Latest CVE Feed
-
5.3
MEDIUMCVE-2021-34687
iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A man in the middle can recover a system's Personal Key when a client attempts to make a LAN connection. The Personal Key is transmitted over the network while only being encrypted vi... Read more
- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-34685
UploadService in Hitachi Vantara Pentaho Business Analytics through 9.1 does not properly verify uploaded user files, which allows an authenticated user to upload various files of different file types. Specifically, a .jsp file is not allowed, but a .jsp.... Read more
Affected Products : vantara_pentaho- Published: Nov. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-34684
Hitachi Vantara Pentaho Business Analytics through 9.1 allows an unauthenticated user to execute arbitrary SQL queries on any Pentaho data source and thus retrieve data from the related databases, as demonstrated by an api/repos/dashboards/editor URI.... Read more
Affected Products : vantara_pentaho- Published: Nov. 08, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-34683
An issue was discovered in EXCELLENT INFOTEK CORPORATION (EIC) E-document System 3.0. A remote attacker can use kw/auth/bbs/asp/get_user_email_info_bbs.asp to obtain the contact information (name and e-mail address) of everyone in the entire organization.... Read more
Affected Products : e-document_system- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-34682
Receita Federal IRPF 2021 1.7 allows a man-in-the-middle attack against the update feature.... Read more
Affected Products : imposto_de_renda_da_pessoa_fisica_2021- Published: Jun. 12, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-34679
Thycotic Password Reset Server before 5.3.0 allows credential disclosure.... Read more
Affected Products : password_reset_server- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-34676
Basix NEX-Forms through 7.8.7 allows authentication bypass for Excel report generation.... Read more
Affected Products : nex-forms- Published: Jul. 19, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-34675
Basix NEX-Forms through 7.8.7 allows authentication bypass for stored PDF reports.... Read more
Affected Products : nex-forms- Published: Jul. 19, 2021
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2021-34668
The WordPress Real Media Library WordPress plugin is vulnerable to Stored Cross-Site Scripting via the name parameter in the ~/inc/overrides/lite/rest/Folder.php file which allows author-level attackers to inject arbitrary web scripts in folder names, in ... Read more
Affected Products : wordpress_real_media_library- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34667
The Calendar_plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of `$_SERVER['PHP_SELF']` in the ~/calendar.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.... Read more
Affected Products : calendar_plugin- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34666
The Add Sidebar WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the add parameter in the ~/wp_sidebarMenu.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.0.... Read more
Affected Products : add_sidebar- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34665
The WP SEO Tags WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the saq_txt_the_filter parameter in the ~/wp-seo-tags.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.2.7.... Read more
Affected Products : wp_seo_tags- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34664
The Moova for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the lat parameter in the ~/Checkout/Checkout.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.5.... Read more
Affected Products : moova_for_woocommerce- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34663
The jQuery Tagline Rotator WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/jquery-tagline-rotator.php file which allows attackers to inject arbitrary web scripts, in versions up to and inclu... Read more
Affected Products : jquery_tagline_rotator- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34661
The WP Fusion Lite WordPress plugin is vulnerable to Cross-Site Request Forgery via the `show_logs_section` function found in the ~/includes/admin/logging/class-log-handler.php file which allows attackers to drop all logs for the plugin, in versions up to... Read more
Affected Products : wp_fusion- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34660
The WP Fusion Lite WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the startdate parameter found in the ~/includes/admin/logging/class-log-table-list.php file which allows attackers to inject arbitrary web scripts, in versions up to a... Read more
Affected Products : wp_fusion- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34659
The Plugmatter Pricing Table Lite WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `email` parameter in the ~/license.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.32.... Read more
Affected Products : plugmatter_pricing_table- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34658
The Simple Popup Newsletter WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/simple-popup-newsletter.php file which allows attackers to inject arbitrary web scripts, in versions up to and inc... Read more
Affected Products : simple_popup_newsletter- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34657
The 2TypoFR WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the text function found in the ~/vendor/Org_Heigl/Hyphenator/index.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.11.... Read more
Affected Products : typofr- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34656
The 2Way VideoCalls and Random Chat - HTML5 Webcam Videochat WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `vws_notice` function found in the ~/inc/requirements.php file which allows attackers to inject arbitrary web scripts, in... Read more
Affected Products : 2way_videocalls_and_random_chat- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024