Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2021-36152

    Apache Gobblin trusts all certificates used for LDAP connections in Gobblin-as-a-Service. This affects versions <= 0.15.0. Users should update to version 0.16.0 which addresses this issue.... Read more

    Affected Products : gobblin
    • EPSS Score: %1.66
    • Published: Feb. 04, 2022
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2021-36151

    In Apache Gobblin, the Hadoop token is written to a temp file that is visible to all local users on Unix-like systems. This affects versions <= 0.15.0. Users should update to version 0.16.0 which addresses this issue.... Read more

    Affected Products : gobblin
    • EPSS Score: %0.06
    • Published: Feb. 04, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-36150

    SilverStripe Framework through 4.8.1 allows XSS.... Read more

    Affected Products : silverstripe
    • EPSS Score: %0.50
    • Published: Oct. 07, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-36148

    An issue was discovered in ACRN before 2.5. dmar_free_irte in hypervisor/arch/x86/vtd.c allows an irte_alloc_bitmap buffer overflow.... Read more

    Affected Products : acrn
    • EPSS Score: %0.21
    • Published: Jul. 02, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-36147

    An issue was discovered in ACRN before 2.5. It allows a devicemodel/hw/pci/virtio/virtio_net.c virtio_net_ping_rxq NULL pointer dereference for vq->used.... Read more

    Affected Products : acrn
    • EPSS Score: %0.34
    • Published: Jul. 02, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-36146

    ACRN before 2.5 has a devicemodel/hw/pci/xhci.c NULL Pointer Dereference for a trb pointer.... Read more

    Affected Products : acrn
    • EPSS Score: %0.32
    • Published: Jul. 02, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-36145

    The Device Model in ACRN through 2.5 has a devicemodel/core/mem.c use-after-free for a freed rb_entry.... Read more

    Affected Products : acrn
    • EPSS Score: %0.39
    • Published: Jul. 02, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-36144

    The polling timer handler in ACRN before 2.5 has a use-after-free for a freed virtio device, related to devicemodel/hw/pci/virtio/*.c.... Read more

    Affected Products : acrn
    • EPSS Score: %0.39
    • Published: Jul. 02, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-36143

    ACRN before 2.5 has a hw/pci/virtio/virtio.c vq_endchains NULL Pointer Dereference.... Read more

    Affected Products : acrn
    • EPSS Score: %0.26
    • Published: Jul. 02, 2021
    • Modified: Nov. 21, 2024
  • 7.4

    HIGH
    CVE-2021-36134

    Out of bounds write vulnerability in the JPEG parsing code of Netop Vision Pro up to and including 9.7.2 allows an adjacent unauthenticated attacker to write to arbitrary memory potentially leading to a Denial of Service (DoS).... Read more

    Affected Products : windows vision_pro
    • EPSS Score: %0.13
    • Published: Sep. 27, 2021
    • Modified: Nov. 21, 2024
  • 7.1

    HIGH
    CVE-2021-36133

    The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operations on Secure World memory. This involves a D... Read more

    • EPSS Score: %0.05
    • Published: Dec. 07, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-36132

    An issue was discovered in the FileImporter extension in MediaWiki through 1.36. For certain relaxed configurations of the $wgFileImporterRequiredRight variable, it might not validate all appropriate user rights, thus allowing a user with insufficient rig... Read more

    Affected Products : mediawiki
    • EPSS Score: %0.33
    • Published: Jul. 02, 2021
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2021-36131

    An XSS issue was discovered in the SportsTeams extension in MediaWiki through 1.36. Within several special pages, a privileged user could inject arbitrary HTML and JavaScript within various data fields. The attack could easily propagate across many pages ... Read more

    Affected Products : mediawiki
    • EPSS Score: %0.25
    • Published: Jul. 02, 2021
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2021-36130

    An XSS issue was discovered in the SocialProfile extension in MediaWiki through 1.36. Within several gift-related special pages, a privileged user with the awardmanage right could inject arbitrary HTML and JavaScript within various gift-related data field... Read more

    Affected Products : mediawiki
    • EPSS Score: %0.27
    • Published: Jul. 02, 2021
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2021-36129

    An issue was discovered in the Translate extension in MediaWiki through 1.36. The Aggregategroups Action API module does not validate the parameter for aggregategroup when action=remove is set, thus allowing users with the translate-manage right to silent... Read more

    Affected Products : mediawiki
    • EPSS Score: %0.14
    • Published: Jul. 02, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-36128

    An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. Autoblocks for CentralAuth-issued suppression blocks are not properly implemented.... Read more

    Affected Products : mediawiki
    • EPSS Score: %0.74
    • Published: Jul. 02, 2021
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2021-36127

    An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalUserRights page provided search results which, for a suppressed MediaWiki user, were different than for any other user, thus easily disclosing suppressed acc... Read more

    Affected Products : mediawiki
    • EPSS Score: %0.15
    • Published: Jul. 02, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-36126

    An issue was discovered in the AbuseFilter extension in MediaWiki through 1.36. If the MediaWiki:Abusefilter-blocker message is invalid within the content language, the filter user falls back to the English version, but that English version could also be ... Read more

    Affected Products : mediawiki
    • EPSS Score: %0.44
    • Published: Jul. 02, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-36125

    An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalRenameRequest page is vulnerable to infinite loops and denial of service attacks when a user's current username is beyond an arbitrary maximum configuration ... Read more

    Affected Products : mediawiki
    • EPSS Score: %0.34
    • Published: Jul. 02, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-36124

    An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when accessing a subset of sensitive resources, leading to the ability for unauthenticated users to access pages that are vulnerable to attacks su... Read more

    Affected Products : sharecare
    • EPSS Score: %0.54
    • Published: Jul. 13, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 291531 Results