Latest CVE Feed
-
9.8
CRITICALCVE-2021-40866
Certain NETGEAR smart switches are affected by a remote admin password change by an unauthenticated attacker via the (disabled by default) /sqfs/bin/sccd daemon, which fails to check authentication when the authentication TLV is missing from a received NS... Read more
Affected Products : gs724tp_firmware gs728tp_firmware gs728tpp_firmware gs752tpp_firmware gs752tp_firmware gs750e_firmware gs108t_firmware gs110tp_firmware gc108p_firmware gc108pp_firmware +30 more products- Published: Sep. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40865
An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should u... Read more
Affected Products : storm- Published: Oct. 25, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40864
The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.data and text fields.... Read more
Affected Products : google_translate- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-40862
HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to authenticated parties, which could be used for privilege escalation or unauthorized modification of a Terraform configuration. Fixed in ... Read more
Affected Products : terraform_enterprise- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-40861
A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) 9.0.017.07 allows an attacker to execute arbitrary SQL queries via the value attribute, with which all data in the database can be extracted and OS com... Read more
Affected Products : intelligent_workload_distribution_manager- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-40860
A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) before 9.0.013.11 allows an attacker to execute arbitrary SQL queries via the ql_expression parameter, with which all data in the database can be extra... Read more
Affected Products : intelligent_workload_distribution_manager- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-40859
Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web based management application full administrative access to the device.... Read more
- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-40858
Auerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure. A sub-admin can read the cleartext Admin password via the fileName=../../etc/passwd substring.... Read more
Affected Products : compact_5500r_ip_firmware compact_5200r_ip_firmware compact_5000r_ip_firmware compact_4000_ip_firmware commander_6000r_ip_firmware commander_6000rx_ip_firmware commander_business\(19\"\)_ip_firmware commander_basic.2\(19\"\)_ip_firmware compact_5010_voip_ip_firmware compact_5020_voip_ip_firmware +10 more products- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-40857
Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1 substring.... Read more
Affected Products : compact_5500r_ip_firmware compact_5200r_ip_firmware compact_5000r_ip_firmware compact_4000_ip_firmware commander_6000r_ip_firmware commander_6000rx_ip_firmware commander_business\(19\"\)_ip_firmware commander_basic.2\(19\"\)_ip_firmware compact_5010_voip_ip_firmware compact_5020_voip_ip_firmware +10 more products- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-40856
Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.... Read more
- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40855
The EU Technical Specifications for Digital COVID Certificates before 1.1 mishandle certificate governance. A non-production public key certificate could have been used in production.... Read more
Affected Products : technical_specifications_for_digital_covid_certificates- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-40854
AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local user to obtain administrator privileges by using the Open Chat Log feature to launch a privileged Notepad process that can launch other applications.... Read more
Affected Products : anydesk- Published: Oct. 14, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-40853
TCMAN GIM does not perform an authorization check when trying to access determined resources. A remote attacker could exploit this vulnerability to access URL that require privileges without having them. The exploitation of this vulnerability might allow ... Read more
Affected Products : gim- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-40852
TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to pages controlled by the attacker. The exploitation of this vulnerability might allow a remote attacker to obtain information.... Read more
Affected Products : gim- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-40851
TCMAN GIM is vulnerable to a lack of authorization in all available webservice methods listed in /PC/WebService.asmx. The exploitation of this vulnerability might allow a remote attacker to obtain information.... Read more
Affected Products : gim- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-40850
TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx.... Read more
Affected Products : gim- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40849
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged into, resulting in information disclosure (at a minimum) and often escalation of privileges.... Read more
Affected Products : mahara- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-40848
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet program could interpret as a command, leading to execution of a malicious string locally on a device, aka CSV injection.... Read more
Affected Products : mahara- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-40847
The update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve remote code execution as root via a MitM attack. While the parental controls themselves are not enabled by default on the routers, the ... Read more
Affected Products : r6700_firmware r6900_firmware r6900p_firmware r7000_firmware r7000p_firmware r6400v2_firmware r6700v3_firmware r7850_firmware r7900_firmware r8000_firmware +12 more products- Published: Sep. 21, 2021
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2021-40846
An issue was discovered in Rhinode Trading Paints through 2.0.36. TP Updater.exe uses cleartext HTTP to check, and request, updates. Thus, attackers can man-in-the-middle a victim to download a malicious binary in place of the real update, with no SSL err... Read more
Affected Products : trading_paints- Published: Mar. 04, 2022
- Modified: Nov. 21, 2024