Latest CVE Feed
-
7.1
HIGHCVE-2021-27364
An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.... Read more
- Published: Mar. 07, 2021
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-27363
An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to... Read more
Affected Products : linux_kernel debian_linux solidfire_baseboard_management_controller_firmware cloud_backup- Published: Mar. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27362
The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a Read Access Violation on Control Flow starting at WPG!ReadWPG_W+0x0000000000000133, which might allow remote attackers to execute arbitrary code.... Read more
- Published: Feb. 17, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-27358
The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.... Read more
- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27357
RIOT-OS 2020.01 contains a buffer overflow vulnerability in /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c.... Read more
Affected Products : riot- Published: Apr. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-27352
An open redirect vulnerability in Ilch CMS version 2.1.42 allows attackers to redirect users to an attacker's site after a successful login.... Read more
Affected Products : ilch_cms- Published: Mar. 29, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-27351
The Terminate Session feature in the Telegram application through 7.2.1 for Android, and through 2.4.7 for Windows and UNIX, fails to invalidate a recently active session.... Read more
Affected Products : telegram- Published: Feb. 19, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-27349
Advanced Order Export before 3.1.8 for WooCommerce allows XSS, a different vulnerability than CVE-2020-11727.... Read more
- Published: Mar. 31, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-27347
Use after free in lzma_decompress_buf function in stream.c in Irzip 0.631 allows attackers to cause Denial of Service (DoS) via a crafted compressed file.... Read more
- Published: Jun. 10, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-27345
A null pointer dereference was discovered in ucompthread in stream.c in Irzip 0.631 which allows attackers to cause a denial of service (DOS) via a crafted compressed file.... Read more
- Published: Jun. 10, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-27343
SerenityOS Unspecified is affected by: Buffer Overflow. The impact is: obtain sensitive information (context-dependent). The component is: /Userland/Libraries/LibCrypto/ASN1/DER.h Crypto::der_decode_sequence() function. The attack vector is: Parsing RSA K... Read more
- Published: Apr. 06, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-27342
An authentication brute-force protection mechanism bypass in telnetd in D-Link Router model DIR-842 firmware version 3.0.2 allows a remote attacker to circumvent the anti-brute-force cool-down delay period via a timing-based side-channel attack... Read more
- Published: May. 17, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27341
OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via the "filename" parameter.... Read more
Affected Products : opensis- Published: Sep. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-27340
OpenSIS Community Edition version <= 7.6 is affected by a reflected XSS vulnerability in EmailCheck.php via the "opt" parameter.... Read more
Affected Products : opensis- Published: Sep. 16, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-27338
Faraday Edge before 3.7 allows XSS via the network/create/ page and its network name parameter.... Read more
Affected Products : edge- Published: Jul. 20, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27335
KollectApps before 4.8.16c is affected by insecure Java deserialization, leading to Remote Code Execution via a ysoserial.payloads.CommonsCollections parameter.... Read more
Affected Products : kollect- Published: Feb. 18, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-27332
Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the class_name parameter to update_class.php.... Read more
Affected Products : casap_automated_enrollment_system- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-27330
Triconsole Datepicker Calendar <3.77 is affected by cross-site scripting (XSS) in calendar_form.php. Attackers can read authentication cookies that are still active, which can be used to perform further attacks such as reading browser history, directory l... Read more
Affected Products : datepicker_calendar- Published: Feb. 25, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-27329
Friendica 2021.01 allows SSRF via parse_url?binurl= for DNS lookups or HTTP requests to arbitrary domain names.... Read more
- Published: Feb. 18, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-27328
Yeastar NeoGate TG400 91.3.0.3 devices are affected by Directory Traversal. An authenticated user can decrypt firmware and can read sensitive information, such as a password or decryption key.... Read more
- Published: Feb. 19, 2021
- Modified: Nov. 21, 2024