The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, misconfigurations, product names, and impact metrics.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2021-20109 - Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a lis... read CVE-2021-20109
    Published: July 19, 2021; 11:15:07 AM -0400

    V3.1: 7.5 HIGH
    V2.0: 5.0 MEDIUM

  • CVE-2021-24482 - The Related Posts for WordPress plugin through 2.0.4 does not sanitise its heading_text and CSS settings, allowing high privilege users (admin) to set XSS payloads in them, leading to Stored Cross-Site Scripting issues.
    Published: July 19, 2021; 7:15:08 AM -0400

    V3.1: 4.8 MEDIUM
    V2.0: 3.5 LOW

  • CVE-2021-24436 - The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulnerability within the "extension" parameter in the Extensions dashboard, which is output in an attribute without being escaped fi... read CVE-2021-24436
    Published: July 19, 2021; 7:15:08 AM -0400

    V3.1: 6.1 MEDIUM
    V2.0: 4.3 MEDIUM

  • CVE-2021-24447 - The WP Image Zoom WordPress plugin before 1.47 did not validate its tab parameter before using it in the include_once() function, leading to a local file inclusion issue in the admin dashboard
    Published: July 19, 2021; 7:15:08 AM -0400

    V3.1: 5.3 MEDIUM
    V2.0: 5.0 MEDIUM

  • CVE-2021-24452 - The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extension" parameter in the Extensions dashboard, when the 'Anonymously track usage to improve product quality' setting is en... read CVE-2021-24452
    Published: July 19, 2021; 7:15:08 AM -0400

    V3.1: 6.1 MEDIUM
    V2.0: 4.3 MEDIUM

  • CVE-2021-24453 - The Include Me WordPress plugin through 1.2.1 is vulnerable to path traversal / local file inclusion, which can lead to Remote Code Execution (RCE) of the system due to log poisoning and therefore potentially a full compromise of the underlying st... read CVE-2021-24453
    Published: July 19, 2021; 7:15:08 AM -0400

    V3.1: 8.8 HIGH
    V2.0: 9.0 HIGH

  • CVE-2021-32574 - HashiCorp Consul and Consul Enterprise 1.3.0 through 1.10.0 Envoy proxy TLS configuration does not validate destination service identity in the encoded subject alternative name. Fixed in 1.8.14, 1.9.8, and 1.10.1.
    Published: July 17, 2021; 2:15:07 PM -0400

    V3.1: 7.5 HIGH
    V2.0: 5.0 MEDIUM

  • CVE-2021-20108 - Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Server. The HTTPS certificates are not verified which allows any arbitrary user on the network to send commands over port 9000. Whil... read CVE-2021-20108
    Published: July 19, 2021; 11:15:07 AM -0400

    V3.1: 7.5 HIGH
    V2.0: 5.0 MEDIUM

  • CVE-2021-35966 - The specific function of the Orca HCM digital learning platform does not filter input parameters properly, which causing the URL can be redirected to any website. Remote attackers can use the vulnerability to execute phishing attacks.
    Published: July 19, 2021; 8:15:08 AM -0400

    V3.1: 6.1 MEDIUM
    V2.0: 5.8 MEDIUM

  • CVE-2021-35964 - The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remote attackers to execute the management function without logging in, access members’ information, modify and delete the courses i... read CVE-2021-35964
    Published: July 19, 2021; 8:15:08 AM -0400

    V3.1: 9.8 CRITICAL
    V2.0: 7.5 HIGH

  • CVE-2019-3752 - Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1, 2.2, 2.3 and 2.4. contain an XML External Entity(XXE) Injection vulnerability. A remote unauthenticated ... read CVE-2019-3752
    Published: July 16, 2021; 6:15:07 PM -0400

    V3.1: 8.2 HIGH
    V2.0: 6.4 MEDIUM

  • CVE-2020-12734 - DEPSTECH WiFi Digital Microscope 3 allows remote attackers to change the SSID and password, and demand a ransom payment from the rightful device owner, because there is no way to reset to Factory Default settings.
    Published: July 15, 2021; 12:15:09 PM -0400

    V3.1: 8.1 HIGH
    V2.0: 4.8 MEDIUM

  • CVE-2020-12732 - DEPSTECH WiFi Digital Microscope 3 has a default SSID of Jetion_xxxxxxxx with a password of 12345678.
    Published: July 15, 2021; 12:15:09 PM -0400

    V3.1: 6.5 MEDIUM
    V2.0: 3.3 LOW

  • CVE-2021-34691 - iDrive RemotePC before 4.0.1 on Linux allows denial of service. A remote and unauthenticated attacker can disconnect a valid user session by connecting to an ephemeral port.
    Published: July 15, 2021; 10:15:21 AM -0400

    V3.1: 7.5 HIGH
    V2.0: 5.0 MEDIUM

  • CVE-2020-15495 - Acronis True Image 2019 update 1 through 2020 on macOS allows local privilege escalation due to an insecure XPC service configuration.
    Published: July 15, 2021; 11:15:08 AM -0400

    V3.1: 7.8 HIGH
    V2.0: 4.6 MEDIUM

  • CVE-2020-25593 - Acronis True Image through 2021 on macOS allows local privilege escalation from admin to root due to insecure folder permissions.
    Published: July 15, 2021; 11:15:08 AM -0400

    V3.1: 6.7 MEDIUM
    V2.0: 7.2 HIGH

  • CVE-2020-25736 - Acronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC service configuration.
    Published: July 15, 2021; 11:15:08 AM -0400

    V3.1: 7.8 HIGH
    V2.0: 4.6 MEDIUM

  • CVE-2021-27845 - A Divide-by-zero vulnerability exists in JasPer Image Coding Toolkit 2.0 in jasper/src/libjasper/jpc/jpc_enc.c
    Published: July 15, 2021; 12:15:09 PM -0400

    V3.1: 5.5 MEDIUM
    V2.0: 4.3 MEDIUM

  • CVE-2020-12730 - MagicMotion Flamingo 2 lacks BLE encryption, enabling data sniffing and packet forgery.
    Published: July 15, 2021; 11:15:08 AM -0400

    V3.1: 5.3 MEDIUM
    V2.0: 2.9 LOW

  • CVE-2021-27847 - Division-By-Zero vulnerability in Libvips 8.10.5 in the function vips_eye_point, eye.c#L83, and function vips_mask_point, mask.c#L85.
    Published: July 15, 2021; 12:15:09 PM -0400

    V3.1: 6.5 MEDIUM
    V2.0: 4.3 MEDIUM