Latest CVE Feed
-
6.5
MEDIUMCVE-2021-26581
A potential security vulnerability has been identified in HPE Superdome Flex server. A denial of service attack can be remotely exploited leaving hung connections to the BMC web interface. The monarch BMC must be rebooted to recover from this situation. O... Read more
- Published: Apr. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26580
A potential security vulnerability has been identified in HPE iLO Amplifier Pack. The vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS). HPE has provided the following software update to resolve the vulnerability in HPE iLO Amp... Read more
- Published: Apr. 01, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-26579
A security vulnerability in HPE Unified Data Management (UDM) could allow the local disclosure of privileged information (CWE-321: Use of Hard-coded Cryptographic Key in a product). HPE has provided updates to versions 1.2009.0 and 1.2101.0 of HPE Unified... Read more
Affected Products : unified_data_management- Published: Mar. 30, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-26578
A potential security vulnerability has been identified in HPE Network Orchestrator (NetO) version(s): Prior to 2.5. The vulnerability could be remotely exploited with SQL injection.... Read more
Affected Products : network_orchestrator- Published: Mar. 22, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26577
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so uploadsshkey function.... Read more
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26576
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so uploadsshkey function.... Read more
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26575
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletesolvideofile function.... Read more
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26574
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletevideofile function.... Read more
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26573
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgeneratesslcfg function.... Read more
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26572
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgetactivexcfg function.... Read more
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26571
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgetactivexcfg function.... Read more
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26570
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webifc_setadconfig function.... Read more
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-26559
Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when `[webserver] expose_config` is set to `False` in `airflow... Read more
Affected Products : airflow- Published: Feb. 17, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-26558
Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link resources. This issue affects Apache ShardingSphere-UI Apache ShardingSphere-UI version 4.1.1 and later versions; Apache ShardingSphere-UI ... Read more
Affected Products : shardingsphere-ui- Published: Nov. 11, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26557
When Octopus Tentacle is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access.... Read more
Affected Products : tentacle- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26556
When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access.... Read more
- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-26551
An issue was discovered in SmartFoxServer 2.17.0. An attacker can execute arbitrary Python code, and bypass the javashell.py protection mechanism, by creating /config/ConsoleModuleUnlock.txt and editing /config/admin/admintool.xml to enable the Console mo... Read more
Affected Products : smartfoxserver- Published: Feb. 09, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-26550
An issue was discovered in SmartFoxServer 2.17.0. Cleartext password disclosure can occur via /config/server.xml.... Read more
Affected Products : smartfoxserver- Published: Feb. 09, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-26549
An XSS issue was discovered in SmartFoxServer 2.17.0. Input passed to the AdminTool console is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML code in a user's browser session in context of an affe... Read more
Affected Products : smartfoxserver- Published: Feb. 09, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-26544
Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicious user could use this flaw to access logs and results of other users' sessions and run jobs with their privileges. This issue is fixed... Read more
Affected Products : livy- Published: Feb. 20, 2021
- Modified: Nov. 21, 2024