Latest CVE Feed
-
6.5
MEDIUM- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-4048
An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using ... Read more
Affected Products : enterprise_linux fedora ceph_storage openshift_container_storage lapack openblas julia openshift_data_foundation- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-4047
The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only affects Red Hat OpenShift 4.9.... Read more
- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-4046
The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks. This vulnerability could be used to carry out a number of browser-based attacks including browser hijacking or theft of sensitive data.... Read more
Affected Products : gim- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-4045
TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root. The exploitation of this vulnerability allows an attacker to take full con... Read more
- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-4044
Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (for example out of memory). Such a negative return value... Read more
Affected Products : h410c_firmware ontap_select_deploy_administration_utility cloud_backup snapcenter openssl h300s_firmware h500s_firmware h700s_firmware h410s_firmware node.js +16 more products- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
5.8
MEDIUM- Actively Exploited
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-4041
A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to parameters getting executed as host's shell command. A developer could unintentionally write code that gets ... Read more
Affected Products : ansible_runner- Published: Aug. 24, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-4040
A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. This flaw allows an attacker to partially disrupt availability to the broker through a sustained attack of ... Read more
- Published: Aug. 24, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-4039
A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on the device.... Read more
- Published: Mar. 01, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-4038
Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) prior to 10.1 Minor 7 allows a remote authenticated administrator to embed a XSS in the administrator interface via specially crafted custom rules containing HTML. NSM did n... Read more
Affected Products : network_security_manager- Published: Dec. 09, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-4037
A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in ... Read more
- Published: Aug. 24, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-4035
A stored cross site scripting have been identified at the comments in the report creation due to an obsolote version of tinymce editor. In order to exploit this vulnerability, the attackers needs an account with enough privileges to view and edit reports.... Read more
Affected Products : wocu_monitoring- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-4033
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)... Read more
- Published: Dec. 09, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-4032
A vulnerability was found in the Linux kernel's KVM subsystem in arch/x86/kvm/lapic.c kvm_free_lapic when a failure allocation was detected. In this flaw the KVM subsystem may crash the kernel due to mishandling of memory errors that happens during VCPU c... Read more
Affected Products : linux_kernel- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-4031
Syltek application before its 10.22.00 version, does not correctly check that a product ID has a valid payment associated to it. This could allow an attacker to forge a request and bypass the payment system by marking items as payed without any verificati... Read more
Affected Products : syltek- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-4030
A cross-site request forgery vulnerability in the HTTP daemon of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary commands if they coerce or trick a local user to visit a compromised website with malicious scripts.... Read more
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-4029
A command injection vulnerability in the CGI program of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary OS commands via a LAN interface.... Read more
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-4028
A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an attacker with local access to setup a socket to listen on a high port allowing for a list element to be used after free. Given the ability to execute code,... Read more
- Published: Aug. 24, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-4026
bookstack is vulnerable to Improper Access Control... Read more
Affected Products : bookstack- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024