Latest CVE Feed
-
7.5
HIGHCVE-2021-37254
In M-Files Web product with versions before 20.10.9524.1 and 20.10.9445.0, a remote attacker could use a flaw to obtain unauthenticated access to 3rd party component license key information on server.... Read more
- EPSS Score: %0.32
- Published: Oct. 28, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-37253
M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range or Request-Range headers). NOTE: this is disputed because the range behavior is the responsibility of the web server, not the responsibi... Read more
- EPSS Score: %3.12
- Published: Dec. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37232
A stack overflow vulnerability occurs in Atomicparsley 20210124.204813.840499f through APar_read64() in src/util.cpp due to the lack of buffer size of uint32_buffer while reading more bytes in APar_read64.... Read more
Affected Products : atomicparsley- EPSS Score: %0.59
- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-37231
A stack-buffer-overflow occurs in Atomicparsley 20210124.204813.840499f through APar_readX() in src/util.cpp while parsing a crafted mp4 file because of the missing boundary check.... Read more
Affected Products : atomicparsley- EPSS Score: %0.34
- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-37223
Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. Any authenticated user can create scheduled reports containing PDF screenshots of any view in the NagiosXI application. Due to lack of ... Read more
Affected Products : nagios_xi- EPSS Score: %0.68
- Published: Oct. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37222
Parsers in the open source project RCDCAP before 1.0.5 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via specially crafted packets.... Read more
Affected Products : rcdcap- EPSS Score: %0.88
- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-37221
A file upload vulnerability exists in Sourcecodester Customer Relationship Management System 1.0 via the account update option & customer create option, which could let a remote malicious user upload an arbitrary php file. .... Read more
Affected Products : customer_relationship_management_system- EPSS Score: %0.40
- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-37220
MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.... Read more
- EPSS Score: %0.12
- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-37219
HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.8.15, 1.9.9 and 1.10.2.... Read more
Affected Products : consul- EPSS Score: %1.72
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-37218
HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.0.10 and 1.1.4.... Read more
Affected Products : nomad- EPSS Score: %0.17
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-37216
QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript without logging in and launch reflected XSS attacks to access and modify specific data.... Read more
- EPSS Score: %4.04
- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-37215
The employee management page of Flygo contains an Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attacker can manipulate the user data and then over-write another employee’s user data by specifyi... Read more
Affected Products : flygo- EPSS Score: %0.11
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-37214
The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID in specific parameters to arbitrary access employee's data, ... Read more
Affected Products : flygo- EPSS Score: %0.57
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-37213
The check-in record page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID and date in specific parameters to access particular employee’s ... Read more
Affected Products : flygo- EPSS Score: %0.11
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-37212
The bulletin function of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the bulletin ID in specific Url parameters and access and modify bulletin particula... Read more
Affected Products : flygo- EPSS Score: %0.11
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37211
The bulletin function of Flygo does not filter special characters while a new announcement is added. Remoter attackers can use the vulnerability with general user’s credential to inject JavaScript and execute stored XSS attacks.... Read more
Affected Products : flygo- EPSS Score: %0.16
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-37207
A vulnerability has been identified in SENTRON powermanager V3 (All versions). The affected application assigns improper access rights to a specific folder containing configuration files. This could allow an authenticated local attacker to inject arbitrar... Read more
Affected Products : sentron_powermanager_3- EPSS Score: %0.03
- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-37206
A vulnerability has been identified in SIPROTEC 5 relays with CPU variants CP050 (All versions < V8.80), SIPROTEC 5 relays with CPU variants CP100 (All versions < V8.80), SIPROTEC 5 relays with CPU variants CP300 (All versions < V8.80). Received webpacket... Read more
- EPSS Score: %0.58
- Published: Sep. 14, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-37205
A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions >= V21.9 < V21.9.4), SIMATIC S7-1200 CPU family (incl. SIPLUS v... Read more
Affected Products : simatic_s7-1500_software_controller_firmware simatic_drive_controller_cpu_1504d_tf_firmware simatic_drive_controller_cpu_1507d_tf_firmware simatic_s7-plcsim_advanced_firmware siplus_tim_1531_irc_firmware tim_1531_irc_firmware simatic_et_200sp_open_controller_cpu_1515sp_pc2_firmware simatic_s7-1200_cpu_1211c_firmware simatic_s7-1200_cpu_1212c_firmware simatic_s7-1200_cpu_1214c_firmware +87 more products- EPSS Score: %1.14
- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-37204
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMAT... Read more
Affected Products : simatic_s7-1500_software_controller_firmware simatic_drive_controller_cpu_1504d_tf_firmware simatic_drive_controller_cpu_1507d_tf_firmware simatic_s7-plcsim_advanced_firmware siplus_tim_1531_irc_firmware tim_1531_irc_firmware simatic_et_200sp_open_controller_cpu_1515sp_pc2_firmware simatic_s7-1200_cpu_1211c_firmware simatic_s7-1200_cpu_1212c_firmware simatic_s7-1200_cpu_1214c_firmware +87 more products- EPSS Score: %1.43
- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024