Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.1

    MEDIUM
    CVE-2021-27330

    Triconsole Datepicker Calendar <3.77 is affected by cross-site scripting (XSS) in calendar_form.php. Attackers can read authentication cookies that are still active, which can be used to perform further attacks such as reading browser history, directory l... Read more

    Affected Products : datepicker_calendar
    • EPSS Score: %22.38
    • Published: Feb. 25, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2021-27329

    Friendica 2021.01 allows SSRF via parse_url?binurl= for DNS lookups or HTTP requests to arbitrary domain names.... Read more

    Affected Products : friendica frendica
    • EPSS Score: %0.29
    • Published: Feb. 18, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-27328

    Yeastar NeoGate TG400 91.3.0.3 devices are affected by Directory Traversal. An authenticated user can decrypt firmware and can read sensitive information, such as a password or decryption key.... Read more

    • EPSS Score: %57.08
    • Published: Feb. 19, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-27320

    Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.... Read more

    Affected Products : doctor_appointment_system
    • EPSS Score: %76.25
    • Published: Mar. 24, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-27319

    Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email parameter.... Read more

    Affected Products : doctor_appointment_system
    • EPSS Score: %72.22
    • Published: Mar. 24, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-27318

    Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or HTML via the lastname parameter.... Read more

    Affected Products : doctor_appointment_system
    • EPSS Score: %0.44
    • Published: Mar. 01, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-27317

    Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or HTML via the comment parameter.... Read more

    Affected Products : doctor_appointment_system
    • EPSS Score: %0.34
    • Published: Mar. 01, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-27316

    Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname parameter.... Read more

    Affected Products : doctor_appointment_system
    • EPSS Score: %71.38
    • Published: Mar. 24, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-27315

    Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter.... Read more

    Affected Products : doctor_appointment_system
    • EPSS Score: %71.38
    • Published: Mar. 24, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-27314

    SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter at login page.... Read more

    Affected Products : doctor_appointment_system
    • EPSS Score: %78.71
    • Published: Mar. 05, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-27310

    Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "language" parameter.... Read more

    Affected Products : clansphere
    • EPSS Score: %4.09
    • Published: Mar. 23, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-27309

    Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "module" parameter.... Read more

    Affected Products : clansphere
    • EPSS Score: %0.87
    • Published: Mar. 23, 2021
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2021-27308

    A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to inject JavaScript via the "redirect" parameter.... Read more

    Affected Products : 4images
    • EPSS Score: %0.48
    • Published: Mar. 22, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-27306

    An improper access control vulnerability in the JWT plugin in Kong Gateway prior to 2.3.2.0 allows unauthenticated users access to authenticated routes without a valid token JWT.... Read more

    Affected Products : kong_gateway
    • EPSS Score: %1.47
    • Published: Mar. 18, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-27293

    RestSharp < 106.11.8-alpha.0.13 uses a regular expression which is vulnerable to Regular Expression Denial of Service (ReDoS) when converting strings into DateTimes. If a server responds with a malicious string, the client using RestSharp will be stuck pr... Read more

    Affected Products : restsharp
    • EPSS Score: %0.46
    • Published: Jul. 12, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-27292

    ua-parser-js >= 0.7.14, fixed in 0.7.24, uses a regular expression which is vulnerable to denial of service. If an attacker sends a malicious User-Agent header, ua-parser-js will get stuck processing it for an extended period of time.... Read more

    Affected Products : ua-parser-js
    • EPSS Score: %0.36
    • Published: Mar. 17, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-27291

    In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input,... Read more

    Affected Products : fedora debian_linux pygments
    • EPSS Score: %2.33
    • Published: Mar. 17, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-27290

    ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the ... Read more

    • EPSS Score: %2.66
    • Published: Mar. 12, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-27288

    Cross Site Scripting (XSS) in X2Engine X2CRM v7.1 allows remote attackers to obtain sensitive information by injecting arbitrary web script or HTML via the "Comment" field in "/profile/activity" page.... Read more

    Affected Products : x2crm
    • EPSS Score: %0.20
    • Published: Apr. 14, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-27279

    MyBB before 1.8.25 allows stored XSS via nested [email] tags with MyCode (aka BBCode).... Read more

    Affected Products : mybb
    • EPSS Score: %0.38
    • Published: Feb. 22, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 291641 Results