• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2021-34684
2021-11-09
N/A
9.8 CRITICAL
Hitachi Vantara Pentaho Business Analytics through 9.1 allows an unauthenticated user to execute arbitrary SQL queries on any Pentaho data source and thus retrieve data from the related databases, as demonstrated by an api/repos/dashboards/editor URI.
CVE-2021-34683
2022-06-28
N/A
5.3 MEDIUM
An issue was discovered in EXCELLENT INFOTEK CORPORATION (EIC) E-document System 3.0. A remote attacker can use kw/auth/bbs/asp/get_user_email_info_bbs.asp to obtain the contact information (name and e-mail address) of everyone in the entire organization. This information can allow remote attackers to perform social engineering or brute force attacks against the system login page.
CVE-2021-34682
2021-06-23
N/A
3.7 LOW
Receita Federal IRPF 2021 1.7 allows a man-in-the-middle attack against the update feature.
CVE-2021-3468
2023-01-20
N/A
5.5 MEDIUM
A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.
CVE-2021-34679
2022-06-28
N/A
7.5 HIGH
Thycotic Password Reset Server before 5.3.0 allows credential disclosure.
CVE-2021-34676
2021-07-29
N/A
7.5 HIGH
Basix NEX-Forms through 7.8.7 allows authentication bypass for Excel report generation.
CVE-2021-34675
2021-07-29
N/A
7.5 HIGH
Basix NEX-Forms through 7.8.7 allows authentication bypass for stored PDF reports.
CVE-2021-3467
2021-03-30
N/A
5.5 MEDIUM
A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened.
CVE-2021-34668
Devowl, Wordpress Real Media Library
Real_media_library, Wordpress_real_cookie_banner, Wordpress_real_media_library
2021-09-02
N/A
5.4 MEDIUM
The WordPress Real Media Library WordPress plugin is vulnerable to Stored Cross-Site Scripting via the name parameter in the ~/inc/overrides/lite/rest/Folder.php file which allows author-level attackers to inject arbitrary web scripts in folder names, in versions up to and including 4.14.1.
CVE-2021-34667
2021-08-24
N/A
6.1 MEDIUM
The Calendar_plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of `$_SERVER['PHP_SELF']` in the ~/calendar.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.
« Previous 1 … 7,587 7,588 7,589 7,590 7,591 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE