Export limit exceeded: 370151 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 370151 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (370151 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-32092 | 1 Nsa | 1 Emissary | 2024-11-21 | 6.1 Medium |
| A Cross-site scripting (XSS) vulnerability in the DocumentAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows remote attackers to inject arbitrary web script or HTML via the uuid parameter. | ||||
| CVE-2021-32091 | 1 Localstack | 1 Localstack | 2024-11-21 | 6.1 Medium |
| A Cross-site scripting (XSS) vulnerability exists in StackLift LocalStack 0.12.6. | ||||
| CVE-2021-32090 | 1 Localstack | 1 Localstack | 2024-11-21 | 9.8 Critical |
| The dashboard component of StackLift LocalStack 0.12.6 allows attackers to inject arbitrary shell commands via the functionName parameter. | ||||
| CVE-2021-32089 | 1 Zebra | 2 Fx9500, Fx9500 Firmware | 2024-11-21 | 9.8 Critical |
| An issue was discovered on Zebra (formerly Motorola Solutions) Fixed RFID Reader FX9500 devices. An unauthenticated attacker can upload arbitrary files to the filesystem that can then be accessed through the web interface. This can lead to information disclosure and code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | ||||
| CVE-2021-32078 | 1 Linux | 1 Linux Kernel | 2024-11-21 | 7.1 High |
| An Out-of-Bounds Read was discovered in arch/arm/mach-footbridge/personal-pci.c in the Linux kernel through 5.12.11 because of the lack of a check for a value that shouldn't be negative, e.g., access to element -2 of an array, aka CID-298a58e165e4. | ||||
| CVE-2021-32077 | 1 Veritystream | 1 Msow Solutions | 2024-11-21 | 7.5 High |
| Primary Source Verification in VerityStream MSOW Solutions before 3.1.1 allows an anonymous internet user to discover Social Security Number (SSN) values via a brute-force attack on a (sometimes hidden) search field, because the last four SSN digits are part of the supported combination of search selectors. This discloses doctors' and nurses' social security numbers and PII. | ||||
| CVE-2021-32076 | 1 Solarwinds | 1 Web Help Desk | 2024-11-21 | 5.3 Medium |
| Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by intercepting the HTTP request and changing the referrer from the public IP address to the loopback. | ||||
| CVE-2021-32075 | 1 Re-logic | 1 Terraria | 2024-11-21 | 9.8 Critical |
| Re-Logic Terraria before 1.4.2.3 performs Insecure Deserialization. | ||||
| CVE-2021-32074 | 1 Hashicorp | 1 Vault-action | 2024-11-21 | 7.5 High |
| HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers to obtain sensitive information from log files because a multi-line secret was not correctly registered with GitHub Actions for log masking. | ||||
| CVE-2021-32073 | 1 Dedecms | 1 Dedecms | 2024-11-21 | 8.8 High |
| DedeCMS V5.7 SP2 contains a CSRF vulnerability that allows a remote attacker to send a malicious request to to the web manager allowing remote code execution. | ||||
| CVE-2021-32072 | 1 Mitel | 1 Micollab | 2024-11-21 | 6.5 Medium |
| The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to get source code information (disclosing sensitive application data) due to insufficient output sanitization. A successful exploit could allow an attacker to view source code methods. | ||||
| CVE-2021-32071 | 1 Mitel | 1 Micollab | 2024-11-21 | 9.8 Critical |
| The MiCollab Client service in Mitel MiCollab before 9.3 could allow an unauthenticated user to gain system access due to improper access control. A successful exploit could allow an attacker to view and modify application data, and cause a denial of service for users. | ||||
| CVE-2021-32070 | 1 Mitel | 1 Micollab | 2024-11-21 | 5.4 Medium |
| The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to perform a clickjacking attack due to an insecure header response. A successful exploit could allow an attacker to modify the browser header and redirect users. | ||||
| CVE-2021-32069 | 1 Mitel | 1 Micollab | 2024-11-21 | 4.8 Medium |
| The AWV component of Mitel MiCollab before 9.3 could allow an attacker to perform a Man-In-the-Middle attack due to improper TLS negotiation. A successful exploit could allow an attacker to view and modify data. | ||||
| CVE-2021-32068 | 1 Mitel | 1 Micollab | 2024-11-21 | 3.7 Low |
| The AWV and MiCollab Client Service components in Mitel MiCollab before 9.3 could allow an attacker to perform a Man-In-the-Middle attack by sending multiple session renegotiation requests, due to insufficient TLS session controls. A successful exploit could allow an attacker to modify application data and state. | ||||
| CVE-2021-32067 | 1 Mitel | 1 Micollab | 2024-11-21 | 6.5 Medium |
| The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to view sensitive system information through an HTTP response due to insufficient output sanitization. | ||||
| CVE-2021-32066 | 3 Oracle, Redhat, Ruby-lang | 6 Jd Edwards Enterpriseone Tools, Enterprise Linux, Rhel E4s and 3 more | 2024-11-21 | 7.4 High |
| An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net::IMAP does not raise an exception when StartTLS fails with an an unknown response, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack." | ||||
| CVE-2021-32062 | 2 Fedoraproject, Osgeo | 2 Fedora, Mapserver | 2024-11-21 | 5.3 Medium |
| MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to control the locations from which a mapfile may be loaded (with MapServer CGI). | ||||
| CVE-2021-32061 | 1 S3scanner Project | 1 S3scanner | 2024-11-21 | 5.3 Medium |
| S3Scanner before 2.0.2 allows Directory Traversal via a crafted bucket, as demonstrated by a <Key>../ substring in a ListBucketResult element. | ||||
| CVE-2021-32056 | 2 Cyrus, Fedoraproject | 2 Imap, Fedora | 2024-11-21 | 4.3 Medium |
| Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall. | ||||