Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2021-03-15 CVE-2020-28149 Cross-site Scripting vulnerability in Mydbr 5.8.3/4262
myDBR 5.8.3/4262 is affected by: Cross Site Scripting (XSS).
network
mydbr CWE-79
6.8
2021-03-15 CVE-2020-24985 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Quadbase Espressdashboard 7.0
An issue was discovered in Quadbase EspressReports ES 7 Update 9.
network
low complexity
quadbase CWE-829
5.5
2021-03-15 CVE-2020-24982 Cross-Site Request Forgery (CSRF) vulnerability in Quadbase Espressdashboard 7.0
An issue was discovered in Quadbase ExpressDashboard (EDAB) 7 Update 9.
network
quadbase CWE-352
4.3
2021-03-15 CVE-2021-27889 Cross-site Scripting vulnerability in Mybb
Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages.
network
mybb CWE-79
4.3
2021-03-15 CVE-2021-27817 Unrestricted Upload of File with Dangerous Type vulnerability in Shopxo 1.9.3
A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which is uploaded after modifying the phar suffix.
network
low complexity
shopxo CWE-434
7.5
2021-03-15 CVE-2021-27695 Cross-site Scripting vulnerability in Openmaint 2.13.3B
Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via any "Add" sections, such as Add Card Building & Floor, or others in the Name and Code Parameters.
network
openmaint CWE-79
4.3
2021-03-15 CVE-2021-27381 Out-of-bounds Read vulnerability in Siemens Solid Edge Se2021
A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP13), Solid Edge SE2021 (All Versions < SE2021MP3).
network
siemens CWE-125
6.8
2021-03-15 CVE-2021-27380 Out-of-bounds Write vulnerability in Siemens Solid Edge Se2020/Se2021
A vulnerability has been identified in Solid Edge SE2020 (All versions < SE2020MP13), Solid Edge SE2021 (All Versions < SE2021MP4).
network
siemens CWE-787
6.8
2021-03-15 CVE-2021-25676 Improper Restriction of Excessive Authentication Attempts vulnerability in Siemens products
A vulnerability has been identified in RUGGEDCOM RM1224 (V6.3), SCALANCE M-800 (V6.3), SCALANCE S615 (V6.3), SCALANCE SC-600 (All Versions >= V2.1 and < V2.1.3).
network
low complexity
siemens CWE-307
5.0
2021-03-15 CVE-2021-25675 Divide By Zero vulnerability in Siemens Simatic S7-Plcsim 5.4
A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 (All versions).
local
low complexity
siemens CWE-369
2.1