Latest CVE Feed
-
9.8
CRITICALCVE-2021-32024
A remote code execution vulnerability in the BMP image codec of BlackBerry QNX SDP version(s) 6.4 to 7.1 could allow an attacker to potentially execute code in the context of the affected process.... Read more
Affected Products : qnx_software_development_platform- EPSS Score: %2.65
- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-32023
An elevation of privilege vulnerability in the message broker of BlackBerry Protect for Windows version(s) versions 1574 and earlier could allow an attacker to potentially execute code in the context of a BlackBerry Cylance service that has admin rights o... Read more
Affected Products : protect- EPSS Score: %0.05
- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-32022
A low privileged delete vulnerability using CEF RPC server of BlackBerry Protect for Windows version(s) versions 1574 and earlier could allow an attacker to potentially execute code in the context of a BlackBerry Cylance service that has admin rights on t... Read more
Affected Products : protect- EPSS Score: %0.06
- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-32021
A denial of service vulnerability in the message broker of BlackBerry Protect for Windows version(s) versions 1574 and earlier could allow an attacker to potentially execute code in the context of a BlackBerry Cylance service that has admin rights on the ... Read more
Affected Products : protect- EPSS Score: %0.05
- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32020
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memory.... Read more
Affected Products : freertos- EPSS Score: %0.30
- Published: May. 03, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-32019
There is missing input validation of host names displayed in OpenWrt before 19.07.8. The Connection Status page of the luci web-interface allows XSS, which can be used to gain full control over the affected system via ICMP.... Read more
Affected Products : openwrt- EPSS Score: %0.22
- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
6.0
MEDIUMCVE-2021-32015
In Nuvoton NPCT75x TPM 1.2 firmware 7.4.0.0, a local authenticated malicious user with high privileges could potentially gain unauthorized access to TPM non-volatile memory. NOTE: Upgrading to firmware version 7.4.0.1 will mitigate against the vulnerabili... Read more
- EPSS Score: %0.04
- Published: Jun. 08, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-32014
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js.... Read more
- EPSS Score: %0.21
- Published: Jul. 19, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-32013
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 2 of 2).... Read more
- EPSS Score: %0.21
- Published: Jul. 19, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-32012
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 1 of 2).... Read more
- EPSS Score: %0.21
- Published: Jul. 19, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-32010
Inadequate Encryption Strength vulnerability in TLS stack of Secomea SiteManager, LinkManager, GateManager may facilitate man in the middle attacks. This issue affects: Secomea SiteManager All versions prior to 9.7. Secomea LinkManager versions prior to 9... Read more
- EPSS Score: %0.10
- Published: May. 04, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-32009
Cross-site Scripting (XSS) vulnerability in firmware section of Secomea GateManager allows logged in user to inject javascript in browser session. This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions.... Read more
Affected Products : gatemanager- EPSS Score: %0.53
- Published: Mar. 11, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2021-32008
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin to delete system Files or Directories.... Read more
Affected Products : gatemanager- EPSS Score: %0.68
- Published: Mar. 04, 2022
- Modified: Nov. 21, 2024
-
5.0
MEDIUMCVE-2021-32006
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Permission Issues vulnerability in LinkManager web portal of Secomea GateManager allows logged in LinkManager user to access stored SiteManager backup files.... Read more
Affected Products : gatemanager- EPSS Score: %0.15
- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-32005
Cross-site Scripting (XSS) vulnerability in log view of Secomea SiteManager allows a logged in user to store javascript for later execution. This issue affects: Secomea SiteManager Version 9.6.621421014 and all prior versions.... Read more
- EPSS Score: %0.58
- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-32004
This issue affects: Secomea GateManager All versions prior to 9.6. Improper Check of host header in web server of Secomea GateManager allows attacker to cause browser cache poisoning.... Read more
- EPSS Score: %0.20
- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2021-32003
Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after provisioning. This issue affects: Secomea SiteManager All versions prior to 9.5 on Hardware.... Read more
- EPSS Score: %0.04
- Published: Aug. 05, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-32002
Improper Access Control vulnerability in web service of Secomea SiteManager allows local attacker without credentials to gather network information and configuration of the SiteManager. This issue affects: Secomea SiteManager All versions prior to 9.5 on ... Read more
- EPSS Score: %0.04
- Published: Aug. 05, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-32001
K3s in SUSE Rancher allows any user with direct access to the datastore, or a copy of a datastore backup, to extract the cluster's confidential keying material (cluster certificate authority private keys, secrets encryption configuration passphrase, etc.)... Read more
- EPSS Score: %0.11
- Published: Jul. 28, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-32000
A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up in SUSE Linux Enterprise Server 12 SP3, SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allows local attackers to delete arbitrary... Read more
- EPSS Score: %0.02
- Published: Jul. 28, 2021
- Modified: Nov. 21, 2024