Latest CVE Feed
-
7.2
HIGHCVE-2021-29350
SQL injection in the getip function in conn/function.php in 发货100-设计素材下载系统 1.1 allows remote attackers to inject arbitrary SQL commands via the X-Forwarded-For header to admin/product_add.php.... Read more
Affected Products : shipment_100-design_material_download_system- EPSS Score: %0.52
- Published: Apr. 29, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-29349
Mahara 20.10 is affected by Cross Site Request Forgery (CSRF) that allows a remote attacker to remove inbox-mail on the server. The application fails to validate the CSRF token for a POST request. An attacker can craft a module/multirecipientnotification/... Read more
Affected Products : mahara- EPSS Score: %0.57
- Published: Mar. 31, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-29343
Ovidentia CMS 6.x contains a SQL injection vulnerability in the "id" parameter of index.php. The "checkbox" property into "text" data can be extracted and displayed in the text region or in source code.... Read more
Affected Products : ovidentia- EPSS Score: %0.19
- Published: Mar. 30, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-29338
Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS). This occurs when the attacker uses the command line option "-ImgDir" on a directory that contains 1048576 files.... Read more
- EPSS Score: %0.09
- Published: Apr. 14, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-29337
MODAPI.sys in MSI Dragon Center 2.0.104.0 allows low-privileged users to access kernel memory and potentially escalate privileges via a crafted IOCTL 0x9c406104 call. This IOCTL provides the MmMapIoSpace feature for mapping physical memory.... Read more
Affected Products : dragon_center- EPSS Score: %0.09
- Published: Jun. 21, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-29329
OpenSource Moddable v10.5.0 was discovered to contain a stack overflow in the fxBinaryExpressionNodeDistribute function at /moddable/xs/sources/xsTree.c.... Read more
- EPSS Score: %0.18
- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-29328
OpenSource Moddable v10.5.0 was discovered to contain buffer over-read in the fxDebugThrow function at /moddable/xs/sources/xsDebug.c.... Read more
- EPSS Score: %0.17
- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-29327
OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fx_ArrayBuffer function at /moddable/xs/sources/xsDataView.c.... Read more
- EPSS Score: %0.18
- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-29326
OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fxIDToString function at /moddable/xs/sources/xsSymbol.c.... Read more
- EPSS Score: %0.18
- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-29325
OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fx_String_prototype_repeat function at /moddable/xs/sources/xsString.c.... Read more
- EPSS Score: %0.18
- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-29324
OpenSource Moddable v10.5.0 was discovered to contain a stack overflow via the component /moddable/xs/sources/xsScript.c.... Read more
- EPSS Score: %0.18
- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-29323
OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow via the component /modules/network/wifi/esp/modwifi.c.... Read more
- EPSS Score: %0.15
- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-29313
Cross Site Scripting (XSS) vulnerability exists in SeaCMS 12.6 via the (1) v_company and (2) v_tvs parameters in /admin_video.php,... Read more
Affected Products : seacms- EPSS Score: %0.20
- Published: Aug. 17, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-29302
TP-Link TL-WR802N(US), Archer_C50v5_US v4_200 <= 2020.06 contains a buffer overflow vulnerability in the httpd process in the body message. The attack vector is: The attacker can get shell of the router by sending a message through the network, which may ... Read more
- EPSS Score: %10.97
- Published: Apr. 12, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-29300
The @ronomon/opened library before 1.5.2 is vulnerable to a command injection vulnerability which would allow a remote attacker to execute commands on the system if the library was used with untrusted input.... Read more
Affected Products : opened- EPSS Score: %38.18
- Published: May. 24, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-29298
Improper Input Validation in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash via crafted traffic from a Man-in-the-Middle (MITM) attack to the component "FrameworX.exe"in the module ... Read more
Affected Products : proficy_machine_edition- EPSS Score: %0.28
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-29297
Buffer Overflow in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash via crafted traffic from a Man-in-the-Middle (MITM) attack to the component "FrameworX.exe" in the module "MSVCR100... Read more
Affected Products : proficy_machine_edition- EPSS Score: %0.33
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29296
Null Pointer Dereference vulnerability in D-Link DIR-825 2.10b02, which could let a remote malicious user cause a denial of service. The vulnerability could be triggered by sending an HTTP request with URL /vct_wan; the sbin/httpd would invoke the strchr ... Read more
- EPSS Score: %0.26
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29295
Null Pointer Dereference vulnerability exists in D-Link DSP-W215 1.10, which could let a remote malicious user cause a denial of servie via usr/bin/lighttpd. It could be triggered by sending an HTTP request without URL in the start line directly to the de... Read more
- EPSS Score: %0.44
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29294
Null Pointer Dereference vulnerability exists in D-Link DSL-2740R UK_1.01, which could let a remove malicious user cause a denial of service via the send_hnap_unauthorized function. It could be triggered by sending crafted POST request to /HNAP1/. NOTE: T... Read more
- EPSS Score: %0.26
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024