Latest CVE Feed
-
6.1
MEDIUMCVE-2021-41798
MediaWiki before 1.36.2 allows XSS. Month related MediaWiki messages are not escaped before being used on the Special:Search results page.... Read more
- Published: Oct. 11, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-41795
The Safari app extension bundled with 1Password for Mac 7.7.0 through 7.8.x before 7.8.7 is vulnerable to authorization bypass. By targeting a vulnerable component of this extension, a malicious web page could read a subset of 1Password vault items that w... Read more
Affected Products : 1password- Published: Sep. 29, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41794
ogs_fqdn_parse in Open5GS 1.0.0 through 2.3.3 inappropriately trusts a client-supplied length value, leading to a buffer overflow. The attacker can send a PFCP Session Establishment Request with "internet" as the PDI Network Instance. The first character ... Read more
Affected Products : open5gs- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-41792
An issue was discovered in Hyland org.alfresco:alfresco-content-services through 6.2.2.18 and org.alfresco:alfresco-transform-services through 1.3. A crafted HTML file, once uploaded, could trigger an unexpected request by the transformation engine. The r... Read more
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-41791
An issue was discovered in Hyland org.alfresco:share through 7.0.0.2 and org.alfresco:community-share through 7.0. An evasion of the XSS filter for HTML input validation in the Alfresco Share User Interface leads to stored XSS that could be exploited by a... Read more
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-41790
An issue was discovered in Hyland org.alfresco:alfresco-content-services through 7.0.1.2. Script Action execution allows executing scripts uploaded outside of the Data Dictionary. This could allow a logged-in attacker to execute arbitrary code inside a sa... Read more
Affected Products : alfresco_content_services- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-41789
In wifi driver, there is a possible system crash due to a missing validation check. This could lead to remote denial of service from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch... Read more
- Published: Jan. 04, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-41788
MediaTek microchips, as used in NETGEAR devices through 2021-12-13 and other devices, mishandle attempts at Wi-Fi authentication flooding. (Affected Chipsets MT7603E, MT7612, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0... Read more
Affected Products : mt7613_firmware mt7615_firmware mt7622_firmware mt7628_firmware mt7629_firmware mt7915_firmware mt7603e_firmware mt7612_firmware mt7603e mt7612 +6 more products- Published: Dec. 26, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-41785
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.... Read more
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-41784
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.... Read more
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-41783
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.... Read more
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-41782
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.... Read more
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-41781
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.... Read more
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-41780
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.... Read more
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41772
Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field.... Read more
- Published: Nov. 08, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41771
ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation.... Read more
- Published: Nov. 08, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41770
Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.... Read more
Affected Products : pingfederate- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41769
A vulnerability has been identified in SIPROTEC 5 6MD85 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 6MD86 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 6MD89 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC ... Read more
Affected Products : 6md85_firmware 6md86_firmware 6md89_firmware 6mu85_firmware 7ke85_firmware 7sa82_firmware 7sa86_firmware 7sa87_firmware 7sd82_firmware 7sd86_firmware +52 more products- Published: Jan. 11, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-41767
Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses. This may allow an authenticated user who already has permission to access a particular connection to read from or inter... Read more
Affected Products : guacamole- Published: Jan. 11, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-41766
Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology that relies on Java serialized objects for client server communication. Whereas the default JMX implement... Read more
Affected Products : karaf- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024