Latest CVE Feed
-
4.8
MEDIUMCVE-2021-29207
A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity... Read more
Affected Products : integrated_lights-out_4 integrated_lights-out_5 proliant_dl120_gen10_server proliant_dl160_gen10_server proliant_dl180_gen10_server proliant_dl360_gen10_server proliant_dl380_gen10_server proliant_dl385_gen10_server proliant_dl560_gen10_server proliant_dl580_gen10_server +19 more products- EPSS Score: %0.11
- Published: May. 25, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-29206
A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity... Read more
Affected Products : integrated_lights-out_4 integrated_lights-out_5 proliant_dl120_gen10_server proliant_dl160_gen10_server proliant_dl180_gen10_server proliant_dl360_gen10_server proliant_dl380_gen10_server proliant_dl385_gen10_server proliant_dl560_gen10_server proliant_dl580_gen10_server +19 more products- EPSS Score: %0.12
- Published: May. 25, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-29205
A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity... Read more
Affected Products : integrated_lights-out_4 integrated_lights-out_5 proliant_dl120_gen10_server proliant_dl160_gen10_server proliant_dl180_gen10_server proliant_dl360_gen10_server proliant_dl380_gen10_server proliant_dl385_gen10_server proliant_dl560_gen10_server proliant_dl580_gen10_server +19 more products- EPSS Score: %0.11
- Published: May. 25, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-29204
A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity... Read more
Affected Products : integrated_lights-out_4 integrated_lights-out_5 proliant_dl120_gen10_server proliant_dl160_gen10_server proliant_dl180_gen10_server proliant_dl360_gen10_server proliant_dl380_gen10_server proliant_dl385_gen10_server proliant_dl560_gen10_server proliant_dl580_gen10_server +19 more products- EPSS Score: %0.11
- Published: May. 25, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-29203
A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software, prior to version 1.22. The vulnerability could be remotely exploited to bypass remote authentication le... Read more
Affected Products : edgeline_infrastructure_manager- EPSS Score: %87.05
- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-29202
A local buffer overflow vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE... Read more
Affected Products : integrated_lights-out_4 integrated_lights-out_5 proliant_dl120_gen10_server proliant_dl160_gen10_server proliant_dl180_gen10_server proliant_dl360_gen10_server proliant_dl380_gen10_server proliant_dl385_gen10_server proliant_dl560_gen10_server proliant_dl580_gen10_server +19 more products- EPSS Score: %0.07
- Published: May. 25, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-29201
A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity... Read more
Affected Products : integrated_lights-out_4 integrated_lights-out_5 proliant_dl120_gen10_server proliant_dl160_gen10_server proliant_dl180_gen10_server proliant_dl360_gen10_server proliant_dl380_gen10_server proliant_dl385_gen10_server proliant_dl560_gen10_server proliant_dl580_gen10_server +19 more products- EPSS Score: %0.12
- Published: May. 25, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-29200
Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack... Read more
Affected Products : ofbiz- EPSS Score: %92.95
- Published: Apr. 27, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-29159
A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x before 3.30.1. An attacker with a local account can create entities with crafted properties that, when viewed by an administrator, can execute arbitrary JavaScr... Read more
Affected Products : nexus_repository_manager- EPSS Score: %0.28
- Published: Apr. 28, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-29158
Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control.... Read more
Affected Products : nexus_repository_manager_3- EPSS Score: %0.22
- Published: Apr. 23, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29157
Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during use of local JWT validation with t... Read more
- EPSS Score: %0.10
- Published: Jun. 28, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29156
ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-character retrieval of password hashes, or retrieve a session token or a private key.... Read more
Affected Products : openam- EPSS Score: %92.18
- Published: Mar. 25, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-29155
An issue was discovered in the Linux kernel through 5.11.x. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from k... Read more
- EPSS Score: %0.24
- Published: Apr. 20, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-29154
BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them to execute arbitrary code within the kernel context. This affects arch/x86/net/bpf_jit_comp.c and arch/x86/net/bpf_jit_comp32.c.... Read more
Affected Products : linux_kernel fedora debian_linux cloud_backup hci_management_node solidfire h300s_firmware h500s_firmware h700s_firmware h410s_firmware +10 more products- EPSS Score: %0.04
- Published: Apr. 08, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-29152
A remote denial of service (DoS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.... Read more
Affected Products : clearpass_policy_manager- EPSS Score: %0.56
- Published: Jul. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-29151
A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.... Read more
Affected Products : clearpass_policy_manager- EPSS Score: %0.14
- Published: Jul. 08, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-29150
A remote insecure deserialization vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.... Read more
Affected Products : clearpass_policy_manager- EPSS Score: %1.43
- Published: Jul. 08, 2021
- Modified: Nov. 21, 2024
-
6.2
MEDIUMCVE-2021-29149
A local bypass security restrictions vulnerability was discovered in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Serie... Read more
- EPSS Score: %0.06
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-29148
A local cross-site scripting (XSS) vulnerability was discovered in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series ... Read more
- EPSS Score: %0.32
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-29147
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address this security vulnerability.... Read more
- EPSS Score: %4.66
- Published: Apr. 29, 2021
- Modified: Nov. 21, 2024