CVE-2021-35227

CVSS v3 Score
7.8
High
CVSS v2 Score
4.6
Medium

Vulnerability Description

The HTTP interface was enabled for RabbitMQ Plugin in ARM 2020.2.6 and the ability to configure HTTPS was not available.

CVSS:7.8(High)

Certain NETGEAR devices are affected by stored XSS. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F be...

CWE-792017
CVSS:7.8(High)

A vulnerability has been identified in SCALANCE M875 (All versions). An attacker with access to the local file system might obtain passwords for administrative users. Successful exploitation requires ...

CWE-792018
CVSS:7.8(High)

Stored XSS in InterMind iMind Server through 3.13.65 allows any user to hijack another user's session by sending a malicious file in the chat.

CWE-792020
CVSS:7.8(High)

xArrow SCADA versions 7.2 and prior permits unvalidated registry keys to be run with application-level privileges.

CWE-792021
CVSS:7.8(High)

A stored cross-site scripting (XSS) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.6. The vulnerability occurs when a user uploads an SVG file containing a malici...

CWE-792021
CVSS:7.8(High)

Cross-site scripting in the Intel(R) EMA software before version 1.8.0 may allow a privileged user to potentially enable escalation of privilege via local access.

CWE-792022