Latest CVE Feed
-
5.5
MEDIUMCVE-2022-0019
An insufficiently protected credentials vulnerability exists in the Palo Alto Networks GlobalProtect app on Linux that exposes the hashed credentials of GlobalProtect users that saved their password during previous GlobalProtect app sessions to other loca... Read more
- Published: Feb. 10, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-0018
An information exposure vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows and MacOS where the credentials of the local user account are sent to the GlobalProtect portal when the Single Sign-On feature is enabled in the GlobalProt... Read more
- Published: Feb. 10, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-0017
An improper link resolution before file access ('link following') vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that enables a local attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM priv... Read more
- Published: Feb. 10, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-0016
An improper handling of exceptional conditions vulnerability exists within the Connect Before Logon feature of the Palo Alto Networks GlobalProtect app that enables a local attacker to escalate to SYSTEM or root privileges when authenticating with Connect... Read more
- Published: Feb. 10, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-0015
A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authenticated local user to execute programs with elevated privileges. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex ... Read more
Affected Products : cortex_xdr_agent- Published: Jan. 12, 2022
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2022-0014
An untrusted search path vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker with file creation privilege in the Windows root directory (such as C:\) to store a program that can then be unintentionally executed by... Read more
- Published: Jan. 12, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0013
A file information exposure vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker to read the contents of arbitrary files on the system with elevated privileges when generating a support file. This issue impacts: Co... Read more
- Published: Jan. 12, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2022-0012
An improper link resolution before file access vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables a local user to delete arbitrary system files and impact the system integrity or cause a denial of service con... Read more
- Published: Jan. 12, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-0011
PAN-OS software provides options to exclude specific websites from URL category enforcement and those websites are blocked or allowed (depending on your rules) regardless of their associated URL category. This is done by creating a custom URL category lis... Read more
- Published: Feb. 10, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-0010
Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering Tools. An attacker, who already has local access to the QCS nodes, could successfully obtain the password for a system user account.... Read more
Affected Products : platform_engineering_tools qcs_800xa_firmware qcs_ac450_firmware qcs_800xa qcs_ac450- Published: May. 22, 2023
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-4439
In the Linux kernel, the following vulnerability has been resolved: isdn: cpai: check ctr->cnr to avoid array index out of bound The cmtp_add_connection() would add a cmtp session to a controller and run a kernel thread to process cmtp. __module_get(T... Read more
Affected Products : linux_kernel- Published: Jun. 20, 2024
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-4437
A vulnerability, which was classified as problematic, has been found in dbartholomae lambda-middleware frameguard up to 1.0.4. Affected by this issue is some unknown functionality of the file packages/json-deserializer/src/JsonDeserializer.ts of the compo... Read more
Affected Products : lambda-middleware- Published: Feb. 12, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-4436
The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJAX action , allowing unauthenticated users to upload arbitrary file to the web server. However, there is a... Read more
Affected Products : 3dprint_lite- Published: Feb. 05, 2024
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-4435
An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be executed in unexpected ways.... Read more
Affected Products : yarn- Published: Feb. 04, 2024
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-4434
The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url' parameter. This allows attackers to execute code on the server.... Read more
Affected Products : social_warfare- Published: Jan. 17, 2024
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-4433
A vulnerability was found in Karjasoft Sami HTTP Server 2.0. It has been classified as problematic. Affected is an unknown function of the component HTTP HEAD Rrequest Handler. The manipulation leads to denial of service. It is possible to launch the atta... Read more
Affected Products : sami_http_server- Published: Jan. 18, 2024
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-4432
A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as problematic. This affects an unknown part of the component USER Command Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. Th... Read more
- Published: Jan. 16, 2024
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-4431
A vulnerability classified as problematic has been found in msyk FMDataAPI up to 22. Affected is an unknown function of the file FMDataAPI_Sample.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading ... Read more
Affected Products : fmdataapi- Published: Nov. 07, 2023
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-4430
A vulnerability classified as problematic has been found in Ortus Solutions ColdBox Elixir 3.1.6. This affects an unknown part of the file src/defaultConfig.js of the component ENV Variable Handler. The manipulation leads to information disclosure. Upgrad... Read more
Affected Products : coldbox_elixir- Published: Nov. 06, 2023
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-4428
A vulnerability has been found in what3words Autosuggest Plugin up to 4.0.0 on WordPress and classified as problematic. Affected by this vulnerability is the function enqueue_scripts of the file w3w-autosuggest/public/class-w3w-autosuggest-public.php of t... Read more
Affected Products : autosuggest- Published: Jul. 18, 2023
- Modified: Nov. 21, 2024