Latest CVE Feed
-
7.5
HIGHCVE-2021-41090
Grafana Agent is a telemetry collector for sending metrics, logs, and trace data to the opinionated Grafana observability stack. Prior to versions 0.20.1 and 0.21.2, inline secrets defined within a metrics instance config are exposed in plaintext over two... Read more
Affected Products : agent- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2021-41089
Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where attempting to copy files using `docker cp` into a specially-crafted container can result in Unix file permission changes fo... Read more
- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-41088
Elvish is a programming language and interactive shell, combined into one package. In versions prior to 0.14.0 Elvish's web UI backend (started by `elvish -web`) hosts an endpoint that allows executing the code sent from the web UI. The backend does not c... Read more
Affected Products : elvish- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-41087
in-toto-golang is a go implementation of the in-toto framework to protect software supply chain integrity. In affected versions authenticated attackers posing as functionaries (i.e., within a trusted set of users for a layout) are able to create attestati... Read more
Affected Products : in-toto-golang- Published: Sep. 21, 2021
- Modified: Nov. 21, 2024
-
8.7
HIGHCVE-2021-41086
jsuites is an open source collection of common required javascript web components. In affected versions users are subject to cross site scripting (XSS) attacks via clipboard content. jsuites is vulnerable to DOM based XSS if the user can be tricked into c... Read more
Affected Products : jsuites- Published: Sep. 21, 2021
- Modified: Nov. 21, 2024
-
8.7
HIGHCVE-2021-41084
http4s is an open source scala interface for HTTP. In affected versions http4s is vulnerable to response-splitting or request-splitting attacks when untrusted user input is used to create any of the following fields: Header names (`Header.name`å), Header ... Read more
Affected Products : http4s- Published: Sep. 21, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-41083
Dada Mail is a web-based e-mail list management system. In affected versions a bad actor could give someone a carefully crafted web page via email, SMS, etc, that - when visited, allows them control of the list control panel as if the bad actor was logged... Read more
Affected Products : dada_mail- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41082
Discourse is a platform for community discussion. In affected versions any private message that includes a group had its title and participating user exposed to users that do not have access to the private messages. However, access control for the private... Read more
Affected Products : discourse- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41081
Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a configuration search.... Read more
Affected Products : manageengine_network_configuration_manager- Published: Nov. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41080
Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware details search.... Read more
Affected Products : manageengine_network_configuration_manager- Published: Nov. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41079
Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinit... Read more
- Published: Sep. 16, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-41078
Nameko through 2.13.0 can be tricked into performing arbitrary code execution when deserializing the config file.... Read more
Affected Products : nameko- Published: Oct. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41077
The activation process in Travis CI, for certain 2021-09-03 through 2021-09-10 builds, causes secret data to have unexpected sharing that is not specified by the customer-controlled .travis.yml file. In particular, the desired behavior (if .travis.yml has... Read more
Affected Products : travis_ci- Published: Sep. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41075
The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API.... Read more
Affected Products : manageengine_opmanager- Published: Oct. 13, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-41073
loop_rw_iter in fs/io_uring.c in the Linux kernel 5.10 through 5.14.6 allows local users to gain privileges by using IORING_OP_PROVIDE_BUFFERS to trigger a free of a kernel buffer, as demonstrated by using /proc/<pid>/maps for exploitation.... Read more
Affected Products : linux_kernel fedora debian_linux h410c_firmware cloud_backup h300s_firmware h500s_firmware h700s_firmware h410s_firmware h300s +11 more products- Published: Sep. 19, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-41072
squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a filesys... Read more
- Published: Sep. 14, 2021
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2021-41067
An issue was discovered in Listary through 6. Improper implementation of the update process leads to the download of software updates with a /check-update HTTP-based connection. This can be exploited with MITM techniques. Together with the lack of package... Read more
Affected Products : listary- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2021-41066
An issue was discovered in Listary through 6. When Listary is configured as admin, Listary will not ask for permissions again if a user tries to access files on the system from Listary itself (it will bypass UAC protection; there is no privilege validatio... Read more
Affected Products : listary- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2021-41065
An issue was discovered in Listary through 6. An attacker can create a \\.\pipe\Listary.listaryService named pipe and wait for a privileged user to open a session on the Listary installed host. Listary will automatically access the named pipe and the atta... Read more
Affected Products : listary- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41063
SQL injection vulnerability was discovered in Aanderaa GeoView Webservice prior to version 2.1.3 that could allow an unauthenticated attackers to execute arbitrary commands.... Read more
Affected Products : aanderaa_geoview- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024