Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-27517 | 1 Foxit | 2 Phantompdf, Reader | 2021-07-29 | 4.3 MEDIUM | 6.1 MEDIUM |
Foxit PDF SDK For Web through 7.5.0 allows XSS. There is arbitrary JavaScript code execution in the browser if a victim uploads a malicious PDF document containing embedded JavaScript code that abuses app.alert (in the Acrobat JavaScript API). | |||||
CVE-2021-27338 | 1 Faraday | 1 Edge | 2021-07-29 | 3.5 LOW | 5.4 MEDIUM |
Faraday Edge before 3.7 allows XSS via the network/create/ page and its network name parameter. | |||||
CVE-2021-3135 | 1 Tagdiv | 1 Newspaper | 2021-07-28 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.php td_block_id parameter in a td_ajax_block API call. | |||||
CVE-2021-37450 | 1 Nchsoftware | 1 Ivm Attendant | 2021-07-28 | 3.5 LOW | 5.4 MEDIUM |
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmprop?id= (reflected). | |||||
CVE-2021-37451 | 1 Nchsoftware | 1 Ivm Attendant | 2021-07-28 | 3.5 LOW | 5.4 MEDIUM |
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected). | |||||
CVE-2021-37453 | 1 Nchsoftware | 1 Axon Pbx | 2021-07-28 | 3.5 LOW | 5.4 MEDIUM |
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored). | |||||
CVE-2021-37454 | 1 Nchsoftware | 1 Axon Pbx | 2021-07-28 | 3.5 LOW | 5.4 MEDIUM |
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored). | |||||
CVE-2021-37456 | 1 Nchsoftware | 1 Axon Pbx | 2021-07-28 | 3.5 LOW | 5.4 MEDIUM |
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored). | |||||
CVE-2021-37455 | 1 Nchsoftware | 1 Axon Pbx | 2021-07-28 | 3.5 LOW | 5.4 MEDIUM |
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the outbound dialing plan (stored). | |||||
CVE-2021-37457 | 1 Nchsoftware | 1 Axon Pbx | 2021-07-28 | 3.5 LOW | 5.4 MEDIUM |
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored). | |||||
CVE-2021-37458 | 1 Nchsoftware | 1 Axon Pbx | 2021-07-28 | 3.5 LOW | 5.4 MEDIUM |
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored). | |||||
CVE-2021-37459 | 1 Nchsoftware | 1 Axon Pbx | 2021-07-28 | 3.5 LOW | 5.4 MEDIUM |
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored). | |||||
CVE-2021-37460 | 1 Nchsoftware | 1 Axon Pbx | 2021-07-28 | 3.5 LOW | 5.4 MEDIUM |
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /planprop?id= (reflected). | |||||
CVE-2021-37462 | 1 Nchsoftware | 1 Axon Pbx | 2021-07-28 | 3.5 LOW | 5.4 MEDIUM |
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /ipblacklist?errorip= (reflected). | |||||
CVE-2021-37461 | 1 Nchsoftware | 1 Axon Pbx | 2021-07-28 | 3.5 LOW | 5.4 MEDIUM |
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /extensionsinstruction?id= (reflected). | |||||
CVE-2021-34821 | 1 Aat | 1 Novus Management System | 2021-07-28 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross Site Scripting (XSS) vulnerability exists in AAT Novus Management System through 1.51.2. The WebUI has wrong HTTP 404 error handling implemented. A remote, unauthenticated attacker may be able to exploit the issue by sending malicious HTTP requests to non-existing URIs. The value of the URL path filename is copied into the HTML document as plain text tags. | |||||
CVE-2021-34617 | 1 Aruba | 1 Aruba Instant | 2021-07-28 | 4.3 MEDIUM | 6.1 MEDIUM |
A remote cross-site scripting (XSS) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.13 and below; Aruba Instant 6.5.x: 6.5.4.13 and below; Aruba Instant 8.3.x: 8.3.0.7 and below; Aruba Instant 8.4.x: 8.4.0.5 and below; Aruba Instant 8.5.x: 8.5.0.0 and below. Aruba has released patches for Aruba Instant that address this security vulnerability. | |||||
CVE-2021-36772 | 1 Zohocorp | 1 Manageengine Admanager Plus | 2021-07-28 | 4.3 MEDIUM | 6.1 MEDIUM |
Zoho ManageEngine ADManager Plus before 7110 allows stored XSS. | |||||
CVE-2021-36771 | 1 Zohocorp | 1 Manageengine Admanager Plus | 2021-07-28 | 4.3 MEDIUM | 6.1 MEDIUM |
Zoho ManageEngine ADManager Plus before 7110 allows reflected XSS. | |||||
CVE-2021-22723 | 1 Schneider-electric | 12 Evlink City Evc1s22p4, Evlink City Evc1s22p4 Firmware, Evlink City Evc1s7p4 and 9 more | 2021-07-28 | 4.3 MEDIUM | 6.1 MEDIUM |
A CWE-79: Improper Neutralization of Input During Web Page Generation (Cross-siteScripting) through Cross-Site Request Forgery (CSRF) vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to impersonate the user who manages the charging station or carry out actions on their behalf when crafted malicious parameters are submitted to the charging station web server. |