Search Results (359370 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-40092 1 Squaredup 1 Squaredup 2024-11-21 5.4 Medium
A cross-site scripting (XSS) vulnerability in Image Tile in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via an SVG file.
CVE-2021-40091 1 Squaredup 1 Squaredup 2024-11-21 9.8 Critical
An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654.
CVE-2021-40089 1 Primekey 1 Ejbca 2024-11-21 2.3 Low
An issue was discovered in PrimeKey EJBCA before 7.6.0. The General Purpose Custom Publisher, which is normally run to invoke a local script upon a publishing operation, was still able to run if the System Configuration setting Enable External Script Access was disabled. With this setting disabled it's not possible to create new such publishers, but existing publishers would continue to run.
CVE-2021-40088 1 Primekey 1 Ejbca 2024-11-21 5.4 Medium
An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate to authenticate enrolling clients. The same RA client certificate is used for revocation requests as well. While enrollment enforces multi tenancy constraints (by verifying that the client certificate has access to the CA and Profiles being enrolled against), this check was not performed when authenticating revocation operations, allowing a known tenant to revoke a certificate belonging to another tenant.
CVE-2021-40087 1 Primekey 1 Ejbca 2024-11-21 2.7 Low
An issue was discovered in PrimeKey EJBCA before 7.6.0. When audit logging changes to the alias configurations of various protocols that use an enrollment secret, any modifications to the secret were logged in cleartext in the audit log (that can only be viewed by an administrator). This affects use of any of the following protocols: SCEP, CMP, or EST.
CVE-2021-40086 1 Primekey 1 Ejbca 2024-11-21 2.2 Low
An issue was discovered in PrimeKey EJBCA before 7.6.0. As part of the configuration of the aliases for SCEP, CMP, EST, and Auto-enrollment, the enrollment secret was reflected on a page (that can only be viewed by an administrator). While hidden from direct view, checking the page source would reveal the secret.
CVE-2021-40085 3 Debian, Openstack, Redhat 3 Debian Linux, Neutron, Openstack 2024-11-21 6.5 Medium
An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsmasq via a crafted extra_dhcp_opts value.
CVE-2021-40084 1 Artixlinux 1 Opensysusers 2024-11-21 9.8 Critical
opensysusers through 0.6 does not safely use eval on files in sysusers.d that may contain shell metacharacters. For example, it allows command execution via a crafted GECOS field whereas systemd-sysusers (a program with the same specification) does not do that.
CVE-2021-40083 1 Nic 1 Knot Resolver 2024-11-21 7.5 High
Knot Resolver before 5.3.2 is prone to an assertion failure, triggerable by a remote attacker in an edge case (NSEC3 with too many iterations used for a positive wildcard proof).
CVE-2021-40067 1 Netmotionsoftware 1 Mobility 2024-11-21 6.8 Medium
The access controls on the Mobility read-write API improperly validate user access permissions; this API is disabled by default. If the API is manually enabled, attackers with both network access to the API and valid credentials can read and write data to it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v12.14.
CVE-2021-40066 1 Netmotionsoftware 1 Mobility 2024-11-21 5.3 Medium
The access controls on the Mobility read-only API improperly validate user access permissions. Attackers with both network access to the API and valid credentials can read data from it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v11.76 and Mobility v12.14.
CVE-2021-40065 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
The communication module has a service logic error vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2021-40064 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
There is a heap-based buffer overflow vulnerability in system components. Successful exploitation of this vulnerability may affect system stability.
CVE-2021-40063 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
There is an improper access control vulnerability in the video module. Successful exploitation of this vulnerability may affect confidentiality.
CVE-2021-40062 1 Huawei 2 Emui, Magic Ui 2024-11-21 7.5 High
There is a vulnerability of copying input buffer without checking its size in the video framework. Successful exploitation of this vulnerability may affect availability.
CVE-2021-40061 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
There is a vulnerability of accessing resources using an incompatible type (type confusion) in the Bastet module. Successful exploitation of this vulnerability may affect integrity.
CVE-2021-40060 1 Huawei 2 Emui, Magic Ui 2024-11-21 7.5 High
There is a heap-based buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability may affect availability.
CVE-2021-40059 1 Huawei 2 Emui, Magic Ui 2024-11-21 6.5 Medium
There is a permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect confidentiality.
CVE-2021-40058 1 Huawei 2 Emui, Magic Ui 2024-11-21 7.5 High
There is a heap-based buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability may affect availability.
CVE-2021-40057 1 Huawei 2 Emui, Magic Ui 2024-11-21 7.5 High
There is a heap-based and stack-based buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability may affect availability.