Latest CVE Feed
-
10.0
CRITICALCVE-2021-27329
Friendica 2021.01 allows SSRF via parse_url?binurl= for DNS lookups or HTTP requests to arbitrary domain names.... Read more
- EPSS Score: %0.29
- Published: Feb. 18, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-27328
Yeastar NeoGate TG400 91.3.0.3 devices are affected by Directory Traversal. An authenticated user can decrypt firmware and can read sensitive information, such as a password or decryption key.... Read more
- EPSS Score: %57.08
- Published: Feb. 19, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-27320
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.... Read more
Affected Products : doctor_appointment_system- EPSS Score: %76.25
- Published: Mar. 24, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-27319
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email parameter.... Read more
Affected Products : doctor_appointment_system- EPSS Score: %72.22
- Published: Mar. 24, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-27318
Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or HTML via the lastname parameter.... Read more
Affected Products : doctor_appointment_system- EPSS Score: %0.44
- Published: Mar. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-27317
Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or HTML via the comment parameter.... Read more
Affected Products : doctor_appointment_system- EPSS Score: %0.34
- Published: Mar. 01, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-27316
Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname parameter.... Read more
Affected Products : doctor_appointment_system- EPSS Score: %71.38
- Published: Mar. 24, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-27315
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter.... Read more
Affected Products : doctor_appointment_system- EPSS Score: %71.38
- Published: Mar. 24, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27314
SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter at login page.... Read more
Affected Products : doctor_appointment_system- EPSS Score: %78.71
- Published: Mar. 05, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-27310
Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "language" parameter.... Read more
Affected Products : clansphere- EPSS Score: %4.09
- Published: Mar. 23, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-27309
Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "module" parameter.... Read more
Affected Products : clansphere- EPSS Score: %0.87
- Published: Mar. 23, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-27308
A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to inject JavaScript via the "redirect" parameter.... Read more
Affected Products : 4images- EPSS Score: %0.48
- Published: Mar. 22, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-27306
An improper access control vulnerability in the JWT plugin in Kong Gateway prior to 2.3.2.0 allows unauthenticated users access to authenticated routes without a valid token JWT.... Read more
Affected Products : kong_gateway- EPSS Score: %1.47
- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-27293
RestSharp < 106.11.8-alpha.0.13 uses a regular expression which is vulnerable to Regular Expression Denial of Service (ReDoS) when converting strings into DateTimes. If a server responds with a malicious string, the client using RestSharp will be stuck pr... Read more
Affected Products : restsharp- EPSS Score: %0.46
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-27292
ua-parser-js >= 0.7.14, fixed in 0.7.24, uses a regular expression which is vulnerable to denial of service. If an attacker sends a malicious User-Agent header, ua-parser-js will get stuck processing it for an extended period of time.... Read more
Affected Products : ua-parser-js- EPSS Score: %0.36
- Published: Mar. 17, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-27291
In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input,... Read more
- EPSS Score: %2.33
- Published: Mar. 17, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-27290
ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the ... Read more
- EPSS Score: %2.66
- Published: Mar. 12, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-27288
Cross Site Scripting (XSS) in X2Engine X2CRM v7.1 allows remote attackers to obtain sensitive information by injecting arbitrary web script or HTML via the "Comment" field in "/profile/activity" page.... Read more
Affected Products : x2crm- EPSS Score: %0.20
- Published: Apr. 14, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-27279
MyBB before 1.8.25 allows stored XSS via nested [email] tags with MyCode (aka BBCode).... Read more
Affected Products : mybb- EPSS Score: %0.38
- Published: Feb. 22, 2021
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2021-27278
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.1-49141. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vul... Read more
Affected Products : parallels_desktop- EPSS Score: %0.05
- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024