Latest CVE Feed
-
7.5
HIGHCVE-2021-30639
A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part of a change to improve error handling during non-blocking I/O meant that the error flag associated with the Request object was not res... Read more
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-30638
Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specially-constructed URL. This was caused by an incomplete fix for CVE-2020-13953. This issue affects Apache Ta... Read more
Affected Products : tapestry- Published: Apr. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-30637
htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.... Read more
Affected Products : htmly- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-30636
In MediaTek LinkIt SDK before 4.6.1, there is a possible memory corruption due to an integer overflow during mishandled memory allocation by pvPortCalloc and pvPortRealloc.... Read more
Affected Products : linkit_software_development_kit- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-30635
Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that exist in a UI-related folder via directory traversal (no customer-specific data is exposed).... Read more
Affected Products : nexus_repository_manager- Published: Apr. 27, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-30630
Inappropriate implementation in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.... Read more
- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-30629
Use after free in Permissions in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-30628
Stack buffer overflow in ANGLE in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page.... Read more
- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-30627
Type confusion in Blink layout in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-30626
Out of bounds memory access in ANGLE in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-30625
Use after free in Selection API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who convinced the user the visit a malicious website to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGH- Published: Sep. 03, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGH- Published: Sep. 03, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGH- Published: Sep. 03, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUM- Published: Sep. 03, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGH- Published: Sep. 03, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUM- Published: Sep. 03, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGH- Published: Sep. 03, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUM- Published: Sep. 03, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGH- Published: Sep. 03, 2021
- Modified: Nov. 21, 2024