Latest CVE Feed
-
7.8
HIGHCVE-2021-36235
An issue was discovered in Ivanti Workspace Control before 10.6.30.0. A locally authenticated user with low privileges can bypass File and Folder Security by leveraging an unspecified attack vector. As a result, the attacker can start applications with el... Read more
Affected Products : workspace_control- EPSS Score: %0.30
- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-36234
Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt credentials via unspecified vectors.... Read more
Affected Products : mik.starlight- EPSS Score: %0.05
- Published: Aug. 31, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-36233
The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary files from the filesystem by specifying the file path.... Read more
Affected Products : mik.starlight- EPSS Score: %0.42
- Published: Aug. 31, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-36232
Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges.... Read more
Affected Products : mik.starlight- EPSS Score: %0.43
- Published: Aug. 31, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-36231
Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operating system commands by crafting serialized objects.... Read more
Affected Products : mik.starlight- EPSS Score: %1.10
- Published: Aug. 31, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-36230
HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner. Fixed in v202107-1.... Read more
Affected Products : terraform- EPSS Score: %0.55
- Published: Jul. 20, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-36224
Western Digital My Cloud devices before OS5 have a nobody account with a blank password.... Read more
- EPSS Score: %0.08
- Published: Feb. 06, 2023
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-36222
ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is ... Read more
- EPSS Score: %5.58
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-36221
Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.... Read more
Affected Products : fedora debian_linux go timesten_in-memory_database scalance_lpe9403_firmware scalance_lpe9403- EPSS Score: %0.17
- Published: Aug. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-36219
An issue was discovered in SKALE sgxwallet 1.58.3. The provided input for ECALL 14 triggers a branch in trustedEcdsaSign that frees a non-initialized pointer from the stack. An attacker can chain multiple enclave calls to prepare a stack that contains a v... Read more
Affected Products : sgxwallet- EPSS Score: %0.31
- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-36218
An issue was discovered in SKALE sgxwallet 1.58.3. sgx_disp_ippsAES_GCMEncrypt allows an out-of-bounds write, resulting in a segfault and compromised enclave. This issue describes a buffer overflow, which was resolved prior to v1.77.0 and not reproducible... Read more
Affected Products : sgxwallet- EPSS Score: %0.26
- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-36216
LINE for Windows 6.2.1.2289 and before allows arbitrary code execution via malicious DLL injection.... Read more
Affected Products : line- EPSS Score: %0.06
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-36215
LINE client for iOS 10.21.3 and before allows address bar spoofing due to inappropriate address handling.... Read more
Affected Products : line- EPSS Score: %0.21
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-36214
LINE client for iOS before 10.16.3 allows cross site script with specific header in WebView.... Read more
Affected Products : line- EPSS Score: %0.21
- Published: Jul. 13, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-36213
HashiCorp Consul and Consul Enterprise 1.9.0 through 1.10.0 default deny policy with a single L7 application-aware intention deny action cancels out, causing the intention to incorrectly fail open, allowing L4 traffic. Fixed in 1.9.8 and 1.10.1.... Read more
Affected Products : consul- EPSS Score: %1.06
- Published: Jul. 17, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-36212
app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view.... Read more
Affected Products : misp- EPSS Score: %0.24
- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-36209
In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset.... Read more
Affected Products : hub- EPSS Score: %0.00
- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-36207
Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow an authenticated user to elevate their privileges to administrator.... Read more
- EPSS Score: %0.16
- Published: Apr. 29, 2022
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-36206
All versions of CEVAS prior to 1.01.46 do not sufficiently validate user-controllable input and could allow a user to bypass authentication and retrieve data with specially crafted SQL queries.... Read more
Affected Products : cevas- EPSS Score: %0.15
- Published: Oct. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-36205
Under certain circumstances the session token is not cleared on logout.... Read more
- EPSS Score: %0.28
- Published: Apr. 15, 2022
- Modified: Nov. 21, 2024