• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2021-38677

February 23, 2023 by

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QcalAgent. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QcalAgent: QcalAgent 1.1.7 and later

CVE-2021-38680

February 23, 2023 by

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Kazoo Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Kazoo Server: Kazoo Server 4.11.20 and later

CVE-2021-38681

February 23, 2023 by

A reflected cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Ragic Cloud DB. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already disabled and removed Ragic Cloud DB from the QNAP App Center, pending a security patch from Ragic.

CVE-2021-38602

February 23, 2023 by

PluXML 5.8.7 allows Article Editing stored XSS via Headline or Content.

CVE-2021-38603

February 23, 2023 by

PluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field.

CVE-2021-38607

February 23, 2023 by

Crocoblock JetEngine before 2.6.1 allows XSS by remote authenticated users via a custom form input.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 1368
  • Go to page 1369
  • Go to page 1370
  • Go to page 1371
  • Go to page 1372
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE