Latest CVE Feed
-
4.3
MEDIUMCVE-2021-22868
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to read f... Read more
Affected Products : enterprise_server- EPSS Score: %0.28
- Published: Sep. 24, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-22867
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to read f... Read more
Affected Products : enterprise_server- EPSS Score: %0.46
- Published: Jul. 14, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-22866
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during a GitHub App's user-authorization web flow than was displayed to the user during approval. To exploit this vulnerability, an... Read more
Affected Products : enterprise_server- EPSS Score: %0.20
- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-22865
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed access tokens generated from a GitHub App's web authentication flow to read private repository metadata via the REST API without having been granted the appro... Read more
Affected Products : enterprise_server- EPSS Score: %0.23
- Published: Apr. 02, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-22864
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to... Read more
Affected Products : enterprise_server- EPSS Score: %2.50
- Published: Mar. 23, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-22863
An improper access control vulnerability was identified in the GitHub Enterprise Server GraphQL API that allowed authenticated users of the instance to modify the maintainer collaboration permission of a pull request without proper authorization. By explo... Read more
- EPSS Score: %0.46
- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-22862
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with the ability to fork a repository to disclose Actions secrets for the parent repository of the fork. This vulnerability existed due ... Read more
- EPSS Score: %0.15
- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-22861
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of the instance to gain write access to unauthorized repositories via specifically crafted pull requests and REST API requests. An attacke... Read more
- EPSS Score: %0.46
- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22860
EIC e-document system does not perform completed identity verification for sorting and filtering personnel data. The vulnerability allows remote attacker to obtain users’ credential information without logging in the system, and further acquire the privil... Read more
Affected Products : e-document_system- EPSS Score: %0.91
- Published: Mar. 17, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22859
The users’ data querying function of EIC e-document system does not filter the special characters which resulted in remote attackers can inject SQL syntax and execute arbitrary commands without privilege.... Read more
Affected Products : e-document_system- EPSS Score: %1.70
- Published: Mar. 17, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-22858
Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrary commands or files after obtaining user permissions.... Read more
Affected Products : changjia_property_management_system- EPSS Score: %0.30
- Published: Feb. 17, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-22857
The CGE page with download function contains a Directory Traversal vulnerability. Attackers can use this loophole to download system files arbitrarily.... Read more
Affected Products : changjia_property_management_system- EPSS Score: %0.43
- Published: Feb. 17, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22856
The CGE property management system contains SQL Injection vulnerabilities. Remote attackers can inject SQL commands into the parameters in Cookie and obtain data in the database without privilege.... Read more
Affected Products : changjia_property_management_system- EPSS Score: %0.31
- Published: Feb. 17, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22855
The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can send malicious serialized objects to execute arbitrary commands.... Read more
Affected Products : hr_portal- EPSS Score: %0.78
- Published: Feb. 17, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-22854
The HR Portal of Soar Cloud System fails to filter specific parameters. Remote attackers can inject SQL syntax and obtain all data in the database without privilege.... Read more
Affected Products : hr_portal- EPSS Score: %0.39
- Published: Feb. 17, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-22853
The HR Portal of Soar Cloud System fails to manage access control. While obtaining user ID, remote attackers can access sensitive data via a specific data packet, such as user’s login information, further causing the login function not to work.... Read more
Affected Products : hr_portal- EPSS Score: %0.26
- Published: Feb. 17, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-22852
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (online registration) to obtain database schema and data.... Read more
Affected Products : oaklouds_openid- EPSS Score: %0.26
- Published: Jan. 19, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22851
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (document management page) to obtain database schema and data.... Read more
Affected Products : oaklouds_openid- EPSS Score: %0.26
- Published: Jan. 19, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22850
HGiga EIP product lacks ineffective access control in certain pages that allow attackers to access database or perform privileged functions.... Read more
Affected Products : oaklouds_portal- EPSS Score: %0.29
- Published: Jan. 19, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-22849
Hyweb HyCMS-J1 backend editing function does not filter special characters. Users after log-in can inject JavaScript syntax to perform a stored XSS (Stored Cross-site scripting) attack.... Read more
Affected Products : hycms-j1- EPSS Score: %0.17
- Published: Jan. 22, 2021
- Modified: Nov. 21, 2024