Latest CVE Feed
-
7.5
HIGHCVE-2021-3795
semver-regex is vulnerable to Inefficient Regular Expression Complexity... Read more
Affected Products : semver-regex- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-3794
vuelidate is vulnerable to Inefficient Regular Expression Complexity... Read more
Affected Products : vuelidate- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-3793
An improper access control vulnerability was reported in some Motorola-branded Binatone Hubble Cameras which could allow an unauthenticated attacker on the same network as the device to access administrative pages that could result in information disclosu... Read more
Affected Products : halo\+_camera_firmware comfort_85_connect_firmware mbp3855_firmware focus_68_firmware focus_72r_firmware cn28_firmware cn50_firmware comfort_40_firmware comfort_50_connect_firmware mbp4855_firmware +32 more products- Published: Nov. 12, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-3792
Some device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypted which could lead to the communication channel being accessible by an attacker.... Read more
Affected Products : halo\+_camera_firmware comfort_85_connect_firmware mbp3855_firmware focus_68_firmware focus_72r_firmware cn28_firmware cn50_firmware comfort_40_firmware comfort_50_connect_firmware mbp4855_firmware +32 more products- Published: Nov. 12, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-3791
An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same subnet to download an encrypted log file containing sensitive information such as WiFi SSID and ... Read more
Affected Products : halo\+_camera_firmware comfort_85_connect_firmware mbp3855_firmware focus_68_firmware focus_72r_firmware cn28_firmware cn50_firmware comfort_40_firmware comfort_50_connect_firmware mbp4855_firmware +32 more products- Published: Nov. 12, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-3790
A buffer overflow was reported in the local web server of some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same network to perform a denial-of-service attack against the device.... Read more
Affected Products : halo\+_camera_firmware comfort_85_connect_firmware mbp3855_firmware focus_68_firmware focus_72r_firmware cn28_firmware cn50_firmware comfort_40_firmware comfort_50_connect_firmware mbp4855_firmware +32 more products- Published: Nov. 12, 2021
- Modified: Nov. 21, 2024
-
4.6
MEDIUMCVE-2021-3789
An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access to obtain the encryption key used to decrypt firmware update packages.... Read more
Affected Products : halo\+_camera_firmware comfort_85_connect_firmware mbp3855_firmware focus_68_firmware focus_72r_firmware cn28_firmware cn50_firmware comfort_40_firmware comfort_50_connect_firmware mbp4855_firmware +32 more products- Published: Nov. 12, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-3788
An exposed debug interface was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access unauthorized access to the device.... Read more
Affected Products : halo\+_camera_firmware comfort_85_connect_firmware mbp3855_firmware focus_68_firmware focus_72r_firmware cn28_firmware cn50_firmware comfort_40_firmware comfort_50_connect_firmware mbp4855_firmware +32 more products- Published: Nov. 12, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-3787
A vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with local access to obtain the MQTT credentials that could result in unauthorized access to backend Hubble services.... Read more
Affected Products : halo\+_camera_firmware comfort_85_connect_firmware mbp3855_firmware focus_68_firmware focus_72r_firmware cn28_firmware cn50_firmware comfort_40_firmware comfort_50_connect_firmware mbp4855_firmware +32 more products- Published: Nov. 12, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-3786
A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data out of the SMRAM range.... Read more
- Published: Nov. 12, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-3785
yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
Affected Products : yourls- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2021-3784
Garuda Linux performs an insecure user creation and authentication that allows any user to impersonate the created account. By creating users from the 'Garuda settings manager', an insecure procedure is performed that keeps the created user without an ass... Read more
Affected Products : garuda_linux- Published: Oct. 04, 2023
- Modified: Nov. 21, 2024
-
6.6
MEDIUMCVE-2021-3783
yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
Affected Products : yourls- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2021-3781
A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the cont... Read more
- Published: Feb. 16, 2022
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2021-3780
peertube is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
Affected Products : peertube- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-3779
A malicious MySQL server can request local file content from a client using ruby-mysql prior to version 2.10.0 without explicit authorization from the user. This issue was resolved in version 2.10.0 and later.... Read more
Affected Products : ruby-mysql- Published: Jun. 28, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGH- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-3777
nodejs-tmpl is vulnerable to Inefficient Regular Expression Complexity... Read more
Affected Products : tmpl- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2021-3776
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)... Read more
Affected Products : showdoc- Published: Nov. 13, 2021
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2021-3775
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)... Read more
Affected Products : showdoc- Published: Nov. 13, 2021
- Modified: Nov. 21, 2024