Latest CVE Feed
-
5.5
MEDIUMCVE-2021-37618
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to pri... Read more
- EPSS Score: %0.08
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2021-37617
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. The Nextcloud Desktop Client invokes its uninstaller script when being installed to make sure there are no remnants of previous installations. In versions 3... Read more
- EPSS Score: %0.30
- Published: Aug. 18, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-37616
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A null pointer dereference was found in Exiv2 versions v0.27.4 and earlier. The null pointer dereference is triggered when Exiv2 is ... Read more
- EPSS Score: %0.08
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-37615
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A null pointer dereference was found in Exiv2 versions v0.27.4 and earlier. The null pointer dereference is triggered when Exiv2 is ... Read more
- EPSS Score: %0.08
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-37614
In certain Progress MOVEit Transfer versions before 2021.0.3 (aka 13.0.3), SQL injection in the MOVEit Transfer web application could allow an authenticated remote attacker to gain access to the database. Depending on the database engine being used (MySQL... Read more
Affected Products : moveit_transfer- EPSS Score: %0.17
- Published: Aug. 05, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-37613
Stormshield Network Security (SNS) 1.0.0 through 4.2.3 allows a Denial of Service.... Read more
Affected Products : stormshield_network_security- EPSS Score: %0.21
- Published: Feb. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37608
Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apache OFBiz version 17.12.07 and prior versions. Upgrade to at least 17.12.08 or apply patches at https://issu... Read more
Affected Products : ofbiz- EPSS Score: %4.52
- Published: Aug. 18, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-37606
Meow hash 0.5/calico does not sufficiently thwart key recovery by an attacker who can query whether there's a collision in the bottom bits of the hashes of two messages, as demonstrated by an attack against a long-running web service that allows the attac... Read more
Affected Products : meow_hash- EPSS Score: %0.17
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-37605
In version 6.5 Microchip MiWi software and all previous versions including legacy products, the stack is validating only two out of four Message Integrity Check (MIC) bytes.... Read more
Affected Products : miwi- EPSS Score: %0.47
- Published: Aug. 05, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-37604
In version 6.5 of Microchip MiWi software and all previous versions including legacy products, there is a possibility of frame counters being validated/updated prior to the message authentication. With this vulnerability in place, an attacker may incremen... Read more
Affected Products : miwi- EPSS Score: %0.48
- Published: Aug. 05, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-37601
muc.lib.lua in Prosody 0.11.0 through 0.11.9 allows remote attackers to obtain sensitive information (list of admins, members, owners, and banned entities of a Multi-User chat room) in some common configurations.... Read more
Affected Products : prosody- EPSS Score: %0.67
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-37600
An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way that leads to a large number in the /proc/sysvipc/sem file. NOTE: this is unexploitable in GNU C Library env... Read more
- EPSS Score: %0.04
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37599
The exporter/Login.aspx login form in the Exporter in Nuance Winscribe Dictation 4.1.0.99 is vulnerable to SQL injection that allows a remote, unauthenticated attacker to read the database (and execute code in some situations) via the txtPassword paramete... Read more
Affected Products : winscribe_dictation- EPSS Score: %8.15
- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-37598
WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.... Read more
Affected Products : wp_cerber- EPSS Score: %0.25
- Published: Aug. 19, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37597
WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation.... Read more
Affected Products : wp_cerber- EPSS Score: %0.80
- Published: Aug. 19, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-37596
Telegram Web K Alpha 0.6.1 allows XSS via a document name.... Read more
Affected Products : web_k_alpha- EPSS Score: %0.22
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37595
In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input checks for a FILECONTENTS_RANGE File Contents Request PDU.... Read more
- EPSS Score: %0.42
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37594
In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input checks for a FILECONTENTS_SIZE File Contents Request PDU.... Read more
- EPSS Score: %0.42
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-37593
PEEL Shopping version 9.4.0 allows remote SQL injection. A public user/guest (unauthenticated) can inject a malicious SQL query in order to affect the execution of predefined SQL commands. Upon a successful SQL injection attack, an attacker can read sensi... Read more
Affected Products : peel_shopping- EPSS Score: %0.70
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37592
Suricata before 5.0.8 and 6.x before 6.0.4 allows TCP evasion via a client with a crafted TCP/IP stack that can send a certain sequence of segments.... Read more
Affected Products : suricata- EPSS Score: %0.18
- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024