‼ CVE-2021-32991 ‼
📖 Read
via "National Vulnerability Database".
Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, which may allow an attacker to cause a user to carry out an action unintentionally.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-34066 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in EdgeGallery/developer before v1.0. There is a "Deserialization of yaml file" vulnerability that can allow attackers to execute system command through uploading the malicious constructed YAML file.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-34646 ‼
📖 Read
via "National Vulnerability Database".
Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a random token generation weakness in the reset_and_mail_activation_link function found in the ~/includes/class-wcj-emails-verification.php file. This allows attackers to impersonate users and trigger an email address verification for arbitrary accounts, including administrative accounts, and automatically be logged in as that user, including any site administrators. This requires the Email Verification module to be active in the plugin and the Login User After Successful Verification setting to be enabled, which it is by default.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-33055 ‼
📖 Read
via "National Vulnerability Database".
Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-35634 ‼
📖 Read
via "National Vulnerability Database".
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser<EW>::read_sface() sfh->boundary_entry_objects Sloop_of. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-36370 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked nor displayed. As a result, a user connects to the server without the ability to verify its authenticity.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-3628 ‼
📖 Read
via "National Vulnerability Database".
OpenKM Community Edition in its 6.3.10 version is vulnerable to authenticated Cross-site scripting (XSS). A remote attacker could exploit this vulnerability by injecting arbitrary code via de uuid parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-27020 ‼
📖 Read
via "National Vulnerability Database".
Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-18126 ‼
📖 Read
via "National Vulnerability Database".
Multiple stored cross-site scripting (XSS) vulnerabilities in the Sections module of Indexhibit 2.1.5 allows attackers to execute arbitrary web scripts or HTML.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-35633 ‼
📖 Read
via "National Vulnerability Database".
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser<EW>::read_sface() store_sm_boundary_item() Edge_of.A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-32967 ‼
📖 Read
via "National Vulnerability Database".
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without being authenticated or authorized, which may allow the attacker to log in and use the device with administrative privileges.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-22022 ‼
📖 Read
via "National Vulnerability Database".
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor with administrative access to vRealize Operations Manager API can read any arbitrary file on server leading to information disclosure.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-22027 ‼
📖 Read
via "National Vulnerability Database".
The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack leading to information disclosure.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-33007 ‼
📖 Read
via "National Vulnerability Database".
A heap-based buffer overflow in Delta Electronics TPEditor: v1.98.06 and prior may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-33019 ‼
📖 Read
via "National Vulnerability Database".
A stack-based buffer overflow vulnerability in Delta Electronics DOPSoft Version 4.00.11 and prior may be exploited by processing a specially crafted project file, which may allow an attacker to execute arbitrary code.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-33003 ‼
📖 Read
via "National Vulnerability Database".
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a weak hashing algorithm.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-29630 ‼
📖 Read
via "National Vulnerability Database".
In FreeBSD 13.0-STABLE before n246938-0729ba2f49c9, 12.2-STABLE before r370383, 11.4-STABLE before r370381, 13.0-RELEASE before p4, 12.2-RELEASE before p10, and 11.4-RELEASE before p13, the ggatec daemon does not validate the size of a response before writing it to a fixed-sized buffer allowing a malicious attacker in a privileged network position to overwrite the stack of ggatec and potentially execute arbitrary code.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-38343 ‼
📖 Read
via "National Vulnerability Database".
The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npBulkActions`, `npBulkEdit`, `npListingSort`, and `npCategoryFilter` `admin_post` actions.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-37421 ‼
📖 Read
via "National Vulnerability Database".
Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.📖 Read
via "National Vulnerability Database".
❌ Army Testing Facial Recognition in Child-Care Centers ❌
📖 Read
via "Threat Post".
Army looking for AI to layer over daycare CCTV to boost ‘family quality of life.’📖 Read
via "Threat Post".
Threat Post
Army Testing Facial Recognition in Child-Care Centers
Army looking for AI to layer over daycare CCTV to boost ‘family quality of life.’
❌ HPE Warns Sudo Bug Gives Attackers Root Privileges to Aruba Platform ❌
📖 Read
via "Threat Post".
HPE joins Apple in warning customers of a high-severity Sudo vulnerability.📖 Read
via "Threat Post".
Threat Post
HPE Warns Sudo Bug Gives Attackers Root Privileges to Aruba Platform
HPE joins Apple in warning customers of a high-severity Sudo vulnerability.