Latest CVE Feed
-
5.5
MEDIUMCVE-2021-32137
Heap buffer overflow in the URL_GetProtocolType function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.... Read more
Affected Products : gpac- EPSS Score: %0.40
- Published: Sep. 13, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-32136
Heap buffer overflow in the print_udta function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.... Read more
Affected Products : gpac- EPSS Score: %0.45
- Published: Sep. 13, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-32135
The trak_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.... Read more
Affected Products : gpac- EPSS Score: %0.10
- Published: Sep. 13, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-32134
The gf_odf_desc_copy function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.... Read more
Affected Products : gpac- EPSS Score: %0.10
- Published: Sep. 13, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-32132
The abst_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.... Read more
Affected Products : gpac- EPSS Score: %0.10
- Published: Sep. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32122
Certain NETGEAR devices are affected by CSRF. This affects EX3700 before 1.0.0.90, EX3800 before 1.0.0.90, EX6120 before 1.0.0.64, and EX6130 before 1.0.0.44.... Read more
Affected Products : ex3700_firmware ex3800_firmware ex6120_firmware ex6130_firmware ex6120 ex3700 ex3800 ex6130- EPSS Score: %0.18
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-32106
In ICEcoder 8.0 allows, a reflected XSS vulnerability was identified in the multipe-results.php page due to insufficient sanitization of the _GET['replace'] variable. As a result, arbitrary Javascript code can get executed.... Read more
Affected Products : icecoder- EPSS Score: %0.24
- Published: Jun. 08, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-32104
A SQL injection vulnerability exists (with user privileges) in interface/forms/eye_mag/save.php in OpenEMR 5.0.2.1.... Read more
Affected Products : openemr- EPSS Score: %0.02
- Published: May. 07, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-32103
A Stored XSS vulnerability in interface/usergroup/usergroup_admin.php in OpenEMR before 5.0.2.1 allows a admin authenticated user to inject arbitrary web script or HTML via the lname parameter.... Read more
Affected Products : openemr- EPSS Score: %0.50
- Published: May. 07, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-32102
A SQL injection vulnerability exists (with user privileges) in library/custom_template/ajax_code.php in OpenEMR 5.0.2.1.... Read more
Affected Products : openemr- EPSS Score: %0.02
- Published: May. 07, 2021
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2021-32101
The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config.php. To exploit the vulnerability, an unauthenticated attacker can register an account, bypassing the permission check of this portal'... Read more
Affected Products : openemr- EPSS Score: %0.22
- Published: May. 07, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-32100
A remote file inclusion vulnerability exists in Artica Pandora FMS 742, exploitable by the lowest privileged user.... Read more
Affected Products : pandora_fms- EPSS Score: %0.51
- Published: May. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32099
A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass.... Read more
Affected Products : pandora_fms- EPSS Score: %60.10
- Published: May. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32098
Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.... Read more
Affected Products : pandora_fms- EPSS Score: %2.79
- Published: May. 07, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-32096
The ConsoleAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows a CSRF attack that results in injecting arbitrary Ruby code (for an eval call) via the CONSOLE_COMMAND_STRING parameter.... Read more
Affected Products : emissary- EPSS Score: %0.14
- Published: May. 07, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-32095
U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to delete arbitrary files.... Read more
Affected Products : emissary- EPSS Score: %0.21
- Published: May. 07, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-32094
U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to upload arbitrary files.... Read more
Affected Products : emissary- EPSS Score: %0.52
- Published: May. 07, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-32093
The ConfigFileAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to read arbitrary files via the ConfigName parameter.... Read more
Affected Products : emissary- EPSS Score: %0.28
- Published: May. 07, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-32092
A Cross-site scripting (XSS) vulnerability in the DocumentAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows remote attackers to inject arbitrary web script or HTML via the uuid parameter.... Read more
Affected Products : emissary- EPSS Score: %0.36
- Published: May. 07, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-32091
A Cross-site scripting (XSS) vulnerability exists in StackLift LocalStack 0.12.6.... Read more
Affected Products : localstack- EPSS Score: %0.24
- Published: May. 07, 2021
- Modified: Nov. 21, 2024