Latest CVE Feed
-
7.5
HIGHCVE-2021-40340
Information Exposure vulnerability in Hitachi Energy LinkOne application, due to a misconfiguration in the ASP server exposes server and ASP.net information, an attacker that manages to exploit this vulnerability can use the exposed information as a recon... Read more
Affected Products : linkone- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-40339
Configuration vulnerability in Hitachi Energy LinkOne application due to the lack of HTTP Headers, allows an attacker that manages to exploit this vulnerability to retrieve sensitive information. This issue affects: Hitachi Energy LinkOne 3.20; 3.22; 3.23... Read more
Affected Products : linkone- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-40338
Hitachi Energy LinkOne product, has a vulnerability due to a web server misconfiguration, that enables debug mode and reveals the full path of the filesystem directory when an attacker generates errors during a query operation. This issue affects: Hitachi... Read more
Affected Products : linkone- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-40337
Cross-site Scripting (XSS) vulnerability in Hitachi Energy LinkOne allows an attacker that manages to exploit the vulnerability can take advantage to exploit multiple web attacks and stole sensitive information. This issue affects: Hitachi Energy LinkOne ... Read more
Affected Products : linkone- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-40336
A vulnerability exists in the http web interface where the web interface does not validate data in an HTTP header. This causes a possible HTTP response splitting, which if exploited could lead an attacker to channel down harmful code into the user’s web b... Read more
- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-40335
A vulnerability exists in the HTTP web interface where the web interface does not sufficiently verify if a well-formed, valid, consistent request was intentionally provided by the user who submitted the request. This cause a Cross Site Request Forgery (CS... Read more
- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-40334
Missing Handler vulnerability in the proprietary management protocol (port TCP 5558) of Hitachi Energy FOX61x, XCM20 allows an attacker that exploits the vulnerability by activating SSH on port TCP 5558 to cause disruption to the NMS and NE communication.... Read more
- Published: Dec. 02, 2021
- Modified: Nov. 21, 2024
-
9.0
CRITICALCVE-2021-40333
Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM20 allows an attacker to gain unauthorized access to the Data Communication Network (DCN) routing configuration. This issue affects: Hitachi Energy FOX61x versions prior to R15A. Hitach... Read more
- Published: Dec. 02, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-40331
An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on a database can alter the ownership of the table in Hive when Apache Ranger Hive Plugin is enabled This iss... Read more
Affected Products : ranger- Published: May. 05, 2023
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-40330
git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cross-protocol requests, as demonstrated by the git://localhost:1234/%0d%0a%0d%0aGET%20/%20HTTP/1.1 substring.... Read more
- Published: Aug. 31, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40329
The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management.... Read more
Affected Products : pingfederate- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-40327
Trusted Firmware-M (TF-M) 1.4.0, when Profile Small is used, has incorrect access control. NSPE can access a secure key (held by the Crypto service) based solely on knowledge of its key ID. For example, there is no authorization check associated with the ... Read more
- Published: Jan. 13, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-40326
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental data in signed documents. An attacker can write to an arbitrary file, and display controlled contents, during signature verification.... Read more
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-40325
Cobbler before 3.3.0 allows authorization bypass for modification of settings.... Read more
- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-40324
Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.... Read more
- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40323
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.... Read more
- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-40317
Piwigo 11.5.0 is affected by a SQL injection vulnerability via admin.php and the id parameter.... Read more
Affected Products : piwigo- Published: May. 26, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-40313
Piwigo v11.5 was discovered to contain a SQL injection vulnerability via the parameter pwg_token in /admin/batch_manager_global.php.... Read more
Affected Products : piwigo- Published: Dec. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-40310
OpenSIS Community Edition version 8.0 is affected by a cross-site scripting (XSS) vulnerability in the TakeAttendance.php via the cp_id_miss_attn parameter.... Read more
Affected Products : opensis- Published: Sep. 24, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-40309
A SQL injection vulnerability exists in the Take Attendance functionality of OS4Ed's OpenSIS 8.0. allows an attacker to inject their own SQL query. The cp_id_miss_attn parameter from TakeAttendance.php is vulnerable to SQL injection. An attacker can make ... Read more
Affected Products : opensis- Published: Sep. 24, 2021
- Modified: Nov. 21, 2024