Latest CVE Feed
-
7.8
HIGHCVE-2021-42855
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) uses the ".debug_command.config" file to store a json string that contains a list of IDs and pre-configured commands. The config file is subsequently used by the "/api/appIn... Read more
Affected Products : steelcentral_appinternals_dynamic_sampling_agent- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42854
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) PluginServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/plugin/pmx" API. The affected endpoint does not have any input validation of the user's... Read more
Affected Products : steelcentral_appinternals_dynamic_sampling_agent- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42853
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDiagnosticServlet has directory traversal vulnerability at the "/api/appInternals/1.0/agent/diagnostic/logs" API. The affected endpoint does not have any input valida... Read more
Affected Products : steelcentral_appinternals_dynamic_sampling_agent- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2021-42852
A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execute operating system commands by sending a crafted packet to the device.... Read more
Affected Products : a1_firmware t1_firmware x1_firmware t2_firmware t2pro_firmware a1 t1 x1 t2 t2pro- Published: May. 18, 2022
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2021-42851
A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to create a standard user account.... Read more
Affected Products : a1_firmware t1_firmware x1_firmware t2_firmware t2pro_firmware a1 t1 x1 t2 t2pro- Published: May. 18, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-42850
A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access.... Read more
Affected Products : a1_firmware t1_firmware x1_firmware t2_firmware t2pro_firmware a1 t1 x1 t2 t2pro- Published: May. 18, 2022
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-42849
A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access.... Read more
Affected Products : a1_firmware t1_firmware x1_firmware t2_firmware t2pro_firmware a1 t1 x1 t2 t2pro- Published: May. 18, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-42848
An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrieve device and networking details.... Read more
Affected Products : a1_firmware t1_firmware x1_firmware t2_firmware t2pro_firmware a1 t1 x1 t2 t2pro- Published: May. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42847
Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files.... Read more
Affected Products : manageengine_adaudit_plus- Published: Nov. 11, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-42841
Insta HMS before 12.4.10 is vulnerable to XSS because of improper validation of user-supplied input by multiple scripts. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security c... Read more
Affected Products : insta_hms- Published: Jan. 06, 2022
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-42840
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only t... Read more
Affected Products : suitecrm- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-42839
Grand Vice info Co. webopac7 file upload function fails to filter special characters. While logging in with general user’s permission, remote attackers can upload malicious script and execute arbitrary code to control the system or interrupt services.... Read more
Affected Products : webopac- Published: Nov. 15, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-42838
Grand Vice info Co. webopac7 book search field parameter does not properly restrict the input of special characters, thus unauthenticated attackers can inject JavaScript syntax remotely, and further perform reflective XSS attacks.... Read more
Affected Products : webopac- Published: Nov. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42837
An issue was discovered in Talend Data Catalog before 7.3-20210930. After setting up SAML/OAuth, authentication is not correctly enforced on the native login page. Any valid user from the SAML/OAuth provider can be used as the username with an arbitrary p... Read more
Affected Products : data_catalog- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-42836
GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.... Read more
Affected Products : gjson- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2021-42835
An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee. An attacker (with a foothold in a endpoint via a low-privileged user account) can access the exposed RPC service of the update service component. This RPC functionality allows the... Read more
- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2021-42833
A Use of Hardcoded Credentials vulnerability exists in AquaView versions 1.60, 7.x, and 8.x that could allow an authenticated local attacker to manipulate users and system settings.... Read more
Affected Products : aquaview- Published: Feb. 07, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-42811
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SafeNet KeySecure allows an authenticated user to read arbitrary files from the underlying system on which the product is deployed.... Read more
Affected Products : safenet_keysecure- Published: Jun. 10, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42810
A flaw in the previous versions of the product may allow an authenticated attacker the ability to execute code as a privileged user on a system where the agent is installed.... Read more
Affected Products : safenet_authentication_service_remote_desktop_gateway- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42809
Improper Access Control of Dynamically-Managed Code Resources (DLL) in Thales Sentinel Protection Installer could allow the execution of arbitrary code.... Read more
- Published: Dec. 20, 2021
- Modified: Nov. 21, 2024