Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2021-40346

    An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.... Read more

    Affected Products : fedora debian_linux haproxy
    • Published: Sep. 08, 2021
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2021-40345

    An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can upload ZIP files. A command injection (within the name of the first file in the archive) allows an attacker to execute system commands.... Read more

    Affected Products : nagios_xi
    • Published: Oct. 26, 2021
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-40344

    An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, an administrator can upload files with arbitrary extensions as long as the MIME type corresponds to an image. Therefore it is possible to upload a crafted PHP s... Read more

    Affected Products : nagios_xi
    • Published: Oct. 26, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-40343

    An issue was discovered in Nagios XI 5.8.5. Insecure file permissions on the nagios_unbundler.py file allow the nagios user to elevate their privileges to the root user.... Read more

    Affected Products : nagios_xi
    • Published: Oct. 26, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-40342

    In the DES implementation, the affected product versions use a default key for encryption. Successful exploitation allows an attacker to obtain sensitive information and gain access to the network elements that are managed by the affected products versio... Read more

    Affected Products : foxman-un unem
    • Published: Jan. 05, 2023
    • Modified: Nov. 21, 2024
  • 7.1

    HIGH
    CVE-2021-40341

    DES cipher, which has inadequate encryption strength, is used Hitachi Energy FOXMAN-UN to encrypt user credentials used to access the Network Elements. Successful exploitation allows sensitive information to be decrypted easily. This issue affects  *... Read more

    Affected Products : foxman-un unem
    • Published: Jan. 05, 2023
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-40340

    Information Exposure vulnerability in Hitachi Energy LinkOne application, due to a misconfiguration in the ASP server exposes server and ASP.net information, an attacker that manages to exploit this vulnerability can use the exposed information as a recon... Read more

    Affected Products : linkone
    • Published: Jan. 28, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-40339

    Configuration vulnerability in Hitachi Energy LinkOne application due to the lack of HTTP Headers, allows an attacker that manages to exploit this vulnerability to retrieve sensitive information. This issue affects: Hitachi Energy LinkOne 3.20; 3.22; 3.23... Read more

    Affected Products : linkone
    • Published: Jan. 28, 2022
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-40338

    Hitachi Energy LinkOne product, has a vulnerability due to a web server misconfiguration, that enables debug mode and reveals the full path of the filesystem directory when an attacker generates errors during a query operation. This issue affects: Hitachi... Read more

    Affected Products : linkone
    • Published: Jan. 28, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-40337

    Cross-site Scripting (XSS) vulnerability in Hitachi Energy LinkOne allows an attacker that manages to exploit the vulnerability can take advantage to exploit multiple web attacks and stole sensitive information. This issue affects: Hitachi Energy LinkOne ... Read more

    Affected Products : linkone
    • Published: Jan. 25, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-40336

    A vulnerability exists in the http web interface where the web interface does not validate data in an HTTP header. This causes a possible HTTP response splitting, which if exploited could lead an attacker to channel down harmful code into the user’s web b... Read more

    • Published: Jul. 25, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-40335

    A vulnerability exists in the HTTP web interface where the web interface does not sufficiently verify if a well-formed, valid, consistent request was intentionally provided by the user who submitted the request. This cause a Cross Site Request Forgery (CS... Read more

    • Published: Jul. 25, 2022
    • Modified: Nov. 21, 2024
  • 8.6

    HIGH
    CVE-2021-40334

    Missing Handler vulnerability in the proprietary management protocol (port TCP 5558) of Hitachi Energy FOX61x, XCM20 allows an attacker that exploits the vulnerability by activating SSH on port TCP 5558 to cause disruption to the NMS and NE communication.... Read more

    • Published: Dec. 02, 2021
    • Modified: Nov. 21, 2024
  • 9.0

    CRITICAL
    CVE-2021-40333

    Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM20 allows an attacker to gain unauthorized access to the Data Communication Network (DCN) routing configuration. This issue affects: Hitachi Energy FOX61x versions prior to R15A. Hitach... Read more

    • Published: Dec. 02, 2021
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2021-40331

    An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on a database can alter the ownership of the table in Hive when Apache Ranger Hive Plugin is enabled This iss... Read more

    Affected Products : ranger
    • Published: May. 05, 2023
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-40330

    git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cross-protocol requests, as demonstrated by the git://localhost:1234/%0d%0a%0d%0aGET%20/%20HTTP/1.1 substring.... Read more

    Affected Products : debian_linux git
    • Published: Aug. 31, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-40329

    The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management.... Read more

    Affected Products : pingfederate
    • Published: Sep. 27, 2021
    • Modified: Nov. 21, 2024
  • 5.9

    MEDIUM
    CVE-2021-40327

    Trusted Firmware-M (TF-M) 1.4.0, when Profile Small is used, has incorrect access control. NSPE can access a secure key (held by the Crypto service) based solely on knowledge of its key ID. For example, there is no authorization check associated with the ... Read more

    • Published: Jan. 13, 2022
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2021-40326

    Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental data in signed documents. An attacker can write to an arbitrary file, and display controlled contents, during signature verification.... Read more

    Affected Products : windows pdf_editor pdf_reader phantompdf
    • Published: Aug. 29, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-40325

    Cobbler before 3.3.0 allows authorization bypass for modification of settings.... Read more

    Affected Products : cobbler cobbler
    • Published: Oct. 04, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 293350 Results