Latest CVE Feed
-
7.8
HIGHCVE-2021-42105
Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please not... Read more
Affected Products : windows apex_one worry-free_business_security worry-free_business_security_services- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42104
Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please not... Read more
Affected Products : windows apex_one worry-free_business_security worry-free_business_security_services- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42103
An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code o... Read more
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42102
An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service agents could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged... Read more
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42101
An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code o... Read more
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42099
Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.... Read more
Affected Products : manageengine_m365_manager_plus- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-42098
An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via batch custom PowerShell.... Read more
Affected Products : remote_desktop_manager- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2021-42097
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack again... Read more
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-42096
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin password, and may be useful in conducting a brute-force attack against that password.... Read more
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-42095
Xshell before 7.0.0.76 allows attackers to cause a crash by triggering rapid changes to the title bar.... Read more
Affected Products : xshell- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42094
An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-42093
An issue was discovered in Zammad before 4.1.1. An admin can execute code on the server via a crafted request that manipulates triggers.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-42092
An issue was discovered in Zammad before 4.1.1. Stored XSS may occur via an Article during addition of an attachment to a Ticket.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-42091
An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42090
An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-42089
An issue was discovered in Zammad before 4.1.1. The REST API discloses sensitive information.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-42088
An issue was discovered in Zammad before 4.1.1. The Chat functionality allows XSS because clipboard data is mishandled.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-42087
An issue was discovered in Zammad before 4.1.1. An admin can discover the application secret via the API.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-42086
An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a crafted request.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-42085
An issue was discovered in Zammad before 4.1.1. There is stored XSS via a custom Avatar.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024