Latest CVE Feed
-
6.1
MEDIUMCVE-2021-27889
Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages.... Read more
Affected Products : mybb- EPSS Score: %2.24
- Published: Mar. 15, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-27888
ZendTo before 6.06-4 Beta allows XSS during the display of a drop-off in which a filename has unexpected characters.... Read more
Affected Products : zendto- EPSS Score: %0.32
- Published: Mar. 02, 2021
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2021-27887
Cross-site Scripting (XSS) vulnerability in the main dashboard of Ellipse APM versions allows an authenticated user or integrated application to inject malicious data into the application that can then be executed in a victim’s browser. This issue affects... Read more
Affected Products : ellipse_asset_performance_management- EPSS Score: %0.27
- Published: Jun. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27886
rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request. NOTE: this is NOT a Docker, Inc. product.... Read more
Affected Products : docker_dashboard- EPSS Score: %4.11
- Published: Mar. 02, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-27885
usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.... Read more
Affected Products : e107- EPSS Score: %0.34
- Published: Mar. 02, 2021
- Modified: Nov. 21, 2024
-
5.1
MEDIUMCVE-2021-27884
Weak JSON Web Token (JWT) signing secret generation in YMFE YApi through 1.9.2 allows recreation of other users' JWT tokens. This occurs because Math.random in Node.js is used.... Read more
Affected Products : yapi- EPSS Score: %0.06
- Published: Mar. 01, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-27878
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authen... Read more
Affected Products : backup_exec- Actively Exploited
- EPSS Score: %0.98
- Published: Mar. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27877
An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An ... Read more
Affected Products : backup_exec- Actively Exploited
- EPSS Score: %0.97
- Published: Mar. 01, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-27876
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authen... Read more
Affected Products : backup_exec- Actively Exploited
- EPSS Score: %0.64
- Published: Mar. 01, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-27859
A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows an authenticated, remote attacker with read-only privileges to create an account with admi... Read more
- EPSS Score: %0.75
- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-27858
A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote attacker to access at least the URL "/fpui/jsp/index.jsp" leading to unknown impa... Read more
- EPSS Score: %0.39
- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-27857
A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, unauthenticated attacker to download a configuration archive. The attacker needs... Read more
- EPSS Score: %0.50
- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27856
FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" that has administrative privileges and no password. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory ide... Read more
- EPSS Score: %0.62
- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-27855
FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, authenticated attacker with read-only privileges to grant themselves administrative privileges. Older versions of FatPipe software may also be vulnerable... Read more
- EPSS Score: %1.14
- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-27851
A security vulnerability that can lead to local privilege escalation has been found in ’guix-daemon’. It affects multi-user setups in which ’guix-daemon’ runs locally. The attack consists in having an unprivileged user spawn a build process, for instance ... Read more
Affected Products : guix- EPSS Score: %0.04
- Published: Apr. 26, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-27850
A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5, 5.5.0, 5.6.2 and 5.7.0. The vulnerability I have found is a bypass of the fix for CVE-2019-0195. Recap: B... Read more
Affected Products : tapestry- EPSS Score: %94.22
- Published: Apr. 15, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-27847
Division-By-Zero vulnerability in Libvips 8.10.5 in the function vips_eye_point, eye.c#L83, and function vips_mask_point, mask.c#L85.... Read more
- EPSS Score: %0.11
- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-27845
A Divide-by-zero vulnerability exists in JasPer Image Coding Toolkit 2.0 in jasper/src/libjasper/jpc/jpc_enc.c... Read more
Affected Products : jasper- EPSS Score: %0.25
- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2021-27839
A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions such as redirecting admins to unknown or harmful websites, or disclosing other clients' details that the user did not... Read more
Affected Products : online_invoicing_system- EPSS Score: %0.22
- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-27836
An issue was discoverered in in function xls_getWorkSheet in xls.c in libxls 1.6.2, allows attackers to cause a denial of service, via a crafted XLS file.... Read more
- EPSS Score: %0.42
- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024