Latest CVE Feed
-
5.4
MEDIUMCVE-2021-21608
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape button labels in the Jenkins UI, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to control button labels.... Read more
Affected Products : jenkins- EPSS Score: %0.34
- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-21607
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not limit sizes provided as query parameters to graph-rendering URLs, allowing attackers to request crafted URLs that use all available memory in Jenkins, potentially leading to out of memory errors.... Read more
Affected Products : jenkins- EPSS Score: %0.26
- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-21606
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier improperly validates the format of a provided fingerprint ID when checking for its existence allowing an attacker to check for the existence of XML files with a short path.... Read more
Affected Products : jenkins- EPSS Score: %0.08
- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2021-21605
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows users with Agent/Configure permission to choose agent names that cause Jenkins to override the global `config.xml` file.... Read more
Affected Products : jenkins- EPSS Score: %0.42
- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2021-21604
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows attackers with permission to create or configure various objects to inject crafted content into Old Data Monitor that results in the instantiation of potentially unsafe objects once discarded by an... Read more
Affected Products : jenkins- EPSS Score: %1.25
- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-21603
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape notification bar response contents, resulting in a cross-site scripting (XSS) vulnerability.... Read more
Affected Products : jenkins- EPSS Score: %0.30
- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-21602
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows reading arbitrary files using the file browser for workspaces and archived artifacts by following symlinks.... Read more
Affected Products : jenkins- EPSS Score: %1.12
- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-21601
Dell EMC Data Protection Search, 19.4 and prior, and IDPA, 2.6.1 and prior, contain an Information Exposure in Log File Vulnerability in CIS. A local low privileged attacker could potentially exploit this vulnerability, leading to the disclosure of certai... Read more
Affected Products : emc_integrated_data_protection_appliance emc_data_protection_search data_protection_search- EPSS Score: %0.04
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-21600
Dell EMC NetWorker, 19.4 or older, contain an uncontrolled resource consumption flaw in its API service. An authorized API user could potentially exploit this vulnerability via the web and desktop user interfaces, leading to denial of service in the manag... Read more
- EPSS Score: %0.24
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-21599
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.1.x contain an OS command injection vulnerability. This may allow a user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE to escalate privileges and escape the compliance guarantees. This only impacts Smartl... Read more
- EPSS Score: %0.30
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
3.9
LOWCVE-2021-21598
Dell Wyse ThinOS, versions 9.0, 9.1, and 9.1 MR1, contain a Sensitive Information Disclosure Vulnerability. An authenticated attacker with physical access to the system could exploit this vulnerability to read sensitive Smartcard data in log files.... Read more
- EPSS Score: %0.06
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-21597
Dell Wyse ThinOS, version 9.0, contains a Sensitive Information Disclosure Vulnerability. An authenticated malicious user with physical access to the system could exploit this vulnerability to read sensitive information written to the log files.... Read more
- EPSS Score: %0.04
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-21596
Dell OpenManage Enterprise versions 3.4 through 3.6.1 and Dell OpenManage Enterprise Modular versions 1.20.00 through 1.30.00, contain a remote code execution vulnerability. A malicious attacker with access to the immediate subnet may potentially exploit ... Read more
- EPSS Score: %1.32
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-21595
Dell EMC PowerScale OneFS versions 8.2.x - 9.1.1.x contain an improper neutralization of special elements used in an OS command. This vulnerability could allow the compadmin user to elevate privileges. This only impacts Smartlock WORM compliance mode clus... Read more
- EPSS Score: %0.19
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2021-21594
Dell PowerScale OneFS versions 8.2.2 - 9.1.0.x contain a use of get request method with sensitive query strings vulnerability. It can lead to potential disclosure of sensitive data. Dell recommends upgrading at your earliest opportunity.... Read more
- EPSS Score: %0.26
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-21592
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x improperly handle an exceptional condition. A remote low privileged user could potentially exploit this vulnerability, leading to unauthorized information disclosure.... Read more
- EPSS Score: %0.22
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-21591
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user... Read more
- EPSS Score: %0.12
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-21590
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user... Read more
- EPSS Score: %0.12
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-21589
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 do not exit on failed Initialization. A local authenticated Service user could potentially exploit this vulnerability to escalate privileges.... Read more
- EPSS Score: %0.04
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-21588
Dell EMC PowerFlex, v3.5.x contain a Cross-Site WebSocket Hijacking Vulnerability in the Presentation Server/WebUI. An unauthenticated attacker could potentially exploit this vulnerability by tricking the user into performing unwanted actions on the Prese... Read more
Affected Products : powerflex_presentation_server- EPSS Score: %0.14
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024