Latest CVE Feed
-
8.8
HIGHCVE-2021-42072
An issue was discovered in Barrier before 2.4.0. The barriers component (aka the server-side implementation of Barrier) does not sufficiently verify the identify of connecting clients. Clients can thus exploit weaknesses in the provided protocol to cause ... Read more
- Published: Nov. 08, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-42071
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header.... Read more
- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-42070
When a user opens manipulated Jupiter Tessellation (.jt) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-42069
When a user opens manipulated Tagged Image File Format (.tif) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-42068
When a user opens a manipulated GIF (.gif) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application.... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-42067
In SAP NetWeaver AS for ABAP and ABAP Platform - versions 701, 702, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 786, an attacker authenticated as a regular user can use the S/4 Hana dashboard to reveal systems and services which they would not ... Read more
- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-42066
SAP Business One - version 10.0, allows an admin user to view DB password in plain text over the network, which should otherwise be encrypted. For an attacker to discover vulnerable function in-depth application knowledge is required, but once exploited t... Read more
Affected Products : business_one- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42064
If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized "in" clause, SAP Commerce - versions 1905, 2005, 2105, 2011, allows attacker to execute crafted database queries, exposing backend da... Read more
Affected Products : commerce- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-42063
A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage of one SAP KW component within a Web browser enables unauthorized attackers to conduct XSS attacks, which might lead to disclose sensi... Read more
Affected Products : knowledge_warehouse- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-42062
SAP ERP HCM Portugal does not perform necessary authorization checks for a report that reads the payroll data of employees in a certain area. Since the affected report only reads the payroll information, the attacker can neither modify any information nor... Read more
- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-42061
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) - version 420, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This allows a low privileged attacker to retrieve some data fr... Read more
Affected Products : businessobjects_business_intelligence_platform- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2021-42060
An issue was discovered in Insyde InsydeH2O Kernel 5.0 through 05.08.41, Kernel 5.1 through 05.16.41, Kernel 5.2 before 05.23.22, and Kernel 5.3 before 05.32.22. An Int15ServiceSmm SMM callout vulnerability allows an attacker to hijack execution flow of c... Read more
Affected Products : insydeh2o- Published: Feb. 03, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-42059
An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.08.41, Kernel 5.1 before 05.16.41, Kernel 5.2 before 05.26.41, Kernel 5.3 before 05.35.41, and Kernel 5.4 before 05.42.20. A stack-based buffer overflow leads toarbitrary code execution in U... Read more
- Published: Feb. 03, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-42057
Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The evalInContext function in executes user input, which allows an attacker to craft malicious Markdown files that will execute arbitrary code once opened. NOTE: 0.4.13 provides a mitigation ... Read more
Affected Products : obsidian_dataview- Published: Nov. 04, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-42056
Thales Safenet Authentication Client (SAC) for Linux and Windows through 10.7.7 creates insecure temporary hid and lock files allowing a local attacker, through a symlink attack, to overwrite arbitrary files, and potentially achieve arbitrary command exec... Read more
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-42055
ASUSTek ZenBook Pro Due 15 UX582 laptop firmware through 203 has Insecure Permissions that allow attacks by a physically proximate attacker.... Read more
- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-42054
ACCEL-PPP 1.12.0 has an out-of-bounds read in triton_context_schedule if the client exits after authentication.... Read more
Affected Products : accel-ppp- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-42053
The Unicorn framework through 0.35.3 for Django allows XSS via component.name.... Read more
Affected Products : unicorn- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-42052
IPESA e-Flow 3.3.6 allows path traversal for reading any file within the web root directory via the lib/js/build/STEResource.res path and the R query parameter.... Read more
Affected Products : e-flow- Published: Aug. 16, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-42051
An issue was discovered in AbanteCart before 1.3.2. Any low-privileged user with file-upload permissions can upload a malicious SVG document that contains an XSS payload.... Read more
Affected Products : abantecart- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024