Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-38608 1 Tranquil 1 Wapt 2022-07-12 7.2 HIGH 7.8 HIGH
Incorrect Access Control in Tranquil WAPT Enterprise - before 1.8.2.7373 and before 2.0.0.9450 allows guest OS users to escalate privileges via WAPT Agent.
CVE-2021-37326 1 Netsarang 1 Xshell 2022-07-12 5.0 MEDIUM 5.3 MEDIUM
NetSarang Xshell 7 before Build 0077 includes unintended code strings in paste operations.
CVE-2021-36793 1 Routes Project 1 Routes 2022-07-12 5.0 MEDIUM 7.5 HIGH
The routes (aka Extbase Yaml Routes) extension before 2.1.1 for TYPO3, when CsrfTokenViewHelper is used, allows Sensitive Information Disclosure because a session identifier is unsafely present in HTML output.
CVE-2021-36791 1 Dated News Project 1 Dated News 2022-07-12 5.0 MEDIUM 5.3 MEDIUM
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows Information Disclosure of application registration data.
CVE-2021-29880 1 Ibm 1 Qradar Security Information And Event Manager 2022-07-12 4.0 MEDIUM 6.5 MEDIUM
IBM QRadar SIEM 7.4.3 GA - 7.4.3 Fix Pack 1 when using domains or multi-tenancy could be vulnerable to information disclosure between tenants by routing SIEM data to the incorrect domain. IBM X-Force ID: 206979.
CVE-2021-38621 1 Netless 1 Flat Server 2022-07-12 6.4 MEDIUM 9.1 CRITICAL
The remove API in v1/controller/cloudStorage/alibabaCloud/remove/index.ts in netless Agora Flat Server before 2021-07-30 mishandles file ownership.
CVE-2021-37349 1 Nagios 1 Nagios Xi 2022-07-12 4.6 MEDIUM 7.8 HIGH
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because cleaner.php does not sanitise input read from the database.
CVE-2021-37347 1 Nagios 1 Nagios Xi 2022-07-12 4.6 MEDIUM 7.8 HIGH
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because getprofile.sh does not validate the directory name it receives as an argument.
CVE-2021-34536 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2022-07-12 4.6 MEDIUM 7.8 HIGH
Storage Spaces Controller Elevation of Privilege Vulnerability
CVE-2021-38606 1 Rengine Project 1 Rengine 2022-07-12 7.5 HIGH 9.8 CRITICAL
reNgine through 0.5 relies on a predictable directory name.
CVE-2021-38599 1 Wal-g Project 1 Wal-g 2022-07-12 5.0 MEDIUM 7.5 HIGH
WAL-G before 1.1, when a non-libsodium build (e.g., one of the official binary releases published as GitHub Releases) is used, silently ignores the libsodium encryption key and uploads cleartext backups. This is arguably a Principle of Least Surprise violation because "the user likely wanted to encrypt all file activity."
CVE-2021-27792 1 Broadcom 1 Fabric Operating System 2022-07-12 7.2 HIGH 7.8 HIGH
The request handling functions in web management interface of Brocade Fabric OS versions before v9.0.1a, v8.2.3a, and v7.4.2h do not properly handle malformed user input, resulting in a service crash. An authenticated attacker could use this weakness to cause the FOS HTTP application handler to crash, requiring a reboot.
CVE-2021-27791 1 Broadcom 1 Fabric Operating System 2022-07-12 5.5 MEDIUM 5.4 MEDIUM
The function that is used to parse the Authentication header in Brocade Fabric OS Web application service before Brocade Fabric OS v9.0.1a and v8.2.3a fails to properly process a malformed authentication header from the client, resulting in reading memory addresses outside the intended range. An unauthenticated attacker could discover a request, which could bypass the authentication process.
CVE-2021-38088 2 Acronis, Microsoft 2 Cyber Protect, Windows 2022-07-12 4.6 MEDIUM 7.8 HIGH
Acronis Cyber Protect 15 for Windows prior to build 27009 allowed local privilege escalation via binary hijacking.
CVE-2021-37841 1 Docker 1 Desktop 2022-07-12 4.6 MEDIUM 7.8 HIGH
Docker Desktop before 3.6.0 suffers from incorrect access control. If a low-privileged account is able to access the server running the Windows containers, it can lead to a full container compromise in both process isolation and Hyper-V isolation modes. This security issue leads an attacker with low privilege to read, write and possibly even execute code inside the containers.
CVE-2021-38587 1 Cpanel 1 Cpanel 2022-07-12 5.0 MEDIUM 7.5 HIGH
In cPanel before 96.0.13, scripts/fix-cpanel-perl mishandles the creation of temporary files (SEC-586).
CVE-2021-38566 1 Foxitsoftware 2 Pdf Editor, Pdf Reader 2022-07-12 5.0 MEDIUM 7.5 HIGH
An issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1. It allows stack consumption during recursive processing of embedded XML nodes.
CVE-2020-25566 1 Sapphireims 1 Sapphireims 2022-07-12 7.5 HIGH 9.8 CRITICAL
In SapphireIMS 5.0, it is possible to take over an account by sending a request to the Save_Password form as shown in POC. Notice that we do not require a JSESSIONID in this request and can reset any user’s password by changing the username to that user and password to base64(desired password).
CVE-2020-25564 1 Sapphireims 1 Sapphireims 2022-07-12 6.5 MEDIUM 8.8 HIGH
In SapphireIMS 5.0, it is possible to create local administrator on any client with credentials of a non-privileged user by directly accessing RemoteMgmtTaskSave (Automation Tasks) feature.
CVE-2021-0196 1 Intel 8 Lapqc71a, Lapqc71a Firmware, Lapqc71b and 5 more 2022-07-12 4.6 MEDIUM 7.8 HIGH
Improper access control in kernel mode driver for some Intel(R) NUC 9 Extreme Laptop Kits before version 2.2.0.20 may allow an authenticated user to potentially enable escalation of privilege via local access.