Latest CVE Feed
-
5.3
MEDIUMCVE-2021-36165
RICON Industrial Cellular Router S9922L 16.10.3(3794) is affected by cleartext storage of sensitive information and sends username and password as base64.... Read more
- EPSS Score: %0.11
- Published: Sep. 28, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-36163
In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST request directly to a HessianSkeleton: New HessianSkeleton are created without any configuration of the seriali... Read more
Affected Products : dubbo- EPSS Score: %1.61
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-36162
Apache Dubbo supports various rules to support configuration override or traffic routing (called routing in Dubbo). These rules are loaded into the configuration center (eg: Zookeeper, Nacos, ...) and retrieved by the customers when making a request in or... Read more
Affected Products : dubbo- EPSS Score: %1.25
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-36161
Some component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for a maliciously customized bean with special toString method. In the latest version, we fix the toString call in timeout, cache and some ... Read more
Affected Products : dubbo- EPSS Score: %2.73
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-36159
libfetch before 2021-07-26, as used in apk-tools, xbps, and other products, mishandles numeric strings for the FTP and HTTP protocols. The FTP passive mode implementation allows an out-of-bounds read because strtol is used to parse the relevant numbers in... Read more
Affected Products : libfetch- EPSS Score: %1.01
- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-36158
In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys are used.... Read more
Affected Products : aports- EPSS Score: %0.08
- Published: Jul. 05, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-36157
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will... Read more
Affected Products : cortex- EPSS Score: %0.32
- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-36156
An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will att... Read more
Affected Products : loki- EPSS Score: %0.40
- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-36155
LengthPrefixedMessageReader in gRPC Swift 1.1.0 and earlier allocates buffers of arbitrary length, which allows remote attackers to cause uncontrolled resource consumption and deny service.... Read more
Affected Products : grpc_swift- EPSS Score: %0.85
- Published: Jul. 09, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-36154
HTTP2ToRawGRPCServerCodec in gRPC Swift 1.1.1 and earlier allows remote attackers to deny service via the delivery of many small messages within a single HTTP/2 frame, leading to Uncontrolled Recursion and stack consumption.... Read more
Affected Products : grpc_swift- EPSS Score: %0.85
- Published: Jul. 09, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-36153
Mismanaged state in GRPCWebToHTTP2ServerCodec.swift in gRPC Swift 1.1.0 and 1.1.1 allows remote attackers to deny service by sending malformed requests.... Read more
Affected Products : grpc_swift- EPSS Score: %1.36
- Published: Jul. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-36152
Apache Gobblin trusts all certificates used for LDAP connections in Gobblin-as-a-Service. This affects versions <= 0.15.0. Users should update to version 0.16.0 which addresses this issue.... Read more
Affected Products : gobblin- EPSS Score: %1.66
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-36151
In Apache Gobblin, the Hadoop token is written to a temp file that is visible to all local users on Unix-like systems. This affects versions <= 0.15.0. Users should update to version 0.16.0 which addresses this issue.... Read more
Affected Products : gobblin- EPSS Score: %0.06
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-36150
SilverStripe Framework through 4.8.1 allows XSS.... Read more
Affected Products : silverstripe- EPSS Score: %0.50
- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-36148
An issue was discovered in ACRN before 2.5. dmar_free_irte in hypervisor/arch/x86/vtd.c allows an irte_alloc_bitmap buffer overflow.... Read more
Affected Products : acrn- EPSS Score: %0.21
- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-36147
An issue was discovered in ACRN before 2.5. It allows a devicemodel/hw/pci/virtio/virtio_net.c virtio_net_ping_rxq NULL pointer dereference for vq->used.... Read more
Affected Products : acrn- EPSS Score: %0.34
- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-36146
ACRN before 2.5 has a devicemodel/hw/pci/xhci.c NULL Pointer Dereference for a trb pointer.... Read more
Affected Products : acrn- EPSS Score: %0.32
- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-36145
The Device Model in ACRN through 2.5 has a devicemodel/core/mem.c use-after-free for a freed rb_entry.... Read more
Affected Products : acrn- EPSS Score: %0.39
- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-36144
The polling timer handler in ACRN before 2.5 has a use-after-free for a freed virtio device, related to devicemodel/hw/pci/virtio/*.c.... Read more
Affected Products : acrn- EPSS Score: %0.39
- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-36143
ACRN before 2.5 has a hw/pci/virtio/virtio.c vq_endchains NULL Pointer Dereference.... Read more
Affected Products : acrn- EPSS Score: %0.26
- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024