Latest CVE Feed
-
9.8
CRITICALCVE-2021-30233
The api/ZRIptv/setIptvInfo interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the iptv_vlan parameter.... Read more
- EPSS Score: %3.19
- Published: Apr. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-30232
The api/ZRIGMP/set_IGMP_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the IGMP_PROXY_WAN_CONNECT parameter.... Read more
- EPSS Score: %3.19
- Published: Apr. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-30231
The api/zrDm/set_ZRElink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the bssaddr, abiaddr, devtoken, devid, elinksync, or elink_proc_enable parameter.... Read more
- EPSS Score: %3.19
- Published: Apr. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-30230
The api/ZRFirmware/set_time_zone interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the zonename parameter.... Read more
- EPSS Score: %3.19
- Published: Apr. 29, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-30229
The api/zrDm/set_zrDm interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the dm_enable, AppKey, or Pwd parameter.... Read more
- EPSS Score: %3.12
- Published: Apr. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-30228
The api/ZRAndlink/set_ZRAndlink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the iandlink_proc_enable parameter.... Read more
- EPSS Score: %3.19
- Published: Apr. 29, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-30227
Cross Site Scripting (XSS) vulnerability in the article comments feature in emlog 6.0.... Read more
Affected Products : emlog- EPSS Score: %0.21
- Published: Apr. 29, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-30224
Cross Site Request Forgery (CSRF) in Rukovoditel v2.8.3 allows attackers to create an admin user with an arbitrary credentials.... Read more
Affected Products : rukovoditel- EPSS Score: %0.11
- Published: Apr. 29, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-30219
samurai 1.2 has a NULL pointer dereference in printstatus() function in build.c via a crafted build file.... Read more
Affected Products : samurai- EPSS Score: %0.27
- Published: Apr. 29, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-30218
samurai 1.2 has a NULL pointer dereference in writefile() in util.c via a crafted build file.... Read more
Affected Products : samurai- EPSS Score: %0.27
- Published: Apr. 29, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-30214
Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' parameter.... Read more
Affected Products : knowage- EPSS Score: %0.26
- Published: May. 12, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-30213
Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in '/servlet/AdapterHTTP' via the 'targetService' parameter.... Read more
Affected Products : knowage- EPSS Score: %2.98
- Published: May. 12, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-30212
Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/documentnotes/saveNote' via the 'nota' parameter.... Read more
Affected Products : knowage- EPSS Score: %0.21
- Published: May. 12, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-30211
Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/signup/update' via the 'surname' parameter.... Read more
Affected Products : knowage- EPSS Score: %0.18
- Published: May. 12, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-30209
Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background without any security verification, which may lead to obtaining system permissions.... Read more
Affected Products : textpattern- EPSS Score: %0.15
- Published: Apr. 15, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-30203
A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers to execute arbitrary web scripts or HTML.... Read more
Affected Products : dzzoffice- EPSS Score: %0.07
- Published: Jun. 27, 2023
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-30201
The API /vsaWS/KaseyaWS.asmx can be used to submit XML to the system. When this XML is processed (external) entities are insecurely processed and fetched by the system and returned to the attacker. Detailed description Given the following request: ``` POS... Read more
Affected Products : vsa- EPSS Score: %0.33
- Published: Jul. 09, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-30199
In filters/reframe_latm.c in GPAC 1.0.1 there is a Null Pointer Dereference, when gf_filter_pck_get_data is called. The first arg pck may be null with a crafted mp4 file,which results in a crash.... Read more
Affected Products : gpac- EPSS Score: %0.10
- Published: Apr. 19, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-30185
CERN Indico before 2.3.4 can use an attacker-supplied Host header in a password reset link.... Read more
Affected Products : indico- EPSS Score: %0.24
- Published: Apr. 07, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-30183
Cleartext storage of sensitive information in multiple versions of Octopus Server where in certain situations when running import or export processes, the password used to encrypt and decrypt sensitive values would be written to the logs in plaintext.... Read more
Affected Products : server- EPSS Score: %0.16
- Published: May. 14, 2021
- Modified: Nov. 21, 2024