| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-3058 | Hig | 0.57 | 8.8 | 0.02 | Nov 10, 2021 | An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permissions to use XML API the ability to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 versions earlier than… | ||
| CVE-2021-3056 | Hig | 0.57 | 8.8 | 0.01 | Nov 10, 2021 | A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN enables an authenticated attacker to execute arbitrary code with root user privileges during SAML authentication. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20;… | ||
| CVE-2021-43564 | — | Hig | 0.49 | 7.5 | 0.01 | Nov 10, 2021 | An issue was discovered in the jobfair (aka Job Fair) extension before 1.0.13 and 2.x before 2.0.2 for TYPO3. The extension fails to protect or obfuscate filenames of uploaded files. This allows unauthenticated users to download files with sensitive data by simply guessing the… | |
| CVE-2021-43563 | Hig | 0.57 | 8.8 | 0.01 | Nov 10, 2021 | An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The Access Control in the bundled media browser is broken, which allows an unauthenticated attacker to perform requests to the pixx.io API for the configured API user. This… | ||
| CVE-2021-41426 | Hig | 0.57 | 8.8 | 0.01 | Nov 10, 2021 | Beeline Smart box 2.0.38 is vulnerable to Cross Site Request Forgery (CSRF) via mgt_end_user.htm. | ||
| CVE-2021-40503 | Hig | 0.51 | 7.8 | 0.00 | Nov 10, 2021 | An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an attacker with sufficient privileges on the local client-side PC to obtain an equivalent of the user’s password. With this highly sensitive data leaked, the… | ||
| CVE-2021-40502 | Hig | 0.57 | 8.8 | 0.01 | Nov 10, 2021 | SAP Commerce - versions 2105.3, 2011.13, 2005.18, 1905.34, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. Authenticated attackers will be able to access and edit data from b2b units they do not belong to. | ||
| CVE-2021-40501 | Hig | 0.53 | 8.1 | 0.01 | Nov 10, 2021 | SAP ABAP Platform Kernel - versions 7.77, 7.81, 7.85, 7.86, does not perform necessary authorization checks for an authenticated business user, resulting in escalation of privileges. That means this business user is able to read and modify data beyond the vulnerable system.… | ||
| CVE-2021-43562 | Hig | 0.57 | 8.8 | 0.01 | Nov 10, 2021 | An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The extension fails to restrict the image download to the configured pixx.io DAM URL, resulting in SSRF. As a result, an attacker can download various content from a remote… | ||
| CVE-2021-39474 | Hig | 0.47 | 7.2 | 0.02 | Nov 10, 2021 | Vulnerability in the product Docsis 3.0 UBC1319BA00 Router supported affected version 1319010201r009. The vulnerability allows an attacker with privileges and network access through the ping.cmd component to execute commands on the device. | ||
| CVE-2021-34598 | Hig | 0.49 | 7.5 | 0.01 | Nov 10, 2021 | In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 the remote logging functionality is impaired by the lack of memory release for data structures from syslog-ng when remote logging is active | ||
| CVE-2021-31853 | Hig | 0.51 | 7.8 | 0.00 | Nov 10, 2021 | DLL Search Order Hijacking Vulnerability in McAfee Drive Encryption (MDE) prior to 7.3.0 HF2 (7.3.0.183) allows local users to execute arbitrary code and escalate privileges via execution from a compromised folder. | ||
| CVE-2021-43209 | Hig | 0.51 | 7.8 | 0.05 | Nov 10, 2021 | 3D Viewer Remote Code Execution Vulnerability | ||
| CVE-2021-43208 | Hig | 0.51 | 7.8 | 0.04 | Nov 10, 2021 | 3D Viewer Remote Code Execution Vulnerability | ||
| CVE-2021-42322 | Hig | 0.51 | 7.8 | 0.00 | Nov 10, 2021 | Visual Studio Code Elevation of Privilege Vulnerability | ||
| CVE-2021-42321 | Hig | 0.85 | 8.8 | 0.90 | KEV | Nov 10, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2021-42316 | Hig | 0.57 | 8.8 | 0.02 | Nov 10, 2021 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | ||
| CVE-2021-42298 | Hig | 0.51 | 7.8 | 0.05 | Nov 10, 2021 | Microsoft Defender Remote Code Execution Vulnerability | ||
| CVE-2021-42296 | Hig | 0.51 | 7.8 | 0.01 | Nov 10, 2021 | Microsoft Word Remote Code Execution Vulnerability | ||
| CVE-2021-42292 | Hig | 0.65 | 7.8 | 0.32 | KEV | Nov 10, 2021 | Microsoft Excel Security Feature Bypass Vulnerability | |
| CVE-2021-42291 | Hig | 0.49 | 7.5 | 0.03 | Nov 10, 2021 | Active Directory Domain Services Elevation of Privilege Vulnerability | ||
| CVE-2021-42287 | Hig | 0.73 | 7.5 | 0.74 | KEV | Nov 10, 2021 | Active Directory Domain Services Elevation of Privilege Vulnerability | |
| CVE-2021-42286 | Hig | 0.51 | 7.8 | 0.00 | Nov 10, 2021 | Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability | ||
| CVE-2021-42285 | Hig | 0.51 | 7.8 | 0.01 | Nov 10, 2021 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2021-42283 | Hig | 0.57 | 8.8 | 0.00 | Nov 10, 2021 | NTFS Elevation of Privilege Vulnerability | ||
| CVE-2021-42282 | Hig | 0.49 | 7.5 | 0.03 | Nov 10, 2021 | Active Directory Domain Services Elevation of Privilege Vulnerability | ||
| CVE-2021-42278 | Hig | 0.72 | 7.5 | 0.70 | KEV | Nov 10, 2021 | Active Directory Domain Services Elevation of Privilege Vulnerability | |
| CVE-2021-42276 | Hig | 0.51 | 7.8 | 0.02 | Nov 10, 2021 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | ||
| CVE-2021-42275 | Hig | 0.57 | 8.8 | 0.02 | Nov 10, 2021 | Microsoft COM for Windows Remote Code Execution Vulnerability | ||
| CVE-2021-41378 | Hig | 0.51 | 7.8 | 0.01 | Nov 10, 2021 | Windows NTFS Remote Code Execution Vulnerability | ||
| CVE-2021-41377 | Hig | 0.51 | 7.8 | 0.00 | Nov 10, 2021 | Windows Fast FAT File System Driver Elevation of Privilege Vulnerability | ||
| CVE-2021-41372 | Hig | 0.49 | 7.6 | 0.01 | Nov 10, 2021 | A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim. Combining these 2 vulnerabilities… | ||
| CVE-2021-41370 | Hig | 0.51 | 7.8 | 0.00 | Nov 10, 2021 | NTFS Elevation of Privilege Vulnerability | ||
| CVE-2021-41367 | Hig | 0.51 | 7.8 | 0.00 | Nov 10, 2021 | NTFS Elevation of Privilege Vulnerability | ||
| CVE-2021-41366 | Hig | 0.51 | 7.8 | 0.00 | Nov 10, 2021 | Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability | ||
| CVE-2021-41356 | Hig | 0.49 | 7.5 | 0.03 | Nov 10, 2021 | Windows Denial of Service Vulnerability | ||
| CVE-2021-40442 | Hig | 0.51 | 7.8 | 0.02 | Nov 10, 2021 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2021-38666 | Hig | 0.58 | 8.8 | 0.13 | Nov 10, 2021 | Remote Desktop Client Remote Code Execution Vulnerability | ||
| CVE-2021-38665 | Hig | 0.49 | 7.4 | 0.06 | Nov 10, 2021 | Remote Desktop Protocol Client Information Disclosure Vulnerability | ||
| CVE-2021-36957 | Hig | 0.51 | 7.8 | 0.00 | Nov 10, 2021 | Windows Desktop Bridge Elevation of Privilege Vulnerability | ||
| CVE-2021-37158 | Hig | 0.00 | 8.8 | 0.02 | Nov 10, 2021 | An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. An authenticated attacker could inject OS commands by starting a Counter-Strike server and using the map field to enter a Bash command. | ||
| CVE-2021-37157 | Hig | 0.57 | 8.8 | 0.01 | Nov 10, 2021 | An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. $HOME/OGP/Cfg/Config.pm has the root password in cleartext. | ||
| CVE-2021-20119 | Hig | 0.46 | 7.1 | 0.00 | Nov 9, 2021 | The password change utility for the Arris SurfBoard SB8200 can have safety measures bypassed that allow any logged-in user to change the administrator password. | ||
| CVE-2020-28419 | Hig | 0.57 | 8.8 | 0.02 | Nov 9, 2021 | During installation with certain driver software or application packages an arbitrary code execution could occur. | ||
| CVE-2021-43174 | — | Hig | 0.49 | 7.5 | 0.01 | Nov 9, 2021 | NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP uses XML which allows… | |
| CVE-2021-43173 | Hig | 0.49 | 7.5 | 0.01 | Nov 9, 2021 | In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feeding bytes to keep the connection alive. This can be used to effectively stall validation. While Routinator has a configurable… | ||
| CVE-2021-43172 | — | Hig | 0.00 | 7.5 | 0.01 | Nov 9, 2021 | NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only… | |
| CVE-2021-43182 | Hig | 0.49 | 7.5 | 0.01 | Nov 9, 2021 | In JetBrains Hub before 2021.1.13415, a DoS via user information is possible. | ||
| CVE-2021-43180 | Hig | 0.49 | 7.5 | 0.01 | Nov 9, 2021 | In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible. | ||
| CVE-2021-43203 | Hig | 0.49 | 7.5 | 0.01 | Nov 9, 2021 | In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly. |
- risk 0.57cvss 8.8epss 0.02
An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permissions to use XML API the ability to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 versions earlier than…
- risk 0.57cvss 8.8epss 0.01
A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN enables an authenticated attacker to execute arbitrary code with root user privileges during SAML authentication. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20;…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in the jobfair (aka Job Fair) extension before 1.0.13 and 2.x before 2.0.2 for TYPO3. The extension fails to protect or obfuscate filenames of uploaded files. This allows unauthenticated users to download files with sensitive data by simply guessing the…
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The Access Control in the bundled media browser is broken, which allows an unauthenticated attacker to perform requests to the pixx.io API for the configured API user. This…
- risk 0.57cvss 8.8epss 0.01
Beeline Smart box 2.0.38 is vulnerable to Cross Site Request Forgery (CSRF) via mgt_end_user.htm.
- risk 0.51cvss 7.8epss 0.00
An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an attacker with sufficient privileges on the local client-side PC to obtain an equivalent of the user’s password. With this highly sensitive data leaked, the…
- risk 0.57cvss 8.8epss 0.01
SAP Commerce - versions 2105.3, 2011.13, 2005.18, 1905.34, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. Authenticated attackers will be able to access and edit data from b2b units they do not belong to.
- risk 0.53cvss 8.1epss 0.01
SAP ABAP Platform Kernel - versions 7.77, 7.81, 7.85, 7.86, does not perform necessary authorization checks for an authenticated business user, resulting in escalation of privileges. That means this business user is able to read and modify data beyond the vulnerable system.…
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The extension fails to restrict the image download to the configured pixx.io DAM URL, resulting in SSRF. As a result, an attacker can download various content from a remote…
- risk 0.47cvss 7.2epss 0.02
Vulnerability in the product Docsis 3.0 UBC1319BA00 Router supported affected version 1319010201r009. The vulnerability allows an attacker with privileges and network access through the ping.cmd component to execute commands on the device.
- risk 0.49cvss 7.5epss 0.01
In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 the remote logging functionality is impaired by the lack of memory release for data structures from syslog-ng when remote logging is active
- risk 0.51cvss 7.8epss 0.00
DLL Search Order Hijacking Vulnerability in McAfee Drive Encryption (MDE) prior to 7.3.0 HF2 (7.3.0.183) allows local users to execute arbitrary code and escalate privileges via execution from a compromised folder.
- risk 0.51cvss 7.8epss 0.05
3D Viewer Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.04
3D Viewer Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
Visual Studio Code Elevation of Privilege Vulnerability
- risk 0.85cvss 8.8epss 0.90
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.05
Microsoft Defender Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Word Remote Code Execution Vulnerability
- risk 0.65cvss 7.8epss 0.32
Microsoft Excel Security Feature Bypass Vulnerability
- risk 0.49cvss 7.5epss 0.03
Active Directory Domain Services Elevation of Privilege Vulnerability
- risk 0.73cvss 7.5epss 0.74
Active Directory Domain Services Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.00
NTFS Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.03
Active Directory Domain Services Elevation of Privilege Vulnerability
- risk 0.72cvss 7.5epss 0.70
Active Directory Domain Services Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.02
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft COM for Windows Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows NTFS Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
- risk 0.49cvss 7.6epss 0.01
A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim. Combining these 2 vulnerabilities…
- risk 0.51cvss 7.8epss 0.00
NTFS Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
NTFS Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows Denial of Service Vulnerability
- risk 0.51cvss 7.8epss 0.02
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.58cvss 8.8epss 0.13
Remote Desktop Client Remote Code Execution Vulnerability
- risk 0.49cvss 7.4epss 0.06
Remote Desktop Protocol Client Information Disclosure Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows Desktop Bridge Elevation of Privilege Vulnerability
- risk 0.00cvss 8.8epss 0.02
An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. An authenticated attacker could inject OS commands by starting a Counter-Strike server and using the map field to enter a Bash command.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. $HOME/OGP/Cfg/Config.pm has the root password in cleartext.
- risk 0.46cvss 7.1epss 0.00
The password change utility for the Arris SurfBoard SB8200 can have safety measures bypassed that allow any logged-in user to change the administrator password.
- risk 0.57cvss 8.8epss 0.02
During installation with certain driver software or application packages an arbitrary code execution could occur.
- risk 0.49cvss 7.5epss 0.01
NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP uses XML which allows…
- risk 0.49cvss 7.5epss 0.01
In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feeding bytes to keep the connection alive. This can be used to effectively stall validation. While Routinator has a configurable…
- risk 0.00cvss 7.5epss 0.01
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only…
- risk 0.49cvss 7.5epss 0.01
In JetBrains Hub before 2021.1.13415, a DoS via user information is possible.
- risk 0.49cvss 7.5epss 0.01
In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible.
- risk 0.49cvss 7.5epss 0.01
In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly.