Latest CVE Feed
-
9.8
CRITICALCVE-2021-41393
Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows forgery of SSH host certificates in some situations.... Read more
Affected Products : teleport- Published: Sep. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41392
static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal Electron API.... Read more
Affected Products : boostnote- Published: Sep. 17, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-41391
In Ericsson ECM before 18.0, it was observed that Security Management Endpoint in User Profile Management Section is vulnerable to stored XSS via a name, leading to session hijacking and full account takeover.... Read more
Affected Products : enterprise_content_management- Published: Sep. 17, 2021
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2021-41390
In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injection.... Read more
Affected Products : enterprise_content_management- Published: Sep. 17, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-41388
Netskope client prior to 89.x on macOS is impacted by a local privilege escalation vulnerability. The XPC implementation of nsAuxiliarySvc process does not perform validation on new connections before accepting the connection. Thus any low privileged user... Read more
- Published: Jan. 04, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-41387
seatd-launch in seatd 0.6.x before 0.6.2 allows privilege escalation because it uses execlp and may be installed setuid root.... Read more
Affected Products : seatd- Published: Sep. 17, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-41385
The third party intelligence connector in Securonix SNYPR 6.3.1 Build 184295_0302 allows an authenticated user to obtain access to server configuration details via SSRF.... Read more
Affected Products : snypr- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-41383
setup.cgi on NETGEAR R6020 1.0.0.48 devices allows an admin to execute arbitrary shell commands via shell metacharacters in the ntp_server field.... Read more
- Published: Sep. 17, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41382
Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface.... Read more
Affected Products : plastic_scm- Published: Sep. 22, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41381
Payara Micro Community 5.2021.6 and below allows Directory Traversal.... Read more
Affected Products : micro_community- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-41380
RealVNC Viewer 6.21.406 allows remote VNC servers to cause a denial of service (application crash) via crafted RFB protocol data. NOTE: It is asserted that this issue requires social engineering a user into connecting to a fake VNC Server. The VNC Viewer ... Read more
Affected Products : vnc_viewer- Published: Sep. 17, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-41378
Windows NTFS Remote Code Execution Vulnerability... Read more
Affected Products : windows_10 windows_server_2016 windows_server_2019 windows_10_1809 windows_10_20h2 windows_server_2022 windows_11_21h2 windows_11 windows_10_21h1 windows_10_1909 +2 more products- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-41377
Windows Fast FAT File System Driver Elevation of Privilege Vulnerability... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 +12 more products- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-41376
Azure Sphere Information Disclosure Vulnerability... Read more
Affected Products : azure_sphere- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-41375
Azure Sphere Information Disclosure Vulnerability... Read more
Affected Products : azure_sphere- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-41374
Azure Sphere Information Disclosure Vulnerability... Read more
Affected Products : azure_sphere- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-41373
FSLogix Information Disclosure Vulnerability... Read more
Affected Products : fslogix- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-41372
A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim. Combining these 2 ... Read more
Affected Products : power_bi_report_server- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-41371
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 +12 more products- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-41370
NTFS Elevation of Privilege Vulnerability... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 +12 more products- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024