Latest CVE Feed
-
7.5
HIGHCVE-2021-41827
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials for read-only access. The credentials are in the source code that corresponds to the DCBackupRestore JAR archive.... Read more
Affected Products : manageengine_remote_access_plus- Published: Sep. 30, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41826
PlaceOS Authentication Service before 1.29.10.0 allows app/controllers/auth/sessions_controller.rb open redirect.... Read more
Affected Products : placeos_authentication- Published: Sep. 30, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-41825
Verint Workforce Optimization (WFO) 15.2.5.1033 allows HTML injection via the /wfo/control/signin username parameter.... Read more
Affected Products : workforce_optimization- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-41824
Craft CMS before 3.7.14 allows CSV injection.... Read more
Affected Products : craft_cms- Published: Sep. 30, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-41821
Wazuh Manager in Wazuh through 4.1.5 is affected by a remote Integer Underflow vulnerability that might lead to denial of service. A crafted message must be sent from an authenticated agent to the manager.... Read more
Affected Products : wazuh- Published: Sep. 29, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41817
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.... Read more
Affected Products : ruby enterprise_linux fedora debian_linux leap software_collections linux_enterprise factory date date- Published: Jan. 01, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41816
CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such as Windows) where size_t and long have different numbers of bytes. This also affects the CGI gem before 0.... Read more
- Published: Feb. 06, 2022
- Modified: Nov. 21, 2024
-
5.2
MEDIUMCVE-2021-41810
Admin tool allows storing configuration data with script which may then get run by another vault administrator. Requires vault admin level authentication and is not remotely exploitable... Read more
- Published: May. 02, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-41809
SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview function allowed making queries from the server with certain document types referencing external entities.... Read more
Affected Products : m-files_server- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2021-41808
In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log wrote sensitive information to log. Mitigating factors are logging is disabled by default.... Read more
Affected Products : m-files_server- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41807
Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier.... Read more
- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-41805
HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in one namespace can be used for unintended privilege escalation in a differe... Read more
Affected Products : consul- Published: Dec. 12, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-41802
HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault ... Read more
Affected Products : vault- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-41801
The ReplaceText extension through 1.41 for MediaWiki has Incorrect Access Control. When a user is blocked after submitting a replace job, the job is still run, even if it may be run at a later time (due to the job queue backlog)... Read more
Affected Products : mediawiki- Published: Oct. 11, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-41800
MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). Visiting Special:Contributions can sometimes result in a long running SQL query because PoolCounter protection is mishandled.... Read more
- Published: Oct. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41799
MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). ApiQueryBacklinks (action=query&list=backlinks) can cause a full table scan.... Read more
- Published: Oct. 11, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41798
MediaWiki before 1.36.2 allows XSS. Month related MediaWiki messages are not escaped before being used on the Special:Search results page.... Read more
- Published: Oct. 11, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-41795
The Safari app extension bundled with 1Password for Mac 7.7.0 through 7.8.x before 7.8.7 is vulnerable to authorization bypass. By targeting a vulnerable component of this extension, a malicious web page could read a subset of 1Password vault items that w... Read more
Affected Products : 1password- Published: Sep. 29, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41794
ogs_fqdn_parse in Open5GS 1.0.0 through 2.3.3 inappropriately trusts a client-supplied length value, leading to a buffer overflow. The attacker can send a PFCP Session Establishment Request with "internet" as the PDI Network Instance. The first character ... Read more
Affected Products : open5gs- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-41792
An issue was discovered in Hyland org.alfresco:alfresco-content-services through 6.2.2.18 and org.alfresco:alfresco-transform-services through 1.3. A crafted HTML file, once uploaded, could trigger an unexpected request by the transformation engine. The r... Read more
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024