Latest CVE Feed
-
7.5
HIGHCVE-2021-22967
In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to a Conversation.To remediate this, a check was added to verify a user has permissions to view files before attaching... Read more
- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-22966
Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below. If a group is granted "view" permissions on the bulkupdate page, then users in that group can escalate to being an administrator with a specially crafted curl... Read more
- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-22965
A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a malformed request is sent to the device.... Read more
- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-22964
A redirect vulnerability in the `fastify-static` module version >= 4.2.4 and < 4.4.1 allows remote attackers to redirect Mozilla Firefox users to arbitrary websites via a double slash `//` followed by a domain: `http://localhost:3000//a//youtube.com/%2e%2... Read more
Affected Products : fastify-static- Published: Oct. 14, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-22963
A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbitrary websites via a double slash // followed by a domain: http://localhost:3000//google.com/%2e%2e.The issue shows up on all the fastif... Read more
Affected Products : fastify-static- Published: Oct. 14, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-22962
An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.... Read more
Affected Products : avalanche- Published: Dec. 19, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22961
A code injection vulnerability exists within the firewall software of GlassWire v2.1.167 that could lead to arbitrary code execution from a file in the user path on first execution.... Read more
Affected Products : glasswire- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-22960
The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions.... Read more
- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-22959
The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS) in llhttp < v2.1.4 and < v6.0.6.... Read more
- Published: Nov. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22958
A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the limitations in place for localhost allowing interaction with local services. Impact can vary depending on services ... Read more
- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-22957
A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allows a malicious actor who has convinced a privileged user to access a URL with malicious code to take over said user’s account.This vulne... Read more
Affected Products : unifi_protect- Published: Nov. 24, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-22956
An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with access to NSIP or SNIP with management interface access to cause a temporary disruption of the Management GUI... Read more
Affected Products : gateway application_delivery_controller_firmware sd-wan application_delivery_controller- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-22955
A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to cause a temporary disruption of the Management GUI, Nitro AP... Read more
Affected Products : gateway application_delivery_controller_firmware application_delivery_controller- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-22954
A cross-site request forgery vulnerability exists in Concrete CMS <v9 that could allow an attacker to make requests on behalf of other users.... Read more
- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2021-22953
A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security Research Team"... Read more
Affected Products : concrete_cms- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-22952
A vulnerability found in UniFi Talk application V1.12.3 and earlier permits a malicious actor who has already gained access to a network to subsequently control Talk device(s) assigned to said network if they are not yet adopted. This vulnerability is fix... Read more
Affected Products : unifi_talk- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-22951
Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) prior to version 8.5.7. Concrete CMS now checks to see if a file has a password in view_inline and, if it does, the file is not rendered... Read more
- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-22950
Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be deleted.Credit for discovery: "Solar Security Research Team"... Read more
Affected Products : concrete_cms- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2021-22949
A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security CMS Research Team"... Read more
Affected Products : concrete_cms- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-22948
Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some circumstances, an attacker could theoretically be able to brute force session IDs in order to take over a ... Read more
Affected Products : revive_adserver- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024