Latest CVE Feed
-
7.8
HIGHCVE-2021-23191
A security issue was found in htmldoc v1.9.12 and before. A NULL pointer dereference in the function image_load_jpeg() in image.cxx may result in denial of service.... Read more
Affected Products : htmldoc- EPSS Score: %0.25
- Published: Mar. 02, 2022
- Modified: Nov. 21, 2024
-
8.7
HIGHCVE-2021-23186
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access and modify database contents of other tenants, in a multi-tenant system.... Read more
Affected Products : odoo- EPSS Score: %0.31
- Published: Apr. 25, 2023
- Modified: Nov. 21, 2024
-
6.0
MEDIUMCVE-2021-23182
Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows OSDP reader master keys to be discoverable in server memory dumps. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (... Read more
Affected Products : command_centre- EPSS Score: %0.03
- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-23180
A flaw was found in htmldoc in v1.9.12 and before. Null pointer dereference in file_extension(),in file.c may lead to execute arbitrary code and denial of service.... Read more
Affected Products : htmldoc- EPSS Score: %0.28
- Published: Mar. 02, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-23178
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be charged in... Read more
Affected Products : odoo- EPSS Score: %0.26
- Published: Apr. 25, 2023
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-23177
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the... Read more
Affected Products : enterprise_linux fedora debian_linux enterprise_linux_server_aus enterprise_linux_server_tus enterprise_linux_eus enterprise_linux_for_ibm_z_systems_eus enterprise_linux_for_power_little_endian enterprise_linux_for_power_little_endian_eus enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions +3 more products- EPSS Score: %0.04
- Published: Aug. 23, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-23176
Improper access control in reporting engine of l10n_fr_fec module in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to extract accounting information via crafted RPC packets.... Read more
Affected Products : odoo- EPSS Score: %0.37
- Published: Apr. 25, 2023
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2021-23175
NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply individual user access controls for users on the same device, which, with user intervention, may lead to escalation of privileges, informat... Read more
- EPSS Score: %0.04
- Published: Dec. 23, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-23174
Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0].... Read more
Affected Products : download_monitor- EPSS Score: %0.42
- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-23173
The affected product is vulnerable to an improper access control, which may allow an authenticated user to gain unauthorized access to sensitive data.... Read more
Affected Products : engage- EPSS Score: %0.12
- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-23169
A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1. An attacker could use this flaw to execute arbitrary code with the permissions of the user running the application compiled against OpenEXR.... Read more
- EPSS Score: %0.18
- Published: Jun. 08, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-23167
Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive information from the Command Centre Server. This issue affects: Gallagher Command Centre 8.50 versions prior to 8.50.2048 (MR3); 8.40 versio... Read more
Affected Products : command_centre- EPSS Score: %0.10
- Published: Nov. 18, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-23163
JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.33.6 versions prior to 7.x; JFrog Artifactor... Read more
Affected Products : artifactory- EPSS Score: %0.13
- Published: Jul. 06, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-23162
Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Connect for Android 15 versions prior to 15.04.04... Read more
Affected Products : command_centre_mobile_connect- EPSS Score: %0.19
- Published: Nov. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23158
A flaw was found in htmldoc in v1.9.12. Double-free in function pspdf_export(),in ps-pdf.cxx may result in a write-what-where condition, allowing an attacker to execute arbitrary code and denial of service.... Read more
Affected Products : htmldoc- EPSS Score: %0.44
- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-23157
WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute code.... Read more
Affected Products : levistudiou- EPSS Score: %0.57
- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
9.0
CRITICALCVE-2021-23155
Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Client for Android 8.60 versions prior to 8.60.065... Read more
Affected Products : command_centre_mobile_client- EPSS Score: %0.13
- Published: Nov. 18, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-23154
In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided arguments which are then executed in the user's shell. Arguments can be provided which cause arbitrary shell commands to run on the system.... Read more
Affected Products : lens- EPSS Score: %0.15
- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-23150
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in AMP for WP – Accelerated Mobile Pages plugin <= 1.0.77.31 versions.... Read more
Affected Products : accelerated_mobile_pages- EPSS Score: %0.32
- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-23147
Netgear Nighthawk R6700 version 1.0.4.120 does not have sufficient protections for the UART console. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection and execute commands as the root user wit... Read more
- EPSS Score: %0.04
- Published: Dec. 30, 2021
- Modified: Nov. 21, 2024