Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2021-42105

    Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please not... Read more

    • Published: Oct. 21, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-42104

    Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please not... Read more

    • Published: Oct. 21, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-42103

    An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code o... Read more

    Affected Products : windows apex_one
    • Published: Oct. 21, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-42102

    An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service agents could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged... Read more

    Affected Products : windows apex_one
    • Published: Oct. 21, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-42101

    An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code o... Read more

    Affected Products : windows apex_one
    • Published: Oct. 21, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-42099

    Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.... Read more

    Affected Products : manageengine_m365_manager_plus
    • Published: Nov. 30, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-42098

    An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via batch custom PowerShell.... Read more

    Affected Products : remote_desktop_manager
    • Published: Oct. 18, 2021
    • Modified: Nov. 21, 2024
  • 8.5

    HIGH
    CVE-2021-42097

    GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack again... Read more

    Affected Products : debian_linux mailman
    • Published: Oct. 21, 2021
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2021-42096

    GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin password, and may be useful in conducting a brute-force attack against that password.... Read more

    Affected Products : debian_linux mailman
    • Published: Oct. 21, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-42095

    Xshell before 7.0.0.76 allows attackers to cause a crash by triggering rapid changes to the title bar.... Read more

    Affected Products : xshell
    • Published: Oct. 07, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-42094

    An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.... Read more

    Affected Products : zammad
    • Published: Oct. 07, 2021
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-42093

    An issue was discovered in Zammad before 4.1.1. An admin can execute code on the server via a crafted request that manipulates triggers.... Read more

    Affected Products : zammad
    • Published: Oct. 07, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-42092

    An issue was discovered in Zammad before 4.1.1. Stored XSS may occur via an Article during addition of an attachment to a Ticket.... Read more

    Affected Products : zammad
    • Published: Oct. 07, 2021
    • Modified: Nov. 21, 2024
  • 9.1

    CRITICAL
    CVE-2021-42091

    An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration.... Read more

    Affected Products : zammad
    • Published: Oct. 07, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-42090

    An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.... Read more

    Affected Products : zammad
    • Published: Oct. 07, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-42089

    An issue was discovered in Zammad before 4.1.1. The REST API discloses sensitive information.... Read more

    Affected Products : zammad
    • Published: Oct. 07, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-42088

    An issue was discovered in Zammad before 4.1.1. The Chat functionality allows XSS because clipboard data is mishandled.... Read more

    Affected Products : zammad
    • Published: Oct. 07, 2021
    • Modified: Nov. 21, 2024
  • 4.9

    MEDIUM
    CVE-2021-42087

    An issue was discovered in Zammad before 4.1.1. An admin can discover the application secret via the API.... Read more

    Affected Products : zammad
    • Published: Oct. 07, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-42086

    An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a crafted request.... Read more

    Affected Products : zammad
    • Published: Oct. 07, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-42085

    An issue was discovered in Zammad before 4.1.1. There is stored XSS via a custom Avatar.... Read more

    Affected Products : zammad
    • Published: Oct. 07, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 293508 Results