Latest CVE Feed
-
8.8
HIGHCVE-2021-23163
JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.33.6 versions prior to 7.x; JFrog Artifactor... Read more
Affected Products : artifactory- Published: Jul. 06, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-23162
Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Connect for Android 15 versions prior to 15.04.04... Read more
Affected Products : command_centre_mobile_connect- Published: Nov. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23158
A flaw was found in htmldoc in v1.9.12. Double-free in function pspdf_export(),in ps-pdf.cxx may result in a write-what-where condition, allowing an attacker to execute arbitrary code and denial of service.... Read more
Affected Products : htmldoc- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-23157
WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute code.... Read more
Affected Products : levistudiou- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
9.0
CRITICALCVE-2021-23155
Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Client for Android 8.60 versions prior to 8.60.065... Read more
Affected Products : command_centre_mobile_client- Published: Nov. 18, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-23154
In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided arguments which are then executed in the user's shell. Arguments can be provided which cause arbitrary shell commands to run on the system.... Read more
Affected Products : lens- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-23150
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in AMP for WP – Accelerated Mobile Pages plugin <= 1.0.77.31 versions.... Read more
Affected Products : accelerated_mobile_pages- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-23147
Netgear Nighthawk R6700 version 1.0.4.120 does not have sufficient protections for the UART console. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection and execute commands as the root user wit... Read more
- Published: Dec. 30, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-23146
An Incomplete Comparison with Missing Factors vulnerability in the Gallagher Controller allows an attacker to bypass PIV verification. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 versions prior to 8.30.1359 (M... Read more
Affected Products : command_centre- Published: Nov. 18, 2021
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2021-23140
Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Command Centre Operator. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 version... Read more
Affected Products : command_centre- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-23139
A null pointer vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 could allow an attacker to crash the CGI program on affected installations.... Read more
Affected Products : windows apex_one worry-free_business_security worry-free_business_security_services- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-23138
WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute code.... Read more
Affected Products : levistudiou- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-23136
Improper Authorization vulnerability in Gallagher Command Centre Server allows macro overrides to be performed by an unprivileged Command Centre Operator. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 versions p... Read more
Affected Products : command_centre- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-23135
Exposure of System Data to an Unauthorized Control Sphere vulnerability in web UI of Argo CD allows attacker to cause leaked secret data into web UI error messages and logs. This issue affects Argo CD 1.8 versions prior to 1.8.7; 1.7 versions prior to 1.7... Read more
- Published: May. 12, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-23134
Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability.... Read more
- Published: May. 12, 2021
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2021-23133
A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_l... Read more
Affected Products : linux_kernel fedora debian_linux solidfire_baseboard_management_controller_firmware h410c_firmware cloud_backup solidfire_\&_hci_management_node h300s_firmware h500s_firmware h700s_firmware +14 more products- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-23132
An issue was discovered in Joomla! 3.0.0 through 3.9.24. com_media allowed paths that are not intended for image uploads... Read more
Affected Products : joomla\!- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-23131
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Missing input validation within the template manager.... Read more
Affected Products : joomla\!- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-23130
An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of feed fields could lead to xss issues.... Read more
Affected Products : joomla\!- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-23129
An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of messages showed to users that could lead to xss issues.... Read more
Affected Products : joomla\!- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024