Latest CVE Feed
-
7.8
HIGHCVE-2021-29261
The unofficial Svelte extension before 104.8.0 for Visual Studio Code allows attackers to execute arbitrary code via a crafted workspace configuration.... Read more
Affected Products : svelte- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29258
An issue was discovered in Envoy 1.14.0. There is a remotely exploitable crash for HTTP2 Metadata, because an empty METADATA map triggers a Reachable Assertion.... Read more
Affected Products : envoy- Published: May. 20, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29255
MicroSeven MYM71080i-B 2.0.5 through 2.0.20 devices send admin credentials in cleartext to pnp.microseven.com TCP port 7007. An attacker on the same network as the device can capture these credentials.... Read more
- Published: Mar. 26, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-29253
The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential storage vulnerability. An malicious attacker with access to the Tableau workbook file may obtain access to credential information to use ... Read more
Affected Products : archer- Published: May. 26, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29252
RSA Archer before 6.9 SP1 P1 (6.9.1.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user with access to modify link name fields could potentially exploit this vulnerability to execute code in a victim's browser.... Read more
Affected Products : archer- Published: May. 26, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-29251
BTCPay Server before 1.0.7.1 mishandles the policy setting in which users can register (in Server Settings > Policies). This affects Docker use cases in which a mail server is configured.... Read more
Affected Products : btcpay_server- Published: Apr. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29250
BTCPay Server through 1.0.7.0 suffers from a Stored Cross Site Scripting (XSS) vulnerability within the POS Add Products functionality. This enables cookie stealing.... Read more
Affected Products : btcpay_server- Published: May. 05, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29249
BTCPay Server before 1.0.6.0, when the payment button is used, has a privacy vulnerability.... Read more
Affected Products : btcpay_server- Published: Mar. 26, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-29248
BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the Secure flag for a cookie.... Read more
Affected Products : btcpay_server- Published: May. 05, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-29247
BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the HTTPOnly flag for a cookie.... Read more
Affected Products : btcpay_server- Published: May. 05, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-29246
BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacker must craft a malicious plugin file with special characters to upload the file outside of the restricted ... Read more
Affected Products : btcpay_server- Published: May. 05, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-29245
BTCPay Server through 1.0.7.0 uses a weak method Next to produce pseudo-random values to generate a legacy API key.... Read more
Affected Products : btcpay_server- Published: May. 05, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-29243
Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS.... Read more
Affected Products : cloudera_manager- Published: Nov. 08, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29242
CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.... Read more
Affected Products : gateway edge_gateway opc_server plchandler control_for_beaglebone_sl control_for_empc-a\/imx6_sl control_for_iot2000_sl control_for_linux_sl control_for_pfc100_sl control_for_pfc200_sl +12 more products- Published: May. 03, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29241
CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS).... Read more
- Published: May. 03, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-29240
The Package Manager of CODESYS Development System 3 before 3.5.17.0 does not check the validity of packages before installation and may be used to install CODESYS packages with malicious content.... Read more
Affected Products : development_system- Published: May. 04, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-29239
CODESYS Development System 3 before 3.5.17.0 displays or executes malicious documents or files embedded in libraries without first checking their validity.... Read more
Affected Products : development_system- Published: May. 03, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-29238
CODESYS Automation Server before 1.16.0 allows cross-site request forgery (CSRF).... Read more
Affected Products : automation_server- Published: May. 03, 2021
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2021-29221
A local privilege escalation vulnerability was discovered in Erlang/OTP prior to version 23.2.3. By adding files to an existing installation's directory, a local attacker could hijack accounts of other users running Erlang programs or possibly coerce a se... Read more
- Published: Apr. 09, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-29220
Multiple buffer overflow security vulnerabilities have been identified in HPE iLO Amplifier Pack version(s): Prior to 2.12. These vulnerabilities could be exploited by a highly privileged user to remotely execute code that could lead to a loss of confiden... Read more
Affected Products : ilo_amplifier_pack- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024