Latest CVE Feed
-
6.5
MEDIUMCVE-2021-40712
Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a improper input validation vulnerability via the path parameter. An authenticated attacker can send a malformed POST request to achieve server-side denial of service.... Read more
Affected Products : experience_manager- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-40711
Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a stored XSS vulnerability when creating Content Fragments. An authenticated attacker can send a malformed POST request to achieve arbitrary code execution. Malicious JavaScript may be ... Read more
Affected Products : experience_manager- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-40710
Adobe Premiere Pro version 15.4 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .svg file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is req... Read more
- Published: Sep. 29, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-40709
Adobe Photoshop versions 21.2.11 (and earlier) and 22.5 (and earlier) are affected by a Buffer Overflow vulnerability when parsing a specially crafted SVG file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execut... Read more
- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2021-40708
Adobe Genuine Service versions 7.3 (and earlier) are affected by a privilege escalation vulnerability in the AGSService installer. An authenticated attacker could leverage this vulnerability to achieve read / write privileges to execute arbitrary code. Us... Read more
- Published: Sep. 29, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-40703
Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious m4a file, potentially resulting in arbitrary code execution in the context of the current user. User intera... Read more
- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-40702
Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious psd file, potentially resulting in arbitrary code execution in the context of the current user. User intera... Read more
- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-40701
Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious m4a file, potentially resulting in arbitrary code execution in the context of the current user. User intera... Read more
- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-40700
Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious TIFF file, potentially resulting in arbitrary code execution in the context of the current user. User inter... Read more
- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2021-40699
ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an improper access control vulnerability when checking permissions in the CFIDE path. An authenticated attacker could leverage this vulnerability to access a... Read more
Affected Products : coldfusion- Published: Sep. 07, 2023
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2021-40698
ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an Use of Inherently Dangerous Function vulnerability that can lead to a security feature bypass . An authenticated attacker could leverage this vulnerabili... Read more
Affected Products : coldfusion- Published: Sep. 07, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-40697
Adobe Framemaker versions 2019 Update 8 (and earlier) and 2020 Release Update 2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mi... Read more
Affected Products : framemaker- Published: Sep. 29, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-40695
It was possible for a student to view their quiz grade before it had been released, using a quiz web service.... Read more
Affected Products : moodle- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-40694
Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account.... Read more
Affected Products : moodle- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-40693
An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.... Read more
Affected Products : moodle- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-40692
Insufficient capability checks made it possible for teachers to download users outside of their courses.... Read more
Affected Products : moodle- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-40691
A session hijack risk was identified in the Shibboleth authentication plugin.... Read more
Affected Products : moodle- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-40690
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to ... Read more
- Published: Sep. 19, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-40684
Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint which allows remote access to the JMX of the runtime container, which would allow an attacker the ability to read o... Read more
Affected Products : esb_runtime- Published: Sep. 22, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-40683
In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquoted path may allow an attacker to hijack the flow of execution.... Read more
- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024