Latest CVE Feed
-
7.1
HIGHCVE-2021-38312
The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress used an incorrect authorization check in the REST API endpoints registered under the “redux/v1/templates/” REST Route in “redux-templates/classes/class-api.php”. The `permissi... Read more
Affected Products : gutenberg_template_library_\&_redux_framework- EPSS Score: %0.22
- Published: Sep. 02, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38311
In Contiki 3.0, potential nonterminating acknowledgment loops exist in the Telnet service. When the negotiated options are already disabled, servers still respond to DONT and WONT requests with WONT or DONT commands, which may lead to infinite acknowledgm... Read more
Affected Products : contiki- EPSS Score: %0.28
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-38306
Network Attached Storage on LG N1T1*** 10124 devices allows an unauthenticated attacker to gain root access via OS command injection in the en/ajp/plugins/access.ssh/checkInstall.php destServer parameter.... Read more
- EPSS Score: %31.59
- Published: Aug. 24, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-38305
23andMe Yamale before 3.0.8 allows remote attackers to execute arbitrary code via a crafted schema file. The schema parser uses eval as part of its processing, and tries to protect from malicious expressions by limiting the builtins that are passed to the... Read more
Affected Products : yamale- EPSS Score: %0.64
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-38304
Improper input validation in the National Instruments NI-PAL driver in versions 20.0.0 and prior may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products : ni-pal- EPSS Score: %0.05
- Published: Sep. 17, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38303
A SQL injection vulnerability exists in Sureline SUREedge Migrator 7.0.7.29360.... Read more
Affected Products : sureedge_migrator- EPSS Score: %0.26
- Published: Sep. 28, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38302
The Newsletter extension through 4.0.0 for TYPO3 allows SQL Injection.... Read more
Affected Products : newsletter- EPSS Score: %0.38
- Published: Aug. 13, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-38300
arch/mips/net/bpf_jit.c in the Linux kernel before 5.4.10 can generate undesirable machine code when transforming unprivileged cBPF programs, allowing execution of arbitrary code within the kernel context. This occurs because conditional branches can exce... Read more
Affected Products : linux_kernel debian_linux h410c_firmware cloud_backup h300s_firmware h500s_firmware h700s_firmware h410s_firmware h300s h410s +9 more products- EPSS Score: %0.06
- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38299
Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to login to a vulnerable service using an attached FIDO2 authenticator without passing a check of the user presence.... Read more
Affected Products : webauthn_framwork- EPSS Score: %0.35
- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38298
Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.... Read more
Affected Products : manageengine_admanager_plus- EPSS Score: %5.60
- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38297
Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module, when GOARCH=wasm GOOS=js is used.... Read more
- EPSS Score: %5.85
- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38296
Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key recovery. After... Read more
- EPSS Score: %0.86
- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2021-38295
In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB admin opens that attachment in a browser, e.g. via the CouchDB admin interface Fauxton, any JavaScript co... Read more
Affected Products : couchdb- EPSS Score: %11.52
- Published: Oct. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38294
A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to auth... Read more
Affected Products : storm- EPSS Score: %87.81
- Published: Oct. 25, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38291
FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion failure at src/libavutil/mathematics.c.... Read more
- EPSS Score: %0.14
- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-38290
A host header attack vulnerability exists in FUEL CMS 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel/modules/fuel/libraries/Asset.php. An attacker can use a man in the middle attack such as phishing.... Read more
Affected Products : fuel_cms- EPSS Score: %0.44
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-38289
An issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allows attackers to view corporate information and SMTP server details, delete users, view roles, and other unspecified impacts.... Read more
Affected Products : novaicare- EPSS Score: %0.29
- Published: Jul. 12, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38283
Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read application log files containing sensitive information via a predictable /log URI.... Read more
Affected Products : holmes- EPSS Score: %0.70
- Published: Nov. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38278
Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the urls parameter in the saveParentControlInfo function.... Read more
- EPSS Score: %0.52
- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38269
Cross-site scripting (XSS) vulnerability in the Gogo Shell module in Liferay Portal 7.1.0 through 7.3.6 and 7.4.0, and Liferay DXP 7.1 before fix pack 23, 7.2 before fix pack 13, and 7.3 before fix pack 2 allows remote attackers to inject arbitrary web sc... Read more
- EPSS Score: %0.18
- Published: Mar. 03, 2022
- Modified: Nov. 21, 2024