CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Netscout
1Ngeniusone
Jun 17, 2026
Sep 30, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
NETSCOUT nGeniusONE 6.3.0 build 1196 and earlier allows Stored Cross-Site Scripting (XSS) in UploadFile.
1Netscout
1Ngeniusone
Jun 17, 2026
Sep 30, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
NETSCOUT nGeniusONE 6.3.0 build 1004 and earlier allows Stored Cross-Site Scripting (XSS) in the Packet Analysis module.
3Debian
FedoraprojectMediawiki
3Debian Linux
FedoraMediawiki
Jun 17, 2026
Jul 2, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot account has a "sitewide block" applied, it is able to still "purge" pages th...Show more
In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot account has a "sitewide block" applied, it is able to still "purge" pages through the MediaWiki Action API (which a "sitewide block" should have prevented).Show less
1Theologeek
1Manuskript
Jun 17, 2026
Jun 21, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Manuskript through 0.12.0 allows remote attackers to execute arbitrary code via a crafted settings.pickle file in a project file, because there is insecure deserialization via the pickle.load() function in settings.py. N...Show more
Manuskript through 0.12.0 allows remote attackers to execute arbitrary code via a crafted settings.pickle file in a project file, because there is insecure deserialization via the pickle.load() function in settings.py. NOTE: the vendor's position is that the product is not intended for opening an untrusted project fileShow less
1Pattersondental
1Eaglesoft
Jun 17, 2026
Jul 30, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Patterson Application Service in Patterson Eaglesoft 18 through 21 accepts the same certificate authentication across different customers' installations (that have the same software version). This provides remote access...Show more
Patterson Application Service in Patterson Eaglesoft 18 through 21 accepts the same certificate authentication across different customers' installations (that have the same software version). This provides remote access to SQL database credentials. (In the normal use of the product, retrieving those credentials only occurs after a username/password authentication step; however, this authentication step is on the client side, and an attacker can develop their own client that skips this step.)Show less
1Meross
1Msg100 Firmware
Jun 17, 2026
Oct 7, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Meross MSG100 devices before 3.2.3 allow an attacker to replay the same data or similar data (e.g., an attacker who sniffs a Close message can transmit an acceptable Open message).
1Connectwise
1Automate
Jun 17, 2026
Jun 21, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.
1Kramerav
1Viaware
Jun 17, 2026
Jul 12, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits running of multiple dangerous commands, including unzip, systemctl and dpkg.
3Debian
FedoraprojectOisf
3Debian Linux
FedoraSuricata
Jun 17, 2026
Jul 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Suricata before 5.0.7 and 6.x before 6.0.3 has a "critical evasion."
1Testzentrum Odw
1Testerfassung
Jun 17, 2026
Aug 30, 2021
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
A Shell Metacharacter Injection vulnerability in result.php in DRK Odenwaldkreis Testerfassung March-2021 allow an attacker with a valid token of a COVID-19 test result to execute shell commands with the permissions of t...Show more
A Shell Metacharacter Injection vulnerability in result.php in DRK Odenwaldkreis Testerfassung March-2021 allow an attacker with a valid token of a COVID-19 test result to execute shell commands with the permissions of the web server.Show less
1Drk Odenwaldkreis
1Testerfassung
Jun 17, 2026
Aug 30, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in DRK Odenwaldkreis Testerfassung March-2021 allow remote attackers to inject arbitrary web script or HTML via all parameters to HTML form fields in all components.
1Openwaygroup
1Way4
Jun 17, 2026
Oct 11, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
/way4acs/enroll in OpenWay WAY4 ACS before 1.2.278-2693 allows unauthenticated attackers to leverage response differences to discover whether a specific payment card number is stored in the system.
1Openwaygroup
1Way4
Jun 17, 2026
Oct 11, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OpenWay WAY4 ACS before 1.2.278-2693 allows XSS via the /way4acs/enroll action parameter.
1Unisys
1Stealth
Jun 17, 2026
Jul 15, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Unisys Stealth 5.1 before 5.1.025.0 and 6.0 before 6.0.055.0 has an unquoted Windows search path for a scheduled task. An unintended executable might run.
1Minecraft
1Minecraft
Jun 17, 2026
Jul 20, 2021
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
Minecraft before 1.17.1, when online-mode=false is configured, allows path traversal for deletion of arbitrary JSON files.
1Fidelissecurity
2Deception
Network
Jun 17, 2026
Jun 25, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
User credentials stored in a recoverable format within Fidelis Network and Deception CommandPost. In the event that an attacker gains access to the CommandPost, these values could be decoded and used to login to the appl...Show more
User credentials stored in a recoverable format within Fidelis Network and Deception CommandPost. In the event that an attacker gains access to the CommandPost, these values could be decoded and used to login to the application. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.3. This vulnerability has been addressed in version 9.3.3 and subsequent versions.Show less
1Fidelissecurity
2Deception
Network
Jun 17, 2026
Jun 25, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could allow a specially crafted HTTP request to execute system commands on t...Show more
Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could allow a specially crafted HTTP request to execute system commands on the CommandPost and return results in an HTTP response in an authenticated session. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.7 and in version 9.4. Patches and updates are available to address this vulnerability.Show less
1Fidelissecurity
2Deception
Network
Jun 17, 2026
Jun 25, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interface. The vulnerability could lead to exposure of authentication tokens in some versions of Fidelis so...Show more
Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interface. The vulnerability could lead to exposure of authentication tokens in some versions of Fidelis software. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.7 and in version 9.4. Patches and updates are available to address this vulnerability.Show less
1Fidelissecurity
2Deception
Network
Jun 17, 2026
Jun 25, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with user level access to the CLI to inject root level commands into the component and neighboring F...Show more
Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with user level access to the CLI to inject root level commands into the component and neighboring Fidelis components. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.7 and in version 9.4. Patches and updates are available to address this vulnerability.Show less
1Icehrm
1Icehrm
Jun 17, 2026
Jun 22, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A session fixation vulnerability was discovered in Ice Hrm 29.0.0 OS which allows an attacker to hijack a valid user session via a crafted session cookie.
1Icehrm
1Icehrm
Jun 17, 2026
Jun 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross site scripting (XSS) vulnerability in Ice Hrm 29.0.0.OS, allows attackers to execute arbitrary code via the parameters to the /app/ endpoint.
3Antisamy Project
NetappOracle
11Active Iq Unified Manager
AntisamyBanking Enterprise Default Management+8 more
Jun 17, 2026
Jul 19, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with &#00058 as the replacement for the : character.
2Djangoproject
Fedoraproject
2Django
Fedora
Jun 17, 2026
Jul 2, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.
1Fisco Bcos
1Fisco Bcos
Jun 17, 2026
Jun 24, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The blockchain node in FISCO-BCOS V2.7.2 may have a bug when dealing with unformatted packet and lead to a crash. A malicious node can send a packet continuously. The packet is in an incorrect format and cannot be decode...Show more
The blockchain node in FISCO-BCOS V2.7.2 may have a bug when dealing with unformatted packet and lead to a crash. A malicious node can send a packet continuously. The packet is in an incorrect format and cannot be decoded by the node correctly. As a result, the node may consume the memory sustainably and crash. More details are shown at: https://github.com/FISCO-BCOS/FISCO-BCOS/issues/1951Show less
2Debian
Linux
2Debian Linux
Linux Kernel
Jun 17, 2026
Jul 7, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
kernel/module.c in the Linux kernel before 5.12.14 mishandles Signature Verification, aka CID-0c18f29aae7c. Without CONFIG_MODULE_SIG, verification that a kernel module is signed, for loading via init_module, does not oc...Show more
kernel/module.c in the Linux kernel before 5.12.14 mishandles Signature Verification, aka CID-0c18f29aae7c. Without CONFIG_MODULE_SIG, verification that a kernel module is signed, for loading via init_module, does not occur for a module.sig_enforce=1 command-line argument.Show less