Headline
CVE-2021-37412:
The TechRadar app 1.1 for Confluence Server allows XSS via the Title field of a Radar.
Related news
CVE-2021-36512: SynchroNet | Maximize Your Team's Productivity. Everywhere.
An issue was discovered in function scanallsubs in src/sbbs3/scansubs.cpp in Synchronet BBS, which may allow attackers to view sensitive information due to an uninitialized value.
CVE-2021-38613: Nascent RemKon Multiple CVEs
The assets/index.php Image Upload feature of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to upload any code to the target system and achieve remote code execution.
CVE-2021-34824: Istio / ISTIO-SECURITY-2021-007
Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.