Latest CVE Feed
-
8.8
HIGHCVE-2021-42126
An improper authorization control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation.... Read more
Affected Products : avalanche- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-42125
An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dangerous files.... Read more
Affected Products : avalanche- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-42124
An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform a session takeover.... Read more
Affected Products : avalanche- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-42123
Unrestricted File Upload in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 in the File Upload Functions allows an authenticated remote attacker with Upload privileges to upload files with any file type, ena... Read more
- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-42122
Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on an object’s attributes with numeric format allows an authenticated remote attacker with Object Modification privileges to i... Read more
- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-42121
Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on an object’s date attribute(s) allows an authenticated remote attacker with Object Modification privileges to insert an unex... Read more
- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-42120
Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on all object attributes allows an authenticated remote attacker with Object Modification privileges to insert arbitrarily lon... Read more
- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2021-42119
Persistent Cross Site Scripting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 via the Search Functionality allows authenticated users with Object Modification privileges to inject arbitrary HTML and Jav... Read more
- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-42118
Persistent Cross Site Scripting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 via the Structure Component allows an authenticated remote attacker with Object Modification privileges to inject arbitrary ... Read more
- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-42117
Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an authenticated remote attacker with Object Modification privileges to insert arbitrary HTML without code execution.... Read more
- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-42116
Incorrect Access Control in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an authenticated remote attacker to view the Shape Editor and Settings, which are functionality for higher privileged users,... Read more
- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-42115
Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an unauthenticated remote attacker to escalate privileges from unauthenticated to authenticated user via stealing and injecting... Read more
- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024
-
9.0
CRITICALCVE-2021-42114
Modern DRAM devices (PC-DDR4, LPDDR4X) are affected by a vulnerability in their internal Target Row Refresh (TRR) mitigation against Rowhammer attacks. Novel non-uniform Rowhammer access patterns, consisting of aggressors with different frequencies, phase... Read more
Affected Products : ddr4_sdram ddr4_sdram ddr4_sdram_firmware lddr4_firmware lddr4_firmware ddr4_sdram_firmware ddr4_sdram_firmware lddr4_firmware ddr4_sdram lddr4 +2 more products- Published: Nov. 16, 2021
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2021-42113
An issue was discovered in StorageSecurityCommandDxe in Insyde InsydeH2O with Kernel 5.1 before 05.14.28, Kernel 5.2 before 05.24.28, and Kernel 5.3 before 05.32.25. An SMM callout vulnerability allows an attacker to hijack execution flow of code running ... Read more
Affected Products : insydeh2o- Published: Feb. 03, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-42112
The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js.... Read more
Affected Products : limesurvey- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-42109
VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root.... Read more
Affected Products : exterity_avediaserver exterity_avediastream_encoders_firmware avediastream_m9605_firmware avediastream_m9400_firmware avediastream_m9405_firmware avediastream_m9305_firmware avediastream_r9300_firmware avediastream_r9310_firmware avediastream_m9325_firmware avediastream_r9350_firmware +9 more products- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42108
Unnecessary privilege vulnerabilities in the Web Console of Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must ... Read more
Affected Products : windows apex_one worry-free_business_security worry-free_business_security_services- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42107
Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please not... Read more
Affected Products : windows apex_one worry-free_business_security worry-free_business_security_services- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42106
Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please not... Read more
Affected Products : windows apex_one worry-free_business_security worry-free_business_security_services- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42105
Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please not... Read more
Affected Products : windows apex_one worry-free_business_security worry-free_business_security_services- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024