Latest CVE Feed
-
6.5
MEDIUMCVE-2021-31806
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy) via HTTP Range request processing.... Read more
- EPSS Score: %67.34
- Published: May. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31805
The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evalu... Read more
Affected Products : struts- EPSS Score: %93.96
- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-31804
LeoCAD before 21.03 sometimes allows a use-after-free during the opening of a new document.... Read more
Affected Products : leocad- EPSS Score: %0.19
- Published: Apr. 26, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-31803
cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581).... Read more
Affected Products : cpanel- EPSS Score: %0.28
- Published: Apr. 26, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-31802
NETGEAR R7000 1.0.11.116 devices have a heap-based Buffer Overflow that is exploitable from the local network without authentication. The vulnerability exists within the handling of an HTTP request. An attacker can leverage this to execute code as root. T... Read more
- EPSS Score: %12.70
- Published: Apr. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31800
Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver instance can list and write to arbitrary files via ../ directory traversal. This could potentially be abused to achi... Read more
- EPSS Score: %39.21
- Published: May. 05, 2021
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2021-31799
In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.... Read more
- EPSS Score: %0.19
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-31798
The effective key space used to encrypt the cache in CyberArk Credential Provider prior to 12.1 has low entropy, and under certain conditions a local malicious user can obtain the plaintext of cache files.... Read more
Affected Products : credential_provider- EPSS Score: %0.11
- Published: Sep. 02, 2021
- Modified: Nov. 21, 2024
-
5.1
MEDIUMCVE-2021-31797
The user identification mechanism used by CyberArk Credential Provider prior to 12.1 is susceptible to a local host race condition, leading to password disclosure.... Read more
Affected Products : credential_provider- EPSS Score: %0.08
- Published: Sep. 02, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-31796
An inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may lead to Information Disclosure. An attacker may realistically have enough information that the number of possible keys (for a credential file) is only one, a... Read more
Affected Products : credential_provider- EPSS Score: %0.61
- Published: Sep. 02, 2021
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2021-31795
The PowerVR GPU kernel driver in pvrsrvkm.ko through 2021-04-24 for the Linux kernel, as used on Alcatel 1S phones, allows attackers to overwrite heap memory via PhysmemNewRamBackedPMR.... Read more
Affected Products : pvrsrvkm.ko- EPSS Score: %0.05
- Published: Apr. 24, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-31794
Settings.aspx?view=About in Directum 5.8.2 allows XSS via the HTTP User-Agent header.... Read more
Affected Products : directum- EPSS Score: %0.28
- Published: Apr. 24, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-31793
An issue exists on NightOwl WDB-20-V2 WDB-20-V2_20190314 devices that allows an unauthenticated user to gain access to snapshots and video streams from the doorbell. The binary app offers a web server on port 80 that allows an unauthenticated user to take... Read more
- EPSS Score: %1.70
- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-31792
XSS in the client account page in SuiteCRM before 7.11.19 allows an attacker to inject JavaScript via the name field... Read more
Affected Products : suitecrm- EPSS Score: %0.38
- Published: Apr. 30, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-31791
In Hardware Sentry KM before 10.0.01 for BMC PATROL, a cleartext password may be discovered after a failure or timeout of a command.... Read more
Affected Products : hardware_sentry_km_for_bmc_patrol- EPSS Score: %0.15
- Published: Apr. 23, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-31787
The Bluetooth Classic implementation on Actions ATS2815 chipsets does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service and shutdown of a device by flooding the targ... Read more
- EPSS Score: %0.13
- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-31786
The Bluetooth Classic Audio implementation on Actions ATS2815 and ATS2819 devices does not properly handle a connection attempt from a host with the same BDAddress as the current connected BT host, allowing attackers to trigger a disconnection and deadloc... Read more
- EPSS Score: %0.10
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-31785
The Bluetooth Classic implementation on Actions ATS2815 and ATS2819 chipsets does not properly handle the reception of multiple LMP_host_connection_req packets, allowing attackers in radio range to trigger a denial of service (deadlock) of the device via ... Read more
- EPSS Score: %0.10
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-31784
An out-of-bounds write vulnerability exists in the file-reading procedure in Open Design Alliance Drawings SDK before 2021.6 on all supported by ODA platforms in static configuration. This can allow attackers to cause a crash, potentially enabling a denia... Read more
- EPSS Score: %0.32
- Published: Apr. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-31783
show_default.php in the LocalFilesEditor extension before 11.4.0.1 for Piwigo allows Local File Inclusion because the file parameter is not validated with a proper regular-expression check.... Read more
Affected Products : localfiles_editor- EPSS Score: %0.18
- Published: Apr. 26, 2021
- Modified: Nov. 21, 2024