Latest CVE Feed
-
10.0
HIGHCVE-2021-37555
TX9 Automatic Food Dispenser v3.2.57 devices allow access to a shell as root/superuser, a related issue to CVE-2019-16734. To connect, the telnet service is used on port 23 with the default password of 059AnkJ for the root account. The user can then downl... Read more
- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-37554
In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.... Read more
Affected Products : youtrack- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-37553
In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used.... Read more
Affected Products : youtrack- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37552
In JetBrains YouTrack before 2021.2.17925, stored XSS was possible.... Read more
Affected Products : youtrack- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-37551
In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.... Read more
Affected Products : youtrack- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-37550
In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used.... Read more
Affected Products : youtrack- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-37549
In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient.... Read more
Affected Products : youtrack- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-37548
In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS.... Read more
Affected Products : teamcity- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-37547
In JetBrains TeamCity before 2020.2.4, insufficient checks during file uploading were made.... Read more
Affected Products : teamcity- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-37546
In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used.... Read more
Affected Products : teamcity- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-37545
In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made.... Read more
Affected Products : teamcity- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37544
In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization.... Read more
Affected Products : teamcity- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-37543
In JetBrains RubyMine before 2021.1.1, code execution without user confirmation was possible for untrusted projects.... Read more
Affected Products : rubymine- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-37542
In JetBrains TeamCity before 2020.2.3, XSS was possible.... Read more
Affected Products : teamcity- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-37541
In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.... Read more
Affected Products : hub- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-37540
In JetBrains Hub before 2021.1.13262, a potentially insufficient CSP for the Widget deployment feature was used.... Read more
Affected Products : hub- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37539
Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.... Read more
Affected Products : manageengine_admanager_plus- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37538
Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to execute arbitrary SQL commands via the day, month, or year parameter to the controllers/front/archive.php archive contr... Read more
Affected Products : smartblog- Published: Aug. 24, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-37535
SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization checks for user privileges.... Read more
- Published: Sep. 14, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37534
app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster.... Read more
Affected Products : misp- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024