Latest CVE Feed
-
8.8
HIGHCVE-2021-42098
An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via batch custom PowerShell.... Read more
Affected Products : remote_desktop_manager- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2021-42097
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack again... Read more
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-42096
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin password, and may be useful in conducting a brute-force attack against that password.... Read more
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-42095
Xshell before 7.0.0.76 allows attackers to cause a crash by triggering rapid changes to the title bar.... Read more
Affected Products : xshell- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42094
An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-42093
An issue was discovered in Zammad before 4.1.1. An admin can execute code on the server via a crafted request that manipulates triggers.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-42092
An issue was discovered in Zammad before 4.1.1. Stored XSS may occur via an Article during addition of an attachment to a Ticket.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-42091
An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42090
An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-42089
An issue was discovered in Zammad before 4.1.1. The REST API discloses sensitive information.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-42088
An issue was discovered in Zammad before 4.1.1. The Chat functionality allows XSS because clipboard data is mishandled.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-42087
An issue was discovered in Zammad before 4.1.1. An admin can discover the application secret via the API.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-42086
An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a crafted request.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-42085
An issue was discovered in Zammad before 4.1.1. There is stored XSS via a custom Avatar.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-42084
An issue was discovered in Zammad before 4.1.1. An attacker with valid agent credentials may send a series of crafted requests that cause an endless loop and thus cause denial of service.... Read more
Affected Products : zammad- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
8.7
HIGHCVE-2021-42083
An authenticated attacker is able to create alerts that trigger a stored XSS attack.... Read more
- Published: Jul. 10, 2023
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42082
Local users are able to execute scripts under root privileges.... Read more
Affected Products : quantastor- Published: Jul. 10, 2023
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-42081
An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API.... Read more
Affected Products : quantastor- Published: Jul. 10, 2023
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2021-42080
An attacker is able to launch a Reflected XSS attack using a crafted URL.... Read more
Affected Products : quantastor- Published: Jul. 10, 2023
- Modified: Nov. 21, 2024
-
6.2
MEDIUMCVE-2021-42079
An authenticated administrator is able to prepare an alert that is able to execute an SSRF attack. This is exclusively with POST requests.... Read more
Affected Products : quantastor- Published: Jul. 10, 2023
- Modified: Nov. 21, 2024