Latest CVE Feed
-
5.4
MEDIUMCVE-2021-30171
Special characters of ERP POS news page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipulate custome... Read more
Affected Products : enterprise_resource_planning_point_of_sale_system- EPSS Score: %0.15
- Published: May. 07, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-30170
Special characters of ERP POS customer profile page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipu... Read more
Affected Products : enterprise_resource_planning_point_of_sale_system- EPSS Score: %0.15
- Published: May. 07, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-30169
The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant user’s credential.... Read more
Affected Products : p2r8852e2_firmware p2r8852e4_firmware p2r6852e2_firmware p2r6852e4_firmware p2r6552e2_firmware p2r6552e4_firmware p2r6352ae2_firmware p2r6352ae4_firmware p2r3052ae2_firmware p2g1052_firmware +72 more products- EPSS Score: %0.94
- Published: Apr. 28, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-30168
The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant administrator’s credential and further control the devices.... Read more
Affected Products : p2r8852e2_firmware p2r8852e4_firmware p2r6852e2_firmware p2r6852e4_firmware p2r6552e2_firmware p2r6552e4_firmware p2r6352ae2_firmware p2r6352ae4_firmware p2r3052ae2_firmware p2g1052_firmware +72 more products- EPSS Score: %1.34
- Published: Apr. 28, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-30167
The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL parameters and further amend user’s information and escalate privileges to control the devices.... Read more
Affected Products : p2r8852e2_firmware p2r8852e4_firmware p2r6852e2_firmware p2r6852e4_firmware p2r6552e2_firmware p2r6552e4_firmware p2r6352ae2_firmware p2r6352ae4_firmware p2r3052ae2_firmware p2g1052_firmware +72 more products- EPSS Score: %3.02
- Published: Apr. 28, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-30166
The NTP Server configuration function of the IP camera device is not verified with special parameters. Remote attackers can perform a command Injection attack and execute arbitrary commands after logging in with the privileged permission.... Read more
Affected Products : p2r8852e2_firmware p2r8852e4_firmware p2r6852e2_firmware p2r6852e4_firmware p2r6552e2_firmware p2r6552e4_firmware p2r6352ae2_firmware p2r6352ae4_firmware p2r3052ae2_firmware p2g1052_firmware +72 more products- EPSS Score: %6.05
- Published: Apr. 28, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-30165
The default administrator account & password of the EDIMAX wireless network camera is hard-coded. Remote attackers can disassemble firmware to obtain the privileged permission and further control the devices.... Read more
- EPSS Score: %0.21
- Published: Apr. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-30164
Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API.... Read more
- EPSS Score: %0.21
- Published: Apr. 06, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-30163
Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have changes to project_id values.... Read more
- EPSS Score: %0.50
- Published: Apr. 06, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-30162
An issue was discovered on LG mobile devices with Android OS 4.4 through 11 software. Attackers can leverage ISMS services to bypass access control on specific content providers. The LG ID is LVE-SMP-210003 (April 2021).... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Apr. 06, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-30161
An issue was discovered on LG mobile devices with Android OS 11 software. Attackers can bypass the lockscreen protection mechanism after an incoming call has been terminated. The LG ID is LVE-SMP-210002 (April 2021).... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Apr. 06, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-30159
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Users can bypass intended restrictions on deleting pages in certain "fast double move" situations. MovePage::isValidMoveTarget() uses FOR UPDATE, but it's only ca... Read more
- EPSS Score: %0.75
- Published: Apr. 09, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-30158
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user might have accidentally shared a token, or might know that... Read more
- EPSS Score: %0.72
- Published: Apr. 06, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-30157
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special pages such as Special:RecentChanges and Special:Watchlist, some of the rcfilters-filter-* label messages are output in HTML unescaped, lead... Read more
- EPSS Score: %1.04
- Published: Apr. 06, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-30156
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Special:Contributions can leak that a "hidden" user exists.... Read more
- EPSS Score: %0.25
- Published: Apr. 09, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-30155
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. ContentModelChange does not check if a user has correct permissions to create and set the content model of a nonexistent page.... Read more
- EPSS Score: %0.53
- Published: Apr. 09, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-30154
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Special:NewFiles, all the mediastatistics-header-* messages are output in HTML unescaped, leading to XSS.... Read more
- EPSS Score: %1.15
- Published: Apr. 06, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-30152
An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki API to "protect" a page, a user is currently able to protect to a higher level than they currently have permissions for.... Read more
- EPSS Score: %0.62
- Published: Apr. 09, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-30151
Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.... Read more
- EPSS Score: %19.11
- Published: Apr. 06, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUM- EPSS Score: %0.32
- Published: Apr. 06, 2021
- Modified: Nov. 21, 2024