Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2021-3160

    Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product allows a remote attacker to inject unsecure serialized Java object using a specially crafted HTTP request, resulting in an unauthentica... Read more

    Affected Products : assuweb
    • Published: Jan. 28, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-3159

    A stored cross site scripting (XSS) vulnerability in the /sys/attachment/uploaderServlet component of Landray EKP V12.0.9.R.20160325 allows attackers to execute arbitrary web scripts or HTML via a crafted SVG, SHTML, or MHT file.... Read more

    Affected Products : landray_ekp
    • Published: Jul. 23, 2021
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2021-3155

    snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04... Read more

    Affected Products : ubuntu_linux snapd
    • Published: Feb. 17, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-3154

    An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords via macro Injection. NOTE: this had a distinct fix relative to CVE-2020-35481.... Read more

    Affected Products : serv-u
    • Published: May. 04, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-3153

    HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two-factor authentication enabled. Fixed in v202103-1.... Read more

    Affected Products : terraform terraform_enterprise
    • Published: Mar. 26, 2021
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-3152

    Home Assistant before 2021.1.3 does not have a protection layer that can help to prevent directory-traversal attacks against custom integrations. NOTE: the vendor's perspective is that the vulnerability itself is in custom integrations written by third pa... Read more

    Affected Products : home-assistant
    • Published: Jan. 26, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-3151

    i-doit before 1.16.0 is affected by Stored Cross-Site Scripting (XSS) issues that could allow remote authenticated attackers to inject arbitrary web script or HTML via C__MONITORING__CONFIG__TITLE, SM2__C__MONITORING__CONFIG__TITLE, C__MONITORING__CONFIG_... Read more

    Affected Products : i-doit
    • Published: Feb. 27, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-3150

    A cross-site scripting (XSS) vulnerability on the Delete Personal Data page in Cryptshare Server before 4.8.0 allows an attacker to inject arbitrary web script or HTML via the user name. The issue is fixed with the version 4.8.1... Read more

    Affected Products : cryptshare_server
    • Published: Mar. 15, 2021
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2021-3149

    On Netshield NANO 25 10.2.18 devices, /usr/local/webmin/System/manual_ping.cgi allows OS command injection (after authentication by the attacker) because the system C library function is used unsafely.... Read more

    Affected Products : nano_25_firmware nano_25
    • Published: Feb. 22, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-3148

    An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quotes. This is related to salt/utils/th... Read more

    Affected Products : fedora debian_linux salt
    • Published: Feb. 27, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-3146

    The Dolby Audio X2 (DAX2) API service before 0.8.8.90 on Windows allows local users to gain privileges.... Read more

    • Published: Apr. 08, 2021
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-3145

    In Ionic Identity Vault before 5, a local root attacker on an Android device can bypass biometric authentication.... Read more

    Affected Products : identity_vault
    • Published: Sep. 10, 2021
    • Modified: Nov. 21, 2024
  • 9.1

    CRITICAL
    CVE-2021-3144

    In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)... Read more

    Affected Products : fedora debian_linux salt
    • Published: Feb. 27, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-3141

    In Unisys Stealth (core) before 6.0.025.0, the Keycloak password is stored in a recoverable format that might be accessible by a local attacker, who could gain access to the Management Server and change the Stealth configuration.... Read more

    Affected Products : stealth
    • Published: Mar. 18, 2021
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2021-3139

    In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For exa... Read more

    Affected Products : tcmu-runner
    • Published: Jan. 13, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-3138

    In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.... Read more

    Affected Products : discourse
    • Published: Jan. 14, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-3137

    XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section.... Read more

    Affected Products : xwiki
    • Published: Jan. 20, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-3135

    An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.php td_block_id parameter in a td_ajax_block API call.... Read more

    Affected Products : newspaper
    • Published: Jul. 19, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-3134

    Mubu 2.2.1 allows local users to gain privileges to execute commands, aka CNVD-2020-68878.... Read more

    Affected Products : mubu
    • Published: Jan. 12, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-3133

    The Elementor Contact Form DB plugin before 1.6 for WordPress allows CSRF via backend admin pages.... Read more

    Affected Products : elementor_contact_form_db
    • Published: Jan. 12, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 293302 Results