Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-42288 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2022-07-12 3.6 LOW 6.1 MEDIUM
Windows Hello Security Feature Bypass Vulnerability
CVE-2020-28419 1 Hp 1503 Laserjet Managed Mfp E62665 3gy14a, Laserjet Managed Mfp E62665 3gy15a, Laserjet Managed Mfp E62665 3gy16a and 1500 more 2022-07-12 6.8 MEDIUM 8.8 HIGH
During installation with certain driver software or application packages an arbitrary code execution could occur.
CVE-2021-43196 1 Jetbrains 1 Teamcity 2022-07-12 5.0 MEDIUM 7.5 HIGH
In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible.
CVE-2021-43183 1 Jetbrains 1 Hub 2022-07-12 7.5 HIGH 9.8 CRITICAL
In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed.
CVE-2021-43114 2 Debian, Fort Validator Project 2 Debian Linux, Fort Validator 2022-07-12 5.0 MEDIUM 7.5 HIGH
FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectively disabling Route Origin Validation.
CVE-2020-4160 1 Ibm 1 Qradar Network Security 2022-07-12 4.3 MEDIUM 5.9 MEDIUM
IBM QRadar Network Security 5.4.0 and 5.5.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 174340.
CVE-2021-28024 1 Servicetonic 1 Servicetonic 2022-07-12 7.5 HIGH 9.8 CRITICAL
Unauthorized system access in the login form in ServiceTonic Helpdesk software version < 9.0.35937 allows attacker to login without using a password.
CVE-2021-32483 1 Cloudera 1 Cloudera Manager 2022-07-12 5.0 MEDIUM 5.3 MEDIUM
Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges to view the restricted Dashboard.
CVE-2021-30132 1 Cloudera 1 Cloudera Manager 2022-07-12 7.5 HIGH 9.8 CRITICAL
Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges.
CVE-2021-42075 1 Barrier Project 1 Barrier 2022-07-12 5.0 MEDIUM 7.5 HIGH
An issue was discovered in Barrier before 2.3.4. The barriers component (aka the server-side implementation of Barrier) does not correctly close file descriptors for established TCP connections. An unauthenticated remote attacker can thus cause file descriptor exhaustion in the server process, leading to denial of service.
CVE-2021-31602 1 Hitachi 2 Vantara Pentaho, Vantara Pentaho Business Intelligence Server 2022-07-12 5.0 MEDIUM 7.5 HIGH
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The Security Model has different layers of Access Control. One of these layers is the applicationContext security, which is defined in the applicationContext-spring-security.xml file. The default configuration allows an unauthenticated user with no previous knowledge of the platform settings to extract pieces of information without possessing valid credentials.
CVE-2021-31601 1 Hitachi 2 Vantara Pentaho, Vantara Pentaho Business Intelligence Server 2022-07-12 4.0 MEDIUM 6.5 MEDIUM
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the backend server. An authenticated user (regardless of privileges) can list all databases connection details and credentials.
CVE-2021-43411 1 Gnu 1 Hurd 2022-07-12 8.5 HIGH 7.5 HIGH
An issue was discovered in GNU Hurd before 0.9 20210404-9. When trying to exec a setuid executable, there's a window of time when the process already has the new privileges, but still refers to the old task and is accessible through the old process port. This can be exploited to get full root access.
CVE-2021-37471 1 Cradlepoint 6 Ibr600, Ibr600 Firmware, Ibr600c and 3 more 2022-07-12 7.8 HIGH 7.5 HIGH
Cradlepoint IBR900-600 devices running versions < 7.21.10 are vulnerable to a restricted shell escape sequence that provides an attacker the capability to simultaneously deny availability to the device's NetCloud Manager console, local console and SSH command-line.
CVE-2021-42837 1 Talend 1 Data Catalog 2022-07-12 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Talend Data Catalog before 7.3-20210930. After setting up SAML/OAuth, authentication is not correctly enforced on the native login page. Any valid user from the SAML/OAuth provider can be used as the username with an arbitrary password, and login will succeed.
CVE-2021-42671 1 Engineers Online Portal Project 1 Engineers Online Portal 2022-07-12 5.0 MEDIUM 7.5 HIGH
An incorrect access control vulnerability exists in Sourcecodester Engineers Online Portal in PHP in nia_munoz_monitoring_system/admin/uploads. An attacker can leverage this vulnerability in order to bypass access controls and access all the files uploaded to the web server without the need of authentication or authorization.
CVE-2021-42663 1 Online Event Booking And Reservation System Project 1 Online Event Booking And Reservation System 2022-07-12 4.3 MEDIUM 4.3 MEDIUM
An HTML injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the msg parameter to /event-management/index.php. An attacker can leverage this vulnerability in order to change the visibility of the website. Once the target user clicks on a given link he will display the content of the HTML code of the attacker's choice.
CVE-2021-39898 1 Gitlab 1 Gitlab 2022-07-12 5.0 MEDIUM 5.3 MEDIUM
In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may allow access to the project which it was exported from.
CVE-2021-39903 1 Gitlab 1 Gitlab 2022-07-12 4.0 MEDIUM 6.5 MEDIUM
In all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility level of a group or a project to a restricted option even after the instance administrator sets that visibility option as restricted in settings.
CVE-2020-6931 1 Hp 1 Print And Scan Doctor 2022-07-12 4.6 MEDIUM 7.8 HIGH
HP Print and Scan Doctor may potentially be vulnerable to local elevation of privilege.