Latest CVE Feed
-
5.5
MEDIUMCVE-2021-20191
A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highe... Read more
- Published: May. 26, 2021
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2021-20188
A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not correctly checked. This flaw can be abused by a low-privileged user inside the container to access any other file in the container, even... Read more
- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-20187
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts via a PHP include used during Shibboleth authentication.... Read more
Affected Products : moodle- Published: Jan. 28, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20186
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX content was required to prevent the risk of stored XSS.... Read more
Affected Products : moodle- Published: Jan. 28, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-20185
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which could result in client-side (browser) denial of service for users receiving very large messages.... Read more
Affected Products : moodle- Published: Jan. 28, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-20184
It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades.... Read more
Affected Products : moodle- Published: Jan. 28, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20183
It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficient escaping of search queries.... Read more
Affected Products : moodle- Published: Jan. 28, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-20182
A privilege escalation flaw was found in openshift4/ose-docker-builder. The build container runs with high privileges using a chrooted environment instead of runc. If an attacker can gain access to this build container, they can potentially utilize the ra... Read more
- Published: Feb. 23, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20181
A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0. This flaw allows a malicious 9p client to cause a use-after-free error, potentially escalating their privileges on the system. The highest threat from thi... Read more
- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-20180
A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credenti... Read more
Affected Products : ansible- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-20179
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data... Read more
- Published: Mar. 15, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-20178
A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credenti... Read more
- Published: May. 26, 2021
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-20177
A flaw was found in the Linux kernel's implementation of string matching within a packet. A privileged user (with root or CAP_NET_ADMIN) when inserting iptables rules could insert a rule which can panic the system. Kernel before kernel 5.5-rc1 is affected... Read more
Affected Products : linux_kernel- Published: May. 26, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-20176
A divide-by-zero flaw was found in ImageMagick 6.9.11-57 and 7.0.10-57 in gem.c. This flaw allows an attacker who submits a crafted file that is processed by ImageMagick to trigger undefined behavior through a division by zero. The highest threat from thi... Read more
- Published: Feb. 06, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20175
Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the SOAP interface. By default, all communication to/from the device's SOAP Interface (port 5000) is sent via HTTP, which causes potentially sensitive information (... Read more
- Published: Dec. 30, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20174
Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the web interface. By default, all communication to/from the device's web interface is sent via HTTP, which causes potentially sensitive information (such as userna... Read more
- Published: Dec. 30, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-20173
Netgear Nighthawk R6700 version 1.0.4.120 contains a command injection vulnerability in update functionality of the device. By triggering a system update check via the SOAP interface, the device is susceptible to command injection via preconfigured values... Read more
- Published: Dec. 30, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-20172
All known versions of the Netgear Genie Installer for macOS contain a local privilege escalation vulnerability. The installer of the macOS version of Netgear Genie handles certain files in an insecure way. A malicious actor who has local access to the end... Read more
Affected Products : genie_installer- Published: Dec. 30, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-20171
Netgear RAX43 version 1.0.3.96 stores sensitive information in plaintext. All usernames and passwords for the device's associated services are stored in plaintext on the device. For example, the admin password is stored in plaintext in the primary configu... Read more
- Published: Dec. 30, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-20170
Netgear RAX43 version 1.0.3.96 makes use of hardcoded credentials. It does not appear that normal users are intended to be able to manipulate configuration backups due to the fact that they are encrypted. This encryption is accomplished via a password-pro... Read more
- Published: Dec. 30, 2021
- Modified: Nov. 21, 2024