Latest CVE Feed
-
7.8
HIGHCVE-2021-23240
selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permis... Read more
- EPSS Score: %0.17
- Published: Jan. 12, 2021
- Modified: Nov. 21, 2024
-
2.5
LOWCVE-2021-23239
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.... Read more
- EPSS Score: %0.04
- Published: Jan. 12, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-23236
Requests may be used to interrupt the normal operation of the device. When exploited, Fresenius Kabi Agilia Link+ version 3.0 must be rebooted via a hard reset triggered by pressing a button on the rack system.... Read more
- EPSS Score: %0.20
- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23233
Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information such as the session cookie. An attacker can send requests to sensitive endpoints as an unauthenticated user to perform critical action... Read more
- EPSS Score: %0.32
- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2021-23230
A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command Centre Operator to modify Command Centre databases undetected. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1... Read more
Affected Products : command_centre- EPSS Score: %0.25
- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-23228
DIAEnergie Version 1.7.5 and prior is vulnerable to a reflected cross-site scripting attack through error pages that are returned by “.NET Request.QueryString”.... Read more
Affected Products : diaenergie- EPSS Score: %0.16
- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-23227
Cross-Site Request Forgery (CSRF) vulnerability in Alexander Fuchs PHP Everywhere plugin <= 2.0.2 versions.... Read more
Affected Products : php_everywhere- EPSS Score: %0.14
- Published: Jan. 13, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-23225
Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "new_username" field during creation of a new user via "Copy" method at user_admin.php.... Read more
- EPSS Score: %0.65
- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-23222
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption.... Read more
Affected Products : postgresql- EPSS Score: %0.37
- Published: Mar. 02, 2022
- Modified: Nov. 21, 2024
-
4.1
MEDIUMCVE-2021-23219
NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to access protected information by identifying, exploiting, and loading vulnerable microcode. Such an attack may lead to... Read more
Affected Products : linux_kernel windows dgx-1_p100 dgx-1_v100 dgx-2 dgx_station_a100 drive_constellation geforce_gt_605 geforce_gt_610 geforce_gt_620 +127 more products- EPSS Score: %0.05
- Published: Nov. 20, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-23218
When running with FIPS mode enabled, Mirantis Container Runtime 20.10.8 leaks memory during TLS Handshakes which could be abused to cause a denial of service.... Read more
Affected Products : mirantis_container_runtime- EPSS Score: %0.33
- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-23217
NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to instantiate a DMA write operation only within a specific time window timed to corrupt code execution, which may impac... Read more
Affected Products : linux_kernel windows geforce_gt_605 geforce_gt_610 geforce_gt_620 geforce_gt_625 geforce_gt_630 geforce_gt_635 geforce_gt_640 geforce_gt_705 +55 more products- EPSS Score: %0.04
- Published: Nov. 20, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-23215
An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR.... Read more
- EPSS Score: %0.09
- Published: Jun. 08, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-23214
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate... Read more
- EPSS Score: %0.59
- Published: Mar. 04, 2022
- Modified: Nov. 21, 2024
-
6.0
MEDIUMCVE-2021-23211
Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows Cloud end-to-end encryption key to be discoverable in server memory dumps. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.4... Read more
Affected Products : command_centre- EPSS Score: %0.01
- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-23209
Multiple Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) vulnerabilities discovered in AMP for WP – Accelerated Mobile Pages WordPress plugin (versions <= 1.0.77.32).... Read more
Affected Products : accelerated_mobile_pages- EPSS Score: %0.32
- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-23207
An attacker with physical access to the host can extract the secrets from the registry and create valid JWT tokens for the Fresenius Kabi Vigilant MasterMed version 2.0.1.3 application and impersonate arbitrary users. An attacker could manipulate RabbitMQ... Read more
- EPSS Score: %0.05
- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-23206
A flaw was found in htmldoc in v1.9.12 and prior. A stack buffer overflow in parse_table() in ps-pdf.cxx may lead to execute arbitrary code and denial of service.... Read more
Affected Products : htmldoc- EPSS Score: %0.52
- Published: Mar. 02, 2022
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2021-23205
Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configuration of Controllers and other hardware items beyond their privilege. This issue affects: Gallagher Command Centre 8.40 versions prior t... Read more
Affected Products : command_centre- EPSS Score: %0.25
- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-23204
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gallagher Command Centre Server allows OSDP key material to be exposed to Command Centre Operators. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (... Read more
Affected Products : command_centre- EPSS Score: %0.18
- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024