Click to open the Alert Filter

 
Year Month
Severity
Categories
Search by Alert Name
Page(s) : 1 ... 763 764 765 766 767 768 769 770 771 772 [773] 774 775 776 777 778 779 780 781 782 783 ... Result(s) : 43529

Alerts Feed Alerts

DATE NAME CATEGORIES DETAIL
9.8 2021-04-26 CVE-2021-20711 cve Aterm WG2600HS firmware Ver1.5.1 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
9.8 2021-04-26 CVE-2021-25927 cve Prototype pollution vulnerability in 'safe-flat' versions 2.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
9.8 2021-04-26 CVE-2021-25928 cve Prototype pollution vulnerability in 'safe-obj' versions 1.0.0 through 1.0.2 allows an attacker to cause a denial of service and may lead to remote code execution.
9.6 2021-04-26 CVE-2021-21223 cve Integer overflow in Mojo in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a ...
9.6 2021-04-26 CVE-2021-21201 cve Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape v...
9.6 2021-04-26 CVE-2021-21226 cve Use after free in navigation in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape vi...
10 2021-04-26 CVE-2021-29475 cve HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker is able to receive arbitrary files from the file system when exporting a note to...
9.8 2021-04-26 CVE-2021-25839 cve A weak password requirement vulnerability exists in the Create New User function of MintHCM RELEASE 3.0.8, which could lead an attacker to easier password brute-forcing.
9.8 2021-04-26 CVE-2021-26797 cve An access control vulnerability in Hame SD1 Wi-Fi firmware
9.8 2021-04-26 CVE-2021-31646 cve Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote). The affected component is the file forgot_pwd.php - it uses a weak algorithm ...
9.6 2021-04-25 CVE-2021-31761 cve Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature.
9.8 2021-04-25 CVE-2021-31726 cve Akuvox C315 115.116.2613 allows remote command Injection via the cfgd_server service. The attack vector is sending a payload to port 189 (default root 0.0.0.0).
9.8 2021-04-25 CVE-2021-30502 cve The unofficial vscode-ghc-simple (aka Simple Glasgow Haskell Compiler) extension before 0.2.3 for Visual Studio Code allows remote code execution via a crafted workspace configu...
10 2021-04-23 CVE-2021-22205 cve An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which re...
9.4 2021-04-23 CVE-2021-31597 cve The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is...
9.1 2021-04-23 CVE-2021-26291 cve Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malic...
10 2021-04-23 CVE-2021-22893 cve Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration feat...
9.1 2021-04-22 CVE-2020-17563 cve Path Traversal in FeiFeiCMS v4.0 allows remote attackers to delete arbitrary files by sending a crafted HTTP request to " /index.php?s=/admin-tpl-del&id=".
9.8 2021-04-22 CVE-2021-24240 cve The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manual update functionality, leading to an unauthenticated rem...
9.1 2021-04-22 CVE-2020-17564 cve Path Traversal in FeiFeiCMS v4.0 allows remote attackers to delete arbitrary files by sending a crafted HTTP request to the " Admin/DataAction.class.php" component.
Page(s) : 1 ... 763 764 765 766 767 768 769 770 771 772 [773] 774 775 776 777 778 779 780 781 782 783 ... Result(s) : 43529