Latest CVE Feed
-
6.1
MEDIUMCVE-2021-20116
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4. The paths provided in the f, d, and dir parameters in tce_select_mediafile.php were not properly validated and could cause reflected XSS via the unsanitized output of the path supp... Read more
Affected Products : tcexam- Published: Aug. 05, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20115
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3. The paths provided in the f, d, and dir parameters in tce_filemanager.php were not properly validated and could cause reflected XSS via the unsanitized output of the path supplied.... Read more
Affected Products : tcexam- Published: Aug. 05, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20114
When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included sensitive database backup files.... Read more
Affected Products : tcexam- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-20113
An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1. If a password reset request was made for an email address that was not registered with a user then we would be presented with an ‘unknown email’ error. If an email is given tha... Read more
Affected Products : tcexam- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20112
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_select_mediafile.php with a filename beggining with a period will be rendered as text/html. An attacker with access to tce_select_mediafile.php could uplo... Read more
Affected Products : tcexam- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20111
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php with a filename beggining with a period will be rendered as text/html. An attacker with access to tce_filemanager.php could upload a malic... Read more
Affected Products : tcexam- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-20110
Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request... Read more
Affected Products : manageengine_assetexplorer- Published: Jul. 19, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20109
Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a listening a... Read more
Affected Products : manageengine_assetexplorer- Published: Jul. 19, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20108
Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Server. The HTTPS certificates are not verified which allows any arbitrary user on the network to send commands over port 9000. While these ... Read more
Affected Products : manageengine_assetexplorer- Published: Jul. 19, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20107
There exists an unauthenticated BLE Interface in Sloan SmartFaucets including Optima EAF, Optima ETF/EBF, BASYS EFX, and Flushometers including SOLIS. The vulnerability allows for unauthenticated kinetic effects and information disclosure on the faucets. ... Read more
- Published: Jun. 30, 2021
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2021-20106
Nessus Agent versions 8.2.5 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus administrator user to upload a specially crafted file that could lead to gaining administrator privileges on the Nessus host.... Read more
- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20105
Machform prior to version 16 is vulnerable to an open redirect in Safari_init.php due to an improperly sanitized 'ref' parameter.... Read more
Affected Products : machform- Published: Jun. 29, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-20104
Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments uploaded with forms through upload.php.... Read more
Affected Products : machform- Published: Jun. 29, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20103
Machform prior to version 16 is vulnerable to stored cross-site scripting due to insufficient sanitization of file attachments uploaded with forms through upload.php.... Read more
Affected Products : machform- Published: Jun. 29, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-20102
Machform prior to version 16 is vulnerable to cross-site request forgery due to a lack of CSRF tokens in place.... Read more
Affected Products : machform- Published: Jun. 29, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20101
Machform prior to version 16 is vulnerable to HTTP host header injection due to improperly validated host headers. This could cause a victim to receive malformed content.... Read more
Affected Products : machform- Published: Jun. 29, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-20100
Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Nessus host. This is different than CVE... Read more
- Published: Jun. 28, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-20099
Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Nessus host. This is different than CVE... Read more
- Published: Jun. 28, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-20096
Cross-site request forgery in OpenOversight 0.6.4 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.... Read more
Affected Products : openoversight- Published: May. 25, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20094
A denial of service vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to crash the CodeMeter Runtime Server.... Read more
- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024