CVE-2021-25282
- EPSS 90.95%
- Veröffentlicht 27.02.2021 05:15:13
- Zuletzt bearbeitet 21.11.2024 05:54:40
An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal.
CVE-2021-25283
- EPSS 10.04%
- Veröffentlicht 27.02.2021 05:15:13
- Zuletzt bearbeitet 21.11.2024 05:54:40
An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks.
CVE-2021-27803
- EPSS 0.34%
- Veröffentlicht 26.02.2021 23:15:11
- Zuletzt bearbeitet 21.11.2024 05:58:35
A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could result in denial of service or other impact (potentially execution of arbitrary code), for an attacke...
CVE-2021-21273
- EPSS 0.39%
- Veröffentlicht 26.02.2021 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:47:54
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, requests to user provided domains were not restricted to...
CVE-2021-21274
- EPSS 0.58%
- Veröffentlicht 26.02.2021 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:47:54
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, a malicious homeserver could redirect requests to their ...
CVE-2020-24455
- EPSS 0.1%
- Veröffentlicht 26.02.2021 03:15:12
- Zuletzt bearbeitet 21.11.2024 05:14:51
Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access. This affects tpm2-tss before 3.0.1 and before 2.4.3.
CVE-2021-21330
- EPSS 0.49%
- Veröffentlicht 26.02.2021 03:15:12
- Zuletzt bearbeitet 21.11.2024 05:48:02
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before version 3.7.4 there is an open redirect vulnerability. A maliciously crafted link to an aiohttp-based web-server could redirect the browser to a differe...
CVE-2021-26701
- EPSS 1.75%
- Veröffentlicht 25.02.2021 23:15:16
- Zuletzt bearbeitet 21.11.2024 05:56:41
.NET Core Remote Code Execution Vulnerability
CVE-2021-20203
- EPSS 0.03%
- Veröffentlicht 25.02.2021 20:15:11
- Zuletzt bearbeitet 21.11.2024 05:46:07
An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest user may use this flaw to cra...
CVE-2021-3406
- EPSS 0.1%
- Veröffentlicht 25.02.2021 20:15:11
- Zuletzt bearbeitet 21.11.2024 06:21:25
A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations.