Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.8

    HIGH
    CVE-2021-42850

    A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access.... Read more

    • Published: May. 18, 2022
    • Modified: Nov. 21, 2024
  • 6.8

    MEDIUM
    CVE-2021-42849

    A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access.... Read more

    • Published: May. 18, 2022
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-42848

    An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrieve device and networking details.... Read more

    • Published: May. 18, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-42847

    Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files.... Read more

    Affected Products : manageengine_adaudit_plus
    • Published: Nov. 11, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-42841

    Insta HMS before 12.4.10 is vulnerable to XSS because of improper validation of user-supplied input by multiple scripts. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security c... Read more

    Affected Products : insta_hms
    • Published: Jan. 06, 2022
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2021-42840

    SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only t... Read more

    Affected Products : suitecrm
    • Published: Oct. 22, 2021
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2021-42839

    Grand Vice info Co. webopac7 file upload function fails to filter special characters. While logging in with general user’s permission, remote attackers can upload malicious script and execute arbitrary code to control the system or interrupt services.... Read more

    Affected Products : webopac
    • Published: Nov. 15, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-42838

    Grand Vice info Co. webopac7 book search field parameter does not properly restrict the input of special characters, thus unauthenticated attackers can inject JavaScript syntax remotely, and further perform reflective XSS attacks.... Read more

    Affected Products : webopac
    • Published: Nov. 15, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-42837

    An issue was discovered in Talend Data Catalog before 7.3-20210930. After setting up SAML/OAuth, authentication is not correctly enforced on the native login page. Any valid user from the SAML/OAuth provider can be used as the username with an arbitrary p... Read more

    Affected Products : data_catalog
    • Published: Nov. 05, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-42836

    GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.... Read more

    Affected Products : gjson
    • Published: Oct. 22, 2021
    • Modified: Nov. 21, 2024
  • 7.0

    HIGH
    CVE-2021-42835

    An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee. An attacker (with a foothold in a endpoint via a low-privileged user account) can access the exposed RPC service of the update service component. This RPC functionality allows the... Read more

    Affected Products : windows media_server plex_media_server
    • Published: Dec. 08, 2021
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2021-42833

    A Use of Hardcoded Credentials vulnerability exists in AquaView versions 1.60, 7.x, and 8.x that could allow an authenticated local attacker to manipulate users and system settings.... Read more

    Affected Products : aquaview
    • Published: Feb. 07, 2022
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-42811

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SafeNet KeySecure allows an authenticated user to read arbitrary files from the underlying system on which the product is deployed.... Read more

    Affected Products : safenet_keysecure
    • Published: Jun. 10, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-42810

    A flaw in the previous versions of the product may allow an authenticated attacker the ability to execute code as a privileged user on a system where the agent is installed.... Read more

    • Published: Jan. 19, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-42809

    Improper Access Control of Dynamically-Managed Code Resources (DLL) in Thales Sentinel Protection Installer could allow the execution of arbitrary code.... Read more

    • Published: Dec. 20, 2021
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-42808

    Improper Access Control in Thales Sentinel Protection Installer could allow a local user to escalate privileges.... Read more

    • Published: Dec. 20, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-42797

    Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access token of the user account configured for accessing external DB resources.... Read more

    Affected Products : aveva_edge edge
    • Published: Dec. 16, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-42796

    An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticated arbitrary commands to be executed.... Read more

    Affected Products : aveva_edge edge
    • Published: Dec. 16, 2023
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-42794

    An issue was discovered in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior. The application allows a client to provide a malicious connection string that could allow an adversary to port scan the LAN, depending on the hosts' responses.... Read more

    Affected Products : aveva_edge edge
    • Published: Dec. 16, 2023
    • Modified: Nov. 21, 2024
  • 7.3

    HIGH
    CVE-2021-42791

    An issue was discovered in VeridiumID VeridiumAD 2.5.3.0. The HTTP request to trigger push notifications for VeridiumAD enrolled users does not enforce proper access control. A user can trigger push notifications for any other user. The text contained in ... Read more

    Affected Products : veridiumad
    • Published: Jan. 28, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 293521 Results