Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2021-29263

    In JetBrains IntelliJ IDEA 2020.3.3, local code execution was possible because of insufficient checks when getting the project from VCS.... Read more

    Affected Products : intellij_idea
    • EPSS Score: %0.00
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-29262

    When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the optional read-only user is configured then Solr would not treat that node as ... Read more

    Affected Products : solr
    • EPSS Score: %26.23
    • Published: Apr. 13, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-29261

    The unofficial Svelte extension before 104.8.0 for Visual Studio Code allows attackers to execute arbitrary code via a crafted workspace configuration.... Read more

    Affected Products : svelte
    • EPSS Score: %0.68
    • Published: Apr. 05, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-29258

    An issue was discovered in Envoy 1.14.0. There is a remotely exploitable crash for HTTP2 Metadata, because an empty METADATA map triggers a Reachable Assertion.... Read more

    Affected Products : envoy
    • EPSS Score: %0.12
    • Published: May. 20, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-29255

    MicroSeven MYM71080i-B 2.0.5 through 2.0.20 devices send admin credentials in cleartext to pnp.microseven.com TCP port 7007. An attacker on the same network as the device can capture these credentials.... Read more

    Affected Products : mym71080i-b_firmware mym71080i-b
    • EPSS Score: %0.12
    • Published: Mar. 26, 2021
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2021-29253

    The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential storage vulnerability. An malicious attacker with access to the Tableau workbook file may obtain access to credential information to use ... Read more

    Affected Products : archer
    • EPSS Score: %0.10
    • Published: May. 26, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-29252

    RSA Archer before 6.9 SP1 P1 (6.9.1.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user with access to modify link name fields could potentially exploit this vulnerability to execute code in a victim's browser.... Read more

    Affected Products : archer
    • EPSS Score: %0.26
    • Published: May. 26, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-29251

    BTCPay Server before 1.0.7.1 mishandles the policy setting in which users can register (in Server Settings > Policies). This affects Docker use cases in which a mail server is configured.... Read more

    Affected Products : btcpay_server
    • EPSS Score: %0.23
    • Published: Apr. 01, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-29250

    BTCPay Server through 1.0.7.0 suffers from a Stored Cross Site Scripting (XSS) vulnerability within the POS Add Products functionality. This enables cookie stealing.... Read more

    Affected Products : btcpay_server
    • EPSS Score: %0.27
    • Published: May. 05, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-29249

    BTCPay Server before 1.0.6.0, when the payment button is used, has a privacy vulnerability.... Read more

    Affected Products : btcpay_server
    • EPSS Score: %0.32
    • Published: Mar. 26, 2021
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-29248

    BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the Secure flag for a cookie.... Read more

    Affected Products : btcpay_server
    • EPSS Score: %0.13
    • Published: May. 05, 2021
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-29247

    BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the HTTPOnly flag for a cookie.... Read more

    Affected Products : btcpay_server
    • EPSS Score: %0.28
    • Published: May. 05, 2021
    • Modified: Nov. 21, 2024
  • 6.7

    MEDIUM
    CVE-2021-29246

    BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacker must craft a malicious plugin file with special characters to upload the file outside of the restricted ... Read more

    Affected Products : btcpay_server
    • EPSS Score: %0.41
    • Published: May. 05, 2021
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-29245

    BTCPay Server through 1.0.7.0 uses a weak method Next to produce pseudo-random values to generate a legacy API key.... Read more

    Affected Products : btcpay_server
    • EPSS Score: %0.36
    • Published: May. 05, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-29243

    Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS.... Read more

    Affected Products : cloudera_manager
    • EPSS Score: %0.46
    • Published: Nov. 08, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-29242

    CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.... Read more

    • EPSS Score: %0.44
    • Published: May. 03, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-29241

    CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS).... Read more

    • EPSS Score: %0.56
    • Published: May. 03, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-29240

    The Package Manager of CODESYS Development System 3 before 3.5.17.0 does not check the validity of packages before installation and may be used to install CODESYS packages with malicious content.... Read more

    Affected Products : development_system
    • EPSS Score: %0.26
    • Published: May. 04, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-29239

    CODESYS Development System 3 before 3.5.17.0 displays or executes malicious documents or files embedded in libraries without first checking their validity.... Read more

    Affected Products : development_system
    • EPSS Score: %0.07
    • Published: May. 03, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-29238

    CODESYS Automation Server before 1.16.0 allows cross-site request forgery (CSRF).... Read more

    Affected Products : automation_server
    • EPSS Score: %0.17
    • Published: May. 03, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 291558 Results