Latest CVE Feed
-
5.5
MEDIUMCVE-2021-4142
The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.... Read more
Affected Products : candlepin- Published: Aug. 24, 2022
- Modified: Nov. 21, 2024
-
9.0
CRITICALCVE-2021-4139
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
Affected Products : pimcore- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-4138
Improved Host header checks to reject requests not sent to a well-known local hostname or IP, or the server-specified hostname.... Read more
Affected Products : geckodriver- Published: May. 02, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-4136
vim is vulnerable to Heap-based Buffer Overflow... Read more
- Published: Dec. 19, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-4135
A memory leak vulnerability was found in the Linux kernel's eBPF for the Simulated networking device driver in the way user uses BPF for the device such that function nsim_map_alloc_elem being called. A local user could use this flaw to get unauthorized a... Read more
Affected Products : linux_kernel- Published: Jul. 14, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-4134
The Fancy Product Designer WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the ID parameter found in the ~/inc/api/class-view.php file which allows attackers with administrative level permissions to inj... Read more
Affected Products : fancy_product_designer- Published: Feb. 16, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-4133
A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default user accounts via the administrative REST API even when new user registration is disabled.... Read more
- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2021-4132
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGH- Published: Dec. 18, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-4130
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)... Read more
Affected Products : snipe-it- Published: Dec. 18, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-4125
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images,... Read more
Affected Products : openshift- Published: Aug. 24, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-4124
janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
Affected Products : janus- Published: Dec. 16, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUM- Published: Dec. 16, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-4122
It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this flaw to force a user into permanentl... Read more
Affected Products : cryptsetup- Published: Aug. 24, 2022
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2021-4121
yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
- Published: Dec. 16, 2021
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2021-4120
snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability for snaps to inject arbitrary AppArmor policy rules via malformed content interface and layout declarations and hence escape strict sn... Read more
- Published: Feb. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-4119
bookstack is vulnerable to Improper Access Control... Read more
Affected Products : bookstack- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGH- Published: Dec. 23, 2021
- Modified: Nov. 21, 2024
-
7.7
HIGHCVE-2021-4117
yetiforcecrm is vulnerable to Business Logic Errors... Read more
Affected Products : yetiforce_customer_relationship_management- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
6.6
MEDIUMCVE-2021-4116
yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024