Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2021-37548

    In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS.... Read more

    Affected Products : teamcity
    • EPSS Score: %0.00
    • Published: Aug. 06, 2021
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-37547

    In JetBrains TeamCity before 2020.2.4, insufficient checks during file uploading were made.... Read more

    Affected Products : teamcity
    • EPSS Score: %0.00
    • Published: Aug. 06, 2021
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-37546

    In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used.... Read more

    Affected Products : teamcity
    • EPSS Score: %0.00
    • Published: Aug. 06, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-37545

    In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made.... Read more

    Affected Products : teamcity
    • EPSS Score: %0.00
    • Published: Aug. 06, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-37544

    In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization.... Read more

    Affected Products : teamcity
    • EPSS Score: %0.02
    • Published: Aug. 06, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-37543

    In JetBrains RubyMine before 2021.1.1, code execution without user confirmation was possible for untrusted projects.... Read more

    Affected Products : rubymine
    • EPSS Score: %0.01
    • Published: Aug. 06, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-37542

    In JetBrains TeamCity before 2020.2.3, XSS was possible.... Read more

    Affected Products : teamcity
    • EPSS Score: %0.01
    • Published: Aug. 06, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-37541

    In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.... Read more

    Affected Products : hub
    • EPSS Score: %0.00
    • Published: Aug. 06, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-37540

    In JetBrains Hub before 2021.1.13262, a potentially insufficient CSP for the Widget deployment feature was used.... Read more

    Affected Products : hub
    • EPSS Score: %0.00
    • Published: Aug. 06, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-37539

    Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.... Read more

    Affected Products : manageengine_admanager_plus
    • EPSS Score: %38.22
    • Published: Sep. 27, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-37538

    Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to execute arbitrary SQL commands via the day, month, or year parameter to the controllers/front/archive.php archive contr... Read more

    Affected Products : smartblog
    • EPSS Score: %84.26
    • Published: Aug. 24, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2021-37535

    SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization checks for user privileges.... Read more

    • EPSS Score: %0.34
    • Published: Sep. 14, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-37534

    app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster.... Read more

    Affected Products : misp
    • EPSS Score: %0.23
    • Published: Jul. 26, 2021
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2021-37532

    SAP Business One version - 10, due to improper input validation, allows an authenticated User to gain access to directory and view the contents of index in the directory, which would otherwise be restricted to high privileged User.... Read more

    Affected Products : business_one
    • EPSS Score: %0.24
    • Published: Sep. 14, 2021
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2021-37531

    SAP NetWeaver Knowledge Management XML Forms versions - 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, contains an XSLT vulnerability which allows a non-administrative authenticated attacker to craft a malicious XSL stylesheet file containing a script with OS-level ... Read more

    • EPSS Score: %4.22
    • Published: Sep. 14, 2021
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2021-37530

    A denial of service vulnerabiity exists in fig2dev through 3.28a due to a segfault in the open_stream function in readpics.c.... Read more

    Affected Products : debian_linux fig2dev
    • EPSS Score: %0.39
    • Published: Jan. 12, 2022
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2021-37529

    A double-free vulnerability exists in fig2dev through 3.28a is affected by: via the free_stream function in readpics.c, which could cause a denial of service (context-dependent).... Read more

    Affected Products : debian_linux fig2dev
    • EPSS Score: %0.39
    • Published: Jan. 12, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-37524

    Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.26 allows remote unauthenticated users to inject arbitrary web script or HTML via an unsanitized "path" parameter in resources/login.php.... Read more

    Affected Products : fusionpbx
    • EPSS Score: %0.95
    • Published: Jul. 01, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-37522

    SQL injection vulnerability in HKing2802 Locke-Bot 2.0.2 allows remote attackers to run arbitrary SQL commands via crafted string to /src/db.js, /commands/mute.js, /modules/event/messageDelete.js.... Read more

    Affected Products : locke-bot
    • EPSS Score: %0.23
    • Published: Jul. 18, 2023
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-37517

    An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application allows email addresses as usernames, which can cause a Denial of Service.... Read more

    Affected Products : dolibarr_erp\/crm
    • EPSS Score: %0.34
    • Published: Mar. 31, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 291712 Results