Latest CVE Feed
-
7.5
HIGHCVE-2021-26733
A broken access control vulnerability in the FirstReset_handler_func function of spx_restservice allows an attacker to arbitrarily send reboot commands to the BMC, causing a Denial-of-Service (DoS) condition. This issue affects: Lanner Inc IAC-AST2500A st... Read more
- Published: Oct. 24, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-26732
A broken access control vulnerability in the First_network_func function of spx_restservice allows an attacker to arbitrarily change the network configuration of the BMC. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.... Read more
- Published: Oct. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26731
Command injection and multiple stack-based buffer overflows vulnerabilities in the modifyUserb_func function of spx_restservice allow an authenticated attacker to execute arbitrary code with the same privileges as the server user (root). This issue affect... Read more
- Published: Oct. 24, 2022
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-26730
A stack-based buffer overflow vulnerability in a subfunction of the Login_handler_func function of spx_restservice allows an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500A... Read more
- Published: Oct. 24, 2022
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-26729
Command injection and multiple stack-based buffer overflows vulnerabilities in the Login_handler_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner In... Read more
- Published: Oct. 24, 2022
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-26728
Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500... Read more
- Published: Oct. 24, 2022
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-26727
Multiple command injections and stack-based buffer overflows vulnerabilities in the SubNet_handler_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner ... Read more
- Published: Oct. 24, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-26726
A remote code execution vulnerability affecting a Valmet DNA service listening on TCP port 1517, allows an attacker to execute commands with SYSTEM privileges This issue affects: Valmet DNA versions from Collection 2012 until Collection 2021.... Read more
Affected Products : dna- Published: Feb. 16, 2022
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-26725
Path Traversal vulnerability when changing timezone using web GUI of Nozomi Networks Guardian, CMC allows an authenticated administrator to read-protected system files. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior versi... Read more
- Published: Feb. 22, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-26724
OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC allows authenticated administrators to perform remote code execution. This issue affects: Nozomi Networks Guardian 20.0.7.3 versio... Read more
- Published: Feb. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26723
Jenzabar 9.2.x through 9.2.2 allows /ics?tool=search&query= XSS.... Read more
Affected Products : jenzabar- Published: Feb. 06, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26722
LinkedIn Oncall through 1.4.0 allows reflected XSS via /query because of mishandling of the "No results found for" message in the search bar.... Read more
Affected Products : oncall- Published: Feb. 05, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26720
avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /ru... Read more
- Published: Feb. 17, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-26719
A directory traversal issue was discovered in Gradle gradle-enterprise-test-distribution-agent before 1.3.2, test-distribution-gradle-plugin before 1.3.2, and gradle-enterprise-maven-extension before 1.8.2. A malicious actor (with certain credentials) can... Read more
- Published: Feb. 09, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-26718
KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus protection.... Read more
Affected Products : internet_security- Published: Apr. 01, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-26717
An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6. When re-negotiating for T.38, if the initial remote response was delayed just enough, Asterisk would send... Read more
- Published: Feb. 18, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26716
Modules/input/Views/schedule.php in Emoncms through 10.2.7 allows XSS via the node parameter.... Read more
Affected Products : emoncms- Published: Feb. 21, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-26715
The OpenID Connect server implementation for MITREid Connect through 1.3.3 contains a Server Side Request Forgery (SSRF) vulnerability. The vulnerability arises due to unsafe usage of the logo_uri parameter in the Dynamic Client Registration request. An u... Read more
Affected Products : connect- Published: Mar. 25, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26714
The Enterprise License Manager portal in Mitel MiContact Center Enterprise before 9.4 could allow a user to access restricted files and folders due to insufficient access control. A successful exploit could allow an attacker to view and modify application... Read more
Affected Products : micontact_center_enterprise- Published: Mar. 29, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-26713
A stack-based buffer overflow in res_rtp_asterisk.c in Sangoma Asterisk before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6 allows an authenticated WebRTC client to cause an Asterisk crash by sending multipl... Read more
- Published: Feb. 19, 2021
- Modified: Nov. 21, 2024