Total
34322 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-41599 | 1 Github | 1 Enterprise Server | 2024-11-21 | 8.8 High |
| A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.3 and was fixed in versions 3.0.21, 3.1.13, 3.2.5. This vulnerability was reported via the GitHub Bug Bounty program. | ||||
| CVE-2021-41594 | 1 Rsa | 1 Archer | 2024-11-21 | 6.5 Medium |
| In RSA Archer 6.9.SP1 P3, if some application functions are precluded by the Administrator, this can be bypassed by intercepting the API request at the /api/V2/internal/TaskPermissions/CheckTaskAccess endpoint. If the parameters of this request are replaced with empty fields, the attacker achieves access to the precluded functions. | ||||
| CVE-2021-41590 | 1 Gradle | 1 Enterprise | 2024-11-21 | 5.3 Medium |
| In Gradle Enterprise through 2021.3, probing of the server-side network environment can occur via an SMTP configuration test. The installation configuration user interface available to administrators allows testing the configured SMTP server settings. This test function can be used to identify the listening TCP ports available to the server, revealing information about the internal network environment. | ||||
| CVE-2021-41562 | 1 Snowsoftware | 1 Snow Inventory Agent | 2024-11-21 | 6.1 Medium |
| A vulnerability in Snow Snow Agent for Windows allows a non-admin user to cause arbitrary deletion of files. This issue affects: Snow Snow Agent for Windows version 5.0.0 to 6.7.1 on Windows. | ||||
| CVE-2021-41558 | 1 Set User Project | 1 Set User | 2024-11-21 | 9.8 Critical |
| The set_user extension module before 3.0.0 for PostgreSQL allows ProcessUtility_hook bypass via set_config. | ||||
| CVE-2021-41545 | 1 Siemens | 8 Desigo Dxr2, Desigo Dxr2 Firmware, Desigo Pxc3 and 5 more | 2024-11-21 | 7.5 High |
| A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). When the controller receives a specific BACnet protocol packet, an exception causes the BACnet communication function to go into a “out of work” state and could result in the controller going into a “factory reset” state. | ||||
| CVE-2021-41532 | 1 Apache | 1 Ozone | 2024-11-21 | 5.3 Medium |
| In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access the data from these endpoints. | ||||
| CVE-2021-41526 | 1 Flexera | 1 Revenera Installshield | 2024-11-21 | 7.8 High |
| A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow privilege escalation when invoked ‘repair’ of the MSI which has an InstallScript custom action. | ||||
| CVE-2021-41525 | 1 Flexera | 1 Flexnet Inventory Agent And Beacon | 2024-11-21 | 5.5 Medium |
| An issue related to modification of otherwise restricted files through a locally authenticated attacker exists in FlexNet inventory agent and inventory beacon versions 2020 R2.5 and prior. | ||||
| CVE-2021-41504 | 1 Dlink | 4 Dcs-5000l, Dcs-5000l Firmware, Dcs-932l and 1 more | 2024-11-21 | 8.0 High |
| An Elevated Privileges issue exists in D-Link DCS-5000L v1.05 and DCS-932L v2.17 and older. The use of the digest-authentication for the devices command interface may allow further attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | ||||
| CVE-2021-41395 | 1 Goteleport | 1 Teleport | 2024-11-21 | 6.5 Medium |
| Teleport before 6.2.12 and 7.x before 7.1.1 allows attackers to control a database connection string, in some situations, via a crafted database name or username. | ||||
| CVE-2021-41394 | 1 Goteleport | 1 Teleport | 2024-11-21 | 5.3 Medium |
| Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows alteration of build artifacts in some situations. | ||||
| CVE-2021-41393 | 1 Goteleport | 1 Teleport | 2024-11-21 | 9.8 Critical |
| Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows forgery of SSH host certificates in some situations. | ||||
| CVE-2021-41382 | 1 Plasticscm | 1 Plastic Scm | 2024-11-21 | 7.5 High |
| Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface. | ||||
| CVE-2021-41378 | 1 Microsoft | 12 Windows 10, Windows 10 1809, Windows 10 1909 and 9 more | 2024-11-21 | 7.8 High |
| Windows NTFS Remote Code Execution Vulnerability | ||||
| CVE-2021-41376 | 1 Microsoft | 1 Azure Sphere | 2024-11-21 | 2.3 Low |
| Azure Sphere Information Disclosure Vulnerability | ||||
| CVE-2021-41375 | 1 Microsoft | 1 Azure Sphere | 2024-11-21 | 4.4 Medium |
| Azure Sphere Information Disclosure Vulnerability | ||||
| CVE-2021-41374 | 1 Microsoft | 1 Azure Sphere | 2024-11-21 | 6.7 Medium |
| Azure Sphere Information Disclosure Vulnerability | ||||
| CVE-2021-41373 | 1 Microsoft | 1 Fslogix | 2024-11-21 | 5.5 Medium |
| FSLogix Information Disclosure Vulnerability | ||||
| CVE-2021-41371 | 1 Microsoft | 22 Windows 10, Windows 10 1507, Windows 10 1607 and 19 more | 2024-11-21 | 4.4 Medium |
| Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | ||||