Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2021-41080

    Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware details search.... Read more

    • Published: Nov. 11, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-41079

    Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinit... Read more

    • Published: Sep. 16, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-41078

    Nameko through 2.13.0 can be tricked into performing arbitrary code execution when deserializing the config file.... Read more

    Affected Products : nameko
    • Published: Oct. 26, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-41077

    The activation process in Travis CI, for certain 2021-09-03 through 2021-09-10 builds, causes secret data to have unexpected sharing that is not specified by the customer-controlled .travis.yml file. In particular, the desired behavior (if .travis.yml has... Read more

    Affected Products : travis_ci
    • Published: Sep. 14, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-41075

    The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API.... Read more

    Affected Products : manageengine_opmanager
    • Published: Oct. 13, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-41073

    loop_rw_iter in fs/io_uring.c in the Linux kernel 5.10 through 5.14.6 allows local users to gain privileges by using IORING_OP_PROVIDE_BUFFERS to trigger a free of a kernel buffer, as demonstrated by using /proc/<pid>/maps for exploitation.... Read more

    • Published: Sep. 19, 2021
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2021-41072

    squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a filesys... Read more

    Affected Products : debian_linux squashfs-tools
    • Published: Sep. 14, 2021
    • Modified: Nov. 21, 2024
  • 7.6

    HIGH
    CVE-2021-41067

    An issue was discovered in Listary through 6. Improper implementation of the update process leads to the download of software updates with a /check-update HTTP-based connection. This can be exploited with MITM techniques. Together with the lack of package... Read more

    Affected Products : listary
    • Published: Dec. 14, 2021
    • Modified: Nov. 21, 2024
  • 7.6

    HIGH
    CVE-2021-41066

    An issue was discovered in Listary through 6. When Listary is configured as admin, Listary will not ask for permissions again if a user tries to access files on the system from Listary itself (it will bypass UAC protection; there is no privilege validatio... Read more

    Affected Products : listary
    • Published: Dec. 14, 2021
    • Modified: Nov. 21, 2024
  • 7.3

    HIGH
    CVE-2021-41065

    An issue was discovered in Listary through 6. An attacker can create a \\.\pipe\Listary.listaryService named pipe and wait for a privileged user to open a session on the Listary installed host. Listary will automatically access the named pipe and the atta... Read more

    Affected Products : listary
    • Published: Dec. 14, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-41063

    SQL injection vulnerability was discovered in Aanderaa GeoView Webservice prior to version 2.1.3 that could allow an unauthenticated attackers to execute arbitrary commands.... Read more

    Affected Products : aanderaa_geoview
    • Published: Dec. 08, 2021
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2021-41061

    In RIOT-OS 2021.01, nonce reuse in 802.15.4 encryption in the ieee820154_security component allows attackers to break encryption by triggering reboots.... Read more

    Affected Products : riot
    • Published: Sep. 15, 2021
    • Modified: Nov. 21, 2024
  • 7.1

    HIGH
    CVE-2021-41057

    In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.... Read more

    • Published: Nov. 14, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-41055

    Gajim 1.2.x and 1.3.x before 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted XMPP Last Message Correction (XEP-0308) message in multi-user chat, where the message ID equals the correction ID.... Read more

    Affected Products : gajim
    • Published: Oct. 11, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-41054

    tftpd_file.c in atftp through 0.7.4 has a buffer overflow because buffer-size handling does not properly consider the combination of data, OACK, and other options.... Read more

    Affected Products : debian_linux atftp
    • Published: Sep. 13, 2021
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2021-41043

    Use after free in tcpslice triggers AddressSanitizer, no other confirmed impact.... Read more

    Affected Products : tcpslice
    • Published: Jan. 05, 2022
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-41042

    In Eclipse Lyo versions 1.0.0 to 4.1.0, a TransformerFactory is initialized with the defaults that do not restrict DTD loading when working with RDF/XML. This allows an attacker to cause an external DTD to be retrieved.... Read more

    Affected Products : lyo
    • Published: Jul. 07, 2022
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-41041

    In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification when verification is triggered by a MethodHandle invocation, allowing unverified methods to be invoked using MethodHandles.... Read more

    Affected Products : openj9 java_se
    • Published: Apr. 27, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-41040

    In Eclipse Wakaama, ever since its inception until 2021-01-14, the CoAP parsing code does not properly sanitize network-received data.... Read more

    Affected Products : wakaama
    • Published: Feb. 01, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-41039

    In versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property properties could cause excessive CPU usage, leading to a loss of performance and possible denial of service.... Read more

    Affected Products : mosquitto
    • Published: Dec. 01, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 293354 Results