Latest CVE Feed
-
8.8
HIGHCVE-2021-40857
Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1 substring.... Read more
Affected Products : compact_5500r_ip_firmware compact_5200r_ip_firmware compact_5000r_ip_firmware compact_4000_ip_firmware commander_6000r_ip_firmware commander_6000rx_ip_firmware commander_business\(19\"\)_ip_firmware commander_basic.2\(19\"\)_ip_firmware compact_5010_voip_ip_firmware compact_5020_voip_ip_firmware +10 more products- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-40856
Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.... Read more
- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40855
The EU Technical Specifications for Digital COVID Certificates before 1.1 mishandle certificate governance. A non-production public key certificate could have been used in production.... Read more
Affected Products : technical_specifications_for_digital_covid_certificates- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-40854
AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local user to obtain administrator privileges by using the Open Chat Log feature to launch a privileged Notepad process that can launch other applications.... Read more
Affected Products : anydesk- Published: Oct. 14, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-40853
TCMAN GIM does not perform an authorization check when trying to access determined resources. A remote attacker could exploit this vulnerability to access URL that require privileges without having them. The exploitation of this vulnerability might allow ... Read more
Affected Products : gim- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-40852
TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to pages controlled by the attacker. The exploitation of this vulnerability might allow a remote attacker to obtain information.... Read more
Affected Products : gim- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-40851
TCMAN GIM is vulnerable to a lack of authorization in all available webservice methods listed in /PC/WebService.asmx. The exploitation of this vulnerability might allow a remote attacker to obtain information.... Read more
Affected Products : gim- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-40850
TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx.... Read more
Affected Products : gim- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40849
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged into, resulting in information disclosure (at a minimum) and often escalation of privileges.... Read more
Affected Products : mahara- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-40848
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet program could interpret as a command, leading to execution of a malicious string locally on a device, aka CSV injection.... Read more
Affected Products : mahara- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-40847
The update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve remote code execution as root via a MitM attack. While the parental controls themselves are not enabled by default on the routers, the ... Read more
Affected Products : r6700_firmware r6900_firmware r6900p_firmware r7000_firmware r7000p_firmware r6400v2_firmware r6700v3_firmware r7850_firmware r7900_firmware r8000_firmware +12 more products- Published: Sep. 21, 2021
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2021-40846
An issue was discovered in Rhinode Trading Paints through 2.0.36. TP Updater.exe uses cleartext HTTP to check, and request, updates. Thus, attackers can man-in-the-middle a victim to download a malicious binary in place of the real update, with no SSL err... Read more
Affected Products : trading_paints- Published: Mar. 04, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-40845
The web part of Zenitel AlphaCom XE Audio Server through 11.2.3.10, called AlphaWeb XE, does not restrict file upload in the Custom Scripts section at php/index.php. Neither the content nor extension of the uploaded files is checked, allowing execution of... Read more
Affected Products : alphacom_xe_audio_server- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2021-40843
Proofpoint Insider Threat Management Server contains an unsafe deserialization vulnerability in the Web Console. An attacker with write access to the local database could cause arbitrary code to execute with SYSTEM privileges on the underlying server when... Read more
- Published: Oct. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40842
Proofpoint Insider Threat Management Server contains a SQL injection vulnerability in the Web Console. The vulnerability exists due to improper input validation on the database name parameter required in certain unauthenticated APIs. A malicious URL visit... Read more
- Published: Oct. 13, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-40841
A Path Traversal vulnerability for a log file in LiveConfig 2.12.2 allows authenticated attackers to read files on the underlying server.... Read more
Affected Products : liveconfig- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-40840
A Stored XSS issue exists in the admin/users user administration form in LiveConfig 2.12.2.... Read more
Affected Products : liveconfig- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-40839
The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that consumes CPU and memory.... Read more
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-40837
A vulnerability affecting F-Secure antivirus engine before Capricorn update 2022-02-01_01 was discovered whereby decompression of ACE file causes the scanner service to stop. The vulnerability can be exploited remotely by an attacker. A successful attack ... Read more
- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-40836
A vulnerability affecting F-Secure antivirus engine was discovered whereby scanning MS outlook .pst files can lead to denial-of-service. The vulnerability can be exploited remotely by an attacker. A successful attack will result in denial-of-service of th... Read more
- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024