Latest CVE Feed
-
8.1
HIGHCVE-2021-26253
A potential vulnerability in Splunk Enterprise's implementation of DUO MFA allows for bypassing the MFA verification in Splunk Enterprise versions before 8.1.6. The potential vulnerability impacts Splunk Enterprise instances configured to use DUO MFA and ... Read more
Affected Products : splunk- EPSS Score: %0.20
- Published: May. 06, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26252
A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of service.... Read more
- EPSS Score: %0.39
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
6.2
MEDIUMCVE-2021-26248
Philips MRI 1.5T and MRI 3T Version 5.x.x assigns an owner who is outside the intended control sphere to a resource.... Read more
- EPSS Score: %0.05
- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26247
As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" to successfully execute the JavaScript payload present in the "ref" URL parameter.... Read more
Affected Products : cacti- EPSS Score: %31.02
- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26237
FastStone Image Viewer <= 7.5 is affected by a user mode write access violation at 0x00402d7d, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Service (DoS) o... Read more
Affected Products : image_viewer- EPSS Score: %0.20
- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26236
FastStone Image Viewer v.<= 7.5 is affected by a Stack-based Buffer Overflow at 0x005BDF49, affecting the CUR file parsing functionality (BITMAPINFOHEADER Structure, 'BitCount' file format field), that will end up corrupting the Structure Exception Handle... Read more
Affected Products : image_viewer- EPSS Score: %1.00
- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26235
FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfc9, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Servi... Read more
Affected Products : image_viewer- EPSS Score: %0.32
- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26234
FastStone Image Viewer <= 7.5 is affected by a user mode write access violation at 0x00402d8a, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Service (DoS) o... Read more
Affected Products : image_viewer- EPSS Score: %0.32
- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26233
FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfcb, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Servi... Read more
Affected Products : image_viewer- EPSS Score: %0.32
- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26232
SQL injection vulnerability in SourceCodester Simple College Website v 1.0 allows remote attackers to execute arbitrary SQL statements via the id parameter to news.php.... Read more
Affected Products : simple_college_website- EPSS Score: %0.49
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26231
SQL injection vulnerability in SourceCodester Fantastic Blog CMS v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to category.php.... Read more
Affected Products : fantastic_blog_cms- EPSS Score: %0.62
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26230
Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the user information to save_user.php.... Read more
Affected Products : casap_automated_enrollment_system- EPSS Score: %0.22
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26229
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_stud.php.... Read more
Affected Products : casap_automated_enrollment_system- EPSS Score: %0.51
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26228
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_class1.php.... Read more
Affected Products : casap_automated_enrollment_system- EPSS Score: %0.62
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26227
Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the student information parameters to edit_stud.php.... Read more
Affected Products : casap_automated_enrollment_system- EPSS Score: %0.22
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26226
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_user.php.... Read more
Affected Products : casap_automated_enrollment_system- EPSS Score: %0.51
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26224
Cross-site scripting (XSS) vulnerability in SourceCodester Fantastic-Blog-CMS V 1.0 allows remote attackers to inject arbitrary web script or HTML via the search field to search.php.... Read more
- EPSS Score: %0.22
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26223
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to view_pay.php.... Read more
Affected Products : casap_automated_enrollment_system- EPSS Score: %0.51
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-26222
The ezxml_new function in ezXML 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool.... Read more
Affected Products : ezxml- EPSS Score: %0.44
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-26221
The ezxml_new function in ezXML 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool.... Read more
Affected Products : ezxml- EPSS Score: %0.44
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024