Latest CVE Feed
-
7.8
HIGHCVE-2021-22965
A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a malformed request is sent to the device.... Read more
- EPSS Score: %11.33
- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-22964
A redirect vulnerability in the `fastify-static` module version >= 4.2.4 and < 4.4.1 allows remote attackers to redirect Mozilla Firefox users to arbitrary websites via a double slash `//` followed by a domain: `http://localhost:3000//a//youtube.com/%2e%2... Read more
Affected Products : fastify-static- EPSS Score: %0.36
- Published: Oct. 14, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-22963
A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbitrary websites via a double slash // followed by a domain: http://localhost:3000//google.com/%2e%2e.The issue shows up on all the fastif... Read more
Affected Products : fastify-static- EPSS Score: %0.17
- Published: Oct. 14, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-22962
An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.... Read more
Affected Products : avalanche- EPSS Score: %27.82
- Published: Dec. 19, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22961
A code injection vulnerability exists within the firewall software of GlassWire v2.1.167 that could lead to arbitrary code execution from a file in the user path on first execution.... Read more
Affected Products : glasswire- EPSS Score: %0.96
- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-22960
The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions.... Read more
- EPSS Score: %0.18
- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-22959
The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS) in llhttp < v2.1.4 and < v6.0.6.... Read more
- EPSS Score: %0.19
- Published: Nov. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22958
A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the limitations in place for localhost allowing interaction with local services. Impact can vary depending on services ... Read more
- EPSS Score: %0.40
- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-22957
A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allows a malicious actor who has convinced a privileged user to access a URL with malicious code to take over said user’s account.This vulne... Read more
Affected Products : unifi_protect- EPSS Score: %0.42
- Published: Nov. 24, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-22956
An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with access to NSIP or SNIP with management interface access to cause a temporary disruption of the Management GUI... Read more
Affected Products : gateway application_delivery_controller_firmware sd-wan application_delivery_controller- EPSS Score: %0.51
- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-22955
A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to cause a temporary disruption of the Management GUI, Nitro AP... Read more
Affected Products : gateway application_delivery_controller_firmware application_delivery_controller- EPSS Score: %0.67
- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-22954
A cross-site request forgery vulnerability exists in Concrete CMS <v9 that could allow an attacker to make requests on behalf of other users.... Read more
- EPSS Score: %0.19
- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2021-22953
A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security Research Team"... Read more
Affected Products : concrete_cms- EPSS Score: %0.09
- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-22952
A vulnerability found in UniFi Talk application V1.12.3 and earlier permits a malicious actor who has already gained access to a network to subsequently control Talk device(s) assigned to said network if they are not yet adopted. This vulnerability is fix... Read more
Affected Products : unifi_talk- EPSS Score: %0.42
- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-22951
Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) prior to version 8.5.7. Concrete CMS now checks to see if a file has a password in view_inline and, if it does, the file is not rendered... Read more
- EPSS Score: %0.31
- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-22950
Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be deleted.Credit for discovery: "Solar Security Research Team"... Read more
Affected Products : concrete_cms- EPSS Score: %0.10
- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2021-22949
A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security CMS Research Team"... Read more
Affected Products : concrete_cms- EPSS Score: %0.09
- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-22948
Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some circumstances, an attacker could theoretically be able to brute force session IDs in order to take over a ... Read more
Affected Products : revive_adserver- EPSS Score: %0.54
- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-22947
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush... Read more
Affected Products : fedora debian_linux curl solidfire_baseboard_management_controller_firmware cloud_backup peoplesoft_enterprise_peopletools macos commerce_guided_search communications_cloud_native_core_network_slice_selection_function communications_cloud_native_core_network_repository_function +24 more products- EPSS Score: %0.09
- Published: Sep. 29, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-22946
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requi... Read more
Affected Products : fedora debian_linux curl solidfire_baseboard_management_controller_firmware cloud_backup peoplesoft_enterprise_peopletools macos oncommand_insight oncommand_workflow_automation snapcenter +27 more products- EPSS Score: %0.07
- Published: Sep. 29, 2021
- Modified: Nov. 21, 2024