Latest CVE Feed
-
5.3
MEDIUMCVE-2021-42762
BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox, by abusing VFS syscalls that manip... Read more
- Published: Oct. 20, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42761
A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 through 6.0.7, 5.9.0 through 5.9.1 may allow a remote, unauthen... Read more
Affected Products : fortiweb- Published: Feb. 16, 2023
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-42760
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclose sensitive information from DB tables via crafted requests.... Read more
Affected Products : fortiwlm- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-42759
A violation of secure design principles in Fortinet Meru AP version 8.6.1 and below, version 8.5.5 and below allows attacker to execute unauthorized code or commands via crafted cli commands.... Read more
- Published: Dec. 09, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-42758
An improper access control vulnerability [CWE-284] in FortiWLC 8.6.1 and below may allow an authenticated and remote attacker with low privileges to execute any command as an admin user with full access rights via bypassing the GUI restrictions.... Read more
Affected Products : fortiwlc- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-42757
A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.... Read more
Affected Products : fortimanager fortios fortimail fortiportal fortiadc fortiproxy fortiweb fortianalyzer fortivoice fortirecorder_firmware +3 more products- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42756
Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve ... Read more
Affected Products : fortiweb- Published: Feb. 16, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-42755
An integer overflow / wraparound vulnerability [CWE-190] in FortiSwitch 7.0.2 and below, 6.4.9 and below, 6.2.x, 6.0.x; FortiRecorder 6.4.2 and below, 6.0.10 and below; FortiOS 7.0.2 and below, 6.4.8 and below, 6.2.10 and below, 6.0.x; FortiProxy 7.0.0, 2... Read more
- Published: Jul. 18, 2022
- Modified: Nov. 21, 2024
-
5.0
MEDIUMCVE-2021-42754
An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5 and below may allow an authenticated attacker to hijack the MacOS camera without the user permission via the malicious dylib file.... Read more
Affected Products : forticlient- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2021-42753
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.x, 6.1.x, 6.0.x, 5.9.x and 5.8.x may allow an authenticated attacker to perfor... Read more
Affected Products : fortiweb- Published: Feb. 02, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-42752
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and below allows attacker to execute malicious javascript code on victim's host via crafted HTTP requests... Read more
Affected Products : fortiwlm- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-42751
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the description of a rule node.... Read more
Affected Products : thingsboard- Published: Aug. 12, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-42750
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the title of a rule node.... Read more
Affected Products : thingsboard- Published: Aug. 12, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-42749
In Beaver Themer, attackers can bypass conditional logic controls (for hiding content) when viewing the post archives. Exploitation requires that a Themer layout is applied to the archives, and that the post excerpt field is not set.... Read more
Affected Products : beaver_themer- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-42748
In Beaver Builder through 2.5.0.3, attackers can bypass the visibility controls protection mechanism via the REST API.... Read more
Affected Products : beaver_builder- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
6.2
MEDIUMCVE-2021-42744
Philips MRI 1.5T and MRI 3T Version 5.x.x exposes sensitive information to an actor not explicitly authorized to have access.... Read more
- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-42743
A misconfiguration in the node default path allows for local privilege escalation from a lower privileged user to the Splunk user in Splunk Enterprise versions before 8.1.1 on Windows.... Read more
- Published: May. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42740
The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex designed to support Windows drive letters. If the output of this package is passed to a real shell as a quoted... Read more
Affected Products : shell-quote- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-42739
The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c, because avc_ca_pmt mishandles bounds checking.... Read more
- Published: Oct. 20, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-42738
Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious MXF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required ... Read more
- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024