Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2021-31939

    Microsoft Excel Remote Code Execution Vulnerability... Read more

    • EPSS Score: %5.59
    • Published: Jun. 08, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-31938

    Microsoft VsCode Kubernetes Tools Extension Elevation of Privilege Vulnerability... Read more

    Affected Products : kubernetes_tools
    • EPSS Score: %3.81
    • Published: Jun. 08, 2021
    • Modified: Nov. 21, 2024
  • 7.4

    HIGH
    CVE-2021-31936

    Microsoft Accessibility Insights for Web Information Disclosure Vulnerability... Read more

    Affected Products : accessibility_insights_for_web
    • EPSS Score: %12.63
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-31935

    OX App Suite 7.10.4 and earlier allows XSS via a crafted distribution list (payload in the common name) that is mishandled in the scheduling view.... Read more

    Affected Products : open-xchange_appsuite
    • EPSS Score: %0.17
    • Published: Apr. 30, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-31934

    OX App Suite 7.10.4 and earlier allows XSS via a crafted contact object (payload in the position or company field) that is mishandled in the App Suite UI on a smartphone.... Read more

    Affected Products : open-xchange_appsuite
    • EPSS Score: %0.17
    • Published: Apr. 30, 2021
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-31933

    A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filtering for certain filenames (e.g., .phar or .pht). A remote authenticated admi... Read more

    Affected Products : chamilo_lms chamilo
    • EPSS Score: %14.78
    • Published: Apr. 30, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-31932

    Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can get access to all the functionalities exposed via the web panel, circumventing the authentication process, by using URL encoding for t... Read more

    Affected Products : bts_trs_web_console
    • EPSS Score: %1.14
    • Published: Feb. 11, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-31930

    Persistent cross-site scripting (XSS) in the web interface of Concerto through 2.3.6 allows an unauthenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into the First Name or Last Name parameter upon registration. When... Read more

    Affected Products : concerto
    • EPSS Score: %0.78
    • Published: May. 19, 2021
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2021-31929

    Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify loyalty campaigns and settings, such as fraud prevention, coupon groups, email templates, or referrals.... Read more

    Affected Products : loyalty_experience_platform
    • EPSS Score: %0.15
    • Published: Jun. 10, 2021
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2021-31928

    Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to escalate privileges to superadministrator. It was fixed in v2021.1.0.2.... Read more

    Affected Products : loyalty_experience_platform
    • EPSS Score: %0.52
    • Published: Jun. 10, 2021
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2021-31927

    An Insecure Direct Object Reference (IDOR) vulnerability in Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify any existing user, including users assigned to different environments and clients. It was fixed in ... Read more

    Affected Products : loyalty_experience_platform
    • EPSS Score: %0.13
    • Published: Jun. 10, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-31926

    AMP Application Deployment Service in CubeCoders AMP 2.1.x before 2.1.1.2 allows a remote, authenticated user to open ports in the local system firewall by crafting an HTTP(S) request directly to the applicable API endpoint (despite not having permission ... Read more

    Affected Products : amp
    • EPSS Score: %0.15
    • Published: Apr. 30, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-31925

    Pexip Infinity 25.x before 25.4 has Improper Input Validation, and thus an unauthenticated remote attacker can cause a denial of service via the administrative web interface.... Read more

    Affected Products : pexip_infinity
    • EPSS Score: %0.36
    • Published: Jul. 07, 2021
    • Modified: Nov. 21, 2024
  • 6.8

    MEDIUM
    CVE-2021-31924

    Yubico pam-u2f before 1.1.1 has a logic issue that, depending on the pam-u2f configuration and the application used, could lead to a local PIN bypass. This issue does not allow user presence (touch) or cryptographic signature verification to be bypassed, ... Read more

    Affected Products : fedora pam-u2f
    • EPSS Score: %0.09
    • Published: May. 26, 2021
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-31923

    Ping Identity PingAccess before 5.3.3 allows HTTP request smuggling via header manipulation.... Read more

    Affected Products : pingaccess
    • EPSS Score: %0.22
    • Published: Sep. 24, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-31922

    An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2 Header. This vulnerability is resolved in 21.1, 20.3R1, 20.2R1, 20.1R2, 19.2R4, and 18.2R3.... Read more

    Affected Products : virtual_traffic_manager
    • EPSS Score: %0.19
    • Published: May. 14, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-31921

    Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can access unexpected services in the cluster, bypassing authorization checks, when a gateway is configured with AUTO_PASSTHROUGH routing conf... Read more

    Affected Products : istio
    • EPSS Score: %0.21
    • Published: Jun. 02, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-31920

    Istio before 1.8.6 and 1.9.x before 1.9.5 has a remotely exploitable vulnerability where an HTTP request path with multiple slashes or escaped slash characters (%2F or %5C) could potentially bypass an Istio authorization policy when path based authorizati... Read more

    Affected Products : istio
    • EPSS Score: %0.24
    • Published: May. 27, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-31919

    An issue was discovered in the rkyv crate before 0.6.0 for Rust. When an archive is created via serialization, the archive content may contain uninitialized values of certain parts of a struct.... Read more

    Affected Products : rkyv
    • EPSS Score: %0.35
    • Published: Apr. 30, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-31918

    A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update and creation. The highest threat from this vulnerability is to data confidentiality.... Read more

    Affected Products : openstack
    • EPSS Score: %0.29
    • Published: May. 06, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 292316 Results