Latest CVE Feed
-
6.3
MEDIUMCVE-2021-27909
For Mautic versions prior to 3.3.4/4.0.0, there is an XSS vulnerability on Mautic's password reset page where a vulnerable parameter, "bundle," in the URL could allow an attacker to execute Javascript code. The attacker would be required to convince or tr... Read more
Affected Products : mautic- EPSS Score: %9.70
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2021-27908
In all versions prior to Mautic 3.3.2, secret parameters such as database credentials could be exposed publicly by an authorized admin user through leveraging Symfony parameter syntax in any of the free text fields in Mautic’s configuration that are used ... Read more
Affected Products : mautic- EPSS Score: %0.11
- Published: Mar. 23, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-27907
Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related information. Abusing this functionality, a malicious user could inject javascript code executing unwanted action in ... Read more
Affected Products : superset- EPSS Score: %2.92
- Published: Mar. 05, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-27906
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.... Read more
Affected Products : fedora webcenter_sites outside_in_technology peoplesoft_enterprise_peopletools hyperion_financial_reporting retail_customer_management_and_segmentation_foundation primavera_unifier flexcube_universal_banking retail_xstore_point_of_service banking_treasury_management +9 more products- EPSS Score: %0.33
- Published: Mar. 19, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27905
The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate index data into the... Read more
Affected Products : solr- EPSS Score: %94.18
- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-27904
An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, the "all org" flag sometimes provided view access to unintended actors.... Read more
Affected Products : misp- EPSS Score: %0.05
- Published: Mar. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27903
An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session)... Read more
Affected Products : craft_cms- EPSS Score: %3.82
- Published: Jun. 30, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-27902
An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms that accepted user uploads.... Read more
Affected Products : craft_cms- EPSS Score: %0.42
- Published: Jun. 30, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-27901
An issue was discovered on LG mobile devices with Android OS 11 software. They mishandle fingerprint recognition because local high beam mode (LHBM) does not function properly during bright illumination. The LG ID is LVE-SMP-210001 (March 2021).... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Mar. 02, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-27900
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is missing an authorization check on several pages in the Web Console. This enables a view-only user to change any configuration setting and delete any registered agents. All vers... Read more
Affected Products : insider_threat_management- EPSS Score: %0.24
- Published: Apr. 06, 2021
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2021-27899
The Proofpoint Insider Threat Management Agents (formerly ObserveIT Agent) for MacOS and Linux perform improper validation of the ITM Server's certificate, which enables a remote attacker to intercept and alter these communications using a man-in-the-midd... Read more
Affected Products : insider_threat_management- EPSS Score: %0.11
- Published: Apr. 06, 2021
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2021-27893
SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions. ConnectSecure on Windows is affected.... Read more
- EPSS Score: %0.05
- Published: Mar. 15, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-27892
SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation. ConnectSecure on Windows is affected.... Read more
- EPSS Score: %0.05
- Published: Mar. 15, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-27891
SSH Tectia Client and Server before 6.4.19 on Windows have weak key generation. ConnectSecure on Windows is affected.... Read more
- EPSS Score: %0.51
- Published: Mar. 15, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-27890
SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.... Read more
Affected Products : mybb- EPSS Score: %5.71
- Published: Mar. 15, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-27889
Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages.... Read more
Affected Products : mybb- EPSS Score: %2.24
- Published: Mar. 15, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-27888
ZendTo before 6.06-4 Beta allows XSS during the display of a drop-off in which a filename has unexpected characters.... Read more
Affected Products : zendto- EPSS Score: %0.32
- Published: Mar. 02, 2021
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2021-27887
Cross-site Scripting (XSS) vulnerability in the main dashboard of Ellipse APM versions allows an authenticated user or integrated application to inject malicious data into the application that can then be executed in a victim’s browser. This issue affects... Read more
Affected Products : ellipse_asset_performance_management- EPSS Score: %0.27
- Published: Jun. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27886
rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request. NOTE: this is NOT a Docker, Inc. product.... Read more
Affected Products : docker_dashboard- EPSS Score: %4.11
- Published: Mar. 02, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-27885
usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.... Read more
Affected Products : e107- EPSS Score: %0.34
- Published: Mar. 02, 2021
- Modified: Nov. 21, 2024