Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In November 2021
Couchbase Server before 6.6.3 and 7.x before 7.0.2 stores Sensitive Information in Cleartext. The issue occurs when the cluster manager forwards a HTTP request from the pluggable UI (query workbench etc) to the specific service. In the backtrace, the Basic Auth Header included in the HTTP request, has the "@" user credentials of the node processing the UI request.
CVSS Score
7.5
EPSS Score
0.002
Published
2021-11-02
An issue was discovered in Nsasoft US LLC SpotAuditor 5.3.5. The program can be crashed by entering 300 bytes char data into the "Key" or "Name" field while registering.
CVSS Score
7.5
EPSS Score
0.007
Published
2021-11-02
Cross Site Scripting (XSS) vulnerability in DynPG 4.9.1, allows authenticated attackers to execute arbitrary code via the groupname.
CVSS Score
5.4
EPSS Score
0.002
Published
2021-11-02
Cross Site Scripting (XSS) vulnerability in ElkarBackup 1.3.3, allows attackers to execute arbitrary code via the name parameter to the add client feature.
CVSS Score
6.1
EPSS Score
0.006
Published
2021-11-02
Missing output sanitization in test sources in org.webjars.bowergithub.vaadin:vaadin-menu-bar versions 1.0.0 through 1.2.0 (Vaadin 14.0.0 through 14.4.4) allows remote attackers to execute malicious JavaScript in browser by opening crafted URL
CVSS Score
6.1
EPSS Score
0.003
Published
2021-11-02
Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to account takeover of the admin.
CVSS Score
9.8
EPSS Score
0.001
Published
2021-11-02
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even when the admin does not allow. This happens due to front-end restriction only.
CVSS Score
6.5
EPSS Score
0.002
Published
2021-11-02
Whale browser for iOS before 1.14.0 has an inconsistent user interface issue that allows an attacker to obfuscate the address bar which may lead to address bar spoofing.
CVSS Score
5.3
EPSS Score
0.002
Published
2021-11-02
validator.js is vulnerable to Inefficient Regular Expression Complexity
CVSS Score
5.3
EPSS Score
0.001
Published
2021-11-02
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Associated Projects feature (/secure/admin/AssociatedProjectsForCustomField.jspa). The affected versions are before version 8.5.19, from version 8.6.0 before 8.13.11, and from version 8.14.0 before 8.19.1.
CVSS Score
6.1
EPSS Score
0.004
Published
2021-11-01


Contact Us

Shodan ® - All rights reserved