Latest CVE Feed
-
8.8
HIGHCVE-2021-25312
HTCondor before 8.9.11 allows a user to submit a job as another user on the system, because of a flaw in the IDTOKENS authentication method.... Read more
Affected Products : htcondor- Published: Jan. 27, 2021
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2021-25311
condor_credd in HTCondor before 8.9.11 allows Directory Traversal outside the SEC_CREDENTIAL_DIRECTORY_OAUTH directory, as demonstrated by creating a file under /etc that will later be executed by root.... Read more
Affected Products : htcondor- Published: Jan. 27, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-25310
The administration web interface on Belkin Linksys WRT160NL 1.0.04.002_US_20130619 devices allows remote authenticated attackers to execute system commands with root privileges via shell metacharacters in the ui_language POST parameter to the apply.cgi fo... Read more
- Published: Feb. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25309
The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout or throttling functionality. This situation (together with the weak password policy that forces a 4-digit password) allows remote atta... Read more
- Published: Mar. 02, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-25306
A buffer overflow vulnerability in the AT command interface of Gigaset DX600A v41.00-175 devices allows remote attackers to force a device reboot by sending relatively long AT commands.... Read more
- Published: Mar. 02, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25299
Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admi... Read more
Affected Products : nagios_xi- Published: Feb. 15, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25295
OpenCATS through 0.9.5-3 has multiple Cross-site Scripting (XSS) issues.... Read more
Affected Products : opencats- Published: Jan. 18, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-25294
OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occurs because lib/DataGrid.php calls unserialize for the parametersactivity:ActivityDataGrid parameter. The PHP object injection exploit ... Read more
Affected Products : opencats- Published: Jan. 18, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-25293
An issue was discovered in Pillow before 8.1.1. There is an out-of-bounds read in SGIRleDecode.c.... Read more
Affected Products : pillow- Published: Mar. 19, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-25292
An issue was discovered in Pillow before 8.1.1. The PDF parser allows a regular expression DoS (ReDoS) attack via a crafted PDF file because of a catastrophic backtracking regex.... Read more
Affected Products : pillow- Published: Mar. 19, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-25291
An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is an out-of-bounds read in TiffreadRGBATile via invalid tile boundaries.... Read more
Affected Products : pillow- Published: Mar. 19, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-25290
An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size.... Read more
- Published: Mar. 19, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25289
An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NOTE: this issue exists because of an incomplete fix for C... Read more
Affected Products : pillow- Published: Mar. 19, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-25288
An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_gray_i.... Read more
- Published: Jun. 02, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-25287
An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_graya_la.... Read more
- Published: Jun. 02, 2021
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-25284
An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level.... Read more
- Published: Feb. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25283
An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks.... Read more
- Published: Feb. 27, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-25282
An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal.... Read more
- Published: Feb. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25281
An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the master.... Read more
- Published: Feb. 27, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-25278
FTAPI 4.0 through 4.10 allows XSS via an SVG document to the Background Image upload feature in the Submit Box Template Editor.... Read more
Affected Products : ftapi- Published: Mar. 19, 2021
- Modified: Nov. 21, 2024