Latest CVE Feed
-
7.5
HIGHCVE-2021-26100
A missing cryptographic step in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an unauthenticated attacker who intercepts the encrypted messages to manipulate them in such a way that makes the tampering and the recovery of the p... Read more
Affected Products : fortimail- EPSS Score: %0.11
- Published: Jul. 09, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-26099
Missing cryptographic steps in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an attacker who comes in possession of the encrypted master keys to compromise their confidentiality by observing a few invariant properties of the ci... Read more
Affected Products : fortimail- EPSS Score: %0.16
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-26098
An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow an attacker in possession of a few information pieces about the state of the device to possibly predict valid session IDs.... Read more
Affected Products : fortisandbox- EPSS Score: %0.31
- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-26097
An improper neutralization of special elements used in an OS Command vulnerability in FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6 may allow an authenticated attacker with access to the web GUI to execute unauthorized cod... Read more
Affected Products : fortisandbox- EPSS Score: %0.43
- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-26096
Multiple instances of heap-based buffer overflow in the command shell of FortiSandbox before 4.0.0 may allow an authenticated attacker to manipulate memory and alter its content by means of specifically crafted command line arguments.... Read more
Affected Products : fortisandbox- EPSS Score: %0.52
- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-26095
The combination of various cryptographic issues in the session management of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6, including the encryption construction of the session cookie, may allow a remote attacker already in possession of a cookie ... Read more
Affected Products : fortimail- EPSS Score: %0.31
- Published: Jul. 20, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26092
Failure to sanitize input in the SSL VPN web portal of FortiOS 5.2.10 through 5.2.15, 5.4.0 through 5.4.13, 5.6.0 through 5.6.14, 6.0.0 through 6.0.12, 6.2.0 through 6.2.7, 6.4.0 through 6.4.4; and FortiProxy 1.2.0 through 1.2.9, 2.0.0 through 2.0.1 may a... Read more
- EPSS Score: %0.53
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-26090
A missing release of memory after its effective lifetime vulnerability in the Webmail of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6 may allow an unauthenticated remote attacker to exhaust available memory via specifically crafted login requests... Read more
Affected Products : fortimail- EPSS Score: %0.42
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26089
An improper symlink following in FortiClient for Mac 6.4.3 and below may allow an non-privileged user to execute arbitrary privileged shell commands during installation phase.... Read more
Affected Products : forticlient- EPSS Score: %0.09
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-26088
An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user to bypass a FSSO firewall policy and access the protected network via sending specifically crafted UDP login notification packets.... Read more
- EPSS Score: %5.48
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-26083
Export HTML Report in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS)... Read more
- EPSS Score: %0.26
- Published: Jul. 20, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-26082
The XML Export in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.17.0 allows remote attackers to inject arbitrary HTML or JavaScript via a stored cross site scripting vu... Read more
- EPSS Score: %0.31
- Published: Jul. 20, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-26081
REST API in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1 allows remote attackers to enumerate usernames via a Sensitive Data Exposure vulnerability in the `/rest/... Read more
- EPSS Score: %0.38
- Published: Jul. 20, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26080
EditworkflowScheme.jspa in Jira Server and Jira Data Center before version 8.5.14, and from version 8.6.0 before version 8.13.6, and from 8.14.0 before 8.16.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) ... Read more
- EPSS Score: %0.38
- Published: Jun. 07, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26079
The CardLayoutConfigTable component in Jira Server and Jira Data Center before version 8.5.15, and from version 8.6.0 before version 8.13.7, and from version 8.14.0 before 8.17.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross s... Read more
- EPSS Score: %0.44
- Published: Jun. 07, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26078
The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitrary HTML or JavaScript via a cross ... Read more
- EPSS Score: %0.82
- Published: Jun. 07, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-26076
The jira.editor.user.mode cookie set by the Jira Editor Plugin in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before version 8.13.4, and from version 8.14.0 before version 8.15.0 allows remote anonymous attackers who can perform ... Read more
- EPSS Score: %0.33
- Published: Apr. 15, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-26075
The Jira importers plugin AttachTemporaryFile rest resource in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before 8.13.4, and from version 8.14.0 before 8.15.1 allowed remote authenticated attackers to obtain the full path of the... Read more
- EPSS Score: %0.34
- Published: Apr. 15, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-26072
The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.... Read more
- EPSS Score: %9.00
- Published: Apr. 01, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-26071
The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to enable and disable Jira Software configu... Read more
- EPSS Score: %0.16
- Published: Apr. 01, 2021
- Modified: Nov. 21, 2024