Latest CVE Feed
-
4.8
MEDIUMCVE-2021-4038
Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) prior to 10.1 Minor 7 allows a remote authenticated administrator to embed a XSS in the administrator interface via specially crafted custom rules containing HTML. NSM did n... Read more
Affected Products : network_security_manager- Published: Dec. 09, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-4037
A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in ... Read more
- Published: Aug. 24, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-4035
A stored cross site scripting have been identified at the comments in the report creation due to an obsolote version of tinymce editor. In order to exploit this vulnerability, the attackers needs an account with enough privileges to view and edit reports.... Read more
Affected Products : wocu_monitoring- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-4033
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)... Read more
- Published: Dec. 09, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-4032
A vulnerability was found in the Linux kernel's KVM subsystem in arch/x86/kvm/lapic.c kvm_free_lapic when a failure allocation was detected. In this flaw the KVM subsystem may crash the kernel due to mishandling of memory errors that happens during VCPU c... Read more
Affected Products : linux_kernel- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-4031
Syltek application before its 10.22.00 version, does not correctly check that a product ID has a valid payment associated to it. This could allow an attacker to forge a request and bypass the payment system by marking items as payed without any verificati... Read more
Affected Products : syltek- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-4030
A cross-site request forgery vulnerability in the HTTP daemon of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary commands if they coerce or trick a local user to visit a compromised website with malicious scripts.... Read more
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-4029
A command injection vulnerability in the CGI program of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary OS commands via a LAN interface.... Read more
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-4028
A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an attacker with local access to setup a socket to listen on a high port allowing for a list element to be used after free. Given the ability to execute code,... Read more
- Published: Aug. 24, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-4026
bookstack is vulnerable to Improper Access Control... Read more
Affected Products : bookstack- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-4024
A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the... Read more
- Published: Dec. 23, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-4023
A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. The kernel can panic when an improper cancellation operation triggers the submission of new io-uring operations during a shortage of free space. This flaw ... Read more
- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-4022
A vulnerability was found in rizin. The bug involves an ELF64 binary for the HPPA architecture. When a specially crafted binarygets analysed by rizin, it causes rizin to crash by freeing an uninitialized (and potentially user controlled, depending on the ... Read more
Affected Products : rizin- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-4021
A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 and 5.5.2. Mapping a huge section filled with zeros of an ELF64 binary for MIPS architecture can lead to uncontrolled resource consumption and DoS.... Read more
Affected Products : radare2- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-4020
janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
Affected Products : janus- Published: Nov. 27, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGH- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2021-4018
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
Affected Products : snipe-it- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-4017
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)... Read more
Affected Products : showdoc- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2021-4016
Rapid7 Insight Agent, versions prior to 3.1.3, suffer from an improper access control vulnerability whereby, the user has access to the snapshot directory. An attacker can access, read and copy any of the files in this directory e.g. asset_info.json or fi... Read more
Affected Products : insight_agent- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-4015
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)... Read more
Affected Products : firefly_iii- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024