Latest CVE Feed
-
7.8
HIGHCVE-2021-31727
Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 where IOCTL's 0x80002014, 0x80002018 expose unrestricted disk read/write capabilities respectively. A non-privileged process can open a handle to \.\ZemanaAntiMalware, r... Read more
- EPSS Score: %0.16
- Published: May. 17, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31726
Akuvox C315 115.116.2613 allows remote command Injection via the cfgd_server service. The attack vector is sending a payload to port 189 (default root 0.0.0.0).... Read more
- EPSS Score: %4.42
- Published: Apr. 25, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-31721
Chevereto before 3.17.1 allows Cross Site Scripting (XSS) via an image title at the image upload stage.... Read more
Affected Products : chevereto- EPSS Score: %0.40
- Published: Jun. 30, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-31718
The server in npupnp before 4.1.4 is affected by DNS rebinding in the embedded web server (including UPnP SOAP and GENA endpoints), leading to remote code execution.... Read more
Affected Products : npupnp- EPSS Score: %0.48
- Published: Apr. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-31712
react-draft-wysiwyg (aka React Draft Wysiwyg) before 1.14.6 allows a javascript: URi in a Link Target of the link decorator in decorators/Link/index.js when a draft is shared across users, leading to XSS.... Read more
Affected Products : react_draft_wysiwyg- EPSS Score: %0.26
- Published: Apr. 24, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31703
Frontier ichris through 5.18 allows users to upload malicious executable files that might later be downloaded and run by any client user.... Read more
Affected Products : ichris- EPSS Score: %0.43
- Published: May. 29, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-31702
Frontier ichris through 5.18 mishandles making a DNS request for the hostname in the HTTP Host header, as demonstrated by submitting 127.0.0.1 multiple times for DoS.... Read more
Affected Products : ichris- EPSS Score: %0.33
- Published: May. 29, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-31701
Mintty before 3.4.7 mishandles Bracketed Paste Mode.... Read more
Affected Products : mintty- EPSS Score: %0.21
- Published: Jun. 06, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-31698
Quectel EG25-G devices through 202006130814 allow executing arbitrary code remotely by using an AT command to place shell metacharacters in quectel_handle_fumo_cfg input in atfwd_daemon.... Read more
- EPSS Score: %0.42
- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-31693
The 10Web Photo Gallery plugin through 1.5.68 for WordPress allows XSS via album_gallery_id_0, bwg_album_search_0, and type_0 for bwg_frontend_data. NOTE: other parameters are covered by CVE-2021-24291, CVE-2021-25041, and CVE-2021-46889. NOTE: VMware inf... Read more
Affected Products : tools- EPSS Score: %0.06
- Published: Nov. 29, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-31684
A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request.... Read more
- EPSS Score: %0.07
- Published: Jun. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-31682
The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS attacks due to the operatorlocale GET parameter not being sanitized. This issue impacts versions 6.5 and below. This issue ... Read more
Affected Products : webctrl- EPSS Score: %33.65
- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-31681
Deserialization of Untrusted Data vulnerability in yolo 3 allows attackers to execute arbitrary code via crafted yaml file.... Read more
Affected Products : yolov3- EPSS Score: %0.03
- Published: Jul. 31, 2023
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-31680
Deserialization of Untrusted Data vulnerability in yolo 5 allows attackers to execute arbitrary code via crafted yaml file.... Read more
Affected Products : yolov5- EPSS Score: %0.03
- Published: Jul. 31, 2023
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-31679
An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that allows attackers to delete admin and other members' account numbers.... Read more
Affected Products : pescms_team- EPSS Score: %0.11
- Published: Jul. 06, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-31678
An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that can delete import information about a user's company.... Read more
Affected Products : pescms_team- EPSS Score: %0.12
- Published: Jul. 06, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-31677
An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that can modify admin and other members' passwords.... Read more
Affected Products : pescms_team- EPSS Score: %0.13
- Published: Jul. 06, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-31676
A reflected XSS was discovered in PESCMS-V2.3.3. When combined with CSRF in the same file, they can cause bigger destruction.... Read more
Affected Products : pescms_team- EPSS Score: %0.27
- Published: Jul. 06, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-31674
Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacker to execute javascript code via undefine enum constant.... Read more
Affected Products : cyclos- EPSS Score: %2.16
- Published: May. 02, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-31673
A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remote attackers to inject arbitrary web script or HTML via the groupId parameter.... Read more
Affected Products : cyclos- EPSS Score: %2.70
- Published: May. 02, 2022
- Modified: Nov. 21, 2024