Latest CVE Feed
-
8.8
HIGHCVE-2021-25318
A Incorrect Permission Assignment for Critical Resource vulnerability in Rancher allows users in the cluster to modify resources they should not have access to. This issue affects: Rancher versions prior to 2.5.9 ; Rancher versions prior to 2.4.16.... Read more
Affected Products : rancher- EPSS Score: %0.12
- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
3.3
LOWCVE-2021-25317
A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2, Factory allows local attackers with control of the lp users to... Read more
Affected Products : fedora leap linux_enterprise_server manager_server factory openldap2 cups openstack_cloud_crowbar- EPSS Score: %0.08
- Published: May. 05, 2021
- Modified: Nov. 21, 2024
-
3.3
LOWCVE-2021-25316
A Insecure Temporary File vulnerability in s390-tools of SUSE Linux Enterprise Server 12-SP5, SUSE Linux Enterprise Server 15-SP2 allows local attackers to prevent VM live migrations This issue affects: SUSE Linux Enterprise Server 12-SP5 s390-tools versi... Read more
- EPSS Score: %0.04
- Published: Apr. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25315
CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows local attackers to execute arbitrary code via salt without the need to specify valid credentials. This issue affects: SUSE Linux Enter... Read more
- EPSS Score: %0.16
- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-25314
A Creation of Temporary File With Insecure Permissions vulnerability in hawk2 of SUSE Linux Enterprise High Availability 12-SP3, SUSE Linux Enterprise High Availability 12-SP5, SUSE Linux Enterprise High Availability 15-SP2 allows local attackers to escal... Read more
- EPSS Score: %0.10
- Published: Apr. 14, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-25313
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rancher allows remote attackers to execute JavaScript via malicious links. This issue affects: SUSE Rancher Rancher versions prior to 2.5.6.... Read more
- EPSS Score: %0.54
- Published: Mar. 05, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-25312
HTCondor before 8.9.11 allows a user to submit a job as another user on the system, because of a flaw in the IDTOKENS authentication method.... Read more
Affected Products : htcondor- EPSS Score: %0.46
- Published: Jan. 27, 2021
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2021-25311
condor_credd in HTCondor before 8.9.11 allows Directory Traversal outside the SEC_CREDENTIAL_DIRECTORY_OAUTH directory, as demonstrated by creating a file under /etc that will later be executed by root.... Read more
Affected Products : htcondor- EPSS Score: %2.77
- Published: Jan. 27, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-25310
The administration web interface on Belkin Linksys WRT160NL 1.0.04.002_US_20130619 devices allows remote authenticated attackers to execute system commands with root privileges via shell metacharacters in the ui_language POST parameter to the apply.cgi fo... Read more
- EPSS Score: %6.30
- Published: Feb. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25309
The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout or throttling functionality. This situation (together with the weak password policy that forces a 4-digit password) allows remote atta... Read more
- EPSS Score: %0.56
- Published: Mar. 02, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-25306
A buffer overflow vulnerability in the AT command interface of Gigaset DX600A v41.00-175 devices allows remote attackers to force a device reboot by sending relatively long AT commands.... Read more
- EPSS Score: %0.85
- Published: Mar. 02, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25299
Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admi... Read more
Affected Products : nagios_xi- EPSS Score: %79.93
- Published: Feb. 15, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25295
OpenCATS through 0.9.5-3 has multiple Cross-site Scripting (XSS) issues.... Read more
Affected Products : opencats- EPSS Score: %0.85
- Published: Jan. 18, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-25294
OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occurs because lib/DataGrid.php calls unserialize for the parametersactivity:ActivityDataGrid parameter. The PHP object injection exploit ... Read more
Affected Products : opencats- EPSS Score: %27.73
- Published: Jan. 18, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-25293
An issue was discovered in Pillow before 8.1.1. There is an out-of-bounds read in SGIRleDecode.c.... Read more
Affected Products : pillow- EPSS Score: %0.12
- Published: Mar. 19, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-25292
An issue was discovered in Pillow before 8.1.1. The PDF parser allows a regular expression DoS (ReDoS) attack via a crafted PDF file because of a catastrophic backtracking regex.... Read more
Affected Products : pillow- EPSS Score: %0.16
- Published: Mar. 19, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-25291
An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is an out-of-bounds read in TiffreadRGBATile via invalid tile boundaries.... Read more
Affected Products : pillow- EPSS Score: %0.54
- Published: Mar. 19, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-25290
An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size.... Read more
- EPSS Score: %0.18
- Published: Mar. 19, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25289
An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NOTE: this issue exists because of an incomplete fix for C... Read more
Affected Products : pillow- EPSS Score: %0.21
- Published: Mar. 19, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-25288
An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_gray_i.... Read more
- EPSS Score: %0.20
- Published: Jun. 02, 2021
- Modified: Nov. 21, 2024