Latest CVE Feed
-
5.9
MEDIUMCVE-2021-38597
wolfSSL before 4.8.1 incorrectly skips OCSP verification in certain situations of irrelevant response data that contains the NoCheck extension.... Read more
Affected Products : wolfssl- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38593
Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).... Read more
- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38592
Wasm3 0.5.0 has a heap-based buffer overflow in op_Const64 (called from EvaluateExpression and m3_LoadModule).... Read more
Affected Products : wasm3- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
3.3
LOWCVE-2021-38591
An issue was discovered on LG mobile devices with Android OS P and Q software for mt6762/mt6765/mt6883. Attackers can change some of the NvRAM content by leveraging the misconfiguration of a debug command. The LG ID is LVE-SMP-210005 (August 2021).... Read more
Affected Products : android- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-38590
In cPanel before 96.0.8, weak permissions on web stats can lead to information disclosure (SEC-584).... Read more
Affected Products : cpanel- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-38589
In cPanel before 96.0.13, scripts/fix-cpanel-perl does not properly restrict the overwriting of files (SEC-588).... Read more
Affected Products : cpanel- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-38588
In cPanel before 96.0.13, fix_cpanel_perl lacks verification of the integrity of downloads (SEC-587).... Read more
Affected Products : cpanel- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38587
In cPanel before 96.0.13, scripts/fix-cpanel-perl mishandles the creation of temporary files (SEC-586).... Read more
Affected Products : cpanel- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-38586
In cPanel before 98.0.1, /scripts/cpan_config performs unsafe operations on files (SEC-589).... Read more
Affected Products : cpanel- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-38585
The WHM Locale Upload feature in cPanel before 98.0.1 allows unserialization attacks (SEC-585).... Read more
Affected Products : cpanel- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-38584
The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585).... Read more
Affected Products : cpanel- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38583
openBaraza HCM 3.1.6 does not properly neutralize user-controllable input, which allows reflected cross-site scripting (XSS) on multiple pages: hr/subscription.jsp and hr/application.jsp and and hr/index.jsp (with view= and data=).... Read more
Affected Products : openbaraza_human_capital_management- Published: Aug. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38578
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.... Read more
- Published: Mar. 03, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-38576
A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system.... Read more
Affected Products : edk2- Published: Jan. 03, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-38575
NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.... Read more
- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38574
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.... Read more
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38573
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because a CombineFiles pathname is not validated.... Read more
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38572
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because the extractPages pathname is not validated.... Read more
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-38571
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows DLL hijacking, aka CNVD-C-2021-68000 and CNVD-C-2021-68502.... Read more
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-38570
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows attackers to delete arbitrary files (during uninstallation) via a symlink.... Read more
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024