Latest CVE Feed
-
9.0
HIGHCVE-2021-26068
An endpoint in Atlassian Jira Server for Slack plugin from version 0.0.3 before version 2.0.15 allows remote attackers to execute arbitrary code via a template injection vulnerability.... Read more
Affected Products : jira_server_for_slack- EPSS Score: %5.00
- Published: Feb. 22, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-26067
Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the path for the home directory in disk and if certain files exists on the tmp directory, via a Sensitive Data Exposure vulnerability in t... Read more
Affected Products : bamboo- EPSS Score: %1.00
- Published: Jan. 28, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-26040
An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command.... Read more
Affected Products : joomla\!- EPSS Score: %0.01
- Published: Aug. 24, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26039
An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the imagelist view of com_media leads to a XSS vulnerability.... Read more
Affected Products : joomla\!- EPSS Score: %2.17
- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-26038
An issue was discovered in Joomla! 2.5.0 through 3.9.27. Install action in com_installer lack the required hardcoded ACL checks for superusers. A default system is not affected cause the default ACL for com_installer is limited to super users already.... Read more
Affected Products : joomla\!- EPSS Score: %0.01
- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-26037
An issue was discovered in Joomla! 2.5.0 through 3.9.27. CMS functions did not properly termine existing user sessions when a user's password was changed or the user was blocked.... Read more
Affected Products : joomla\!- EPSS Score: %0.01
- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-26036
An issue was discovered in Joomla! 2.5.0 through 3.9.27. Missing validation of input could lead to a broken usergroups table.... Read more
Affected Products : joomla\!- EPSS Score: %0.01
- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26035
An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the rules field of the JForm API leads to a XSS vulnerability.... Read more
Affected Products : joomla\!- EPSS Score: %2.17
- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-26034
An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in data download endpoints in com_banners and com_sysinfo.... Read more
Affected Products : joomla\!- EPSS Score: %0.01
- Published: May. 26, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-26033
An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in the AJAX reordering endpoint.... Read more
Affected Products : joomla\!- EPSS Score: %0.01
- Published: May. 26, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26032
An issue was discovered in Joomla! 3.0.0 through 3.9.26. HTML was missing in the executable block list of MediaHelper::canUpload, leading to XSS attack vectors.... Read more
Affected Products : joomla\!- EPSS Score: %1.61
- Published: May. 26, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-26031
An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate filters on module layout settings could lead to an LFI.... Read more
Affected Products : joomla\!- EPSS Score: %0.01
- Published: Apr. 14, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26030
An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate escaping allowed XSS attacks using the logo parameter of the default templates on error page... Read more
Affected Products : joomla\!- EPSS Score: %46.05
- Published: Apr. 14, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-26029
An issue was discovered in Joomla! 1.6.0 through 3.9.24. Inadequate filtering of form contents could allow to overwrite the author field.... Read more
Affected Products : joomla\!- EPSS Score: %0.02
- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-26028
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path.... Read more
- EPSS Score: %0.01
- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-26027
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Incorrect ACL checks could allow unauthorized change of the category for an article.... Read more
Affected Products : joomla\!- EPSS Score: %0.01
- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26026
PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDStd!JPEGTransW+0x000000000000c7f4 via a crafted BMP image.... Read more
- EPSS Score: %0.17
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26025
PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDStd!zlibVersion+0x0000000000004e5e via a crafted BMP image.... Read more
- EPSS Score: %0.17
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-26024
The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for any other user account.... Read more
- EPSS Score: %1.10
- Published: Feb. 03, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26023
The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS.... Read more
- EPSS Score: %64.79
- Published: Feb. 03, 2021
- Modified: Nov. 21, 2024