Latest CVE Feed
-
6.5
MEDIUMCVE-2021-3557
A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-server, the unprivileged user is able to read all resources of the cluster including all secrets which might en... Read more
- Published: Feb. 16, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-3555
A Buffer Overflow vulnerability in the RSTP server component of Eufy Indoor 2K Indoor Camera allows a local attacker to achieve remote code execution. This issue affects: Eufy Indoor 2K Indoor Camera 2.0.9.3 version and prior versions.... Read more
Affected Products : solo_indoorcam_c24_firmware solo_indoorcam_p24_firmware solo_indoorcam_c24 solo_indoorcam_p24- Published: May. 31, 2022
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-3554
Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for Linux as a relay role allows an attacker to manipulate the remote address used for pulling patches. This issue affects: Bitdefender En... Read more
- Published: Nov. 24, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-3553
A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService of Bitdefender Endpoint Security Tools allows an attacker to use the Endpoint Protection relay as a proxy for any remote host. This issue affects: Bitdefender Endpoint Security Too... Read more
- Published: Nov. 24, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-3552
A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to proxy requests to the relay server. This issue affects: Bitdefender Endpoint Security Tools versions prior to... Read more
- Published: Nov. 24, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-3551
A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password and gain admin privileges t... Read more
Affected Products : enterprise_linux fedora enterprise_linux_server_aus enterprise_linux_server_tus enterprise_linux_eus linux enterprise_linux_for_ibm_z_systems_eus enterprise_linux_for_power_little_endian enterprise_linux_for_power_little_endian_eus enterprise_linux_server_update_services_for_sap_solutions +2 more products- Published: Feb. 16, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-3550
A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.500.5102, that could allow privilege escalation.... Read more
Affected Products : pcmanager- Published: Jul. 16, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-3548
A flaw was found in dmg2img through 20170502. dmg2img did not validate the size of the read buffer during memcpy() inside the main() function. This possibly leads to memory layout information leaking in the data. This might be used in a chain of vulnerabi... Read more
Affected Products : dmg2img- Published: May. 26, 2021
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2021-3547
OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.... Read more
Affected Products : openvpn- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2021-3546
An out-of-bounds write vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The flaw occurs while processing the 'VIRTIO_GPU_CMD_GET_CAPSET' command from the guest. It could allow a priv... Read more
- Published: Jun. 02, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-3545
An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The flaw exists in virgl_cmd_get_capset_info() in contrib/vhost-user-gpu/virgl.c and could occur due to the... Read more
- Published: Jun. 02, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-3544
Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. They exist in contrib/vhost-user-gpu/vhost-user-gpu.c and contrib/vhost-user-gpu/virgl.c due to improper release of memory (i... Read more
- Published: Jun. 02, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-3543
A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descriptor. A local user of a host machine could use this flaw to crash the system or escalate their privileges ... Read more
- Published: Jun. 01, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-3541
A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.... Read more
Affected Products : zfs_storage_appliance_kit active_iq_unified_manager h410c_firmware ontap_select_deploy_administration_utility cloud_backup libxml2 h300s_firmware h500s_firmware h700s_firmware h410s_firmware +17 more products- Published: Jul. 09, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-3540
By abusing the 'install rpm info detail' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.... Read more
Affected Products : mobileiron- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2021-3539
EspoCRM 6.1.6 and prior suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This issue was fixed in version 6.1.7 of the product.... Read more
Affected Products : espocrm- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-3538
A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45. Due to insecure randomness in the g.rand.Read function the generated UUIDs are predictable for an a... Read more
- Published: Jun. 02, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-3537
A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could be u... Read more
- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-3536
A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity.... Read more
- Published: May. 20, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-3535
Rapid7 Nexpose is vulnerable to a non-persistent cross-site scripting vulnerability affecting the Security Console's Filtered Asset Search feature. A specific search criterion and operator combination in Filtered Asset Search could have allowed a user to ... Read more
Affected Products : nexpose- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024