Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.5

    MEDIUM
    CVE-2021-4145

    A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in mirror_wait_on_conflicts() without ensuring that it's not NULL. A malicious unprivileged user within the guest c... Read more

    Affected Products : enterprise_linux qemu
    • Published: Jan. 25, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-4144

    TP-Link wifi router TL-WR802N V4(JP), with firmware version prior to 211202, is vulnerable to OS command injection.... Read more

    Affected Products : tl-wr802n_firmware tl-wr802n
    • Published: Dec. 23, 2021
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2021-4143

    Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0.... Read more

    Affected Products : bigbluebutton
    • Published: Jan. 19, 2022
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2021-4142

    The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.... Read more

    Affected Products : candlepin
    • Published: Aug. 24, 2022
    • Modified: Nov. 21, 2024
  • 9.0

    CRITICAL
    CVE-2021-4139

    pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more

    Affected Products : pimcore
    • Published: Dec. 21, 2021
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-4138

    Improved Host header checks to reject requests not sent to a well-known local hostname or IP, or the server-specified hostname.... Read more

    Affected Products : geckodriver
    • Published: May. 02, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-4136

    vim is vulnerable to Heap-based Buffer Overflow... Read more

    Affected Products : fedora vim macos mac_os_x
    • Published: Dec. 19, 2021
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2021-4135

    A memory leak vulnerability was found in the Linux kernel's eBPF for the Simulated networking device driver in the way user uses BPF for the device such that function nsim_map_alloc_elem being called. A local user could use this flaw to get unauthorized a... Read more

    Affected Products : linux_kernel
    • Published: Jul. 14, 2022
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-4134

    The Fancy Product Designer WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the ID parameter found in the ~/inc/api/class-view.php file which allows attackers with administrative level permissions to inj... Read more

    Affected Products : fancy_product_designer
    • Published: Feb. 16, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-4133

    A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default user accounts via the administrative REST API even when new user registration is disabled.... Read more

    • Published: Jan. 25, 2022
    • Modified: Nov. 21, 2024
  • 7.3

    HIGH
    CVE-2021-4132

    livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more

    Affected Products : live_helper_chat livehelperchat
    • Published: Dec. 17, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-4131

    livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)... Read more

    Affected Products : live_helper_chat livehelperchat
    • Published: Dec. 18, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-4130

    snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)... Read more

    Affected Products : snipe-it
    • Published: Dec. 18, 2021
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2021-4125

    It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images,... Read more

    Affected Products : openshift
    • Published: Aug. 24, 2022
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2021-4124

    janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more

    Affected Products : janus
    • Published: Dec. 16, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-4123

    livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)... Read more

    Affected Products : live_helper_chat livehelperchat
    • Published: Dec. 16, 2021
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2021-4122

    It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this flaw to force a user into permanentl... Read more

    Affected Products : cryptsetup
    • Published: Aug. 24, 2022
    • Modified: Nov. 21, 2024
  • 6.4

    MEDIUM
    CVE-2021-4121

    yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more

    • Published: Dec. 16, 2021
    • Modified: Nov. 21, 2024
  • 8.2

    HIGH
    CVE-2021-4120

    snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability for snaps to inject arbitrary AppArmor policy rules via malformed content interface and layout declarations and hence escape strict sn... Read more

    Affected Products : ubuntu_linux fedora snapd
    • Published: Feb. 17, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-4119

    bookstack is vulnerable to Improper Access Control... Read more

    Affected Products : bookstack
    • Published: Dec. 15, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 294514 Results