Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.2

    HIGH
    CVE-2021-38520

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.52, R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R6700v2 before 1.2.0.62, R6900v2 before 1.2.0.62, and R7000P before 1.3.2.124.... Read more

    • EPSS Score: %0.26
    • Published: Aug. 11, 2021
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-38519

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6250 before 1.0.4.36, R6300v2 before 1.0.4.36, R6400 before 1.0.1.50, R6400v2 before 1.0.2.66, R6700v3 before 1.0.2.66, R6700 before 1.0.2.8, R6900 before 1.... Read more

    • EPSS Score: %0.14
    • Published: Aug. 11, 2021
    • Modified: Nov. 21, 2024
  • 8.4

    HIGH
    CVE-2021-38518

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX200 before 1.0.4.120, RAX75 before 1.0.4.120, RAX80 before 1.0.4.120, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.... Read more

    • EPSS Score: %1.14
    • Published: Aug. 11, 2021
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-38517

    Certain NETGEAR devices are affected by out-of-bounds reads and writes. This affects R6400 before 1.0.1.70, RAX75 before 1.0.4.120, RAX80 before 1.0.4.120, and XR300 before 1.0.3.50.... Read more

    • EPSS Score: %0.31
    • Published: Aug. 11, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2021-38516

    Certain NETGEAR devices are affected by lack of access control at the function level. This affects D6220 before 1.0.0.48, D6400 before 1.0.0.82, D7000v2 before 1.0.0.52, D7800 before 1.0.1.44, D8500 before 1.0.3.43, DC112A before 1.0.0.40, DGN2200v4 befor... Read more

    • EPSS Score: %0.44
    • Published: Aug. 11, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-38515

    Certain NETGEAR devices are affected by denial of service. This affects R6400v2 before 1.0.4.98, R6700v3 before 1.0.4.98, R7900 before 1.0.3.18, and R8000 before 1.0.4.46.... Read more

    • EPSS Score: %0.12
    • Published: Aug. 11, 2021
    • Modified: Nov. 21, 2024
  • 4.0

    MEDIUM
    CVE-2021-38514

    Certain NETGEAR devices are affected by authentication bypass. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72, D6100 before 1.0.0.63, D6200 before 1.1.00.34, D6220 before 1.0.0.48, D6400 before 1.0.0.86, D7000 before 1.0.1.70, D7000v2 before 1.... Read more

    • EPSS Score: %0.25
    • Published: Aug. 11, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2021-38513

    Certain NETGEAR devices are affected by authentication bypass. This affects RBK852 before 3.2.10.11, RBR850 before 3.2.10.11, RBS850 before 3.2.10.11, CBR40 before 2.5.0.10, EAX20 before 1.0.0.48, MK62 before 1.0.6.110, MR60 before 1.0.6.110, MS60 before ... Read more

    • EPSS Score: %0.32
    • Published: Aug. 11, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-38512

    An issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggling (aka HRS) can occur, potentially leading to credential disclosure.... Read more

    Affected Products : fedora actix-http
    • EPSS Score: %0.42
    • Published: Aug. 10, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-38511

    An issue was discovered in the tar crate before 0.4.36 for Rust. When symlinks are present in a TAR archive, extraction can create arbitrary directories via .. traversal.... Read more

    Affected Products : tar
    • EPSS Score: %0.34
    • Published: Aug. 10, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-38510

    The executable file warning was not presented when downloading .inetloc files, which, due to a flaw in Mac OS, can run commands on a user's computer.*Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This v... Read more

    Affected Products : firefox firefox_esr thunderbird macos
    • EPSS Score: %0.47
    • Published: Dec. 08, 2021
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2021-38509

    Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top an uncontrolled webpage of the attacker's choosing. This vulnerability affects Firefox < 94, Thun... Read more

    • EPSS Score: %0.40
    • Published: Dec. 08, 2021
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2021-38508

    By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could have obscured the prompt, resulting in the user potentially being tricked into granting the permiss... Read more

    • EPSS Score: %0.32
    • Published: Dec. 08, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-38507

    The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while retaining the visual properties of an HTTP connection, including being same-origin with unencrypted connections on port 80. However, if ... Read more

    • EPSS Score: %0.34
    • Published: Dec. 08, 2021
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2021-38506

    Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3,... Read more

    • EPSS Score: %0.24
    • Published: Dec. 08, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-38505

    Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it available on other computers in certain scenarios. Applications that wish to prevent copied dat... Read more

    • EPSS Score: %0.44
    • Published: Dec. 08, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-38504

    When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-after-free could have resulted, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 94, Thunderbird < 91.3,... Read more

    • EPSS Score: %0.43
    • Published: Dec. 08, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2021-38503

    The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < ... Read more

    • EPSS Score: %1.39
    • Published: Dec. 08, 2021
    • Modified: Nov. 21, 2024
  • 5.9

    MEDIUM
    CVE-2021-38502

    Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen by the... Read more

    Affected Products : thunderbird debian_linux
    • EPSS Score: %0.46
    • Published: Nov. 03, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-38501

    Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This v... Read more

    Affected Products : firefox firefox_esr thunderbird
    • EPSS Score: %0.88
    • Published: Nov. 03, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 291782 Results