CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-41312

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collectors on Jira Service Management projects via an Improper Authentication vulnerability in the /secure/ViewCollectors endpoint. The affected versions are before version 8.19.1.

    Published: 3 Nov 2021
    9.8
    Critical

    CVE-2020-5955

    Last Modified: 21 Nov 2024

    An issue was discovered in Int15MicrocodeSmm in Insyde InsydeH2O before 2021-10-14 on Intel client chipsets. A caller may be able to escalate privileges.

    Published: 3 Nov 2021
    4.6
    Medium

    CVE-2021-39237

    Last Modified: 21 Nov 2024

    Certain HP LaserJet, HP LaserJet Managed, HP PageWide, and HP PageWide Managed printers may be vulnerable to potential information disclosure.

    Published: 3 Nov 2021
    9.8
    Critical

    CVE-2021-39238

    Last Modified: 21 Nov 2024

    Certain HP Enterprise LaserJet, HP LaserJet Managed, HP Enterprise PageWide, HP PageWide Managed products may be vulnerable to potential buffer overflow.

    Published: 3 Nov 2021
    8.1
    High

    CVE-2021-29993

    Last Modified: 19 Aug 2026

    Firefox for Android allowed navigations through the `intent://` protocol, which could be used to cause crashes and UI spoofs. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92.

    Published: 3 Nov 2021
    6.5
    Medium

    CVE-2021-38491

    Last Modified: 21 Nov 2024

    Mixed-content checks were unable to analyze opaque origins which led to some mixed content being loaded. This vulnerability affects Firefox < 92.

    Published: 3 Nov 2021
    8.8
    High

    CVE-2021-38494

    Last Modified: 21 Nov 2024

    Mozilla developers reported memory safety bugs present in Firefox 91. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 92.

    Published: 3 Nov 2021
    8.8
    High

    CVE-2021-38499

    Last Modified: 21 Nov 2024

    Mozilla developers reported memory safety bugs present in Firefox 92. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 93.

    Published: 3 Nov 2021
    6.9
    Medium

    CVE-2021-41174

    Last Modified: 21 Nov 2024

    Grafana is an open-source platform for monitoring and observability. In affected versions if an attacker is able to convince a victim to visit a URL referencing a vulnerable page, arbitrary JavaScript content may be executed within the context of the victim's browser. The user visiting the malicious link must be unauthenticated and the link must be for a page that contains the login button in the menu bar. The url has to be crafted to exploit AngularJS rendering and contain the interpolation binding for AngularJS expressions. AngularJS uses double curly braces for interpolation binding: {{ }} ex: {{constructor.constructor(‘alert(1)’)()}}. When the user follows the link and the page renders, the login button will contain the original link with a query parameter to force a redirect to the login page. The URL is not validated and the AngularJS rendering engine will execute the JavaScript expression contained in the URL. Users are advised to upgrade as soon as possible. If for some reason you cannot upgrade, you can use a reverse proxy or similar to block access to block the literal string {{ in the path.

    Published: 3 Nov 2021
    7.5
    High

    CVE-2021-20705

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote file upload via network.

    Published: 2 Nov 2021
    7.5
    High

    CVE-2021-20707

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to read files upload via network..

    Published: 2 Nov 2021
    9.8
    Critical

    CVE-2021-20703

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network.

    Published: 2 Nov 2021
    9.8
    Critical

    CVE-2021-20701

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network.

    Published: 2 Nov 2021
    7.5
    High

    CVE-2021-20706

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote file upload via network.

    Published: 2 Nov 2021
    9.8
    Critical

    CVE-2021-20704

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in the compatible API with previous versions CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network.

    Published: 2 Nov 2021
    9.8
    Critical

    CVE-2021-20702

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network.

    Published: 2 Nov 2021
    9.8
    Critical

    CVE-2021-20700

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network.

    Published: 2 Nov 2021
    6.7
    Medium

    CVE-2021-20135

    Last Modified: 21 Nov 2024

    Nessus versions 8.15.2 and earlier were found to contain a local privilege escalation vulnerability which could allow an authenticated, local administrator to run specific executables on the Nessus Agent host. Tenable has included a fix for this issue in Nessus 10.0.0. The installation files can be obtained from the Tenable Downloads Portal (https://www.tenable.com/downloads/nessus).

    Published: 2 Nov 2021
    9.8
    Critical

    CVE-2021-41036

    Last Modified: 21 Nov 2024

    In versions prior to 1.1 of the Eclipse Paho MQTT C Client, the client does not check rem_len size in readpacket.

    Published: 2 Nov 2021
    7.5
    High

    CVE-2021-43270

    Last Modified: 21 Nov 2024

    Datalust Seq.App.EmailPlus (aka seq-app-htmlemail) 3.1.0-dev-00148, 3.1.0-dev-00170, and 3.1.0-dev-00176 can use cleartext SMTP on port 25 in some cases where encryption on port 465 was intended.

    Published: 2 Nov 2021
    9.6
    Critical

    CVE-2020-6492

    Last Modified: 21 Nov 2024

    Use after free in ANGLE in Google Chrome prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

    Published: 2 Nov 2021
    3.3
    Low

    CVE-2021-43264

    Last Modified: 21 Nov 2024

    In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, adjusting the path component for the page help file allows attackers to bypass the intended access control for HTML files via directory traversal. It replaces the - character with the / character.

    Published: 2 Nov 2021
    5.4
    Medium

    CVE-2021-43265

    Last Modified: 21 Nov 2024

    In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, certain tag syntax could be used for XSS, such as via a SCRIPT element.

    Published: 2 Nov 2021
    7.3
    High

    CVE-2021-43266

    Last Modified: 21 Nov 2024

    In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exporting collections via PDF export could lead to code execution via shell metacharacters in a collection name. Additional, in Mahara before 20.10.4, 21.04.3, and 21.10.1, exporting collections via PDF export could cause code execution

    Published: 2 Nov 2021
    7.5
    High

    CVE-2021-42697

    Last Modified: 21 Nov 2024

    Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote attacker to conduct a Denial of Service attack by sending a User-Agent header with deeply nested comments.

    Published: 2 Nov 2021
    —
    Unknown

    CVE-2019-13776

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: some publications have used this number when they meant to use CVE-2019-13376

    Published: 2 Nov 2021
    —
    Unknown

    CVE-2018-6044

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-16064. Reason: This candidate is a reservation duplicate of CVE-2018-16064. Notes: All CVE users should reference CVE-2018-16064 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 2 Nov 2021
    5.5
    Medium

    CVE-2021-37996

    Last Modified: 21 Nov 2024

    Insufficient validation of untrusted input Downloads in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictions via a malicious file.

    Published: 2 Nov 2021
    6.5
    Medium

    CVE-2021-37995

    Last Modified: 21 Nov 2024

    Inappropriate implementation in WebApp Installer in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially overlay and spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 2 Nov 2021
    6.5
    Medium

    CVE-2021-37994

    Last Modified: 21 Nov 2024

    Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 2 Nov 2021
    8.8
    High

    CVE-2021-37993

    Last Modified: 21 Nov 2024

    Use after free in PDF Accessibility in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 2 Nov 2021
    8.8
    High

    CVE-2021-37992

    Last Modified: 21 Nov 2024

    Out of bounds read in WebAudio in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 2 Nov 2021
    7.5
    High

    CVE-2021-37991

    Last Modified: 21 Nov 2024

    Race in V8 in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 2 Nov 2021
    5.5
    Medium

    CVE-2021-37990

    Last Modified: 21 Nov 2024

    Inappropriate implementation in WebView in Google Chrome on Android prior to 95.0.4638.54 allowed a remote attacker to leak cross-origin data via a crafted app.

    Published: 2 Nov 2021
    6.5
    Medium

    CVE-2021-37989

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Blink in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to abuse content security policy via a crafted HTML page.

    Published: 2 Nov 2021
    8.8
    High

    CVE-2021-37988

    Last Modified: 21 Nov 2024

    Use after free in Profiles in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who convinced a user to engage in specific gestures to potentially exploit heap corruption via a crafted HTML page.

    Published: 2 Nov 2021
    8.8
    High

    CVE-2021-37987

    Last Modified: 21 Nov 2024

    Use after free in Network APIs in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 2 Nov 2021
    8.8
    High

    CVE-2021-37986

    Last Modified: 21 Nov 2024

    Heap buffer overflow in Settings in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to engage with Dev Tools to potentially exploit heap corruption via a crafted HTML page.

    Published: 2 Nov 2021
    8.8
    High

    CVE-2021-37985

    Last Modified: 21 Nov 2024

    Use after free in V8 in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who had convinced a user to allow for connection to debugger to potentially exploit heap corruption via a crafted HTML page.

    Published: 2 Nov 2021
    8.8
    High

    CVE-2021-37984

    Last Modified: 21 Nov 2024

    Heap buffer overflow in PDFium in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 2 Nov 2021
    8.8
    High

    CVE-2021-37983

    Last Modified: 21 Nov 2024

    Use after free in Dev Tools in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 2 Nov 2021
    8.8
    High

    CVE-2021-37982

    Last Modified: 21 Nov 2024

    Use after free in Incognito in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 2 Nov 2021
    9.6
    Critical

    CVE-2021-37981

    Last Modified: 21 Nov 2024

    Heap buffer overflow in Skia in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 2 Nov 2021
    —
    Unknown

    CVE-2021-37960

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 2 Nov 2021
    —
    Unknown

    CVE-2021-30631

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 2 Nov 2021
    7.4
    High

    CVE-2021-37980

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Sandbox in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially bypass site isolation via Windows.

    Published: 2 Nov 2021
    8.8
    High

    CVE-2021-37979

    Last Modified: 21 Nov 2024

    heap buffer overflow in WebRTC in Google Chrome prior to 94.0.4606.81 allowed a remote attacker who convinced a user to browse to a malicious website to potentially exploit heap corruption via a crafted HTML page.

    Published: 2 Nov 2021
    8.8
    High

    CVE-2021-37978

    Last Modified: 21 Nov 2024

    Heap buffer overflow in Blink in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 2 Nov 2021
    8.8
    High

    CVE-2021-37977

    Last Modified: 21 Nov 2024

    Use after free in Garbage Collection in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 2 Nov 2021
    4.3
    Medium

    CVE-2020-15935

    Last Modified: 21 Nov 2024

    A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and below may allow a remote authenticated attacker to retrieve some sensitive information such as users LDAP passwords and RADIUS shared secret by deobfuscating the passwords entry fields.

    Published: 2 Nov 2021