Latest CVE Feed
-
9.8
CRITICALCVE-2021-45331
An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for the 2FA can be submitted correctly more than once.... Read more
Affected Products : gitea- EPSS Score: %0.20
- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45092
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.... Read more
Affected Products : thinfinity_virtualui- EPSS Score: %88.00
- Published: Dec. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45330
An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse.... Read more
Affected Products : gitea- EPSS Score: %1.32
- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45327
Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. which could let a remote malisious user execute arbitrary code.... Read more
Affected Products : gitea- EPSS Score: %0.87
- Published: Feb. 08, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45005
Artifex MuJS v1.1.3 was discovered to contain a heap buffer overflow which is caused by conflicting JumpList of nested try/finally statements.... Read more
Affected Products : mujs- EPSS Score: %0.14
- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44908
SailsJS Sails.js <=1.4.0 is vulnerable to Prototype Pollution via controller/load-action-modules.js, function loadActionModules().... Read more
Affected Products : sails- EPSS Score: %0.43
- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44949
glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php.... Read more
Affected Products : glfusion- EPSS Score: %0.32
- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45039
Multiple models of the Uniview IP Camera (e.g., IPC_G6103 B6103.16.10.B25.201218, IPC_G61, IPC21, IPC23, IPC32, IPC36, IPC62, and IPC_HCMN) offer an undocumented UDP service on port 7788 that allows a remote unauthenticated attacker to overflow an interna... Read more
Affected Products : camera_firmware- EPSS Score: %1.37
- Published: May. 31, 2023
- Modified: Jan. 10, 2025
-
9.8
CRITICALCVE-2021-44681
An issue (5 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP serv... Read more
Affected Products : enterprise_vault- EPSS Score: %0.50
- Published: Dec. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44790
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issu... Read more
Affected Products : fedora zfs_storage_appliance_kit debian_linux cloud_backup macos http_server mac_os_x http_server communications_session_report_manager communications_session_route_manager +4 more products- EPSS Score: %86.66
- Published: Dec. 20, 2021
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2021-44610
Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) default_group, and (8) page group parameters in the settings mode in admin/index.... Read more
Affected Products : bloofoxcms- EPSS Score: %0.71
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44685
Git-it through 4.4.0 allows OS command injection at the Branches Aren't Just For Birds challenge step. During the verification process, it attempts to run the reflog command followed by the current branch name (which is not sanitized for execution).... Read more
Affected Products : git-it- EPSS Score: %1.96
- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44676
Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects of the application state.... Read more
Affected Products : manageengine_access_manager_plus- EPSS Score: %6.94
- Published: Dec. 20, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44684
naholyr github-todos 3.1.0 is vulnerable to command injection. The range argument for the _hook subcommand is concatenated without any validation, and is directly used by the exec function.... Read more
Affected Products : github-todos- EPSS Score: %4.43
- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44550
An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159).... Read more
Affected Products : corenlp- EPSS Score: %0.48
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44538
The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of the ch... Read more
- EPSS Score: %1.42
- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44675
Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which authentication is not required.... Read more
Affected Products : manageengine_servicedesk_plus_msp- EPSS Score: %4.28
- Published: Dec. 20, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44663
A Remote Code Execution (RCE) vulnerability exists in the Xerte Project Xerte through 3.8.4 via a crafted php file through elfinder in connetor.php.... Read more
Affected Products : xerte_online_toolkits- EPSS Score: %4.29
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44529
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).... Read more
Affected Products : endpoint_manager_cloud_services_appliance- Actively Exploited
- EPSS Score: %94.46
- Published: Dec. 08, 2021
- Modified: Mar. 13, 2025
-
9.8
CRITICALCVE-2021-44350
SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php.... Read more
Affected Products : thinkphp- EPSS Score: %1.03
- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024