Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.7

    MEDIUM
    CVE-2021-35056

    Unisys Stealth 5.1 before 5.1.025.0 and 6.0 before 6.0.055.0 has an unquoted Windows search path for a scheduled task. An unintended executable might run.... Read more

    Affected Products : stealth
    • EPSS Score: %0.06
    • Published: Jul. 15, 2021
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2021-35055

    MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. (Affected Chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software... Read more

    • EPSS Score: %0.55
    • Published: Dec. 26, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-35054

    Minecraft before 1.17.1, when online-mode=false is configured, allows path traversal for deletion of arbitrary JSON files.... Read more

    Affected Products : minecraft
    • EPSS Score: %0.37
    • Published: Jul. 20, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-35053

    Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the system to make the system unbootable.... Read more

    Affected Products : windows endpoint_security
    • EPSS Score: %1.28
    • Published: Nov. 03, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-35052

    A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High.... Read more

    Affected Products : password_manager
    • EPSS Score: %0.06
    • Published: Nov. 23, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-35050

    User credentials stored in a recoverable format within Fidelis Network and Deception CommandPost. In the event that an attacker gains access to the CommandPost, these values could be decoded and used to login to the application. The vulnerability is prese... Read more

    Affected Products : deception network
    • EPSS Score: %0.31
    • Published: Jun. 25, 2021
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2021-35049

    Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could allow a specially crafted HTTP request to execute system commands on the CommandPost and return results i... Read more

    Affected Products : deception network
    • EPSS Score: %3.37
    • Published: Jun. 25, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-35048

    Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interface. The vulnerability could lead to exposure of authentication tokens in some versions of Fidelis software. The vulnerability is presen... Read more

    Affected Products : deception network
    • EPSS Score: %0.78
    • Published: Jun. 25, 2021
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2021-35047

    Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with user level access to the CLI to inject root level commands into the component and neighboring Fidelis components. The vulnerabilit... Read more

    Affected Products : deception network
    • EPSS Score: %0.89
    • Published: Jun. 25, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-35046

    A session fixation vulnerability was discovered in Ice Hrm 29.0.0 OS which allows an attacker to hijack a valid user session via a crafted session cookie.... Read more

    Affected Products : icehrm
    • EPSS Score: %0.20
    • Published: Jun. 22, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-35045

    Cross site scripting (XSS) vulnerability in Ice Hrm 29.0.0.OS, allows attackers to execute arbitrary code via the parameters to the /app/ endpoint.... Read more

    Affected Products : icehrm
    • EPSS Score: %0.40
    • Published: Jun. 22, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-35043

    OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with &#00058 as the replacement for the : character.... Read more

    • EPSS Score: %0.33
    • Published: Jul. 19, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-35042

    Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.... Read more

    Affected Products : fedora django
    • EPSS Score: %6.96
    • Published: Jul. 02, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-35041

    The blockchain node in FISCO-BCOS V2.7.2 may have a bug when dealing with unformatted packet and lead to a crash. A malicious node can send a packet continuously. The packet is in an incorrect format and cannot be decoded by the node correctly. As a resul... Read more

    Affected Products : fisco-bcos
    • EPSS Score: %0.33
    • Published: Jun. 24, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-35039

    kernel/module.c in the Linux kernel before 5.12.14 mishandles Signature Verification, aka CID-0c18f29aae7c. Without CONFIG_MODULE_SIG, verification that a kernel module is signed, for loading via init_module, does not occur for a module.sig_enforce=1 comm... Read more

    Affected Products : linux_kernel debian_linux
    • EPSS Score: %0.07
    • Published: Jul. 07, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-35037

    Jamf Pro before 10.30.1 allows for an unvalidated URL redirect vulnerability affecting Jamf Pro customers who host their environments on-premises. An attacker may craft a URL that appears to be for a customer's Jamf Pro instance, but when clicked will for... Read more

    Affected Products : jamf
    • EPSS Score: %0.15
    • Published: Jul. 12, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-35036

    A cleartext storage of information vulnerability in the Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k could allow an authenticated attacker to obtain sensitive information from the configuration file.... Read more

    • EPSS Score: %0.20
    • Published: Mar. 01, 2022
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-35035

    A cleartext storage of sensitive information vulnerability in the Zyxel NBG6604 firmware could allow a remote, authenticated attacker to obtain sensitive information from the configuration file.... Read more

    Affected Products : nbg6604_firmware nbg6604
    • EPSS Score: %0.07
    • Published: Dec. 29, 2021
    • Modified: Nov. 21, 2024
  • 9.1

    CRITICAL
    CVE-2021-35034

    An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device if the correct token can be intercepted.... Read more

    Affected Products : nbg6604_firmware nbg6604
    • EPSS Score: %0.27
    • Published: Dec. 29, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-35033

    A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password management could allow an attacker to obtain root access of the device, if the local attacker dismantles the device and us... Read more

    • EPSS Score: %0.04
    • Published: Nov. 23, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 291368 Results