Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2021-26738

    Zscaler Client Connector for macOS prior to 3.7 had an unquoted search path vulnerability via the PATH variable. A local adversary may be able to execute code with root privileges. ... Read more

    Affected Products : client_connector
    • EPSS Score: %0.04
    • Published: Oct. 23, 2023
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2021-26737

    The Zscaler Client Connector for macOS prior to 3.6 did not sufficiently validate RPC clients. A local adversary without sufficient privileges may be able to shutdown the Zscaler tunnel by exploiting a race condition. ... Read more

    Affected Products : client_connector
    • EPSS Score: %0.02
    • Published: Oct. 23, 2023
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-26736

    Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed execution of binaries from a low privileged path. A local adversary may be able to execute code with SYSTEM privileges. ... Read more

    Affected Products : client_connector
    • EPSS Score: %0.03
    • Published: Oct. 23, 2023
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-26735

    The Zscaler Client Connector Installer and Unsintallers for Windows prior to 3.6 had an unquoted search path vulnerability. A local adversary may be able to execute code with SYSTEM privileges. ... Read more

    Affected Products : client_connector
    • EPSS Score: %0.04
    • Published: Oct. 23, 2023
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2021-26734

    Zscaler Client Connector Installer on Windows before version 3.4.0.124 improperly handled directory junctions during uninstallation. A local adversary may be able to delete folders in an elevated context. ... Read more

    Affected Products : client_connector
    • EPSS Score: %0.02
    • Published: Oct. 23, 2023
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-26733

    A broken access control vulnerability in the FirstReset_handler_func function of spx_restservice allows an attacker to arbitrarily send reboot commands to the BMC, causing a Denial-of-Service (DoS) condition. This issue affects: Lanner Inc IAC-AST2500A st... Read more

    Affected Products : iac-ast2500a_firmware iac-ast2500a
    • EPSS Score: %0.04
    • Published: Oct. 24, 2022
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-26732

    A broken access control vulnerability in the First_network_func function of spx_restservice allows an attacker to arbitrarily change the network configuration of the BMC. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.... Read more

    Affected Products : iac-ast2500a_firmware iac-ast2500a
    • EPSS Score: %0.04
    • Published: Oct. 24, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-26731

    Command injection and multiple stack-based buffer overflows vulnerabilities in the modifyUserb_func function of spx_restservice allow an authenticated attacker to execute arbitrary code with the same privileges as the server user (root). This issue affect... Read more

    Affected Products : iac-ast2500a_firmware iac-ast2500a
    • EPSS Score: %0.33
    • Published: Oct. 24, 2022
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2021-26730

    A stack-based buffer overflow vulnerability in a subfunction of the Login_handler_func function of spx_restservice allows an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500A... Read more

    Affected Products : iac-ast2500a_firmware iac-ast2500a
    • EPSS Score: %0.19
    • Published: Oct. 24, 2022
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2021-26729

    Command injection and multiple stack-based buffer overflows vulnerabilities in the Login_handler_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner In... Read more

    Affected Products : iac-ast2500a_firmware iac-ast2500a
    • EPSS Score: %0.36
    • Published: Oct. 24, 2022
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2021-26728

    Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500... Read more

    Affected Products : iac-ast2500a_firmware iac-ast2500a
    • EPSS Score: %0.64
    • Published: Oct. 24, 2022
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2021-26727

    Multiple command injections and stack-based buffer overflows vulnerabilities in the SubNet_handler_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner ... Read more

    Affected Products : iac-ast2500a_firmware iac-ast2500a
    • EPSS Score: %0.49
    • Published: Oct. 24, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-26726

    A remote code execution vulnerability affecting a Valmet DNA service listening on TCP port 1517, allows an attacker to execute commands with SYSTEM privileges This issue affects: Valmet DNA versions from Collection 2012 until Collection 2021.... Read more

    Affected Products : dna
    • EPSS Score: %1.08
    • Published: Feb. 16, 2022
    • Modified: Nov. 21, 2024
  • 8.6

    HIGH
    CVE-2021-26725

    Path Traversal vulnerability when changing timezone using web GUI of Nozomi Networks Guardian, CMC allows an authenticated administrator to read-protected system files. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior versi... Read more

    • EPSS Score: %0.53
    • Published: Feb. 22, 2021
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2021-26724

    OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC allows authenticated administrators to perform remote code execution. This issue affects: Nozomi Networks Guardian 20.0.7.3 versio... Read more

    • EPSS Score: %2.71
    • Published: Feb. 22, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-26723

    Jenzabar 9.2.x through 9.2.2 allows /ics?tool=search&query= XSS.... Read more

    Affected Products : jenzabar
    • EPSS Score: %64.22
    • Published: Feb. 06, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-26722

    LinkedIn Oncall through 1.4.0 allows reflected XSS via /query because of mishandling of the "No results found for" message in the search bar.... Read more

    Affected Products : oncall
    • EPSS Score: %29.91
    • Published: Feb. 05, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-26720

    avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /ru... Read more

    Affected Products : debian_linux avahi
    • EPSS Score: %0.03
    • Published: Feb. 17, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-26719

    A directory traversal issue was discovered in Gradle gradle-enterprise-test-distribution-agent before 1.3.2, test-distribution-gradle-plugin before 1.3.2, and gradle-enterprise-maven-extension before 1.8.2. A malicious actor (with certain credentials) can... Read more

    • EPSS Score: %0.59
    • Published: Feb. 09, 2021
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2021-26718

    KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus protection.... Read more

    Affected Products : internet_security
    • EPSS Score: %0.05
    • Published: Apr. 01, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 291564 Results