Latest CVE Feed
-
6.7
MEDIUMCVE-2021-35939
It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw ... Read more
- EPSS Score: %0.13
- Published: Aug. 26, 2022
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-35938
A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file a... Read more
- EPSS Score: %0.08
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2021-35937
A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vuln... Read more
- EPSS Score: %0.01
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-35936
If remote logging is not used, the worker (in the case of CeleryExecutor) or the scheduler (in the case of LocalExecutor) runs a Flask logging server and is listening on a specific port and also binds on 0.0.0.0 by default. This logging server had no auth... Read more
Affected Products : airflow- EPSS Score: %0.17
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-35689
A potential vulnerability in the Oracle Talent Acquisition Cloud - Taleo Enterprise Edition. This high severity potential vulnerability allows attackers to perform remote code execution on Taleo Enterprise Edition system. Successful attacks of this vulner... Read more
Affected Products : talent_acquisition_cloud- EPSS Score: %2.52
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-35687
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Unified Metadata Manager). Supported versions that are affected are 8.0.7-8.1.1. Easily exploitable vulnera... Read more
Affected Products : financial_services_analytical_applications_infrastructure- EPSS Score: %1.18
- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-35686
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Unified Metadata Manager). Supported versions that are affected are 8.0.7-8.1.1. Easily exploitable vulnera... Read more
Affected Products : financial_services_analytical_applications_infrastructure- EPSS Score: %0.30
- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2021-35683
Vulnerability in the Oracle Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported version that is affected is Prior to 11.1.2.4.047. Easily exploitable vulnerability allows low privileged attacker with network a... Read more
- EPSS Score: %1.54
- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-35666
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OSSL Module). The supported version that is affected is 11.1.1.9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to... Read more
Affected Products : http_server- EPSS Score: %1.32
- Published: Oct. 20, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-35665
Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported version that is affected is 11.2.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to comp... Read more
- EPSS Score: %0.58
- Published: Oct. 20, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-35662
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access vi... Read more
Affected Products : outside_in_technology- EPSS Score: %1.80
- Published: Oct. 20, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-35661
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access vi... Read more
Affected Products : outside_in_technology- EPSS Score: %1.80
- Published: Oct. 20, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-35660
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access vi... Read more
Affected Products : outside_in_technology- EPSS Score: %1.80
- Published: Oct. 20, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-35659
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access vi... Read more
Affected Products : outside_in_technology- EPSS Score: %1.80
- Published: Oct. 20, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-35658
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access vi... Read more
Affected Products : outside_in_technology- EPSS Score: %1.80
- Published: Oct. 20, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-35657
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access vi... Read more
Affected Products : outside_in_technology- EPSS Score: %1.80
- Published: Oct. 20, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-35656
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access vi... Read more
Affected Products : outside_in_technology- EPSS Score: %1.80
- Published: Oct. 20, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-35655
Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported versions that are affected are Prior to 11.1.2.4.046 and Prior to 21.3. Easily exploitable vulnerability allows unauthenticated attacker... Read more
- EPSS Score: %0.77
- Published: Oct. 20, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-35654
Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported versions that are affected are Prior to 11.1.2.4.046 and Prior to 21.3. Easily exploitable vulnerability allows unauthenticated attacker... Read more
- EPSS Score: %1.64
- Published: Oct. 20, 2021
- Modified: Nov. 21, 2024
-
7.7
HIGHCVE-2021-35653
Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported versions that are affected are Prior to 11.1.2.4.046 and Prior to 21.3. Easily exploitable vulnerability allows low privileged attacker ... Read more
- EPSS Score: %0.40
- Published: Oct. 20, 2021
- Modified: Nov. 21, 2024