Latest CVE Feed
-
8.6
HIGHCVE-2021-26725
Path Traversal vulnerability when changing timezone using web GUI of Nozomi Networks Guardian, CMC allows an authenticated administrator to read-protected system files. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior versi... Read more
- EPSS Score: %0.53
- Published: Feb. 22, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-26724
OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC allows authenticated administrators to perform remote code execution. This issue affects: Nozomi Networks Guardian 20.0.7.3 versio... Read more
- EPSS Score: %2.71
- Published: Feb. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26723
Jenzabar 9.2.x through 9.2.2 allows /ics?tool=search&query= XSS.... Read more
Affected Products : jenzabar- EPSS Score: %64.22
- Published: Feb. 06, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26722
LinkedIn Oncall through 1.4.0 allows reflected XSS via /query because of mishandling of the "No results found for" message in the search bar.... Read more
Affected Products : oncall- EPSS Score: %29.91
- Published: Feb. 05, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26720
avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /ru... Read more
- EPSS Score: %0.03
- Published: Feb. 17, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-26719
A directory traversal issue was discovered in Gradle gradle-enterprise-test-distribution-agent before 1.3.2, test-distribution-gradle-plugin before 1.3.2, and gradle-enterprise-maven-extension before 1.8.2. A malicious actor (with certain credentials) can... Read more
- EPSS Score: %0.59
- Published: Feb. 09, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-26718
KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus protection.... Read more
Affected Products : internet_security- EPSS Score: %0.05
- Published: Apr. 01, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-26717
An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6. When re-negotiating for T.38, if the initial remote response was delayed just enough, Asterisk would send... Read more
- EPSS Score: %0.44
- Published: Feb. 18, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26716
Modules/input/Views/schedule.php in Emoncms through 10.2.7 allows XSS via the node parameter.... Read more
Affected Products : emoncms- EPSS Score: %0.22
- Published: Feb. 21, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-26715
The OpenID Connect server implementation for MITREid Connect through 1.3.3 contains a Server Side Request Forgery (SSRF) vulnerability. The vulnerability arises due to unsafe usage of the logo_uri parameter in the Dynamic Client Registration request. An u... Read more
Affected Products : connect- EPSS Score: %0.55
- Published: Mar. 25, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26714
The Enterprise License Manager portal in Mitel MiContact Center Enterprise before 9.4 could allow a user to access restricted files and folders due to insufficient access control. A successful exploit could allow an attacker to view and modify application... Read more
Affected Products : micontact_center_enterprise- EPSS Score: %0.92
- Published: Mar. 29, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-26713
A stack-based buffer overflow in res_rtp_asterisk.c in Sangoma Asterisk before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6 allows an authenticated WebRTC client to cause an Asterisk crash by sending multipl... Read more
- EPSS Score: %0.16
- Published: Feb. 19, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-26712
Incorrect access controls in res_srtp.c in Sangoma Asterisk 13.38.1, 16.16.0, 17.9.1, and 18.2.0 and Certified Asterisk 16.8-cert5 allow a remote unauthenticated attacker to prematurely terminate secure calls by replaying SRTP packets.... Read more
- EPSS Score: %1.65
- Published: Feb. 18, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-26711
A frame-injection issue in the online help in Redwood Report2Web 4.3.4.5 allows remote attackers to render an external resource inside a frame via the help/Online_Help/NetHelp/default.htm turl parameter.... Read more
Affected Products : report2web- EPSS Score: %0.26
- Published: Feb. 05, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26710
A cross-site scripting (XSS) issue in the login panel in Redwood Report2Web 4.3.4.5 and 4.5.3 allows remote attackers to inject JavaScript via the signIn.do urll parameter.... Read more
Affected Products : report2web- EPSS Score: %17.80
- Published: Feb. 05, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-26709
D-Link DSL-320B-D1 devices through EU_1.25 are prone to multiple Stack-Based Buffer Overflows that allow unauthenticated remote attackers to take over a device via the login.xgi user and pass parameters. NOTE: This vulnerability only affects products that... Read more
- EPSS Score: %39.84
- Published: Apr. 07, 2021
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2021-26708
A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implementation are caused by wrong locking in net/vmw_vsock/af_vsock.c. The race conditions were implicitly introduced in the commits ... Read more
Affected Products : linux_kernel cloud_backup solidfire_\&_hci_management_node aff_baseboard_management_controller fas_baseboard_management_controller solidfire_baseboard_management_controller hci_h410c_firmware baseboard_management_controller_500f_firmware baseboard_management_controller_a250_firmware hci_h410c +2 more products- EPSS Score: %1.02
- Published: Feb. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26707
The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attack... Read more
- EPSS Score: %1.09
- Published: Jun. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26706
An issue was discovered in lib_mem.c in Micrium uC/OS uC/LIB 1.38.x and 1.39.00. The following memory allocation functions do not check for integer overflow when allocating a pool whose size exceeds the address space: Mem_PoolCreate, Mem_DynPoolCreate, an... Read more
Affected Products : uc\/lib- EPSS Score: %0.76
- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-26705
An issue was discovered in SquareBox CatDV Server through 9.2. An attacker can invoke sensitive RMI methods such as getConnections without authentication, the results of which can be used to generate valid authentication tokens. These tokens can then be u... Read more
Affected Products : catdv- EPSS Score: %0.48
- Published: Mar. 05, 2021
- Modified: Nov. 21, 2024