Latest CVE Feed
-
9.8
CRITICALCVE-2021-27362
The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a Read Access Violation on Control Flow starting at WPG!ReadWPG_W+0x0000000000000133, which might allow remote attackers to execute arbitrary code.... Read more
- EPSS Score: %4.24
- Published: Feb. 17, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-27358
The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.... Read more
- EPSS Score: %79.64
- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27357
RIOT-OS 2020.01 contains a buffer overflow vulnerability in /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c.... Read more
Affected Products : riot- EPSS Score: %0.46
- Published: Apr. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-27352
An open redirect vulnerability in Ilch CMS version 2.1.42 allows attackers to redirect users to an attacker's site after a successful login.... Read more
Affected Products : ilch_cms- EPSS Score: %0.20
- Published: Mar. 29, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-27351
The Terminate Session feature in the Telegram application through 7.2.1 for Android, and through 2.4.7 for Windows and UNIX, fails to invalidate a recently active session.... Read more
Affected Products : telegram- EPSS Score: %0.18
- Published: Feb. 19, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-27349
Advanced Order Export before 3.1.8 for WooCommerce allows XSS, a different vulnerability than CVE-2020-11727.... Read more
- EPSS Score: %0.21
- Published: Mar. 31, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-27347
Use after free in lzma_decompress_buf function in stream.c in Irzip 0.631 allows attackers to cause Denial of Service (DoS) via a crafted compressed file.... Read more
- EPSS Score: %0.09
- Published: Jun. 10, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-27345
A null pointer dereference was discovered in ucompthread in stream.c in Irzip 0.631 which allows attackers to cause a denial of service (DOS) via a crafted compressed file.... Read more
- EPSS Score: %0.09
- Published: Jun. 10, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-27343
SerenityOS Unspecified is affected by: Buffer Overflow. The impact is: obtain sensitive information (context-dependent). The component is: /Userland/Libraries/LibCrypto/ASN1/DER.h Crypto::der_decode_sequence() function. The attack vector is: Parsing RSA K... Read more
- EPSS Score: %0.50
- Published: Apr. 06, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-27342
An authentication brute-force protection mechanism bypass in telnetd in D-Link Router model DIR-842 firmware version 3.0.2 allows a remote attacker to circumvent the anti-brute-force cool-down delay period via a timing-based side-channel attack... Read more
- EPSS Score: %8.97
- Published: May. 17, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27341
OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via the "filename" parameter.... Read more
Affected Products : opensis- EPSS Score: %0.84
- Published: Sep. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-27340
OpenSIS Community Edition version <= 7.6 is affected by a reflected XSS vulnerability in EmailCheck.php via the "opt" parameter.... Read more
Affected Products : opensis- EPSS Score: %0.38
- Published: Sep. 16, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-27338
Faraday Edge before 3.7 allows XSS via the network/create/ page and its network name parameter.... Read more
Affected Products : edge- EPSS Score: %0.18
- Published: Jul. 20, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27335
KollectApps before 4.8.16c is affected by insecure Java deserialization, leading to Remote Code Execution via a ysoserial.payloads.CommonsCollections parameter.... Read more
Affected Products : kollect- EPSS Score: %1.99
- Published: Feb. 18, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-27332
Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the class_name parameter to update_class.php.... Read more
Affected Products : casap_automated_enrollment_system- EPSS Score: %0.28
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-27330
Triconsole Datepicker Calendar <3.77 is affected by cross-site scripting (XSS) in calendar_form.php. Attackers can read authentication cookies that are still active, which can be used to perform further attacks such as reading browser history, directory l... Read more
Affected Products : datepicker_calendar- EPSS Score: %22.38
- Published: Feb. 25, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-27329
Friendica 2021.01 allows SSRF via parse_url?binurl= for DNS lookups or HTTP requests to arbitrary domain names.... Read more
- EPSS Score: %0.29
- Published: Feb. 18, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-27328
Yeastar NeoGate TG400 91.3.0.3 devices are affected by Directory Traversal. An authenticated user can decrypt firmware and can read sensitive information, such as a password or decryption key.... Read more
- EPSS Score: %57.08
- Published: Feb. 19, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-27320
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.... Read more
Affected Products : doctor_appointment_system- EPSS Score: %76.25
- Published: Mar. 24, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-27319
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email parameter.... Read more
Affected Products : doctor_appointment_system- EPSS Score: %72.22
- Published: Mar. 24, 2021
- Modified: Nov. 21, 2024