Latest CVE Feed
-
5.4
MEDIUMCVE-2021-34073
A Cross Site Scripting (XSS) vulnerabilty exists in Sourcecodester Gadget Works Online Ordering System in PHP/MySQLi 1.0 via the Category parameter in an add function in category/index.php.... Read more
Affected Products : gadget_works_online_ordering_system- EPSS Score: %0.28
- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-34071
Heap based buffer overflow in tsMuxer 2.6.16 allows attackers to cause a Denial of Service (DoS) by running the application with a crafted file.... Read more
Affected Products : tsmuxer- EPSS Score: %0.29
- Published: Jun. 23, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-34070
Out-of-bounds Read in tsMuxer 2.6.16 allows attackers to cause a Denial of Service (DoS) by running the application with a crafted file.... Read more
Affected Products : tsmuxer- EPSS Score: %0.29
- Published: Jun. 23, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-34069
Divide-by-zero bug in tsMuxer 2.6.16 allows attackers to cause a Denial of Service (DoS) by running the application with a crafted file.... Read more
Affected Products : tsmuxer- EPSS Score: %0.29
- Published: Jun. 23, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-34068
Heap based buffer overflow in tsMuxer 2.6.16 allows attackers to cause a Denial of Service (DoS) by running the application with a crafted file.... Read more
Affected Products : tsmuxer- EPSS Score: %0.29
- Published: Jun. 23, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-34067
Heap based buffer overflow in tsMuxer 2.6.16 allows attackers to cause a Denial of Service (DoS) by running the application with a crafted file.... Read more
Affected Products : tsmuxer- EPSS Score: %0.29
- Published: Jun. 23, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-34066
An issue was discovered in EdgeGallery/developer before v1.0. There is a "Deserialization of yaml file" vulnerability that can allow attackers to execute system command through uploading the malicious constructed YAML file.... Read more
Affected Products : developer-be- EPSS Score: %0.41
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-33990
Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the exploit reference link only shows frmfolders.html is accessible and does not demonstrate how an... Read more
Affected Products : liferay_portal- EPSS Score: %58.07
- Published: Apr. 16, 2023
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-33988
Cross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2.7 via the Login form, which could let a malicious user execute Javascript by Inserting code in the request form.... Read more
- EPSS Score: %0.83
- Published: Oct. 19, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-33982
An insufficient session expiration vulnerability exists in the "Fish | Hunt FL" iOS app version 3.8.0 and earlier, which allows a remote attacker to reuse, spoof, or steal other user and admin sessions.... Read more
Affected Products : fish_\|_hunt_fl- EPSS Score: %0.24
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-33981
An insecure, direct object vulnerability in hunting/fishing license retrieval function of the "Fish | Hunt FL" iOS app versions 3.8.0 and earlier allows a remote authenticated attacker to retrieve other people's personal information and images of their hu... Read more
Affected Products : fish_\|_hunt_fl- EPSS Score: %0.15
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-33966
Cross site scripting (XSS) vulnerability in spotweb 1.4.9, allows authenticated attackers to execute arbitrary code via crafted GET request to the login page.... Read more
Affected Products : spotweb- EPSS Score: %0.31
- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-33965
China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRMesh/set_ZRMesh which receives parameters by POST request, and the parameter mesh_enable and mesh_device have a command injection vulnerability. An attacker can use the vulnerabili... Read more
- EPSS Score: %3.90
- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-33964
China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRRuleFilter/set_firewall_level which receives parameters by POST request, and the parameter firewall_level has a command injection vulnerability. An attacker can use the vulnerabili... Read more
- EPSS Score: %3.90
- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-33963
China Mobile An Lianbao WF-1 v1.0.1 router web interface through /api/ZRMacClone/mac_addr_clone receives parameters by POST request, and the parameter macType has a command injection vulnerability. An attacker can use the vulnerability to execute remote c... Read more
- EPSS Score: %1.83
- Published: Jan. 15, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-33962
China Mobile An Lianbao WF-1 router v1.0.1 is affected by an OS command injection vulnerability in the web interface /api/ZRUsb/pop_usb_device component.... Read more
- EPSS Score: %3.83
- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-33961
A Cross Site Scripting (XSS) vulnerabililty exists in enhanced-github v5.0.11 via the file name parameter.... Read more
Affected Products : enhanced-github- EPSS Score: %0.31
- Published: Mar. 22, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-33945
RICOH Printer series SP products 320DN, SP 325DNw, SP 320SN, SP 320SFN, SP 325SNw, SP 325SFNw, SP 330SN, Aficio SP 3500SF, SP 221S, SP 220SNw, SP 221SNw, SP 221SF, SP 220SFNw, SP 221SFNw v1.06 were discovered to contain a stack buffer overflow in the file... Read more
Affected Products : sp_c250sf_firmware sp_c252sf_firmware sp_c250dn_firmware sp_c252dn_firmware sp_320dn_firmware sp_325dnw_firmware sp_320sn_firmware sp_320sfn_firmware sp_325snw_firmware sp_325sfnw_firmware +122 more products- EPSS Score: %0.54
- Published: Feb. 15, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-33938
Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service.... Read more
Affected Products : libsolv- EPSS Score: %0.06
- Published: Sep. 02, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-33930
Buffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.... Read more
Affected Products : libsolv- EPSS Score: %0.06
- Published: Sep. 02, 2021
- Modified: Nov. 21, 2024