Latest CVE Feed
-
6.1
MEDIUMCVE-2021-42112
The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js.... Read more
Affected Products : limesurvey- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-42109
VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root.... Read more
Affected Products : exterity_avediaserver exterity_avediastream_encoders_firmware avediastream_m9605_firmware avediastream_m9400_firmware avediastream_m9405_firmware avediastream_m9305_firmware avediastream_r9300_firmware avediastream_r9310_firmware avediastream_m9325_firmware avediastream_r9350_firmware +9 more products- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42108
Unnecessary privilege vulnerabilities in the Web Console of Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must ... Read more
Affected Products : windows apex_one worry-free_business_security worry-free_business_security_services- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42107
Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please not... Read more
Affected Products : windows apex_one worry-free_business_security worry-free_business_security_services- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42106
Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please not... Read more
Affected Products : windows apex_one worry-free_business_security worry-free_business_security_services- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42105
Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please not... Read more
Affected Products : windows apex_one worry-free_business_security worry-free_business_security_services- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42104
Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please not... Read more
Affected Products : windows apex_one worry-free_business_security worry-free_business_security_services- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42103
An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code o... Read more
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42102
An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service agents could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged... Read more
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42101
An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code o... Read more
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42099
Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.... Read more
Affected Products : manageengine_m365_manager_plus- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-42098
An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via batch custom PowerShell.... Read more
Affected Products : remote_desktop_manager- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2021-42097
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack again... Read more
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-42096
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin password, and may be useful in conducting a brute-force attack against that password.... Read more
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-42095
Xshell before 7.0.0.76 allows attackers to cause a crash by triggering rapid changes to the title bar.... Read more
Affected Products : xshell- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42094
An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-42093
An issue was discovered in Zammad before 4.1.1. An admin can execute code on the server via a crafted request that manipulates triggers.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-42092
An issue was discovered in Zammad before 4.1.1. Stored XSS may occur via an Article during addition of an attachment to a Ticket.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-42091
An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42090
An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024