Latest CVE Feed
-
9.1
CRITICALCVE-2021-46825
Symantec Advanced Secure Gateway (ASG) and ProxySG are susceptible to an HTTP desync vulnerability. When a remote unauthenticated attacker and other web clients communicate through the proxy with the same web server, the attacker can send crafted HTTP req... Read more
- Published: Jul. 07, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-46824
Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Lastname parameter to the Update Account form in student_profile.php.... Read more
Affected Products : school_file_management_system- Published: Jun. 23, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-46823
python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions, because of a regular expression denial of service (ReDoS) flaw in the LDAP schema parser. By sending crafted regex input, a remote aut... Read more
Affected Products : python-ldap- Published: Jun. 18, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-46822
The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This is related to a heap-based buffer overflow in the get_w... Read more
Affected Products : libjpeg-turbo- Published: Jun. 18, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-46820
Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /shop/admin/categories.php... Read more
Affected Products : xos_shop_system- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-46818
Adobe Media Encoder version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this is... Read more
- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-46817
Adobe Media Encoder version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this is... Read more
- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-46816
Adobe Premiere Pro version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this iss... Read more
- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-46814
The video framework has an out-of-bounds memory read/write vulnerability. Successful exploitation of this vulnerability may affect system availability.... Read more
- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-46813
Vulnerability of residual files not being deleted after an update in the ChinaDRM module. Successful exploitation of this vulnerability may affect availability.... Read more
- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-46812
The Device Manager has a vulnerability in multi-device interaction. Successful exploitation of this vulnerability may affect data integrity.... Read more
- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-46811
HwSEServiceAPP has a vulnerability in permission management. Successful exploitation of this vulnerability may cause disclosure of the Card Production Life Cycle (CPLC) information.... Read more
- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-46790
ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions.... Read more
- Published: May. 02, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-46789
Configuration defects in the secure OS module. Successful exploitation of this vulnerability can affect availability.... Read more
- Published: May. 13, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-46788
Third-party pop-up window coverage vulnerability in the iConnect module.Successful exploitation of this vulnerability may cause system pop-up window may be covered to mislead users to perform incorrect operations.... Read more
- Published: May. 13, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-46787
The AMS module has a vulnerability of improper permission control.Successful exploitation of this vulnerability may cause non-system application processes to crash.... Read more
- Published: May. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-46786
The audio module has a vulnerability in verifying the parameters passed by the application space.Successful exploitation of this vulnerability may cause out-of-bounds memory access.... Read more
- Published: May. 13, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-46785
The Property module has a vulnerability in permission control.This vulnerability can be exploited to obtain the unique device identifier.... Read more
- Published: May. 13, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-46784
In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses.... Read more
- Published: Jul. 17, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-46782
The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : price_table- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024