Latest CVE Feed
-
6.0
MEDIUMCVE-2021-23211
Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows Cloud end-to-end encryption key to be discoverable in server memory dumps. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.4... Read more
Affected Products : command_centre- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-23209
Multiple Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) vulnerabilities discovered in AMP for WP – Accelerated Mobile Pages WordPress plugin (versions <= 1.0.77.32).... Read more
Affected Products : accelerated_mobile_pages- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-23207
An attacker with physical access to the host can extract the secrets from the registry and create valid JWT tokens for the Fresenius Kabi Vigilant MasterMed version 2.0.1.3 application and impersonate arbitrary users. An attacker could manipulate RabbitMQ... Read more
- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-23206
A flaw was found in htmldoc in v1.9.12 and prior. A stack buffer overflow in parse_table() in ps-pdf.cxx may lead to execute arbitrary code and denial of service.... Read more
Affected Products : htmldoc- Published: Mar. 02, 2022
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2021-23205
Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configuration of Controllers and other hardware items beyond their privilege. This issue affects: Gallagher Command Centre 8.40 versions prior t... Read more
Affected Products : command_centre- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-23204
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gallagher Command Centre Server allows OSDP key material to be exposed to Command Centre Operators. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (... Read more
Affected Products : command_centre- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-23201
NVIDIA GPU and Tegra hardware contain a vulnerability in an internal microcontroller, which may allow a user with elevated privileges to generate valid microcode by identifying, exploiting, and loading vulnerable microcode. Such an attack could lead to in... Read more
Affected Products : linux_kernel windows geforce_gtx_950 geforce_gtx_960 geforce_gtx_970 geforce_gtx_980 geforce_gtx_titan_x jetson_nano jetson_tx1 quadro_m1000m +27 more products- Published: Nov. 20, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-23198
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.... Read more
Affected Products : mypro- Published: Dec. 23, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-23197
Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the account that runs the Controller Service. This issue affects: Gallagher Command Centre 8.50 versions prior to 8.50.2048 (M... Read more
Affected Products : command_centre- Published: Nov. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23196
The web application on Agilia Link+ version 3.0 implements authentication and session management mechanisms exclusively on the client-side and does not protect authentication attributes sufficiently.... Read more
- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-23195
Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 has the option for automated indexing (directory listing) activated. When accessing a directory, a web server delivers its entire content in HTML form. If an index file does not ... Read more
- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-23193
Improper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unprivileged operators to retrieve sensitive information from the Command Centre Server. This issue affects: Gallagher Command Centre 8.50... Read more
Affected Products : command_centre- Published: Nov. 18, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-23192
A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an attacker could replace later fragments with their own data, bypassing the signature requirements.... Read more
Affected Products : samba- Published: Mar. 02, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-23191
A security issue was found in htmldoc v1.9.12 and before. A NULL pointer dereference in the function image_load_jpeg() in image.cxx may result in denial of service.... Read more
Affected Products : htmldoc- Published: Mar. 02, 2022
- Modified: Nov. 21, 2024
-
8.7
HIGHCVE-2021-23186
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access and modify database contents of other tenants, in a multi-tenant system.... Read more
Affected Products : odoo- Published: Apr. 25, 2023
- Modified: Nov. 21, 2024
-
6.0
MEDIUMCVE-2021-23182
Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows OSDP reader master keys to be discoverable in server memory dumps. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (... Read more
Affected Products : command_centre- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-23180
A flaw was found in htmldoc in v1.9.12 and before. Null pointer dereference in file_extension(),in file.c may lead to execute arbitrary code and denial of service.... Read more
Affected Products : htmldoc- Published: Mar. 02, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-23178
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be charged in... Read more
Affected Products : odoo- Published: Apr. 25, 2023
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-23177
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the... Read more
Affected Products : enterprise_linux fedora debian_linux enterprise_linux_server_aus enterprise_linux_server_tus enterprise_linux_eus enterprise_linux_for_ibm_z_systems_eus enterprise_linux_for_power_little_endian enterprise_linux_for_power_little_endian_eus enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions +3 more products- Published: Aug. 23, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-23176
Improper access control in reporting engine of l10n_fr_fec module in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to extract accounting information via crafted RPC packets.... Read more
Affected Products : odoo- Published: Apr. 25, 2023
- Modified: Nov. 21, 2024