Latest CVE Feed
-
5.3
MEDIUMCVE-2021-31923
Ping Identity PingAccess before 5.3.3 allows HTTP request smuggling via header manipulation.... Read more
Affected Products : pingaccess- Published: Sep. 24, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-31922
An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2 Header. This vulnerability is resolved in 21.1, 20.3R1, 20.2R1, 20.1R2, 19.2R4, and 18.2R3.... Read more
Affected Products : virtual_traffic_manager- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31921
Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can access unexpected services in the cluster, bypassing authorization checks, when a gateway is configured with AUTO_PASSTHROUGH routing conf... Read more
Affected Products : istio- Published: Jun. 02, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-31920
Istio before 1.8.6 and 1.9.x before 1.9.5 has a remotely exploitable vulnerability where an HTTP request path with multiple slashes or escaped slash characters (%2F or %5C) could potentially bypass an Istio authorization policy when path based authorizati... Read more
Affected Products : istio- Published: May. 27, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-31919
An issue was discovered in the rkyv crate before 0.6.0 for Rust. When an archive is created via serialization, the archive content may contain uninitialized values of certain parts of a struct.... Read more
Affected Products : rkyv- Published: Apr. 30, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-31918
A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update and creation. The highest threat from this vulnerability is to data confidentiality.... Read more
Affected Products : openstack- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31917
A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authentication on all REST endpoints when DIGEST is used as the authentication method. The highest threat from this v... Read more
- Published: Sep. 21, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-31916
An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module in the Linux kernel before 5.12. A bound check failure allows an attacker with special user (CAP_SYS_ADMIN) privilege to gain acc... Read more
- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31915
In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible.... Read more
Affected Products : teamcity- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31914
In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible.... Read more
- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-31913
In JetBrains TeamCity before 2020.2.3, insufficient checks of the redirect_uri were made during GitHub SSO token exchange.... Read more
Affected Products : teamcity- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-31912
In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset.... Read more
Affected Products : teamcity- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-31911
In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages.... Read more
Affected Products : teamcity- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-31910
In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible.... Read more
Affected Products : teamcity- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31909
In JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possible.... Read more
Affected Products : teamcity- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-31908
In JetBrains TeamCity before 2020.2.3, stored XSS was possible on several pages.... Read more
Affected Products : teamcity- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-31907
In JetBrains TeamCity before 2020.2.2, permission checks for changing TeamCity plugins were implemented improperly.... Read more
Affected Products : teamcity- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2021-31906
In JetBrains TeamCity before 2020.2.2, audit logs were not sufficient when an administrator uploaded a file.... Read more
Affected Products : teamcity- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-31905
In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible.... Read more
Affected Products : youtrack- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-31904
In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page.... Read more
Affected Products : teamcity- Published: May. 11, 2021
- Modified: Nov. 21, 2024