Latest CVE Feed
-
6.5
MEDIUMCVE-2021-46823
python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions, because of a regular expression denial of service (ReDoS) flaw in the LDAP schema parser. By sending crafted regex input, a remote aut... Read more
Affected Products : python-ldap- Published: Jun. 18, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-46822
The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This is related to a heap-based buffer overflow in the get_w... Read more
Affected Products : libjpeg-turbo- Published: Jun. 18, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-46820
Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /shop/admin/categories.php... Read more
Affected Products : xos_shop_system- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-46818
Adobe Media Encoder version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this is... Read more
- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-46817
Adobe Media Encoder version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this is... Read more
- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-46816
Adobe Premiere Pro version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this iss... Read more
- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-46814
The video framework has an out-of-bounds memory read/write vulnerability. Successful exploitation of this vulnerability may affect system availability.... Read more
- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-46813
Vulnerability of residual files not being deleted after an update in the ChinaDRM module. Successful exploitation of this vulnerability may affect availability.... Read more
- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-46812
The Device Manager has a vulnerability in multi-device interaction. Successful exploitation of this vulnerability may affect data integrity.... Read more
- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-46811
HwSEServiceAPP has a vulnerability in permission management. Successful exploitation of this vulnerability may cause disclosure of the Card Production Life Cycle (CPLC) information.... Read more
- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-46790
ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions.... Read more
- Published: May. 02, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-46789
Configuration defects in the secure OS module. Successful exploitation of this vulnerability can affect availability.... Read more
- Published: May. 13, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-46788
Third-party pop-up window coverage vulnerability in the iConnect module.Successful exploitation of this vulnerability may cause system pop-up window may be covered to mislead users to perform incorrect operations.... Read more
- Published: May. 13, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-46787
The AMS module has a vulnerability of improper permission control.Successful exploitation of this vulnerability may cause non-system application processes to crash.... Read more
- Published: May. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-46786
The audio module has a vulnerability in verifying the parameters passed by the application space.Successful exploitation of this vulnerability may cause out-of-bounds memory access.... Read more
- Published: May. 13, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-46785
The Property module has a vulnerability in permission control.This vulnerability can be exploited to obtain the unique device identifier.... Read more
- Published: May. 13, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-46784
In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses.... Read more
- Published: Jul. 17, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-46782
The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : price_table- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-46781
The Coming Soon by Supsystic WordPress plugin before 1.7.6 does not sanitise and escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : coming_soon- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-46780
The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : easy_google_maps- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024