Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.1

    CRITICAL
    CVE-2021-26291

    Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a p... Read more

    • EPSS Score: %45.48
    • Published: Apr. 23, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-26277

    The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to perform privileged actions.... Read more

    Affected Products : android frame_service
    • EPSS Score: %0.33
    • Published: Feb. 17, 2023
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-26276

    scripts/cli.js in the GoDaddy node-config-shield (aka Config Shield) package before 0.2.2 for Node.js calls eval when processing a set command. NOTE: the vendor reportedly states that this is not a vulnerability. The set command was not intended for use w... Read more

    Affected Products : node-config-shield
    • EPSS Score: %0.24
    • Published: Jan. 27, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2021-26275

    The eslint-fixer package through 0.1.5 for Node.js allows command injection via shell metacharacters to the fix function. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. The ozum/eslint-fixer GitHub repositor... Read more

    Affected Products : eslint-fixer
    • EPSS Score: %5.59
    • Published: Mar. 19, 2021
    • Modified: Nov. 21, 2024
  • 7.1

    HIGH
    CVE-2021-26274

    The Agent in NinjaRMM 5.0.909 has Insecure Permissions.... Read more

    Affected Products : ninjarmm
    • EPSS Score: %0.04
    • Published: Jul. 07, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-26273

    The Agent in NinjaRMM 5.0.909 has Incorrect Access Control.... Read more

    Affected Products : ninjarmm
    • EPSS Score: %0.14
    • Published: Jul. 07, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-26272

    It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).... Read more

    • EPSS Score: %0.20
    • Published: Jan. 26, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-26271

    It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).... Read more

    • EPSS Score: %0.64
    • Published: Jan. 26, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-26267

    cPanel before 92.0.9 allows a MySQL user (who has an old-style password hash) to bypass suspension (SEC-579).... Read more

    Affected Products : cpanel
    • EPSS Score: %0.24
    • Published: Jan. 26, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-26266

    cPanel before 92.0.9 allows a Reseller to bypass the suspension lock (SEC-578).... Read more

    Affected Products : cpanel
    • EPSS Score: %0.24
    • Published: Jan. 26, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-26263

    Cross-site scripting (XSS) issue in Discuss app of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to inject arbitrary web script in the browser of a victim, by posting crafted contents.... Read more

    Affected Products : odoo
    • EPSS Score: %0.11
    • Published: Apr. 25, 2023
    • Modified: Nov. 21, 2024
  • 6.2

    MEDIUM
    CVE-2021-26262

    Philips MRI 1.5T and MRI 3T Version 5.x.x does not restrict or incorrectly restricts access to a resource from an unauthorized actor.... Read more

    • EPSS Score: %0.11
    • Published: Nov. 19, 2021
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2021-26260

    An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215.... Read more

    Affected Products : fedora debian_linux openexr
    • EPSS Score: %0.09
    • Published: Jun. 08, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-26259

    A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in render_table_row(),in ps-pdf.cxx may lead to arbitrary code execution and denial of service.... Read more

    Affected Products : htmldoc
    • EPSS Score: %0.26
    • Published: Mar. 03, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-26256

    Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Survey Maker WordPress plugin (versions <= 2.0.6).... Read more

    Affected Products : survey_maker
    • EPSS Score: %1.29
    • Published: Feb. 21, 2022
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2021-26253

    A potential vulnerability in Splunk Enterprise's implementation of DUO MFA allows for bypassing the MFA verification in Splunk Enterprise versions before 8.1.6. The potential vulnerability impacts Splunk Enterprise instances configured to use DUO MFA and ... Read more

    Affected Products : splunk
    • EPSS Score: %0.20
    • Published: May. 06, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-26252

    A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of service.... Read more

    Affected Products : enterprise_linux fedora htmldoc
    • EPSS Score: %0.39
    • Published: Feb. 24, 2022
    • Modified: Nov. 21, 2024
  • 6.2

    MEDIUM
    CVE-2021-26248

    Philips MRI 1.5T and MRI 3T Version 5.x.x assigns an owner who is outside the intended control sphere to a resource.... Read more

    • EPSS Score: %0.05
    • Published: Nov. 19, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-26247

    As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" to successfully execute the JavaScript payload present in the "ref" URL parameter.... Read more

    Affected Products : cacti
    • EPSS Score: %31.02
    • Published: Jan. 19, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-26237

    FastStone Image Viewer <= 7.5 is affected by a user mode write access violation at 0x00402d7d, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Service (DoS) o... Read more

    Affected Products : image_viewer
    • EPSS Score: %0.20
    • Published: Mar. 18, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 291737 Results