %2.13
- Published: Sep. 08, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34228
Cross-site scripting in parent_control.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Description" field and "Service Name" field.... Read more
- EPSS Score: %1.81
- Published: Aug. 20, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34223
Cross-site scripting in urlfilter.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "URL Address" field.... Read more
- EPSS Score: %0.19
- Published: Aug. 20, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34220
Cross-site scripting in tr069config.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "User Name" field or "Password" field.... Read more
- EPSS Score: %0.19
- Published: Aug. 20, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-34218
Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /add/ , /img/, /js/, and /mobile directories via GET Parameter.... Read more
- EPSS Score: %0.21
- Published: Aug. 20, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34215
Cross-site scripting in tcpipwan.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Service Name" field.... Read more
- EPSS Score: %0.19
- Published: Aug. 20, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34207
Cross-site scripting in ddns.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Domain Name" field, "Server Address" field, "User Name/Email", or "Password/Key" fie... Read more
- EPSS Score: %0.21
- Published: Aug. 20, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-34204
D-Link DIR-2640-US 1.01B04 is affected by Insufficiently Protected Credentials. D-Link AC2600(DIR-2640) stores the device system account password in plain text. It does not use linux user management. In addition, the passwords of all devices are the same,... Read more
- EPSS Score: %0.06
- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-34203
D-Link DIR-2640-US 1.01B04 is vulnerable to Incorrect Access Control. Router ac2600 (dir-2640-us), when setting PPPoE, will start quagga process in the way of whole network monitoring, and this function uses the original default password and port. An atta... Read more
- EPSS Score: %0.07
- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024