Latest CVE Feed
-
6.1
MEDIUMCVE-2021-34370
Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are configurable security flags and we are unable to reproduce them with the available information.... Read more
Affected Products : civic_platform- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-34369
portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensitive information via a modified contactSeqNumber value. NOTE: the vendor states "the information that is being queried is authorized for ... Read more
Affected Products : civic_platform- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34364
The Refined GitHub browser extension before 21.6.8 might allow XSS via a link in a document. NOTE: github.com sends Content-Security-Policy headers to, in general, address XSS and other concerns.... Read more
Affected Products : refined-github- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-34363
The thefuck (aka The Fuck) package before 3.31 for Python allows Path Traversal that leads to arbitrary file deletion via the "undo archive operation" feature.... Read more
- Published: Jun. 10, 2021
- Modified: Nov. 21, 2024
-
8.7
HIGHCVE-2021-34362
A command injection vulnerability has been reported to affect QNAP device running Media Streaming add-on. If exploited, this vulnerability allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions... Read more
- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-34361
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions ... Read more
- Published: Feb. 25, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-34360
A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following ve... Read more
- Published: May. 26, 2022
- Modified: Nov. 21, 2024
-
6.9
MEDIUMCVE-2021-34359
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions ... Read more
- Published: Feb. 25, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-34358
We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and later... Read more
- Published: Nov. 20, 2021
- Modified: Nov. 21, 2024
-
6.9
MEDIUMCVE-2021-34357
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QmailAgent. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of... Read more
- Published: Nov. 13, 2021
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2021-34356
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions... Read more
- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2021-34355
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of... Read more
- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2021-34354
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions... Read more
- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-34352
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR ... Read more
Affected Products : qvr- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-34351
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR ... Read more
Affected Products : qvr- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-34349
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR ... Read more
Affected Products : qvr- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-34348
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR ... Read more
Affected Products : qvr- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-34346
A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of... Read more
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-34345
A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of... Read more
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-34344
A stack buffer overflow vulnerability has been reported to affect QNAP device running QUSBCam2. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QUSBCam2: QT... Read more
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024