Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2021-36793

    The routes (aka Extbase Yaml Routes) extension before 2.1.1 for TYPO3, when CsrfTokenViewHelper is used, allows Sensitive Information Disclosure because a session identifier is unsafely present in HTML output.... Read more

    Affected Products : routes
    • EPSS Score: %0.25
    • Published: Aug. 13, 2021
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-36792

    The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 has incorrect Access Control for confirming various applications.... Read more

    Affected Products : dated_news
    • EPSS Score: %0.18
    • Published: Aug. 13, 2021
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-36791

    The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows Information Disclosure of application registration data.... Read more

    Affected Products : dated_news
    • EPSS Score: %0.19
    • Published: Aug. 13, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-36790

    The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows XSS.... Read more

    Affected Products : dated_news
    • EPSS Score: %0.28
    • Published: Aug. 13, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-36789

    The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection.... Read more

    Affected Products : dated_news
    • EPSS Score: %0.38
    • Published: Aug. 13, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-36788

    The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS.... Read more

    Affected Products : yoast_seo
    • EPSS Score: %0.26
    • Published: Aug. 13, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-36787

    The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document.... Read more

    Affected Products : femanager
    • EPSS Score: %0.69
    • Published: Aug. 13, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-36786

    The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows Sensitive Data Exposure of API credentials and private keys.... Read more

    Affected Products : saml
    • EPSS Score: %0.25
    • Published: Aug. 13, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-36785

    The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows XSS.... Read more

    Affected Products : saml
    • EPSS Score: %0.26
    • Published: Aug. 13, 2021
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-36784

    A Improper Privilege Management vulnerability in SUSE Rancher allows users with the restricted-admin role to escalate to full admin. This issue affects: SUSE Rancher Rancher versions prior to 2.5.13; Rancher versions prior to 2.6.4.... Read more

    Affected Products : rancher rancher
    • EPSS Score: %0.34
    • Published: May. 02, 2022
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2021-36783

    A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners and Project Members to read credentials, passwords and API tokens that have been stored in cleartext and exposed via ... Read more

    Affected Products : rancher rancher
    • EPSS Score: %0.28
    • Published: Sep. 07, 2022
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2021-36782

    A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners, Project Members and User Base to use the Kubernetes API to retrieve plaintext version of sensitive data. This ... Read more

    Affected Products : rancher rancher
    • EPSS Score: %77.97
    • Published: Sep. 07, 2022
    • Modified: Nov. 21, 2024
  • 5.9

    MEDIUM
    CVE-2021-36781

    A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local attackers to imitate the service leading to DoS or clients talking to an imposter service. This issue affects: openSUSE Factory parsec versions prior to 0... Read more

    Affected Products : factory openldap2
    • EPSS Score: %0.09
    • Published: Jan. 14, 2022
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2021-36780

    A Missing Authentication for Critical Function vulnerability in longhorn of SUSE Longhorn allows attackers to connect to a longhorn-engine replica instance granting it the ability to read and write data to and from a replica that they should not have acce... Read more

    Affected Products : longhorn
    • EPSS Score: %0.14
    • Published: Dec. 17, 2021
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2021-36779

    A Missing Authentication for Critical Function vulnerability in SUSE Longhorn allows any workload in the cluster to execute any binary present in the image on the host without authentication. This issue affects: SUSE Longhorn longhorn versions prior to 1.... Read more

    Affected Products : longhorn
    • EPSS Score: %0.05
    • Published: Dec. 17, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-36778

    A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather credentials that are sent to their servers. This issue affects: SUSE Rancher Rancher versions prior to 2.5.12; Rancher versions prior to 2.... Read more

    Affected Products : rancher rancher
    • EPSS Score: %0.30
    • Published: May. 02, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-36777

    A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login proxy of the openSUSE Build service allowed attackers to present users with a expected login form that then sends the clear text credentials to an attacker specified server. ... Read more

    Affected Products : open_build_service
    • EPSS Score: %0.29
    • Published: Mar. 09, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-36776

    A Improper Access Control vulnerability in SUSE Rancher allows remote attackers impersonate arbitrary users. This issue affects: SUSE Rancher Rancher versions prior to 2.5.10.... Read more

    Affected Products : rancher rancher
    • EPSS Score: %0.21
    • Published: Apr. 04, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-36775

    a Improper Access Control vulnerability in SUSE Rancher allows users to keep privileges that should have been revoked. This issue affects: SUSE Rancher Rancher versions prior to 2.4.18; Rancher versions prior to 2.5.12; Rancher versions prior to 2.6.3.... Read more

    Affected Products : rancher rancher
    • EPSS Score: %0.07
    • Published: Apr. 04, 2022
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-36774

    Apache Kylin allows users to read data from other database systems using JDBC. The MySQL JDBC driver supports certain properties, which, if left unmitigated, can allow an attacker to execute arbitrary code from a hacker-controlled malicious MySQL server w... Read more

    Affected Products : kylin
    • EPSS Score: %0.83
    • Published: Jan. 06, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 291608 Results