CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2021-20876

    Last Modified: 21 Nov 2024

    Path traversal vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows an attacker with an administrative privilege to obtain sensitive information stored in the hierarchy above the directory on the published site's server via unspecified vectors.

    Published: 24 Dec 2021
    6.1
    Medium

    CVE-2021-20875

    Last Modified: 21 Nov 2024

    Open redirect vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks by having a user to access a specially crafted URL.

    Published: 24 Dec 2021
    7.5
    High

    CVE-2021-20874

    Last Modified: 21 Nov 2024

    Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to access arbitrary files on the server and obtain sensitive information via unspecified vectors.

    Published: 24 Dec 2021
    7.5
    High

    CVE-2021-20827

    Last Modified: 21 Nov 2024

    Plaintext storage of a password vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, WindEDIT Lite v1.3.1 and earlier, and Data File Manager v2.12.1 and earlier) allows an attacker to obtain the PLC Web server user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the attacker may access the PLC Web server and hijack the PLC, and manipulation of the PLC output and/or suspension of the PLC may be conducted.

    Published: 24 Dec 2021
    7.6
    High

    CVE-2021-20826

    Last Modified: 21 Nov 2024

    Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, WindEDIT Lite v1.3.1 and earlier, and Data File Manager v2.12.1 and earlier) allows an attacker to obtain the PLC Web server user credentials from the communication between the PLC and the software. As a result, the complete access privileges to the PLC Web server may be obtained, and manipulation of the PLC output and/or suspension of the PLC may be conducted.

    Published: 24 Dec 2021
    5.3
    Medium

    CVE-2020-35398

    Last Modified: 21 Nov 2024

    An issue was discovered in UTI Mutual fund Android application 5.4.18 and prior, allows attackers to brute force enumeration of usernames determined by the error message returned after invalid credentials are attempted.

    Published: 23 Dec 2021
    7.5
    High

    CVE-2021-45470

    Last Modified: 21 Nov 2024

    lib/DatabaseLayer.py in cve-search before 4.1.0 allows regular expression injection, which can lead to ReDoS (regular expression denial of service) or other impacts.

    Published: 23 Dec 2021
    4.4
    Medium

    CVE-2021-27006

    Last Modified: 21 Nov 2024

    StorageGRID (formerly StorageGRID Webscale) versions 11.5 prior to 11.5.0.5 are susceptible to a vulnerability which may allow an administrative user to escalate their privileges and modify settings in SANtricity System Manager.

    Published: 23 Dec 2021
    9.8
    Critical

    CVE-2021-27007

    Last Modified: 21 Nov 2024

    NetApp Virtual Desktop Service (VDS) when used with an HTML5 gateway is susceptible to a vulnerability which when successfully exploited could allow an unauthenticated attacker to takeover a Remote Desktop Session.

    Published: 23 Dec 2021
    6.1
    Medium

    CVE-2021-44543

    Last Modified: 21 Nov 2024

    An XSS vulnerability was found in Privoxy which was fixed in cgi_error_no_template() by encode the template name when Privoxy is configured to servce the user-manual itself.

    Published: 23 Dec 2021
    7.5
    High

    CVE-2021-44542

    Last Modified: 21 Nov 2024

    A memory leak vulnerability was found in Privoxy when handling errors.

    Published: 23 Dec 2021
    7.5
    High

    CVE-2021-44540

    Last Modified: 21 Nov 2024

    A vulnerability was found in Privoxy which was fixed in get_url_spec_param() by freeing memory of compiled pattern spec before bailing.

    Published: 23 Dec 2021
    7.5
    High

    CVE-2021-44541

    Last Modified: 21 Nov 2024

    A vulnerability was found in Privoxy which was fixed in process_encrypted_request_headers() by freeing header memory when failing to get the request destination.

    Published: 23 Dec 2021
    9.1
    Critical

    CVE-2021-43985

    Last Modified: 21 Nov 2024

    An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization.

    Published: 23 Dec 2021
    7.5
    High

    CVE-2021-43989

    Last Modified: 21 Nov 2024

    mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker to crack the previously retrieved password hashes.

    Published: 23 Dec 2021
    10
    Critical

    CVE-2021-43981

    Last Modified: 21 Nov 2024

    mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.

    Published: 23 Dec 2021
    10
    Critical

    CVE-2021-44453

    Last Modified: 21 Nov 2024

    mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands.

    Published: 23 Dec 2021
    10
    Critical

    CVE-2021-43984

    Last Modified: 21 Nov 2024

    mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.

    Published: 23 Dec 2021
    10
    Critical

    CVE-2021-22657

    Last Modified: 21 Nov 2024

    mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.

    Published: 23 Dec 2021
    9.8
    Critical

    CVE-2021-43987

    Last Modified: 21 Nov 2024

    An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web interface, which cannot be deleted or changed through the regular web interface.

    Published: 23 Dec 2021
    10
    Critical

    CVE-2021-23198

    Last Modified: 21 Nov 2024

    mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.

    Published: 23 Dec 2021
    5.3
    Medium

    CVE-2021-35243

    Last Modified: 21 Nov 2024

    The HTTP PUT and DELETE methods were enabled in the Web Help Desk web server (12.7.7 and earlier), allowing users to execute dangerous HTTP requests. The HTTP PUT method is normally used to upload data that is saved on the server with a user-supplied URL. While the DELETE method requests that the origin server removes the association between the target resource and its current functionality. Improper use of these methods may lead to a loss of integrity.

    Published: 23 Dec 2021
    5.5
    Medium

    CVE-2021-30767

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. A local user may be able to modify protected parts of the file system.

    Published: 23 Dec 2021
    7.8
    High

    CVE-2020-3886

    Last Modified: 21 Nov 2024

    A use after free issue was addressed with improved memory management. This issue is fixed in macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published: 23 Dec 2021
    5.5
    Medium

    CVE-2020-3896

    Last Modified: 21 Nov 2024

    This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra. A malicious application may be able to overwrite arbitrary files.

    Published: 23 Dec 2021
    5.5
    Medium

    CVE-2019-8702

    Last Modified: 21 Nov 2024

    This issue was addressed with a new entitlement. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra, iOS 12.4, tvOS 12.4. A local user may be able to read a persistent account identifier.

    Published: 23 Dec 2021
    9.8
    Critical

    CVE-2019-8703

    Last Modified: 21 Nov 2024

    This issue was addressed with improved entitlements. This issue is fixed in watchOS 6, tvOS 13, macOS Catalina 10.15, iOS 13. An application may be able to gain elevated privileges.

    Published: 23 Dec 2021
    7.8
    High

    CVE-2017-13908

    Last Modified: 21 Nov 2024

    An issue in handling file permissions was addressed with improved validation. This issue is fixed in macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan, macOS High Sierra 10.13. A local attacker may be able to execute non-executable text files via an SMB share.

    Published: 23 Dec 2021
    7.8
    High

    CVE-2018-4302

    Last Modified: 21 Nov 2024

    A null pointer dereference was addressed with improved validation. This issue is fixed in macOS High Sierra 10.13, iCloud for Windows 7.0, watchOS 4, iOS 11, iTunes 12.7 for Windows. Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution.

    Published: 23 Dec 2021
    9.8
    Critical

    CVE-2019-8643

    Last Modified: 21 Nov 2024

    CVE-2019-8643: Arun Sharma of VMWare This issue is fixed in macOS Mojave 10.14. Description: A logic issue was addressed with improved state management..

    Published: 23 Dec 2021
    5.5
    Medium

    CVE-2017-13910

    Last Modified: 21 Nov 2024

    An access issue was addressed with additional sandbox restrictions on applications. This issue is fixed in macOS High Sierra 10.13. An application may be able to access restricted files.

    Published: 23 Dec 2021
    6.8
    Medium

    CVE-2018-4478

    Last Modified: 21 Nov 2024

    A validation issue was addressed with improved logic. This issue is fixed in macOS High Sierra 10.13.5, Security Update 2018-003 Sierra, Security Update 2018-003 El Capitan. An attacker with physical access to a device may be able to elevate privileges.

    Published: 23 Dec 2021
    5.5
    Medium

    CVE-2017-13909

    Last Modified: 21 Nov 2024

    An issue existed in the storage of sensitive tokens. This issue was addressed by placing the tokens in Keychain. This issue is fixed in macOS High Sierra 10.13. A local attacker may gain access to iCloud authentication tokens.

    Published: 23 Dec 2021
    7.8
    High

    CVE-2017-13906

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan, macOS High Sierra 10.13. A malicious application may be able to elevate privileges.

    Published: 23 Dec 2021
    6.8
    Medium

    CVE-2017-13907

    Last Modified: 21 Nov 2024

    A state management issue was addressed with improved state validation. This issue is fixed in macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan. The screen lock may unexpectedly remain unlocked.

    Published: 23 Dec 2021
    7.5
    High

    CVE-2017-13892

    Last Modified: 21 Nov 2024

    An issue existed in the handling of Contact sharing. This issue was addressed with improved handling of user information. This issue is fixed in macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan. Sharing contact information may lead to unexpected data sharing.

    Published: 23 Dec 2021
    7.8
    High

    CVE-2017-13835

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS High Sierra 10.13. An application may be able to execute arbitrary code with elevated privileges.

    Published: 23 Dec 2021
    7.8
    High

    CVE-2017-13880

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 11.2, watchOS 4.2. An application may be able to execute arbitrary code with kernel privilege.

    Published: 23 Dec 2021
    8.1
    High

    CVE-2017-13905

    Last Modified: 21 Nov 2024

    A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.2, macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan, watchOS 4.2. An application may be able to gain elevated privileges.

    Published: 23 Dec 2021
    3.3
    Low

    CVE-2017-2375

    Last Modified: 21 Nov 2024

    An issue existed in preventing the uploading of CallKit call history to iCloud. This issue was addressed through improved logic. This issue is fixed in iOS 10.2.1. Updates for CallKit call history are sent to iCloud.

    Published: 23 Dec 2021
    7.5
    High

    CVE-2017-2488

    Last Modified: 21 Nov 2024

    A cryptographic weakness existed in the authentication protocol of Remote Desktop. This issue was addressed by implementing the Secure Remote Password authentication protocol. This issue is fixed in Apple Remote Desktop 3.9. An attacker may be able to capture cleartext passwords.

    Published: 23 Dec 2021
    7.8
    High

    CVE-2021-40161

    Last Modified: 21 Nov 2024

    A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through PDFTron earlier than 9.0.7 version.

    Published: 23 Dec 2021
    7.8
    High

    CVE-2021-40160

    Last Modified: 21 Nov 2024

    PDFTron prior to 9.0.7 version may be forced to read beyond allocated boundaries when parsing a maliciously crafted PDF file. This vulnerability can be exploited to execute arbitrary code.

    Published: 23 Dec 2021
    7.5
    High

    CVE-2021-43854

    Last Modified: 21 Nov 2024

    NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Versions prior to 3.6.5 are vulnerable to regular expression denial of service (ReDoS) attacks. The vulnerability is present in PunktSentenceTokenizer, sent_tokenize and word_tokenize. Any users of this class, or these two functions, are vulnerable to the ReDoS attack. In short, a specifically crafted long input to any of these vulnerable functions will cause them to take a significant amount of execution time. If your program relies on any of the vulnerable functions for tokenizing unpredictable user input, then we would strongly recommend upgrading to a version of NLTK without the vulnerability. For users unable to upgrade the execution time can be bounded by limiting the maximum length of an input to any of the vulnerable functions. Our recommendation is to implement such a limit.

    Published: 23 Dec 2021
    7.8
    High

    CVE-2021-4118

    Last Modified: 21 Nov 2024

    pytorch-lightning is vulnerable to Deserialization of Untrusted Data

    Published: 23 Dec 2021
    6.2
    Medium

    CVE-2021-43849

    Last Modified: 21 Nov 2024

    cordova-plugin-fingerprint-aio is a plugin provides a single and simple interface for accessing fingerprint APIs on both Android 6+ and iOS. In versions prior to 5.0.1 The exported activity `de.niklasmerz.cordova.biometric.BiometricActivity` can cause the app to crash. This vulnerability occurred because the activity didn't handle the case where it is requested with invalid or empty data which results in a crash. Any third party app can constantly call this activity with no permission. A 3rd party app/attacker using event listener can continually stop the app from working and make the victim unable to open it. Version 5.0.1 of the cordova-plugin-fingerprint-aio doesn't export the activity anymore and is no longer vulnerable. If you want to fix older versions change the attribute android:exported in plugin.xml to false. Please upgrade to version 5.0.1 as soon as possible.

    Published: 23 Dec 2021
    8.2
    High

    CVE-2021-23175

    Last Modified: 21 Nov 2024

    NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply individual user access controls for users on the same device, which, with user intervention, may lead to escalation of privileges, information disclosure, data tampering, and denial of service, affecting other resources beyond the intended security authority of GameStream.

    Published: 23 Dec 2021
    9.8
    Critical

    CVE-2021-44526

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.

    Published: 23 Dec 2021
    7.5
    High

    CVE-2021-44600

    Last Modified: 11 Feb 2025

    The password parameter on Simple Online Mens Salon Management System (MSMS) 1.0 appears to be vulnerable to SQL injection attacks through the password parameter. The predictive tests of this application interacted with that domain, indicating that the injected SQL query was executed. The attacker can retrieve all authentication and information about the users of this system.

    Published: 23 Dec 2021
    7.5
    High

    CVE-2021-44599

    Last Modified: 21 Nov 2024

    The id parameter from Online Enrollment Management System 1.0 system appears to be vulnerable to SQL injection attacks. A crafted payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The application interacted with that domain, indicating that the injected SQL query was executed. The attacker can retrieve sensitive information for all users of this system.

    Published: 23 Dec 2021