CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2021-3793

    Last Modified: 21 Nov 2024

    An improper access control vulnerability was reported in some Motorola-branded Binatone Hubble Cameras which could allow an unauthenticated attacker on the same network as the device to access administrative pages that could result in information disclosure or device firmware update with verified firmware.

    Published: 12 Nov 2021
    5.3
    Medium

    CVE-2021-3792

    Last Modified: 21 Nov 2024

    Some device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypted which could lead to the communication channel being accessible by an attacker.

    Published: 12 Nov 2021
    6.5
    Medium

    CVE-2021-3791

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same subnet to download an encrypted log file containing sensitive information such as WiFi SSID and password.

    Published: 12 Nov 2021
    6.5
    Medium

    CVE-2021-3790

    Last Modified: 21 Nov 2024

    A buffer overflow was reported in the local web server of some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same network to perform a denial-of-service attack against the device.

    Published: 12 Nov 2021
    4.2
    Medium

    CVE-2021-3789

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access to obtain the encryption key used to decrypt firmware update packages.

    Published: 12 Nov 2021
    6.8
    Medium

    CVE-2021-3788

    Last Modified: 21 Nov 2024

    An exposed debug interface was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access unauthorized access to the device.

    Published: 12 Nov 2021
    6.4
    Medium

    CVE-2021-3787

    Last Modified: 21 Nov 2024

    A vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with local access to obtain the MQTT credentials that could result in unauthorized access to backend Hubble services.

    Published: 12 Nov 2021
    4.4
    Medium

    CVE-2021-3786

    Last Modified: 21 Nov 2024

    A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data out of the SMRAM range.

    Published: 12 Nov 2021
    7.2
    High

    CVE-2021-3723

    Last Modified: 21 Nov 2024

    A command injection vulnerability was reported in the Integrated Management Module (IMM) of legacy IBM System x 3550 M3 and IBM System x 3650 M3 servers that could allow the execution of operating system commands over an authenticated SSH or Telnet session.

    Published: 12 Nov 2021
    5.5
    Medium

    CVE-2021-3720

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability was reported in the Time Weather system widget on Legion Phone Pro (L79031) and Legion Phone2 Pro (L70081) that could allow other applications to access device GPS data.

    Published: 12 Nov 2021
    6.7
    Medium

    CVE-2021-3719

    Last Modified: 21 Nov 2024

    A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCentre and ThinkStation models may allow an attacker with local access and elevated privileges to execute arbitrary code.

    Published: 12 Nov 2021
    4.3
    Medium

    CVE-2021-3718

    Last Modified: 21 Nov 2024

    A denial of service vulnerability was reported in some ThinkPad models that could cause a system to crash when the Enhanced Biometrics setting is enabled in BIOS.

    Published: 12 Nov 2021
    6.7
    Medium

    CVE-2021-3599

    Last Modified: 21 Nov 2024

    A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.

    Published: 12 Nov 2021
    8.8
    High

    CVE-2021-3577

    Last Modified: 21 Nov 2024

    An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker on the same network unauthorized access to the device.

    Published: 12 Nov 2021
    6.4
    Medium

    CVE-2021-3519

    Last Modified: 21 Nov 2024

    A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes.

    Published: 12 Nov 2021
    8.8
    High

    CVE-2020-21141

    Last Modified: 21 Nov 2024

    iCMS v7.0.15 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admincp.php?app=members&do=add.

    Published: 12 Nov 2021
    7.5
    High

    CVE-2021-43610

    Last Modified: 21 Nov 2024

    Belledonne Belle-sip before 5.0.20 can crash applications such as Linphone via an invalid From header (request URI without a parameter) in an unauthenticated SIP message, a different issue than CVE-2021-33056.

    Published: 12 Nov 2021
    7.5
    High

    CVE-2021-43611

    Last Modified: 21 Nov 2024

    Belledonne Belle-sip before 5.0.20 can crash applications such as Linphone via " \ " in the display name of a From header.

    Published: 12 Nov 2021
    7.8
    High

    CVE-2021-42563

    Last Modified: 21 Nov 2024

    There is an Unquoted Service Path in NI Service Locator (nisvcloc.exe) in versions prior to 18.0 on Windows. This may allow an authorized local user to insert arbitrary code into the unquoted service path and escalate privileges.

    Published: 12 Nov 2021
    6.5
    Medium

    CVE-2021-43332

    Last Modified: 21 Nov 2024

    In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could potentially be cracked by a moderator via an offline brute-force attack.

    Published: 12 Nov 2021
    6.1
    Medium

    CVE-2021-43331

    Last Modified: 21 Nov 2024

    In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for XSS.

    Published: 12 Nov 2021
    9.8
    Critical

    CVE-2021-39303

    Last Modified: 21 Nov 2024

    The server in Jamf Pro before 10.32.0 has an SSRF vulnerability, aka PI-006352. NOTE: Jamf Nation will also publish an article about this vulnerability.

    Published: 12 Nov 2021
    6.5
    Medium

    CVE-2021-41972

    Last Modified: 21 Nov 2024

    Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed in a non-trivial way.

    Published: 12 Nov 2021
    9.8
    Critical

    CVE-2021-41264

    Last Modified: 21 Nov 2024

    OpenZeppelin Contracts is a library for smart contract development. In affected versions upgradeable contracts using `UUPSUpgradeable` may be vulnerable to an attack affecting uninitialized implementation contracts. A fix is included in version 4.3.2 of `@openzeppelin/contracts` and `@openzeppelin/contracts-upgradeable`. For users unable to upgrade; initialize implementation contracts using `UUPSUpgradeable` by invoking the initializer function (usually called `initialize`). An example is provided [in the forum](https://forum.openzeppelin.com/t/security-advisory-initialize-uups-implementation-contracts/15301).

    Published: 12 Nov 2021
    7.8
    High

    CVE-2021-43579

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linking to a crafted BMP file.

    Published: 12 Nov 2021
    8.8
    High

    CVE-2021-41254

    Last Modified: 21 Nov 2024

    kustomize-controller is a Kubernetes operator, specialized in running continuous delivery pipelines for infrastructure and workloads defined with Kubernetes manifests and assembled with Kustomize. Users that can create Kubernetes Secrets, Service Accounts and Flux Kustomization objects, could execute commands inside the kustomize-controller container by embedding a shell script in a Kubernetes Secret. This can be used to run `kubectl` commands under the Service Account of kustomize-controller, thus allowing an authenticated Kubernetes user to gain cluster admin privileges. In affected versions multitenant environments where non-admin users have permissions to create Flux Kustomization objects are affected by this issue. This vulnerability was fixed in kustomize-controller v0.15.0 (included in flux2 v0.18.0) released on 2021-10-08. Starting with v0.15, the kustomize-controller no longer executes shell commands on the container OS and the `kubectl` binary has been removed from the container image. To prevent the creation of Kubernetes Service Accounts with `secrets` in namespaces owned by tenants, a Kubernetes validation webhook such as Gatekeeper OPA or Kyverno can be used.

    Published: 12 Nov 2021
    4.3
    Medium

    CVE-2021-38985

    Last Modified: 21 Nov 2024

    IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

    Published: 12 Nov 2021
    2.7
    Low

    CVE-2021-38973

    Last Modified: 21 Nov 2024

    IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

    Published: 12 Nov 2021
    4.3
    Medium

    CVE-2021-38972

    Last Modified: 21 Nov 2024

    IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

    Published: 12 Nov 2021
    5.3
    Medium

    CVE-2020-4146

    Last Modified: 21 Nov 2024

    IBM Security SiteProtector System 3.1.1 could allow a remote attacker to obtain sensitive information, caused by missing 'HttpOnly' flag. A remote attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 174129.

    Published: 12 Nov 2021
    5.4
    Medium

    CVE-2020-4140

    Last Modified: 21 Nov 2024

    IBM Security SiteProtector System 3.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174052.

    Published: 12 Nov 2021
    7.5
    High

    CVE-2021-43492

    Last Modified: 21 Nov 2024

    AlquistManager branch as of commit 280d99f43b11378212652e75f6f3159cde9c1d36 is affected by a directory traversal vulnerability. This attack can cause the disclosure of critical secrets stored anywhere on the system andcan significantly aid in getting remote code access.

    Published: 12 Nov 2021
    7.5
    High

    CVE-2021-43493

    Last Modified: 21 Nov 2024

    ServerManagement master branch as of commit 49491cc6f94980e6be7791d17be947c27071eb56 is affected by a directory traversal vulnerability. This vulnerability can be used to extract credentials which can in turn be used to execute code.

    Published: 12 Nov 2021
    7.5
    High

    CVE-2021-43494

    Last Modified: 21 Nov 2024

    OpenCV-REST-API master branch as of commit 69be158c05d4dd5a4aff38fdc680a162dd6b9e49 is affected by a directory traversal vulnerability. This attack can cause the disclosure of critical secrets stored anywhere on the system and can significantly aid in getting remote code access.

    Published: 12 Nov 2021
    7.5
    High

    CVE-2021-43496

    Last Modified: 21 Nov 2024

    Clustering master branch as of commit 53e663e259bcfc8cdecb56c0bb255bd70bfcaa70 is affected by a directory traversal vulnerability. This attack can cause the disclosure of critical secrets stored anywhere on the system and can significantly aid in getting remote code access.

    Published: 12 Nov 2021
    7.5
    High

    CVE-2021-3934

    Last Modified: 21 Nov 2024

    ohmyzsh is vulnerable to Improper Neutralization of Special Elements used in an OS Command

    Published: 12 Nov 2021
    8.1
    High

    CVE-2021-43578

    Last Modified: 21 Nov 2024

    Jenkins Squash TM Publisher (Squash4Jenkins) Plugin 1.0.0 and earlier implements an agent-to-controller message that does not implement any validation of its input, allowing attackers able to control agent processes to replace arbitrary files on the Jenkins controller file system with an attacker-controlled JSON string.

    Published: 12 Nov 2021
    7.1
    High

    CVE-2021-43577

    Last Modified: 21 Nov 2024

    Jenkins OWASP Dependency-Check Plugin 5.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

    Published: 12 Nov 2021
    6.5
    Medium

    CVE-2021-43576

    Last Modified: 21 Nov 2024

    Jenkins pom2config Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers with Overall/Read and Item/Read permissions to have Jenkins parse a crafted XML file that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.

    Published: 12 Nov 2021
    6.5
    Medium

    CVE-2021-21701

    Last Modified: 21 Nov 2024

    Jenkins Performance Plugin 3.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

    Published: 12 Nov 2021
    5.4
    Medium

    CVE-2021-21700

    Last Modified: 21 Nov 2024

    Jenkins Scriptler Plugin 3.3 and earlier does not escape the name of scripts on the UI when asking to confirm their deletion, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by exploitable by attackers able to create Scriptler scripts.

    Published: 12 Nov 2021
    5.4
    Medium

    CVE-2021-21699

    Last Modified: 21 Nov 2024

    Jenkins Active Choices Plugin 2.5.6 and earlier does not escape the parameter name of reactive parameters and dynamic reference parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

    Published: 12 Nov 2021
    9.8
    Critical

    CVE-2021-30321

    Last Modified: 21 Nov 2024

    Possible buffer overflow due to lack of parameter length check during MBSSID scan IE parse in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity

    Published: 12 Nov 2021
    7.5
    High

    CVE-2021-30284

    Last Modified: 21 Nov 2024

    Possible information exposure and denial of service due to NAS not dropping messages when integrity check fails in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 12 Nov 2021
    6.7
    Medium

    CVE-2021-30266

    Last Modified: 21 Nov 2024

    Possible use after free due to improper memory validation when initializing new interface via Interface add command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 12 Nov 2021
    6.7
    Medium

    CVE-2021-30265

    Last Modified: 21 Nov 2024

    Possible memory corruption due to improper validation of memory address while processing user-space IOCTL for clearing Filter and Route statistics in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 12 Nov 2021
    6.7
    Medium

    CVE-2021-30264

    Last Modified: 21 Nov 2024

    Possible use after free due improper validation of reference from call back to internal store table in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 12 Nov 2021
    6.7
    Medium

    CVE-2021-30263

    Last Modified: 21 Nov 2024

    Possible race condition can occur due to lack of synchronization mechanism when On-Device Logging node open twice concurrently in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

    Published: 12 Nov 2021
    7.8
    High

    CVE-2021-30259

    Last Modified: 21 Nov 2024

    Possible out of bound access due to improper validation of function table entries in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 12 Nov 2021
    7.8
    High

    CVE-2021-30255

    Last Modified: 21 Nov 2024

    Possible buffer overflow due to improper input validation in PDM DIAG command in FTM in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 12 Nov 2021