Latest CVE Feed
-
10.0
HIGHCVE-2021-45733
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function NTPSyncWithHost. This vulnerability allows attackers to execute arbitrary commands via the parameter host_time.... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-45732
Netgear Nighthawk R6700 version 1.0.4.120 makes use of a hardcoded credential. It does not appear that normal users are intended to be able to manipulate configuration backups due to the fact that they are encrypted/obfuscated. By extracting the configura... Read more
- Published: Dec. 30, 2021
- Modified: Nov. 21, 2024
-
6.0
MEDIUMCVE-2021-45730
JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for Platform Administrators.... Read more
Affected Products : artifactory- Published: May. 19, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45729
The Privilege Escalation vulnerability discovered in the WP Google Map WordPress plugin (versions <= 1.8.0) allows authenticated low-role users to create, edit, and delete maps.... Read more
Affected Products : wp_google_map- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-45721
JFrog Artifactory prior to version 7.29.8 and 6.23.38 is vulnerable to Reflected Cross-Site Scripting (XSS) through one of the XHR parameters in Users REST API endpoint. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.36.1 ... Read more
Affected Products : artifactory- Published: Jul. 06, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45720
An issue was discovered in the lru crate before 0.7.1 for Rust. The iterators have a use-after-free, as demonstrated by an access after a pop operation.... Read more
Affected Products : lru- Published: Dec. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45719
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. update_hook has a use-after-free.... Read more
Affected Products : rusqlite- Published: Dec. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45718
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. rollback_hook has a use-after-free.... Read more
Affected Products : rusqlite- Published: Dec. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45717
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. commit_hook has a use-after-free.... Read more
Affected Products : rusqlite- Published: Dec. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45716
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_collation has a use-after-free.... Read more
Affected Products : rusqlite- Published: Dec. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45715
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_window_function has a use-after-free.... Read more
Affected Products : rusqlite- Published: Dec. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45714
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_aggregate_function has a use-after-free.... Read more
Affected Products : rusqlite- Published: Dec. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45713
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_scalar_function has a use-after-free.... Read more
Affected Products : rusqlite- Published: Dec. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45712
An issue was discovered in the rust-embed crate before 6.3.0 for Rust. A ../ directory traversal can sometimes occur in debug mode.... Read more
Affected Products : rust-embed- Published: Dec. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45711
An issue was discovered in the simple_asn1 crate 0.6.0 before 0.6.1 for Rust. There is a panic if UTCTime data, supplied by a remote attacker, has a second character greater than 0x7f.... Read more
Affected Products : simple_asn1- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-45710
An issue was discovered in the tokio crate before 1.8.4, and 1.9.x through 1.13.x before 1.13.1, for Rust. In certain circumstances involving a closed oneshot channel, there is a data race and memory corruption.... Read more
Affected Products : tokio- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45709
An issue was discovered in the crypto2 crate through 2021-10-08 for Rust. During Chacha20 encryption and decryption, an unaligned read of a u32 may occur.... Read more
Affected Products : crypto2- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45708
An issue was discovered in the abomonation crate through 2021-10-17 for Rust. Because transmute operations are insufficiently constrained, there can be an information leak or ASLR bypass.... Read more
Affected Products : abomonation- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45707
An issue was discovered in the nix crate 0.16.0 and later before 0.20.2, 0.21.x before 0.21.2, and 0.22.x before 0.22.2 for Rust. unistd::getgrouplist has an out-of-bounds write if a user is in more than 16 /etc/groups groups.... Read more
Affected Products : nix- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45706
An issue was discovered in the zeroize_derive crate before 1.1.1 for Rust. Dropped memory is not zeroed out for an enum.... Read more
Affected Products : zeroize_derive- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024