Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.3

    HIGH
    CVE-2021-27030

    A user may be tricked into opening a malicious FBX file which may exploit a Directory Traversal Remote Code Execution vulnerability in FBX’s Review causing it to run arbitrary code on the system.... Read more

    Affected Products : fbx_review
    • EPSS Score: %49.33
    • Published: Apr. 19, 2021
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2021-27029

    The user may be tricked into opening a malicious FBX file which may exploit a Null Pointer Dereference vulnerability in FBX's Review version 1.5.0 and prior causing the application to crash leading to a denial of service.... Read more

    Affected Products : fbx_review
    • EPSS Score: %0.14
    • Published: Apr. 19, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-27028

    A Memory Corruption Vulnerability in Autodesk FBX Review version 1.5.0 and prior may lead to remote code execution through maliciously crafted DLL files.... Read more

    Affected Products : fbx_review
    • EPSS Score: %0.73
    • Published: Apr. 19, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-27027

    An Out-Of-Bounds Read Vulnerability in Autodesk FBX Review version 1.5.0 and prior may lead to code execution through maliciously crafted DLL files or information disclosure.... Read more

    Affected Products : fbx_review
    • EPSS Score: %0.32
    • Published: Apr. 19, 2021
    • Modified: Nov. 21, 2024
  • 4.4

    MEDIUM
    CVE-2021-27026

    A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged... Read more

    • EPSS Score: %0.06
    • Published: Nov. 18, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-27025

    A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.... Read more

    • EPSS Score: %0.17
    • Published: Nov. 18, 2021
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2021-27024

    A flaw was discovered in Continuous Delivery for Puppet Enterprise (CD4PE) that results in a user with lower privileges being able to access a Puppet Enterprise API token. This issue is resolved in CD4PE 4.10.0... Read more

    Affected Products : continuous_delivery
    • EPSS Score: %0.32
    • Published: Nov. 18, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-27023

    A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007... Read more

    • EPSS Score: %0.26
    • Published: Nov. 18, 2021
    • Modified: Nov. 21, 2024
  • 4.9

    MEDIUM
    CVE-2021-27022

    A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue only affects SSH/WinRM nodes (inventory service nodes).... Read more

    Affected Products : puppet_enterprise puppet
    • EPSS Score: %0.34
    • Published: Sep. 07, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-27021

    A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query.... Read more

    Affected Products : puppet_enterprise puppet puppetdb
    • EPSS Score: %0.63
    • Published: Jul. 20, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-27020

    Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export.... Read more

    Affected Products : puppet_enterprise
    • EPSS Score: %0.82
    • Published: Aug. 30, 2021
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2021-27019

    PuppetDB logging included potentially sensitive system information.... Read more

    Affected Products : puppet_enterprise puppetdb
    • EPSS Score: %0.20
    • Published: Aug. 30, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-27018

    The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate authority to not be properly validated. This issue only affects clients that are configured to utilize Tenabl... Read more

    Affected Products : remediate
    • EPSS Score: %0.10
    • Published: Aug. 30, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-27007

    NetApp Virtual Desktop Service (VDS) when used with an HTML5 gateway is susceptible to a vulnerability which when successfully exploited could allow an unauthenticated attacker to takeover a Remote Desktop Session.... Read more

    Affected Products : virtual_desktop_service
    • EPSS Score: %0.71
    • Published: Dec. 23, 2021
    • Modified: Nov. 21, 2024
  • 4.4

    MEDIUM
    CVE-2021-27006

    StorageGRID (formerly StorageGRID Webscale) versions 11.5 prior to 11.5.0.5 are susceptible to a vulnerability which may allow an administrative user to escalate their privileges and modify settings in SANtricity System Manager.... Read more

    Affected Products : storagegrid
    • EPSS Score: %0.06
    • Published: Dec. 23, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-27005

    Clustered Data ONTAP versions 9.6 and higher prior to 9.6P16, 9.7P16, 9.8P7 and 9.9.1P3 are susceptible to a vulnerability which could allow a remote attacker to cause a crash of the httpd server.... Read more

    • EPSS Score: %0.70
    • Published: Nov. 01, 2021
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2021-27004

    System Manager 9.x versions 9.7 and higher prior to 9.7P16, 9.8P7 and 9.9.1P2 are susceptible to a vulnerability which could allow a local attacker to discover plaintext iSCSI CHAP credentials.... Read more

    Affected Products : ontap_system_manager
    • EPSS Score: %0.13
    • Published: Nov. 01, 2021
    • Modified: Nov. 21, 2024
  • 4.7

    MEDIUM
    CVE-2021-27003

    Clustered Data ONTAP versions prior to 9.5P18, 9.6P15, 9.7P14, 9.8P5 and 9.9.1 are missing an X-Frame-Options header which could allow a clickjacking attack.... Read more

    Affected Products : clustered_data_ontap
    • EPSS Score: %0.21
    • Published: Oct. 12, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-27002

    NetApp Cloud Manager versions prior to 3.9.10 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to retrieve sensitive data via the web proxy.... Read more

    Affected Products : cloud_manager
    • EPSS Score: %0.75
    • Published: Oct. 11, 2021
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2021-27001

    Clustered Data ONTAP versions 9.x prior to 9.5P18, 9.6P16, 9.7P16, 9.8P7 and 9.9.1P2 are susceptible to a vulnerability which could allow an authenticated privileged local attacker to arbitrarily modify Compliance-mode WORM data prior to the end of the re... Read more

    Affected Products : clustered_data_ontap
    • EPSS Score: %0.06
    • Published: Oct. 19, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 291728 Results