• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2021-35210
2021-06-29
N/A
6.1 MEDIUM
Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table that will be executed in the browser when the system log is called in the back end.
CVE-2021-3521
2023-02-12
N/A
4.7 MEDIUM
There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary key via a "binding signature." RPM does not check the binding signature of subkeys prior to importing them. If an attacker is able to add or socially engineer another party to add a malicious subkey to a legitimate public key, RPM could wrongly trust a malicious signature. The greatest impact of this flaw is to data integrity. To exploit this flaw, an attacker must either compromise an RPM repository or convince an administrator to install an untrusted RPM or public key. It is strongly recommended to only use RPMs and public keys from trusted sources.
CVE-2021-35209
2021-09-20
N/A
9.8 CRITICAL
An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.x before 9.0.0 Patch 16. The value of the X-Host header overwrites the value of the Host header in proxied requests. The value of X-Host header is not checked against the whitelist of hosts Zimbra is allowed to proxy to (the zimbraProxyAllowedDomains setting).
CVE-2021-35208
2022-04-06
N/A
5.4 MEDIUM
An issue was discovered in ZmMailMsgView.js in the Calendar Invite component in Zimbra Collaboration Suite 8.8.x before 8.8.15 Patch 23. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.
CVE-2021-35207
2021-07-09
N/A
6.1 MEDIUM
An issue was discovered in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.0 before 9.0.0 Patch 16. An XSS vulnerability exists in the login component of Zimbra Web Client, in which an attacker can execute arbitrary JavaScript by adding executable JavaScript to the loginErrorCode parameter of the login url.
CVE-2021-35206
2021-06-24
N/A
6.1 MEDIUM
Gitpod before 0.6.0 allows unvalidated redirects.
CVE-2021-35205
Netscout, Ngeniusone
Airmagnet_enterprise, Cdm_agent_firmware_maintenance_release, Ngenius_client, Ngenius_express_appliance, Ngenius_flow_recorder, Ngenius_infinistream, Ngeniusone, Ngenius_performance_manager, Ngenius_probes, Ngenius_trace_analyzer_integrator
2021-10-04
N/A
5.4 MEDIUM
NETSCOUT Systems nGeniusONE version 6.3.0 build 1196 allows URL redirection in redirector.
CVE-2021-35204
Netscout, Ngeniusone
Airmagnet_enterprise, Cdm_agent_firmware_maintenance_release, Ngenius_client, Ngenius_express_appliance, Ngenius_flow_recorder, Ngenius_infinistream, Ngeniusone, Ngenius_performance_manager, Ngenius_probes, Ngenius_trace_analyzer_integrator
2021-10-04
N/A
5.4 MEDIUM
NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Reflected Cross-Site Scripting (XSS) in the support endpoint.
CVE-2021-35203
Netscout, Ngeniusone
Airmagnet_enterprise, Cdm_agent_firmware_maintenance_release, Ngenius_client, Ngenius_express_appliance, Ngenius_flow_recorder, Ngenius_infinistream, Ngeniusone, Ngenius_performance_manager, Ngenius_probes, Ngenius_trace_analyzer_integrator
2021-10-04
N/A
5.7 MEDIUM
NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Arbitrary File Read operations via the FDSQueryService endpoint.
CVE-2021-35202
Netscout, Ngeniusone
Airmagnet_enterprise, Cdm_agent_firmware_maintenance_release, Ngenius_client, Ngenius_express_appliance, Ngenius_flow_recorder, Ngenius_infinistream, Ngeniusone, Ngenius_performance_manager, Ngenius_probes, Ngenius_trace_analyzer_integrator
2022-07-12
N/A
4.3 MEDIUM
NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Authorization Bypass (to access an endpoint) in FDSQueryService.
« Previous 1 … 7,544 7,545 7,546 7,547 7,548 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE