31 Dec 2021 | STAT52 | |
|
30 Dec 2021 | VULN677 | Qnap : Exposure of Sensitive Information in QTS, QuTS hero, and QuTScloud | Systems running
|
30 Dec 2021 | VULN676 | Wireshark 3.6.1, 3.4.11 fixes multiple vulnerabilities | Systems running Wireshark versions prior to
|
30 Dec 2021 | VULN675 | Apache Log4j 2.17.1 fixes remote code execution (RCE) attack CVE-2021-44832 | Systems running log4j-api (maven), log4j-core
|
24 Dec 2021 | STAT51 | |
|
24 Dec 2021 | VULN674 | Apache : Apache HTTP Server 2.4.52 fixes security vulnerabilities | Systems running Apache HTTP Server versions prior
|
24 Dec 2021 | VULN673 | Apache Log4j2 : Improper Input Validation and Uncontrolled Recursion in Apache Log4j2 | Systems running log4j-api (maven), log4j-core
|
21 Dec 2021 | VULN672 | (IBM : There are multiple vulnerabilities in the Apache Log4j used,in IBM(R) QRadar Risk Manager that may allow for remote code execution (RCE)) | Systems running IBM(R) QRadar Risk Manager
|
21 Dec 2021 | VULN671 | Mozilla : Security Vulnerabilities fixed in Thunderbird 91.4.1 | Systems running Thunderbird versions prior to
|
21 Dec 2021 | VULN670 | Xen : frontends vulnerable to backends and Rogue backends can cause DoS of guests | Systems running Xen.
|
20 Dec 2021 | VULN669 | (IBM : Vulnerability in Apache Log4j affects some features of IBM® Db2® On Openshift and IBM® Db2® and Db2 Warehouse® on Cloud Pak for Data (CVE-2021-44228)) | Linux running IBM Db2 On Openshift,
|
20 Dec 2021 | VULN668 | (IBM : Log4j as used in IBM® QRadar User Behavior Analytics application add on to IBM® QRadar SIEM is vulnerable to remote code execution (RCE) (CVE-2021-44228)) | Linux running IBM QRadar SIEM versions prior to
|
20 Dec 2021 | VULN667 | Apache : CVE-2021-44548 Apache Solr information disclosure vulnerability and relation to Apache Log4J CVE-2021-44228 | Systems running Apache Solr versions prior to
|
20 Dec 2021 | VULN666 | MediaWiki : Security and maintenance release 1.35.5 / 1.36.3 / 1.37.1 | Systems running MediaWiki versions prior to 1.35.5,
|
17 Dec 2021 | STAT50 | |
|
17 Dec 2021 | VULN665 | Elastic : Apache Log4j2 Remote Code Execution (RCE) Vulnerability - CVE-2021-44228, CVE-2021-45046 - ESA-2021-31 | Systems running Elasticsearch, Elastic Cloud,
|
17 Dec 2021 | VULN664 | Sulu CMS : Privilege escalation and PHP file inclusion in the Sulu Admin panel | Systems running Sulu (composer) versions prior to
|
17 Dec 2021 | VULN663 | nextjs-auth0 : Open redirect in @auth0/nextjs-auth0 | Systems running nextjs-auth0 (npm) versions prior
|
17 Dec 2021 | VULN662 | vault-cli : vault-cli possible RCE when reading user-defined data | Systems running vault-cli (pip) versions prior to
|
17 Dec 2021 | VULN661 | pear-archetype : Critical vulnerability in log4j may affect generated PEAR projects | Systems running pear-archetype (maven).
|
17 Dec 2021 | VULN660 | Citrix : Citrix Security Advisory for Apache CVE-2021-44228 and CVE-2021-45046 | Systems running Citrix customer-managed
|
17 Dec 2021 | VULN659 | (VMware : VMware Workspace ONE UEM console patches address SSRF vulnerability (CVE-2021-22054)) | Systems running VMware Workspace ONE UEM console
|
17 Dec 2021 | VULN658 | TYPO3 : TYPO3-PSA-2021-003 Mitigation of Cache Poisoning Caused by Untrusted URL Query Parameters | Systems running TYPO3 CMS.
|
17 Dec 2021 | VULN657 | SPIP : Mise à jour CRITIQUE de sécurité sortie de SPIP 4.0.1 et SPIP 3.2.12 | Systems running SPIP versions prior to 4.0.1,
|
16 Dec 2021 | VULN656 | SAP : SAP Security Patch Day - December 2021 | Systems running SAP Business Client, SAP Commerce,
|
16 Dec 2021 | VULN655 | APPLE : APPLE-SA-2021-12-15-5 tvOS 15.2 | tvOS versions prior to 15.2.
|
16 Dec 2021 | VULN654 | APPLE : APPLE-SA-2021-12-15-6 watchOS 8.3 | watchOS versions prior to 8.3.
|
16 Dec 2021 | VULN653 | APPLE : APPLE-SA-2021-12-15-7 Safari 15.2 | Systems running Safari versions prior to 15.2.
|
16 Dec 2021 | VULN652 | Apache Log4j : Incomplete fix for Apache Log4j vulnerability | Systems running log4j-api (maven) versions prior
|
16 Dec 2021 | VULN651 | APPLE : APPLE-SA-2021-12-15 macOS Monterey 12.1, Big Sur 11.6.2 and Security Update 2021-008 Catalina | macOS versions prior to 12.1, 11.6.2.
|
16 Dec 2021 | VULN650 | APPLE : APPLE-SA-2021-12-15-1 iOS 15.2 and iPadOS 15.2 | iOS, iPadOS versions prior to 15.2.
|
15 Dec 2021 | VULN649 | GitLab : GitLab Runner Critical Security Release: 14.5.2, 14.4.2, and 14.3.4 | Systems running GitLab Runner versions prior
|
15 Dec 2021 | VULN648 | Google Chrome : Stable channel 96.0.4664.110 fixes multiple security vulnerabilities | Systems running Google Chrome versions prior
|
15 Dec 2021 | VULN647 | pax-logging-log4j2 : Remote code injection in Log4j (through pax-logging-log4j2) | Systems running pax-logging-log4j2 (maven) versions
|
15 Dec 2021 | VULN646 | Microsoft : Microsoft Security Update Summary for December 14, 2021 | Systems running Apps, SDK Azure Bot Framework, ASP.NET Core et Visual Studio, BizTalk ESB Toolkit...
|
15 Dec 2021 | VULN645 | X.Org : X.Org Security Advisory: December 14, 2021 | Systems running xorg-server versions prior
|
13 Dec 2021 | STAT49 | |
|
13 Dec 2021 | ALER001 | Vulnérabilité dans la bibliothèque de journalisation Apache Log4j CVE-2021-44228 |
|
10 Dec 2021 | VULN644 | Grafana Agent : Instance config inline secret exposure | Systems running grafana/agent (go) versions prior
|
10 Dec 2021 | VULN643 | Apache : CVE-2021-44228 Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints | Systems running Apache Log4j2 versions prior to
|
7 Dec 2021 | STAT48 | |
|
7 Dec 2021 | VULN642 | runc : Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration | Systems running runc (go) versions prior to 1.0.3.
|
7 Dec 2021 | VULN641 | GitLab : GitLab Security Release: 14.5.2, 14.4.4, and 14.3.6 | Systems running GitLab versions prior to 14.5.2,
|
7 Dec 2021 | VULN640 | Zoho : Authentication bypass vulnerability identified and fixed in Desktop Central and Desktop Central MSP | Systems running Zoho Desktop Central,
|
7 Dec 2021 | VULN639 | Apache : CVE-2021-43410 Apache Airavata Django Portal: airavata-django-portal allows CRLF log injection | Systems running Apache Airavata Django Portal
|
7 Dec 2021 | VULN638 | Django : Django security releases issued 3.2.10, 3.1.14, and 2.2.25 | Systems running Django versions prior to 3.2.10,
|
2 Dec 2021 | VULN637 | Mozilla : CVE-2021-43527 Memory corruption via DER-encoded DSA and RSA-PSS signatures | -
|
30 Nov 2021 | VULN636 | Nodebb : Multiple vulnerabilities fixed in Nodebb | -
|
30 Nov 2021 | VULN635 | F-Secure : CVE-2021-40833 Denial-of-Service (DoS) Vulnerability | -
|
30 Nov 2021 | VULN634 | Kaspersky : Vulnerabilities fixed in multiple Kaspersky products | -
|
30 Nov 2021 | VULN633 | Fortinet : FortiClientWindows & FortiClient EMS - Privilege escalation via DLL Hijacking | -
|
26 Nov 2021 | STAT47 | |
|
26 Nov 2021 | VULN632 | US-CERT : Compilers permit Unicode control and homoglyph characters | -
|
25 Nov 2021 | VULN631 | Django-helpdesk : Cross-site Scripting in django-helpdesk | Systems running django-helpdesk (pip) versions
|
25 Nov 2021 | VULN630 | Matrix-synapse : Path traversal when downloading remote media | -
|
25 Nov 2021 | VULN629 | Roundcube : Security updates 1.4.12 and 1.3.17 released | -
|
25 Nov 2021 | VULN628 | Zimbra : NEW Zimbra Patches: 9.0.0 Patch 21 + 8.8.15 Patch 28 | Systems running Zimbra versions prior to
|
25 Nov 2021 | VULN627 | Cisco : Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021 | -
|
25 Nov 2021 | VULN626 | IBM : WebSphere Application Server is vulnerable to a Privilege Escalation vulnerability and affects Content Collector for Email | -
|
25 Nov 2021 | VULN625 | Ruby: Spoofing, Buffer Overrun and DoS vulnerabilities fixed in Rub and gems | Systems running Ruby versions prior to 2.6.9,
|
24 Nov 2021 | VULN624 | Symfony : Multiple vulnerabilities fixed in Symfony | Systems running Symfony.
|
24 Nov 2021 | VULN623 | Aim UI : Arbitrary file reading vulnerability | Systems running aim (pip) versions prior to 3.1.0.
|
24 Nov 2021 | VULN622 | containerd : Ambiguous OCI manifest parsing | Systems running containerd (go) versions prior to
|
24 Nov 2021 | VULN621 | Xen : Multiple vulnerabilities fixed in Xen | -
|
24 Nov 2021 | VULN620 | Apache : Apache JSPWiki Arbitrary file deletion and XSS vulnerabilities | -
|
24 Nov 2021 | VULN619 | (VMware : VMware vCenter Server updates address arbitrary file read and SSRF vulnerabilities (CVE-2021-21980, CVE-2021-22049)) | -
|
24 Nov 2021 | VULN618 | opencontainers : Clarify Content-Type and `mediaType` handling | Systems running OCI Distribution Specification
|
22 Nov 2021 | VULN617 | Apache : Multiple vulnerabilities fixed in Apache Ozone | -
|
22 Nov 2021 | VULN616 | Xen : certain VT-d IOMMUs may not work in shared page table mode | -
|
19 Nov 2021 | STAT46 | |
|
18 Nov 2021 | VULN615 | Apache : CVE-2021-42250 Apache Superset: Possible log injection | -
|
18 Nov 2021 | VULN614 | Google Chrome : Multiple vulnerabilities fixed in Chrome 96.0.4664.45 | Systems running Chrome versions prior to
|
18 Nov 2021 | VULN613 | Drupal : Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2021-011 | Systems running Drupal core versions prior to
|
18 Nov 2021 | VULN612 | CKEditor 4 : Vulnerabilities allowing to execute arbitrary JavaScript code | -
|
18 Nov 2021 | VULN611 | Cisco : Multiple vulnerabilities fixed in Cisco Common Services Platform | -
|
16 Nov 2021 | VULN610 | Grafana : Fine-grained access control enables organization admins to create/modify/delete user roles in other organization | Systems running Grafana versions versions prior to
|
16 Nov 2021 | VULN609 | rails_multisite : Secure/signed cookies share secrets between sites in a multi-site application | -
|
16 Nov 2021 | VULN608 | Moodle : CVE-2021-26558: Multiple vulnerabilities fixed in Moodle 3.11.4, 3.10.8 and 3.9.11 | -
|
16 Nov 2021 | VULN607 | Ruby : CVE-2021-41817 Regular Expression Denial of Service Vunlerability of Date,Parsing Methods | -
|
12 Nov 2021 | VULN606 | Apache : CVE-2021-26558: Apache ShardingSphere-UI Deserialization of Untrusted Data | Systems running Apache ShardingSphere-UI versions 4.1.1 and later, versions prior to 5.0.0.
|
12 Nov 2021 | VULN605 | TYPO3 : Vulnerabilities fixed in multiple TYPO3 extensions | Systems running jobfair for TYPO3 versions prior to 1.0.13, 2.0.2, "pixx.io...
|
12 Nov 2021 | VULN604 | Jenkins : Jenkins Security Advisory 2021-11-12 | Systems running Active Choices Plugin; OWASP Dependency-Check Plugin...
|
12 Nov 2021 | VULN603 | Apache : CVE-2021-43350 Apache Traffic Control: LDAP filter injection ,vulnerability in Traffic Ops | Systems running Apache Traffic Control versions prior to 6.0.1, 5.1.4.
|
12 Nov 2021 | VULN602 | Apache : CVE-2021-4197 Apache Superset Credentials leak | Systems running Apache Superset versions prior to 1.3.2.
|
12 Nov 2021 | VULN601 | FreeRDP : Vulnerabiities in FreeRDP allow out of bounds write to memory | Systems running FreeRDP versions prior to 2.4.1.
|
12 Nov 2021 | VULN600 | VMware : VMware Tanzu Application Service for VMs updates address a ,denial-of-service vulnerability (CVE-2021-22101) | Systems running VMware Tanzu Application Service for VMs versions prior to 2.12.1, 2.11.8, 2.10.20, 2.9.28, 2.7.40.
|
10 Nov 2021 | VULN599 | (VMware : VMware vCenter Server updates address a privilege escalation vulnerability (CVE-2021-22048)) | -
|
10 Nov 2021 | VULN598 | Citrix : Citrix Application Delivery Controller, Citrix Gateway, and Citrix SD-WAN WANOP Edition appliance Security Update | Systems running Citrix ADC and Citrix Gateway
|
10 Nov 2021 | VULN597 | Samba : Multiple Security Vulnerabilities fixed in Samba 4.15.2, 4.14.10 and 4.13.14 | -
|
10 Nov 2021 | VULN596 | Adobe : Security Update Available for Adobe InCopy APSB21-110 | Windows, macOS running Adobe InCopy versions prior
|
10 Nov 2021 | VULN595 | Adobe : Security hotfix available for RoboHelp Server  APSB21-87 | Systems running Adobe RoboHelp Server versions
|
10 Nov 2021 | VULN594 | Microsoft : Microsoft Security Update Summary for November 9, 2021 | Systems running Microsoft 3D Viewer,
|
5 Nov 2021 | STAT44 | |
|
5 Nov 2021 | VULN593 | Nagios XI : Multiple Security Vulnerabilities fixed in 5.8.7 | Systems running Nagios XI versions prior to 5.8.7.
|
5 Nov 2021 | VULN592 | Jenkins : Jenkins Security Advisory 2021-11-04 | Systems running Jenkins (core) versions prior to
|
4 Nov 2021 | VULN591 | Jupyter : Stored XSS in Jupyter nbdime | Systems running Jupyter nbdime versions prior to
|
4 Nov 2021 | VULN590 | Grafana : XSS vulnerability allowing arbitrary JavaScript execution | Systems running Grafana versions prior to 8.2.3.
|
4 Nov 2021 | VULN589 | Mozilla : Security Vulnerabilities fixed in Thunderbird 91.3 | Systems running Thunderbird versions prior to 91.3,
|
4 Nov 2021 | VULN588 | Atlassian : Multiple Products Security Advisory - Unrendered unicode bidirectional override characters - CVE-2021-42574 | Systems running Bamboo Server and Data Center
|
4 Nov 2021 | VULN587 | Cisco : Cisco Security Advisories Published on November 03, 2021 | Systems running Cisco Policy Suite,
|
3 Nov 2021 | VULN586 | TinyMCE : Cross-site scripting vulnerability in TinyMCE plugins | Systems running tinymce versions prior to 5.10.0.
|
3 Nov 2021 | VULN585 | Mozilla : Security Vulnerabilities fixed in Firefox ESR 91.3 and 94 | Systems running Firefox versions prior to ESR 91.3,
|
3 Nov 2021 | VULN584 | Apache : Apache Traffic Server is vulnerable to various smuggle, DOS, and validation attacks | Systems running Apache Traffic Server versions
|
3 Nov 2021 | VULN583 | Apache : CVE-2021-27644: Apache DolphinScheduler DolphinScheduler mysql jdbc connector parameters deserialize remote code execution | Systems running Apache DolphinScheduler versions
|
3 Nov 2021 | VULN582 | Apache : CVE-2021-41973 Apache MINA HTTP listener DOS | Systems running Apache MINA versions prior to
|
29 Oct 2021 | STAT43 | |
|
29 Oct 2021 | VULN581 | Lakefs : Improper Access Control in S3 copy-object, and API restore-refs,dump-refs, get-range, get-metarange | Systems running Lakefs versions prior to 0.53.1.
|
29 Oct 2021 | VULN580 | JupyterHub : Improper Access Control in jupyterhub-firstuseauthenticator | Systems running jupyterhub-firstuseauthenticator
|
29 Oct 2021 | VULN579 | GitLab : GitLab Security Release:14.4.1, 14.3.4, and 14.2.6 | Systems running GitLab versions prior to 14.4.1,
|
29 Oct 2021 | VULN578 | (Uyuni : Security bugfix for CVE-2021-40348 (Uyuni Server)) | Systems running Uyuni versions prior to 2021.11.
|
29 Oct 2021 | VULN577 | Google : Chrome 95.0.4638.69 fix currently exploited Zero-Day vulnerabilities | Systems running Google Chrome versions prior to
|
28 Oct 2021 | VULN576 | Cisco : Multiple vulnerabilities fixed in Cisco ASA, FTD, FMC and UTD Software | Systems running Cisco ASA Software,
|
28 Oct 2021 | VULN575 | BIND : CVE-2021-25219 Lame cache can be abused to severely degrade resolver performance | Systems running BIND versions prior to 9.11.36,
|
28 Oct 2021 | VULN574 | Dask : Remote code execution in Dask | Systems running Dask (python-dask) versions
|
27 Oct 2021 | VULN573 | Adobe : Security Updates Available for Adobe XMP Toolkit SDK APSB21-108 | Systems running Adobe XMP Toolkit SDK versions
|
27 Oct 2021 | VULN572 | Adobe : Security Updates Available for Adobe Premiere Pro APSB21-100 | Systems running Adobe Premiere Pro versions
|
27 Oct 2021 | VULN571 | Adobe : Security Updates Available for Adobe Character Animator APSB21-95 | Systems running Adobe Character Animator versions
|
27 Oct 2021 | VULN570 | Adobe : Security Updates Available for Adobe Prelude APSB21-96 | Systems running Adobe Prelude versions prior to
|
27 Oct 2021 | VULN569 | Adobe : Security Updates Available for Adobe Bridge | APSB21-94 | Systems running Security Updates Available for
|
27 Oct 2021 | VULN568 | Adobe : Security updates available for Adobe Premiere Elements  APSB21-106 | Systems running Adobe Premiere Elements versions
|
27 Oct 2021 | VULN567 | Adobe : Security Update Available for Adobe InDesign APSB21-107 | Systems running Adobe InDesign versions prior to
|
27 Oct 2021 | VULN566 | Adobe : Security updates available for Adobe Photoshop APSB21-109 | Systems running Adobe Photoshop versions prior to
|
27 Oct 2021 | VULN565 | Adobe : Security Updates Available for Adobe Illustrator APSB21-98 | Systems running Adobe Illustrator versions prior to
|
27 Oct 2021 | VULN564 | APPLE : APPLE-SA-2021-10-26-7 tvOS 15.1 | tvOS versions prior to 15.1.
|
27 Oct 2021 | VULN563 | APPLE : APPLE-SA-2021-10-26-6 watchOS 8.1 | watchOS versions prior to 8.1.
|
27 Oct 2021 | VULN562 | APPLE : APPLE-SA-2021-10-26-5 Security Update 2021-007 Catalina | macOS Catalina.
|
27 Oct 2021 | VULN561 | APPLE : macOS Monterey 12.0.1 and Big Sur 11.6.1 | macOS versions prior to 12.0.1, 11.6.1.
|
27 Oct 2021 | VULN560 | APPLE: iOS and iPadOS 15.1 and 14.8.1 | iOS, iPadOS versions prior to 15.1, 14.8.1.
|
27 Oct 2021 | VULN559 | WebKit : WebKitGTK and WPE WebKit Security Advisory | Systems running WebKitGTK, WPE WebKit versions
|
27 Oct 2021 | VULN558 | jquery-ui : Multiple XSS vulnerabilities fixed | Systems running Redmine versions prior to 1.13.0.
|
26 Oct 2021 | VULN557 | (Redmine : Redmine 4.2.3 and 4.1.5 released (security fix)) | Systems running Redmine versions prior to 4.2.3,
|
26 Oct 2021 | VULN556 | TinyMCE : Cross-site scripting vulnerability in TinyMCE | Systems running TinyMCE versions prior to 5.9.0.
|
26 Oct 2021 | VULN555 | ua-parser-js (npm) : Embedded malware in ua-parser-js | Systems running ua-parser-js for NPM versions
|
26 Oct 2021 | VULN554 | Docker CLI : Docker CLI leaks private registry credentials to registry-1.docker.io | Systems running Docker CLI versions prior to
|
22 Oct 2021 | STAT42 | |
|
22 Oct 2021 | VULN553 | Kubernetes : CVE-2021-25742 Ingress-nginx custom snippets allows retrieval of ingress-nginx serviceaccount token and secrets across all namespaces | Systems running ingress-nginx versions prior to
|
22 Oct 2021 | VULN552 | Apache : CVE-2021-38294 Apache Storm Shell Command Injection and Unsafe Pre-Authentication Deserialization Vulnerability | Systems running Apache Storm versions prior to
|
21 Oct 2021 | VULN551 | shell-quote : shell-quote package for Node.js vulnerability allows command injection | Systems running shell-quote for Node.js versions
|
21 Oct 2021 | VULN550 | Cisco : Cisco Security Advisories Published on October 20, 2021 | Standalone IOS XE SD-WAN Software,
|
21 Oct 2021 | VULN549 | Discourse : RCE via malicious SNS subscription payload | Systems running Discourse versions prior to 2.7.9,
|
21 Oct 2021 | VULN548 | Mailman : Mailman 2.1 security release | Systems running Mailman versions prior to 2.1.
|
20 Oct 2021 | VULN547 | Tenable : Stand-alone Security Patch Available for Tenable.sc versions 5.16.0 to 5.19.1: Patch 202110.1 | Systems running Tenable.sc versions up to and
|
20 Oct 2021 | VULN546 | Google : Google Chrome 95.0.4638.54 fixes multiple vulnerabilities | Systems running Google Chrome versions prior to
|
20 Oct 2021 | VULN545 | (VMware : VMware vRealize Operations Tenant App update addresses Information Disclosure Vulnerability (CVE-2021-22034)) | Systems running VMware vRealize Operations Tenant
|
20 Oct 2021 | VULN544 | October : October 2021 Critical Patch Update Released | Systems running Oracle Database Server,
|
19 Oct 2021 | VULN543 | Go : Go 1.17.2 and Go 1.16.9 are released | Systems running Go versions prior to 1.17.2,
|
19 Oct 2021 | VULN542 | strongSwan : Denial-of-service vulnerabilities fixed in StrongSwan | Systems running StrongSwan versions prior to
|
18 Oct 2021 | VULN541 | Apache : Apache Superset Possible SQL Injection and XSS vulnerabilities | Systems running Apache Superset versions prior to
|
18 Oct 2021 | VULN540 | LibreOffice : Multiple vulnerabilities fixed in LibreOffice | Systems running LibreOffice versions prior to
|
18 Oct 2021 | STAT41 | |
|
15 Oct 2021 | VULN539 | IBM : Kernel as used by IBM QRadar Network Packet Capture contains multiple vulnerabilities | Systems running IBM QRadar Network Packet Capture
|
15 Oct 2021 | VULN538 | Palo Alto : CVE-2020-1968 PAN-OS Impact of the Raccoon Attack Vulnerability CVE-2020-1968 | PAN-OS versions 8.1, 9.0, 9.1.
|
15 Oct 2021 | VULN537 | Palo Alto : Security update for Adobe Acrobat and Reader APSB21-104 | Windows, Universal Windows Platform running
|
15 Oct 2021 | VULN536 | Apache : CVE-2021-42340 Denial of Service in Apache Tomcat | Systems running Apache Tomcat versions prior to
|
13 Oct 2021 | VULN535 | Adobe : Security update for Adobe Acrobat and Reader APSB21-104 | Systems running Adobe Acrobat, Adobe Reader
|
13 Oct 2021 | VULN534 | SAP : SAP Security Patch Day – October 2021 | Systems running SAP Business Client,
|
13 Oct 2021 | VULN533 | Microsoft : Microsoft Security Update Summary for October 12, 2021 | Systems running .NET Core, Visual Studio,
|
13 Oct 2021 | VULN532 | (VMware : VMware vRealize Log Insight updates address CSV injection vulnerability (CVE-2021-22035)) | Systems running VMware vRealize Log Insight
|
13 Oct 2021 | VULN531 | (VMware : VMware vRealize Orchestrator update addresses open redirect vulnerability (CVE-2021-22036)) | Systems running VMware vRealize Orchestrator
|
13 Oct 2021 | VULN530 | (VMware : VMware vRealize Operations update addresses SSRF Vulnerability (CVE-2021-22033)) | Systems running vRealize Operations versions prior
|
13 Oct 2021 | VULN529 | Flatpak : CVE-2021-41133 Sandbox bypass via recent VFS-manipulating syscalls | Systems running Flatpak versions prior to 1.10.5,
|
12 Oct 2021 | VULN528 | Apache : CVE-2021-38295: Apache CouchDB Privilege Escalation | Systems running Apache CouchDB versions prior to
|
12 Oct 2021 | VULN527 | APPLE : APPLE-SA-2021-10-11-1 iOS 15.0.2 and iPadOS 15.0.2 | iOS, iPadOS versions prior to 15.0.2.
|
8 Oct 2021 | STAT40 | |
|
8 Oct 2021 | VULN526 | Google : Google Chrome versions 94.0.4606.81 fix multiple vulnerabilities | Systems running Google Chrome versions prior to
|
8 Oct 2021 | VULN525 | (Apache : CVE-2021-42013 Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)) | Systems running Apache HTTP Server versions 2.4.49,
|
8 Oct 2021 | VULN524 | Apache : Apache OpenOffice 4.1.11 fix multiple vulnerabilities | Systems running Apache OpenOffice versions pprior
|
7 Oct 2021 | VULN523 | Cisco : Cisco Security Advisories Published on October 06, 2021 | Systems running Cisco AsyncOS for Cisco WSA,
|
7 Oct 2021 | VULN522 | Jenkins : Jenkins Security Advisory 2021-10-06 | Systems running Jenkins (core) versions prior to
|
6 Oct 2021 | VULN521 | Fortinet : FortiSDNConnector - Credential leak | Systems running FortiSDNConnector versions prior to
|
6 Oct 2021 | VULN520 | Fortinet : FortiSandbox - Buffer overflow due to use of size of source buffer in libc safe functions | Systems running FortiSandbox versions prior to
|
6 Oct 2021 | VULN519 | Fortinet : FortiWebManager - Injection vulnerabilities | Systems running FortiWebManager versions prior to
|
6 Oct 2021 | VULN518 | Fortinet : Session cookie does not expire after logout and Directory Traversal vulnerability | Systems running FortiClientEMS versions prior to
|
6 Oct 2021 | VULN517 | Fortinet : FortiAnalyzer & FortiManager vulnerabilities fixed | Systems running FortiAnalyzer versions prior to
|
6 Oct 2021 | VULN516 | Squid : Out-Of-Bounds memory access in WCCPv2 and Improper Certificate Validation in TLS | Systems running Squid versions prior to 4.17, 5.2.
|
6 Oct 2021 | VULN515 | Node.js : October 12th 2021 Security Releases | Systems running Node.js.
|
6 Oct 2021 | VULN514 | Xen : PCI devices with RMRRs not deassigned correctly | Systems running Xen versions from 4.4 onward.
|
6 Oct 2021 | VULN513 | Grafana : Snapshot authentication bypass | Systems running Grafana versions prior to 7.5.11,
|
5 Oct 2021 | VULN512 | OpenSSH :OpenSSH 8.8 fix security vulnerabilities | Systems running OpenSSH versions prior to 8.8.
|
5 Oct 2021 | VULN511 | Mozilla : Security Vulnerabilities fixed in Firefox ESR 91.2, ESR 78.15, 93 | Systems running Firefox versions ESR 91.2,
|
5 Oct 2021 | VULN510 | Apache : Apache HTTP Server Path traversal, file disclosure vulnerability and null pointer dereference | Systems running Apache HTTP Server versions up to
|
5 Oct 2021 | VULN509 | TYPO3 : HTTP Host Header Injection and Cross-Site-Request-Forgery fixed | Systems running TYPO3 CMS versions prior to 11.5.0.
|
5 Oct 2021 | VULN508 | Containerd : Insufficiently restricted permissions on container root and plugin directories | Systems running containerd versions prior to
|
5 Oct 2021 | VULN507 | Moby : Vulnerabilities fixed in Moby (Docker Engine) 20.10.9 | Systems running Moby (Docker Engine) versions prior
|
4 Oct 2021 | VULN506 | Google Chrome : Chrome 94.0.4606.71 addresses multiple security vulnerabilities | Systems running Chrome versions prior to
|
4 Oct 2021 | VULN505 | GitLab : GitLab Security Release 14.3.1, 14.2.5, and 14.1.7 | Systems running GitLab versions prior to 14.3.1,
|
4 Oct 2021 | VULN504 | MediaWiki : Security and maintenance release: 1.31.16 / 1.35.4 / 1.36.2 | Systems running MediaWiki versions prior to
|
1 Oct 2021 | STAT39 | |
|
30 Sep 2021 | VULN503 | Apache : CVE-2021-41616 Apache ddlutils 1.0 readobject vulnerability | Systems running Apache ddlutils versions 1.0.
|
27 Sep 2021 | STAT38 | |
|
23 Sep 2021 | VULN502 | Cisco : Cisco Security Advisories Published on September 22, 2021 | Cisco IOS XE, Cisco IOS, Cisco IOS XR,
|
22 Sep 2021 | VULN501 | Google : Chrome 94.0.4606.54 addresses multiple security vulnerabilities | Systems running Chrome versions prior to
|
22 Sep 2021 | VULN500 | Apache : CVE-2021-38153 Timing Attack Vulnerability for Apache Kafka Connect and Clients | Systems running Apache Kafka versions 2 prior to
|
22 Sep 2021 | VULN499 | VMware : VMware vCenter Server updates address multiple security vulnerabilities | Systems running vCenter Server,
|
21 Sep 2021 | VULN498 | Moodle : Multiple vulnerabilities fixed in Moodle 3.11.3, 3.10.7 and 3.9.10 | Systems running Moodle versions prior to 3.11.3,
|
21 Sep 2021 | VULN497 | APPLE : APPLE-SA-2021-09-20-3 tvOS 15 | tvOS running versions prior to 15.
|
21 Sep 2021 | VULN496 | APPLE : APPLE-SA-2021-09-20-2 watchOS 8 | watchOS versions prior to 8.
|
21 Sep 2021 | VULN495 | APPLE : APPLE-SA-2021-09-20-4 Xcode 13 | Systems running Xcode versions prior to 13.
|
21 Sep 2021 | VULN494 | APPLE : APPLE-SA-2021-09-20-10 iTunes 12.12 for Windows | Windows running iTunes versions prior to 12.12,
|
21 Sep 2021 | VULN493 | APPLE : APPLE-SA-2021-09-20-5 Safari 15 | Systems running Safari versions prior to 15.
|
21 Sep 2021 | VULN492 | APPLE : APPLE-SA-2021-09-20-1 iOS 15 and iPadOS 15 | iOS, iPadOS versions prior to 15.
|
20 Sep 2021 | VULN491 | WebKit : WebKitGTK and WPE WebKit Security Advisory WSA-2021-0005 | Systems running WebKitGTK, WPE WebKit versions
|
17 Sep 2021 | VULN490 | Apache : Apache HTTPd 2.4.49 fix multiple vulbnerabilities | Systems running Apache HTTPd versions prior to
|
17 Sep 2021 | VULN489 | (Apache : [CVE-2021-40690] - Apache Santuario - Bypass of the secureValidation property (CVE-2021-40690)) | Systems running Apache Santuario versions prior to
|
20 Sep 2021 | STAT37 | |
|
17 Sep 2021 | VULN488 | Apache : CVE-2021-39239 Apache Jena: XML External Entity (XXE) vulnerability | Systems running Apache Jena versions prior to
|
17 Sep 2021 | VULN487 | Apache : Apache Shiro specially crafted HTTP request may cause an authentication bypass | Systems running Apache Shiro versions prior to
|
17 Sep 2021 | VULN486 | GLPI : GLPI 9.5.6 fixes multiple security vulnerabilities | Systems running GLPI versions prior to 9.5.6.
|
16 Sep 2021 | VULN485 | Drupal : Entity Embed - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2021-028 | Systems running Entity Embed for Drupal versions
|
16 Sep 2021 | VULN484 | Drupal : GraphQL - Moderately critical - Access bypass - SA-CONTRIB-2021-029 | Systems running GraphQL for Drupal versions 8.x-4.x
|
16 Sep 2021 | VULN483 | Drupal : Drupal core multiple Security Vulnerabilities | Systems running Drupal core versions prior to
|
16 Sep 2021 | VULN482 | Kubernetes : Security Vulnerabilities in Kubernetes and kube-apiserver | Systems running Kubernetes versions prior to
|
16 Sep 2021 | VULN481 | Apache : CVE-2021-41079 Apache Tomcat DoS | Systems running Apache Tomcat versions prior to
|
15 Sep 2021 | VULN480 | Adobe : Security Updates Available for Adobe Genuine Service APSB21-81 | Windows, macOS running Adobe Genuine Service
|
15 Sep 2021 | VULN479 | Adobe : Security updates available for Adobe Premiere Elements APSB21-78 | Windows, macOS running Adobe Premiere Elements
|
15 Sep 2021 | VULN478 | Adobe : Security Updates Available for Adobe SVG-Native-Viewer APSB21-72 | Linux running Adobe SVG-Native-Viewer.
|
15 Sep 2021 | VULN477 | Adobe : Security Updates Available for Adobe XMP Toolkit SDK APSB21-85 | Systems running Adobe XMP Toolkit SDK versions
|
15 Sep 2021 | VULN476 | Adobe : Security updates available for Adobe Photoshop Elements  APSB21-77 | Windows, macOS running Adobe Photoshop Elements
|
15 Sep 2021 | VULN475 | Adobe : Security updates available for Adobe Experience Manager APSB21-82 | Systems running Adobe Experience Manager versions
|
15 Sep 2021 | VULN474 | Adobe : Security Updates Available for Adobe Digital Editions APSB21-80 | MacOS running Adobe Digital Editions versions prior
|
15 Sep 2021 | VULN473 | Adobe : Security Updates Available for Adobe Framemaker | APSB21-74 | Windows running Adobe Framemaker versions prior to
|
15 Sep 2021 | VULN472 | Adobe : Security Updates Available for Adobe Premiere Pro APSB21-67 | Windows, macOS running Adobe Premiere Pro versions
|
15 Sep 2021 | VULN471 | Adobe : Security update available for Adobe Creative Cloud Desktop Application APSB21-76 | -
|
15 Sep 2021 | VULN470 | Adobe : Security Update Available for Adobe InCopy APSB21-71 | Windows, macOS running Adobe InCopy versions prior
|
15 Sep 2021 | VULN469 | Adobe : Security updates available for Adobe Photoshop APSB21-84 | Systems running Adobe Photoshop versions prior to
|
15 Sep 2021 | VULN468 | SAP : SAP Security Patch Day – September 2021 | Systems running SAP Business Client,
|
15 Sep 2021 | VULN467 | Adobe : Security update available for Adobe Acrobat and Reader APSB21-55 | Systems running Adobe Acrobat, Adobe Reader
|
15 Sep 2021 | VULN466 | Adobe : Security updates available for Adobe ColdFusion APSB21-75 | Systems running Adobe ColdFusion versions prior to
|
15 Sep 2021 | VULN465 | Citrix : Citrix ShareFile Storage Zones Controller Security Update | Systems running Citrix ShareFile storage zones
|
15 Sep 2021 | VULN464 | curl : Multiple vulnerabilities fixed in curl | Systems running curl versions from 7.20.0 and prior
|
15 Sep 2021 | VULN463 | Microsoft : Microsoft Security Update Summary for September 14, 2021 | Systems running Azure Sphere,
|
14 Sep 2021 | VULN462 | Google : Google Chrome 93.0.4577.82 fix multiple vulnerabilities | Systems running Google Chrome versions prior to
|
14 Sep 2021 | VULN461 | Apache : (RCE) and (XXE) injection vulnerabilities | Systems running Apache Any23 versions prior to 2.5.
|
14 Sep 2021 | VULN460 | APPLE : watchOS 7.6.2 | Systems running watchOS versions prior to 7.6.2.
|
14 Sep 2021 | VULN459 | APPLE : iOS 14.8 and iPadOS 14.8 | iOS, iPadOS versions prior to 14.8.
|
14 Sep 2021 | VULN458 | APPLE : Safari 14.1.2* | Systems running Safari versions prior to
|
14 Sep 2021 | VULN457 | APPLE : macOS Big Sur 11.6 and Security Update 2021-005 Catalina | macOS Big Sur versions prior to 11.6,
|
10 Sep 2021 | STAT36 | |
|
9 Sep 2021 | VULN456 | Apache Airflow : CVE-2021-38540 Apache Airflow Variable Import endpoint missed authentication check | Systems running Apache Airflow versions 2 prior to
|
9 Sep 2021 | VULN455 | Openstack : OSSA-2021-006 Routes middleware memory leak for nonexistent controllers | Systems running Openstack Neutron versions prior to
|
9 Sep 2021 | VULN454 | WordPress : WordPress 5.8.1 Security and Maintenance Release | Systems running WordPress versions prior to 5.8.1.
|
9 Sep 2021 | VULN453 | Citrix : CTX325319,Citrix Hypervisor Security Update | Systems running Citrix Hypervisor.
|
9 Sep 2021 | VULN452 | Cisco : Cisco Security Advisories Published on September 08, 2021 | Cisco IOS XR,
|
8 Sep 2021 | VULN451 | Mozilla : Security Vulnerabilities fixed in Thunderbird 91.1 and 78.14 | Systems running Thunderbird versions prior to 91.1,
|
8 Sep 2021 | VULN450 | Fortinet : FortiAuthenticator - Command injection in CLI | Systems running FortiAuthenticator versions prior
|
8 Sep 2021 | VULN449 | Fortinet : FortiClient Linux - Command injection vulnerability | FortiClient Linux versions prior to 6.2.9, 6.4.3.
|
8 Sep 2021 | VULN448 | Fortinet : FortiManager Arbitrary Code Execution and improper authentication vulnerabilities fixed | Systems running FortiManager versions prior to
|
8 Sep 2021 | VULN447 | Fortinet : FortiSandbox Denial of Service and Information Disclosure Vulnerabilities | Systems running FortiSandbox versions prior to
|
8 Sep 2021 | VULN446 | Fortinet : Multiple Vulnerabilities fixed in FortiOS | FortiOS versions prior to 7.0.1, 6.4.7, 6.2.3,
|
8 Sep 2021 | VULN445 | Fortinet : OS command injections and stack-based buffer overflow vulnerabilities fixed | Systems running FortiWeb versions prior to 6.4.0,
|
8 Sep 2021 | VULN444 | Xen : Another race in XENMAPSPACE_grant_table handling | Systems running Xen.
|
7 Sep 2021 | VULN443 | Cisco : Cisco Identity Services Engine Cross-Site Scripting Vulnerability | Systems running Cisco Identity Services Engine
|
7 Sep 2021 | VULN442 | Cisco : Cisco Prime Collaboration Provisioning Cross-Site Scripting Vulnerability | Systems running Cisco Prime Collaboration
|
7 Sep 2021 | VULN441 | Cisco : Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Information Disclosure Vulnerability | Systems running Cisco Prime Infrastructure versions
|
7 Sep 2021 | VULN440 | Cisco : Cisco Enterprise NFV Infrastructure Software Authentication Bypass Vulnerability | Systems running Cisco Enterprise NFVIS versions
|
7 Sep 2021 | VULN439 | Google Chrome : Google Chrome versions 93.0.4577.63 fixes multiple security vulnerabilities | Systems running Google Chrome versions prior to
|
7 Sep 2021 | VULN438 | Aruba : Multiple vulnerabilities fixed in Aruba products | ArubaOS versions prior to 6.4.4.25, 6.5.4.20,
|
7 Sep 2021 | VULN437 | GitLab : GitLab Security Release 14.2.2, 14.1.4, and 14.0.9 | Systems running GitLab versions prior to 14.2.2,
|
7 Sep 2021 | VULN436 | OTRS : OTRS Security Advisory 2021-18 | Systems running OTRS versions prior to 7.0.29.
|
7 Sep 2021 | VULN435 | Mozilla : Multiple vulnerabilities in Firefox ESR 91.1, 78.14, 92 | Systems running Mozilla Firefox versions prior to
|
7 Sep 2021 | VULN434 | Node.js : August 31 2021 Security Releases | Systems running Node.js versions prior to
|
7 Sep 2021 | VULN433 | Apache : Apache Zeppelin Command injection, permissions bypass and XSS vulnerabilities fixed | Systems running Apache Zeppelin versions prior to
|
7 Sep 2021 | VULN432 | Openstack : OSSA-2021-005 Arbitrary dnsmasq reconfiguration via extra_dhcp_opts | Systems running Openstack Neutron versions prior to
|
7 Sep 2021 | VULN431 | Jenkins : Jenkins Security Advisory 2021-08-31 | Systems running Jenkins (core),
|
3 Sep 2021 | STAT35 | |
|
27 Aug 2021 | STAT34 | |
|
27 Aug 2021 | VULN430 | libssh : Possible heap-buffer overflow when rekeying | Systems running libssh versions prior to 0.9.6.
|
27 Aug 2021 | VULN429 | Node.js : August 31 2021 Security Releases | Systems running Node.js.
|
27 Aug 2021 | VULN428 | fetchmail : fetchmail-SA-2021-02 STARTTLS session encryption bypassing | Systems running fetchmail versions prior to 6.4.22,
|
26 Aug 2021 | VULN427 | Nbgitpuller : Code injection in nbgitpuller | Systems running nbgitpuller (pip) versions prior
|
26 Aug 2021 | VULN426 | Binderhub : remote code execution via git repo provider | Systems running binderhub (helm) versions prior
|
26 Aug 2021 | VULN425 | (VMware : VMware vRealize Log Insight updates address Cross Site Scripting (XSS) vulnerability (CVE-2021-22021)) | Systems running VMware vRealize Log Insight,
|
26 Aug 2021 | VULN424 | Cisco : Cisco Security Advisories Published on August 25, 2021 | Systems running Cisco Application Policy
|
25 Aug 2021 | VULN423 | OpenSSL : SM2 Decryption Buffer Overflow and Read buffer overruns vulnerabilities fixed | Systems running OpenSSL versions prior to 1.1.1l,
|
25 Aug 2021 | VULN422 | Apache : CVE-2021-33191 Apache NiFi - MiNiFi C++: MiNiFi CPP arbitrary script execution is possible on the agent's host machine through the c2 protocol | Systems running Apache NiFi MiNiFi C++ versions
|
25 Aug 2021 | VULN421 | Joomla! : Core - Insufficient access control for com_media deletion endpoint | Systems running Joomla! versions prior to 4.0.1.
|
25 Aug 2021 | VULN420 | Xen : Multiple security vulnerabilities fixed in Xen | Systems running Xen.
|
25 Aug 2021 | VULN419 | VMware : VMware vRealize Operations updates address multiple security vulnerabilities | Systems running VMware vRealize Operations,
|
20 Aug 2021 | STAT33 | |
|
20 Aug 2021 | VULN418 | Citrix : Citrix ShareFile storage zonescontroller security update | Sstems running Citrix ShareFile storage zones
|
20 Aug 2021 | VULN417 | (VMware : Important Severity - VMSA-2021-0016 - VMware Workspace One Access, Identity Manager and vRealize Automation address multiple vulnerabilities (CVE-2021-22002, CVE-2021-22003)) | Systems running VMware Workspace ONE Access
|
20 Aug 2021 | VULN416 | F5 : K43346111: Linux kernel eBPF vulnerability CVE-2021-3490 Security Advisory | BIG-IP software, BIG-IQ Centralized Management
|
20 Aug 2021 | VULN415 | IBM : Multiple vulnerabilities in IBMJava SDK affects WebSphere Application Server July 2021 CPU that is bundledwith IBM WebSphere Application Server Patterns | AIX, Linux running WebSphere Application Server
|
20 Aug 2021 | VULN414 | (VMware : VMware Workspace ONE UEMconsole patches address a denial of service vulnerability (CVE-2021-22029)) | Systems running VMware Workspace ONE UEM console
|
20 Aug 2021 | VULN413 | Adobe : Security Updates Available forAdobe Bridge APSB21-69 | Windows, macOS running Adobe Bridge versions prior
|
19 Aug 2021 | VULN412 | Fortinet : FortiWeb - OS command injection vulnerability | Systems running FortiWeb versions prior to 6.3.15,
|
19 Aug 2021 | VULN411 | Adobe : Security Updates Available for Adobe Commerce APSB21-64 | Systems running Adobe Commerce versions prior to
|
19 Aug 2021 | VULN410 | Adobe : Security update available for Adobe Captivate APSB21-60 | Systems running Adobe Captivate 2019 versions up to
|
19 Aug 2021 | VULN409 | Apache : CVE-2021-37578 Apache jUDDI Remote code execution | Systems running Apache jUDDI versions prior to
|
19 Aug 2021 | VULN408 | Apache : CVE-2021-21501 Apache ServiceComb ServiceComb ServiceCenter Directory Traversal | Systems running Apache ServiceComb ServiceCenter
|
19 Aug 2021 | VULN407 | OpenStack : OSSA-2021-002 Open Redirect in noVNC proxy | Systems running OpenStack Nova versions prior
|
19 Aug 2021 | VULN406 | Openstack : OSSA-2021-003 Account name and UUID oracles in account locking | Systems running Openstack Keystone versions from
|
19 Aug 2021 | VULN405 | OpenStack : OSSA-2021-004: Linuxbridge ARP filter bypass on Netfilter platforms | Systems running OpenStack Neutron versions prior
|
19 Aug 2021 | VULN404 | Apache : CVE-2021-33580 Apache Roller regex injection leading to DoS | Systems running Apache Roller versions prior to
|
19 Aug 2021 | VULN403 | Cisco : Cisco Security Advisories Published on August 18, 2021 | Cisco products running BlackBerry QNX,
|
19 Aug 2021 | VULN402 | ISC : CVE-2021-25218 A too-strict assertion check could be triggered when responses in BIND 9.16.19 and 9.17.16 require UDP fragmentation if RRL is in use | Systems running BIND versions prior to
|
18 Aug 2021 | VULN401 | Drupal core : Drupal core - Moderately critical - Third-party libraries - SA-CORE-2021-005 | Systems running Drupal core versions prior to
|
18 Aug 2021 | VULN400 | CKEditor : CKEditor 4.16.2 with browser improvements and security fixes | Systems running CKEditor versions prior to 4.16.2.
|
18 Aug 2021 | VULN399 | fetchmail : fetchmail denial of service or information disclosure when logging long messages | Systems running fetchmail versions prior to 6.4.21.
|
18 Aug 2021 | VULN398 | Node.js : August 2021 Security Releases | Systems running Node.js versions prior to
|
18 Aug 2021 | VULN397 | Google Chrome : Google Chrome versions 92.0.4515.159 fixes multiple security vulnerabilities | Systems running Google Chrome versions prior to
|
18 Aug 2021 | VULN396 | Adobe : Security Updates Available for Adobe Media Encoder APSB21-70 | Windows, macOS running Adobe Media Encoder versions
|
18 Aug 2021 | VULN395 | Adobe : Security updates available for Adobe Photoshop APSB21-68 | Windows, macOS running Adobe Photoshop versions
|
18 Aug 2021 | VULN394 | Mozilla : Security Vulnerabilities fixed in Firefox and Thunderbird prior to 91.0.1 | Systems running Firefox, Thunderbird versions prior
|
18 Aug 2021 | VULN393 | Apache : CVE-2021-35936 Apache Airflow No Authentication on Logging Server | Systems running Apache Airflow versions prior to
|
18 Aug 2021 | VULN392 | Apache : [CVE-2021-37608] Arbitrary file upload vulnerability in OFBiz | Sstems running Apache OFBiz versions prior to
|
13 Aug 2021 | STAT32 | |
|
11 Aug 2021 | VULN391 | Microsoft : Microsoft Security Update Summary for August 10, 2021 | Systèmes utisnt .NET Core et Visual Studio;
|
10 Aug 2021 | VULN390 | TYPO3 : Cross-Site Scripting via Rich-Text Content | All systems using TYPO3
|
6 Aug 2021 | STAT31 | |
|
30 Jul 2021 | STAT30 | |
|
28 Jul 2021 | VULN389 | APPLE : About the security content of macOS Big Sur 11.5.1 | macOS Big Sur versions prior to 11.5.1.
|
28 Jul 2021 | VULN388 | APPLE : About the security content of iOS 14.7.1 and iPadOS 14.7.1 | iOS versions prior to 14.7.1.
|
23 Jul 2021 | VULN387 | APPLE : APPLE-SA-2021-07-21-6 tvOS 14.7 | tvOS versions prior to 14.7.
|
23 Jul 2021 | VULN386 | APPLE : APPLE-SA-2021-07-21-5 watchOS 7.6 | watchOS versions prior to 7.6.
|
23 Jul 2021 | VULN385 | Apache : CVE-2021-28131 Apache Impala: Impala logs contain secrets | Systems running Apache Impala versions prior to
|
23 Jul 2021 | VULN384 | WebKit : WebKitGTK and WPE WebKit Security Advisory | Systems running WebKitGTK, WPE WebKit versions
|
23 Jul 2021 | VULN383 | Tenable : [R1] Tenable.sc 5.19.0 Fixes Multiple Third-party Vulnerabilities | Systems running Tenable.sc versions prior to
|
22 Jul 2021 | VULN382 | Drupal : Drupal core - Critical - Drupal core - Critical - Third-party libraries - SA-CORE-2021-004 | Systems running Drupal core versions prior to
|
23 Jul 2021 | STAT29 | |
|
22 Jul 2021 | VULN381 | APPLE : APPLE-SA-2021-07-21-7 Safari 14.1.2 | Systems running Safari versions prior to 14.1.2.
|
22 Jul 2021 | VULN380 | APPLE : APPLE-SA-2021-07-21-4 Security Update 2021-005 Mojave | macOS Mojave.
|
22 Jul 2021 | VULN379 | APPLE : APPLE-SA-2021-07-21-3 Security Update 2021-004 Catalina | macOS Catalina.
|
22 Jul 2021 | VULN378 | APPLE : APPLE-SA-2021-07-21-2 macOS Big Sur 11.5 | macOS versions prior to Big Sur 11.5.
|
22 Jul 2021 | VULN377 | APPLE : APPLE-SA-2021-07-21-1 iOS 14.7 and iPadOS 14.7 | iOS, iPadOS versions prior to 14.7.
|
22 Jul 2021 | VULN376 | Adobe : Security Updates Available for Adobe Prelude | Systems running Adobe Prelude versions prior to
|
22 Jul 2021 | VULN375 | Adobe : Security Updates Available for Adobe After Effects | Systems running Adobe After Effects versions prior
|
22 Jul 2021 | VULN374 | Adobe : Security Updates Available for Adobe Illustrator | Systems running Adobe Illustrator versions prior to
|
22 Jul 2021 | VULN373 | Adobe : Security updates available for Adobe Photoshop | Systems running Photoshop versions prior to
|
21 Jul 2021 | VULN372 | Cisco : Cisco Security Advisories Published on July 21, 2021 | Cisco Intersight Virtual Appliance versions prior
|
21 Jul 2021 | VULN371 | (Red Hat : RHSB-2021-006 Long path name in mountpoint flaws in the kernel and systemd (CVE-2021-33909, CVE-2021-33910)) | Red Hat Enterprise Linux versions 6, 7, 8,
|
21 Jul 2021 | VULN370 | Windows : Windows Elevation of Privilege Vulnerability | Windows.
|
21 Jul 2021 | VULN369 | Oracle : July 2021 Critical Patch Update Released | Systems running Oracle Database Server,
|
21 Jul 2021 | VULN368 | Curl : Multiple vulnerabilities fixed in curl | Systems running curl versions prior to 7.78.0.
|
20 Jul 2021 | VULN367 | Node.js : July 2021 Security Releases | Systems running Node.js versions prior to
|
20 Jul 2021 | VULN366 | Fortinet : FortiManager & FortiAnalyzer - Use after free vulnerability in fgfmsd daemon | Systems running FortiManager, FortiAnalyzer
|
20 Jul 2021 | VULN365 | Citrix : Citrix Application Delivery Controller, Citrix Gateway and Citrix SD-WAN WANOP Edition appliance Security Update | Systems running Citrix ADC, Citrix Gateway versions
|
20 Jul 2021 | VULN364 | Moodle : Multiple vulnerabilities fixed in Moodle | Systems running Moodle versions prior to 3.11.1,
|
19 Jul 2021 | VULN363 | Citrix : Citrix Virtual Apps and Desktops Security Update | Systems running Citrix Virtual Apps and Desktops,
|
19 Jul 2021 | VULN362 | Google : Chrome 91.0.4472.164 fixes multiple security vulnerabilities | Systems running Google Chrome versions prior to
|
19 Jul 2021 | STAT28 | |
|
15 Jul 2021 | VULN361 | Adobe : Security update available for Adobe Acrobat and Reader | Systems running Adobe Acrobat, Adobe Reader
|
15 Jul 2021 | VULN360 | SonicWall : Improper Neutralization of Special Elements used in an SQL Command leading to SQL Injection vulnerability Impacting End-Of-Life SRA Appliances | Systems running SonicWall SSLVPN SMA/SRA versions
|
15 Jul 2021 | VULN359 | Wireshark : wnpa-sec-2021-06 · DNP dissector crash | Systems running Wireshark versions prior to
|
15 Jul 2021 | VULN358 | Mozilla : Security Vulnerabilities fixed in Thunderbird 78.12 | Systems running Thunderbird versions prior to
|
15 Jul 2021 | VULN357 | Apache : Apache Commons Compress denial of service vulnerabilities | Systems running Apache Commons Compress versions
|
15 Jul 2021 | VULN356 | Mozilla : Security Vulnerabilities fixed in Firefox ESR 78.12 and 90 | Systems running Firefox versions prior to
|
15 Jul 2021 | VULN355 | Apache : CVE-2021-36373 Apache Ant TAR, ZIP, and ZIP based archive denial of service vulnerabilities | Systems running Apache Ant versions prior to
|
15 Jul 2021 | VULN354 | Kubernetes : CVE-2021-25740 Endpoint & EndpointSlice permissions allow cross-Namespace forwarding | Systems running Kubernetes.
|
15 Jul 2021 | VULN353 | Microsoft : Microsoft Security Update Summary for July 13, 2021 | Systems running Windows Common Internet File System,
|
15 Jul 2021 | VULN352 | (VMware : VMware ThinApp update addresses a DLL hijacking vulnerability (CVE-2021-22000)) | Systems running VMware ThinApp versions 5.x prior
|
12 Jul 2021 | VULN351 | Ruby : StartTLS stripping and Trusting FTP PASV responses vulnerabilities | Systems running Ruby versions prior to 2.6.7,
|
12 Jul 2021 | STAT27 | |
|
8 Jul 2021 | VULN350 | GitLab : GitLab Critical Security Release: 14.0.4, 13.12.8, and 13.11.7 | Systems running GitLab versions prior to 14.0.4,
|
8 Jul 2021 | VULN349 | Cisco : Cisco Security Advisories Published on July 07, 2021 | Systems running Cisco Business Process Automation,
|
8 Jul 2021 | INFO1 | : Information sur les attaques de type Smishing |
|
7 Jul 2021 | VULN348 | (QNAP : Improper Access Control Vulnerability in Legacy HBS 3 (Hybrid Backup Sync)) | Systems running QNAP NAS running HBS 3 versions
|
7 Jul 2021 | VULN347 | Apache : CVE-2021-33192 Apache Jena Fuseki Display information UI XSS | Systems running Apache Jena Fuseki versions prior
|
7 Jul 2021 | VULN346 | Joomla : Joomla 3.9.28 addresses 5 security vulnerabilities | Systems running Joomla versions prior to 3.9.28.
|
2 Jul 2021 | STAT26 | |
|
2 Jul 2021 | VULN345 | MediaWiki: Security and maintenance release: 1.31.15 / 1.35.3 / 1.36.1 | Systems running MediaWiki versions prior to
|
2 Jul 2021 | VULN344 | Apache: CVE-2021-26920 Apache Druid The HTTP inputSource allows authenticated users to read data from other sources than intended | Systems running Apache Druid versions prior to
|
1 Jul 2021 | VULN343 | Drupal : Vulnerabilies fixed in multiple modules for Drupal | Systems running Block Content Revision UI for
|
1 Jul 2021 | VULN342 | Zimbra : NEW Zimbra Patches: 9.0.0 Patch 16 + 8.8.15 Patch 23 | Systems running Zimbra versions prior to 9.0.0 P16,
|
1 Jul 2021 | VULN341 | PHP : PHP versions 7.3.29 fix multiple security vulnerabilities | Systems running PHP versions prior to 7.3.29.
|
1 Jul 2021 | VULN340 | Google Chrome OS: Stable channel for Chrome OS updated to 91.0.4472.147 | Chrome OS versions prior to 91.0.4472.147.
|
1 Jul 2021 | VULN339 | Django : Django security releases issued 3.2.5 and 3.1.13 | Systems running Django versions prior to 3.2.5,
|
1 Jul 2021 | VULN338 | Jenkins : Jenkins Security Advisory 2021-06-30 | Systems running Jenkins (core),
|
25 Jun 2021 | STAT25 | |
|
23 Jun 2021 | VULN337 | Palo Alto Networks : CVE-2021-3044 Cortex XSOAR Unauthorized Usage of the REST API,047910 | Systems running Cortex XSOAR versions prior to
|
23 Jun 2021 | VULN336 | VMware : VMware Carbon Black App Control update addresses authentication bypass | Systems running VMware Carbon Black App Control
|
23 Jun 2021 | VULN335 | (VMware : VMware Tools, VMRC and VMware App Volumes update addresses a local privilege escalation vulnerability (CVE-2021-21999)) | Systems running VMware Tools for Windows versions
|
23 Jun 2021 | VULN334 | Apache : CVE-2021-26461 Apache NuttX(incubating) malloc, realloc and memalign implementations are vulnerable tointeger wrap-arounds | Systems running Apache NuttX versions prior to
|
18 Jun 2021 | STAT24 | |
|
18 Jun 2021 | VULN333 | PHPMailer : Remote Code Execution and Code Injection vulnerabilities in PHPMailer | Systems running PHPMailer versions prior to 6.5.0.
|
18 Jun 2021 | VULN332 | Jenkins : Vulnerabilities in Scriptler and the Generic Webhook Trigger Plugins | Systems running Scriptler Plugin for Jenkins
|
18 Jun 2021 | VULN331 | Cisco : Cisco Security Advisories Published on June 16, 2021 | Cisco Small Business 220 Series Smart Switches
|
18 Jun 2021 | VULN330 | Google Chrome : Google Chrome 91.0.4472.114 fixes multiple security vulnerabilities | Systems running Google Chrome versions prior to
|
18 Jun 2021 | VULN329 | Symfony : CVE-2021-32693 Authentication granted to all firewalls instead of just one | Systems running Symfony versions 5.3.x prior to
|
18 Jun 2021 | VULN328 | (VMware : VMware Tools for Windows update addresses a denial-of-service ,vulnerability (CVE-2021-21997)) | Windows running VMware Tools for Windows versions
|
16 Jun 2021 | VULN327 | APPLE : About the security content of iOS 12.5.4 | iOS versions prior to 12.5.4.
|
16 Jun 2021 | VULN326 | Trend Micro : Trend Micro InterScan Web Security Virtual Appliance 6.5 Reflected XSS Vulnerability | Systems running Trend Micro InterScan Web Security
|
16 Jun 2021 | VULN325 | Mozilla : Security Vulnerabilities fixed in Firefox 89.0.1 | Systems running Firefox versions prior to 89.0.1.
|
16 Jun 2021 | VULN324 | Apache : CVE-2021-30468 Apache CXF Denial of service vulnerability in parsing JSON via JsonMapObjectReaderWriter | Systems running Apache CXF versions prior to 3.4.4,
|
16 Jun 2021 | VULN323 | Apache : CVE-2020-9493 Apache Chainsaw Java deserialization in Chainsaw | Systems running Apache Chainsaw versions prior to
|
14 Jun 2021 | VULN322 | QNAP : Out-of-Bounds Read Vulnerability and Inclusion of Sensitive Information in QSS | Systems running Certain QNAP Switches.
|
14 Jun 2021 | VULN321 | QNAP : Improper Access Control Vulnerability in Helpdesk | Systems running QNAP NAS Helpdesk versions prior to
|
14 Jun 2021 | VULN320 | Qnap : Vulnerability in Roon Server | Systems running QNAP NAS running Roon Server
|
14 Jun 2021 | VULN319 | Citrix : Citrix Hypervisor Security Update | Systems running Citrix Hypervisor.
|
14 Jun 2021 | VULN318 | Apache : Apache PDFBox A carefully crafted PDF file can trigger DoS while loading a file | Systems running Apache PDFBox versions prior to
|
14 Jun 2021 | VULN317 | Silverstripe : Vulnerabilities fixed in SilverStripe's supported modules | Systems running silverstripe/framework versions
|
11 Jun 2021 | STAT23 | |
|
11 Jun 2021 | VULN316 | Nagios XI : Nagios XI 5.8.4 fixes SQL injection and XSS vulnerabilities | Systems running Nagios XI versions prior to 5.8.4.
|
11 Jun 2021 | VULN315 | Google : Multiple security vulnerabilities fixed in Chrome 91.0.4472.101 | Systems running Google Chrome versions prior to
|
10 Jun 2021 | VULN314 | Xen : Multiple security vulnerabilities fixed in Xen | Systems running Xen.
|
9 Jun 2021 | VULN313 | Adobe : Security updates available for Adobe Photoshop APSB21-38 | Systems running Adobe Photoshop versions prior to
|
9 Jun 2021 | VULN312 | Citrix : CTX297155 Citrix Application Delivery Controller, Citrix Gateway, and Citrix SD-WAN WANOP appliance Security Update | Systems running Citrix ADC, Citrix Gateway,
|
9 Jun 2021 | VULN311 | Adobe : Security update available for Adobe Acrobat and Reader APSB21-37 | Systems running Adobe Acrobat, Adobe Reader
|
9 Jun 2021 | VULN310 | Wireshark : DVB-S2-BB dissector infinite loop | Systems running Wireshark versions prior to 3.4.6.
|
9 Jun 2021 | VULN309 | Microsoft : Microsoft Security Update Summary for June 8, 2021 | Systems running .NET Core & Visual Studio,
|
8 Jun 2021 | VULN308 | Apache : CVE-2021-33190 Apache APISIX Dashboard: Bypass network access control | Systems running Apache APISIX Dashboard versions
|
8 Jun 2021 | VULN307 | SAP : SAP Security Patch Day – June 2021 | Systems running SAP Commerce,
|
4 Jun 2021 | STAT22 | |
|
3 Jun 2021 | VULN306 | QNAP : Command Injection Vulnerability in Video Station | Systems running QNAP NAS running Video Station
|
3 Jun 2021 | VULN305 | QNAP : Post-Authentication Reflected XSS Vulnerability in Q'center | Systems running QNAP NAS running Q'center versions
|
3 Jun 2021 | VULN304 | Drupal : Multiple vulnerabilities fixed in plugins for Drupal | Systems running OpenID Connect / OAuth client for
|
2 Jun 2021 | VULN303 | Django : Django security releases issued 3.2.4, 3.1.12, and 2.2.24 | Systems running Django versions prior to 3.2.4,
|
1 Jun 2021 | VULN302 | Mozilla : Security Vulnerabilities fixed in Firefox 89 and ESR 78.11 | Systems running Firefox versions prior to 89,
|
1 Jun 2021 | VULN301 | Cisco : Lasso SAML Implementation Vulnerability Affecting Cisco Products: June 2021 | Cisco ASA Software, Cisco SMA, Cisco ESA,
|
28 May 2021 | STAT21 | |
|
28 May 2021 | VULN300 | APPLE : APPLE-SA-2021-05-25-2 macOS Big Sur 11.4 | macOS versions prior to Big Sur 11.4.
|
28 May 2021 | VULN299 | APPLE : APPLE-SA-2021-05-25-1 iOS 14.6 and iPadOS 14.6 | iOS, iPadOS versions prior to 14.6.
|
28 May 2021 | VULN298 | APPLE : APPLE-SA-2021-05-25-8 Boot Camp | Systems running Boot Camp versions prior to 6.1.14.
|
28 May 2021 | VULN297 | APPLE : APPLE-SA-2021-05-25-7 tvOS 14.6 | tvOS versions prior to 14.6.
|
28 May 2021 | VULN296 | APPLE : APPLE-SA-2021-05-25-6 watchOS 7.5 | watchOS versions prior to 7.5.
|
28 May 2021 | VULN295 | APPLE : APPLE-SA-2021-05-25-5 Safari 14.1.1 | Systems running Safari versions prior to 14.1.1.
|
28 May 2021 | VULN294 | Apache : CVE-2020-17514 Apache Fineract Disabled hostname verification for HTTPS | Systems running Apache Fineract versions prior to
|
28 May 2021 | VULN293 | Apache : Authentication with JWT allows use of "none"-algorithm | Systems running Apache Pulsar versions prior to
|
28 May 2021 | VULN292 | Apache : CVE-2021-23937 Apache Wicket DNS proxy and possible amplification attack | Systems running Apache Wicket versions prior to
|
28 May 2021 | VULN291 | Drupal : Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2021-003 | Systems running Drupal core versions prior to
|
27 May 2021 | VULN290 | ISC : CVE-2021-25217 Buffer overrun in lease file parsing code | Systems running ISC DHCP versions prior to
|
27 May 2021 | VULN289 | Jenkins : Jenkins Security Advisory 2021-05-25 | Systems running Filesystem Trigger Plugin for
|
27 May 2021 | VULN288 | Joomla : Security vulnerabilities fixed in Joomla 3.9.27 | Systems running Joomla versions prior to 3.9.27.
|
27 May 2021 | VULN287 | curl : Vulnerabilities fixed in curl, libcurl | Systems running curl, libcurl versions prior to
|
27 May 2021 | VULN286 bis | VMware : VMware vCenter Server updates address remote code execution and authentication vulnerabilities | Systems running VMware vCenter Server versions
|
21 May 2021 | STAT20 | |
|
21 May 2021 | VULN286 | VMware :VMware Workstation and Horizon Client for Windows updates address multiple security vulnerabilities | Systems running VMware Workstation Pro/Player
|
20 May 2021 | VULN285 | (Prometheus : Prometheus v2.26.1 / v2.27.1 (Security Release)) | Systems running Prometheus versions prior to 2.26.1,
|
20 May 2021 | VULN284 | runc : mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs | Systems running runc versions prior to 1.0.0-rc95.
|
20 May 2021 | VULN283 | Cisco : Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Command Injection Vulnerability | Systems running Cisco Prime Infrastructure versions
|
20 May 2021 | VULN282 | Cisco : Cisco Modeling Labs Web UI Command Injection Vulnerability | Systems running Cisco Modeling Labs versions
|
19 May 2021 | VULN281 | Kubernetes : CVE-2021-25738 Code exec via yaml parsing | Systems running Kubernetes Java Client versions
|
19 May 2021 | VULN280 | Kubernetes : CVE-2021-25737 Holes in EndpointSlice Validation Enable Host Network Hijack | Systems running Kubernetes versions prior to 1.21.1,
|
18 May 2021 | VULN279 | LibreOffice : fileloc extension added to macOS executable denylist | Systems running LibreOffice versions prior to 7.0.6,
|
18 May 2021 | VULN278 | Wordpress : WordPress 5.7.2 Security Release | Systems running WordPress versions prior to 5.7.2.
|
18 May 2021 | VULN277 | Moodle : Multiple Security Vulnerabilities fixed in Moodle | Systems running Moodle versions prior to 3.11,
|
18 May 2021 | VULN276 | X.Org : Missing request length checks in libX11 | Systems running X.Org libX11 versions prior to
|
17 May 2021 | STAT19 | |
|
12 May 2021 | VULN275 | Adobe : Security Updates Available for Adobe Illustrator | APSB21-24 | Systems running Adobe Illustrator versions
|
12 May 2021 | VULN274 | Adobe : Security Update Available for Adobe InDesign APSB21-22 | Windows, macOS running Adobe InDesign versions prior
|
12 May 2021 | VULN273 | Adobe : Security update available for Adobe Acrobat and Reader APSB21-29 | Systems running Adobe Acrobat, Adobe Reader versions
|
12 May 2021 | VULN272 | Kubernetes : CVE-2021-25736 Windows kube-proxy LoadBalancer contention | Systems running Kubernetes versions prior to 1.21.0,
|
12 May 2021 | VULN271 | Jenkins : Jenkins Security Advisory 2021-05-11 | Systems running Credentials Plugin for Jenkins,
|
12 May 2021 | VULN270 | Microsoft : Microsoft Security Update Summary for May 11, 2021 | Systems running .NET Core & Visual Studio,
|
11 May 2021 | VULN269 | SAP : SAP Security Patch Day – May 2021 | Systems running SAP Business Client, SAP Commerce,
|
11 May 2021 | VULN268 | Google Chrome : Chrome 90.0.4430.212 fixes multiple vulnerabilities | Systems running Google Chrome versions prior to
|
11 May 2021 | VULN267 | (VMware : VMware Workspace ONE UEM console patches address a Cross-site scripting vulnerability (CVE-2021-21990)) | Systems running VMware Workspace ONE UEM console
|
11 May 2021 | VULN266 | Squid : Multiple security vulnerabilities fixed in Squid | Systems running Squid versions prior to 4.15,
|
7 May 2021 | STAT18 | |
|
6 May 2021 | VULN265 | (VMware : VMware vRealize Business for Cloud updates address a remote code execution vulnerability (CVE-2021-21984)) | Systems running VMware vRealize Business for Cloud
|
6 May 2021 | VULN264 | Django : Django security releases issued 3.2.2, 3.1.10, and 2.2.22 | Systems running Django versions prior to 3.2.2,
|
5 May 2021 | VULN263 | Xen : x86 Speculative vulnerabilities with bare (non-shim) 32-bit PV guests | Systems running Xen.
|
5 May 2021 | VULN262 | Exim : Exim 4.94.2 - security update released | Systems running Exim versions prior to 4.94.2.
|
5 May 2021 | VULN261 | APPLE : APPLE-SA-2021-05-03-3 watchOS 7.4.1 | watchOS versions prior to 7.4.1.
|
5 May 2021 | VULN260 | APPLE : APPLE-SA-2021-05-03-4 macOS Big Sur 11.3.1 | macOS versions prior to Big Sur 11.3.1.
|
5 May 2021 | VULN259 | Django : Django security releases issued 3.2.1, 3.1.9, and 2.2.21 | Systems running Django versions prior to 3.2.1,
|
5 May 2021 | VULN258 | APPLE : iOS 14.5.1 and iPadOS 14.5.1 et iOS 12.5.3 fix WebKit security vulnerabilities | iOS, iPadOS versions prior to 14.5.1.
|
4 May 2021 | VULN257 | PHPMailer : Object injection in PHPMailer/PHPMailer | Systems running PHPMailer versions prior to 6.4.1.
|
3 May 2021 | VULN256 | Ruby : CVE-2021-31799 A command injection vulnerability in RDoc | Systems running RDoc versions prior to 6.3.1.
|
30 Apr 2021 | STAT17 | |
|
30 Apr 2021 | VULN255 | Apache : CVE-2021-30638 An Information Disclosure due to insufficient input validation exists in Apache Tapestry 5.4.0 and later | Systems running Apache Tapestry versions prior to
|
30 Apr 2021 | VULN254 | Samba : Negative idmap cache entries can cause incorrect group entries in the Samba file server process token | Systems running Samba versions since 3.6.0 and
|
30 Apr 2021 | VULN253 | BIND : A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack | Systems running BIND versions prior to 9.11.31,
|
30 Apr 2021 | VULN252 | KDE : KMail: Deleting attachments can disclose content of encrypted messages | Systems running KMail, messagelib versions prior to
|
30 Apr 2021 | VULN251 | Drupal : SAML Authentication - Moderately critical - Access bypass - SA-CONTRIB-2021-006 | Systems running samlauth for Drupal versions prior
|
29 Apr 2021 | VULN250 | Cisco : Cisco Adaptive Security Appliance Software and Cisco Firepower Threat Defense Software Vulnerabilities fixed | Cisco ASA Software versions prior to 9.8.4.35,
|
28 Apr 2021 | VULN249 | Fortinet : Authentication bypass in FortiWAN | Systems running FortiWAN versions prior to 4.5.8,
|
28 Apr 2021 | VULN248 | Elastic : Kibana 7.12.1 fix DoS and XML External Entity Injection issues | Systems running Kibana versions prior to 7.12.1.
|
28 Apr 2021 | VULN247 | Apache : Unsafe deserialization and RCE vulnerability in Apache OFBiz | Systems running Apache OFBiz versions prior to
|
28 Apr 2021 | VULN246 | APPLE : APPLE-SA-2021-04-26-10 Xcode 12.5 | Systems running Xcode versions prior to 12.5.
|
28 Apr 2021 | VULN245 | APPLE : APPLE-SA-2021-04-26-6 tvOS 14.5 | tvOS versions prior to 14.5.
|
28 Apr 2021 | VULN244 | APPLE : APPLE-SA-2021-04-26-8 iCloud for Windows 12.3 | Windows running iCloud versions prior to 12.3.
|
28 Apr 2021 | VULN243 | APPLE : APPLE-SA-2021-04-26-9 iTunes 12.11.3 for Windows | Systems running iTunes versions prior to 12.11.3.
|
28 Apr 2021 | VULN242 | APPLE : APPLE-SA-2021-04-26-5 watchOS 7.4 | watchOS versions prior to 7.4.
|
27 Apr 2021 | VULN241 | Shibboleth : Shibboleth Service Provider Security Advisory [26 April 2021] | Systems running Shibboleth Service Provider
|
27 Apr 2021 | VULN240 | Google Chrome : Google Chrome 90.0.4430.93 fix multiple vulnerabilities | Systems running Google Chrome versions prior to
|
27 Apr 2021 | VULN239 | Zimbra : NEW Zimbra Patches 9.0.0 Patch 14 + 8.8.15 Patch 21 | Systems running Zimbra versions prior to
|
27 Apr 2021 | VULN238 | Apache : CVE-2020-17517 Apache Ozone Ozone S3 Gateway allows bucket and key access to non authenticated users | Systems running Apache Ozone versions prior to
|
27 Apr 2021 | VULN237 | Apache : CVE-2021-28125 Apache Superset Open Redirect | Systems running Apache Superset versions prior to
|
27 Apr 2021 | VULN236 | APPLE : About the security content of Safari 14.1 | Systems running Safari versions prior to 14.1.
|
27 Apr 2021 | VULN235 | Sympa : 2021-001 Inappropriate use of the cookie parameter | Systems running Sympa versions prior to 6.2.62.
|
27 Apr 2021 | VULN234 | TYPO3 : Vulnerabilities fixed in multiple TYPO3 extensions | Systems running "2 Clicks for External Media"
|
27 Apr 2021 | VULN233 | APPLE : macOS Big Sur 11.3 and Security Update for Catalina and Mojave | macOS versions prior to Big Sur 11.3.
|
27 Apr 2021 | VULN232 | APPLE : APPLE-SA-2021-04-26-1 iOS 14.5 and iPadOS 14.5 | iOS, iPadOS versions prior to 14.5.
|
23 Apr 2021 | STAT16 | |
|
23 Apr 2021 | VULN231 | Oracle : April 2021 Critical Patch Update Released | Systems running Oracle Database Server,
|
23 Apr 2021 | VULN230 | Wireshark : MS-WSP dissector excessive memory consumption | Systems running Wireshark versions prior to 3.4.5,
|
22 Apr 2021 | VULN229 | Drupal : Drupal core - Critical - Cross-site scripting - SA-CORE-2021-002 | Systems running Drupal versions prior to 9.1.7,
|
22 Apr 2021 | VULN228 | Jenkins : Jenkins Security Advisory 2021-04-21 | Systems running CloudBees CD Plugin for Jenkins
|
20 Apr 2021 | VULN227 | Mozilla : Security Vulnerabilities fixed in Firefox 88 and 78.10 | Systems running Firefox versions prior to 88,
|
20 Apr 2021 | VULN226 | Mozilla : Security Vulnerabilities fixed in Thunderbird 78.10 | Systems running Thunderbird versions prior to
|
16 Apr 2021 | STAT15 | |
|
16 Apr 2021 | VULN225 | WordPress : WordPress 5.7.1 Security and Maintenance Release | Systems running WordPress versions prior
|
16 Apr 2021 | VULN224 | GitLab : GitLab Critical Security Release: 13.10.3, 13.9.6, and 13.8.8 | Systems running GitLab versions prior to 13.10.3,
|
16 Apr 2021 | VULN223 | LibreOffice : Denylist of executable filename extensions possible to bypass under windows | Systems running LibreOffice versions prior
|
15 Apr 2021 | VULN222 | Django : SQL Injection via Select, Explain and Analyze forms of the SQLPanel for Django Debug Toolbar >= 0.10.0 | Systems running Django Debug Toolbar versions prior
|
15 Apr 2021 | VULN221 | Kubernetes : CVE-2021-25735 Validating Admission Webhook does not observe some previous fields | Systems running kube-apiserver versions prior to
|
14 Apr 2021 | VULN220 | GLPI : GLPI 9.5.5 fix Stored XSS in plugins information | Systems running GLPI versions prior to 9.5.5.
|
14 Apr 2021 | VULN219 | Microsoft : Microsoft Security Update Summary for April 13, 2021 | Microsoft Windows, Windows Server
|
14 Apr 2021 | VULN218 | X.Org : Input validation failures in X server XInput extension | Systems running X.Org server versions prior to
|
14 Apr 2021 | VULN217 | Adobe : Security update available for RoboHelp APSB21-20 | Systems running Adobe RoboHelp versions prior to
|
14 Apr 2021 | VULN216 | Adobe : Security Updates Available for Adobe Bridge APSB21-23 | Systems running Adobe Bridge versions prior to
|
14 Apr 2021 | VULN215 | Adobe : Security Updates Available for Adobe Digital Editions | Systems running Adobe Digital Editions versions
|
14 Apr 2021 | VULN214 | Adobe : Security updates available for Adobe Photoshop APSB21-28 | Systems running Adobe Photoshop versions prior to
|
14 Apr 2021 | VULN213 | Google Chrome : Stable Channel for Desktop 89.0.4389.128 fix possible arbitrary code execution | Systems running Google Chrome versions prior to
|
14 Apr 2021 | VULN212 | Joomla! : Escape xss in logo parameter error pages and Inadequate filters on module | Systems running Joomla! CMS versions prior to
|
13 Apr 2021 | VULN211 | Apache : Multiple vulnerabilities fixed in Apache Solr 8.8.2 | Systems running Apache Solr versions prior to
|
12 Apr 2021 | VULN210 | WhatsApp : April Update fix cache configuration issue and out-of-bounds write | Android, iOS running WhatsApp, WhatsApp Business
|
12 Apr 2021 | VULN209 | Redmine : Redmine 4.1.2 and 4.0.8 fix security vulnerabilities | Systems running Redmine versions prior to 4.1.2,
|
12 Apr 2021 | VULN208 | MediaWiki : Security and maintenance release 1.31.13 / 1.35.2 / 1.31.14 | Systems running MediaWiki versions prior to
|
9 Apr 2021 | STAT14 | |
|
9 Apr 2021 | VULN207 | Ruby : Ruby 3.0.1, 2.7.3, 2.6.7, 2.5.9 fix security vulnerabilities | Systems running Ruby versions prior to 3.0.1,
|
7 Apr 2021 | VULN206 | Jenkins : Jenkins Security Advisory 2021-04-07 | Systems running Jenkins
|
6 Apr 2021 | VULN205 | QNAP : QNAP QTS 4.3.6.1620-20210322 fix command injection and Apache HTTP server vulnerabilities | Systems running QNAP QTS versions prior to
|
6 Apr 2021 | VULN204 | Google Android : Bulletin de sécurité Android - Avril 2021 | Systems running Google Android versions prior to
|
6 Apr 2021 | VULN203 | Django : Django security releases issued: 3.1.8, 3.0.14, and 2.2.20 | Systems running Django versions prior to 3.1.8,
|
2 Apr 2021 | STAT13 | |
|
2 Apr 2021 | VULN202 | Apache CXF : CVE-2021-22696 Apache CXF OAuth 2 authorization service vulnerable to DDos attacks | Systems running Apache CXF versions prior to 3.4.3,
|
2 Apr 2021 | VULN201 | Jetty : Multiple vulnerabilities fixed in Jetty | Systems running Jetty versions prior to 9.4.39,
|
2 Apr 2021 | VULN200 | Netty : Possible request smuggling in HTTP/2 due missing validation of content-length | Systems running Netty versions prior to 4.1.61.
|
2 Apr 2021 | VULN199 | VMware : VMware Carbon Black Cloud Workload appliance update addresses incorrect URL handling vulnerability | Systems running VMware Carbon Black Cloud Workload
|
2 Apr 2021 | VULN198 | Nagios : Nagios 5.8.3 fix XSS and possible RCE vulnerabilities | Systems running Nagios versions prior to 5.8.3.
|
2 Apr 2021 | VULN197 | GitLab : GitLab Security Release: 13.10.1, 13.9.5 and 13.8.7 | Systems running GitLab versions prior to 13.10.1,
|
1 Apr 2021 | VULN196 | Wordpress : Stored Authenticated XSS in WordPress Plugin Virtual Robots.txt | Systems running WordPress Plugin Virtual
|
1 Apr 2021 | VULN195 | Zimbra : NEW Zimbra Patches 9.0.0 Patch 13 + 8.8.15 Patch 20 | Systems running Zimbra versions prior to 9.0.0
|
1 Apr 2021 | VULN194 | Google Chrome : Stable Channel Update for Desktop 89.0.4389.114 for Windows, Mac and Linux | Systems running Google Chrome versions prior to
|
1 Apr 2021 | VULN193 | Citrix : CTX306565 Citrix Hypervisor Security Update | Systems running Citrix Hypervisor version up to and
|
1 Apr 2021 | VULN192 | Jenkins : Jenkins Security Advisory 2021-03-30 | Systems running Build With Parameters Plugin for
|
31 Mar 2021 | VULN191 | VMware : VMware vRealize Operations updates address Server Side Request Forgery and Arbitrary File Write vulnerabilities | Systems running VMware vRealize Operations,
|
31 Mar 2021 | VULN190 | curl : Automatic referer leaks credentials and TLS 1.3 session ticket proxy host mixup | Systems running libcurl versions prior to 7.76.0.
|
30 Mar 2021 | VULN189 | Apache : CVE-2021-28657 Infinite loop in Apache Tika's MP3 parser | Systems running Apache Tika versions 1.26.
|
30 Mar 2021 | VULN188 | Xen : Linux blkback driver may leak persistent grants | All Linux versions having the fix for XSA-365
|
30 Mar 2021 | VULN187 | Apache : [CVE-2021-26919] Authenticated users can execute arbitrary code from malicious MySQL database systems | Systems running Apache Druid prior to 0.20.2.
|
30 Mar 2021 | VULN186 | WebKit : WebKitGTK and WPE WebKit Security Advisory WSA-2021-0003 | Systems running WebKitGTK, WPE WebKit versions
|
29 Mar 2021 | VULN185 | Apple : iOS 14.4.2 and iPadOS 14.4.2 fix WebKit universal cross site scripting vulnerability | iOS, iPadOS versions prior to 14.4.2.
|
29 Mar 2021 | VULN184 | Apple : watchOS 7.3.3 fixes WebKit universal cross site scripting vulnerability | watchOS versions prior to 7.3.3.
|
26 Mar 2021 | VULN183 | Adobe : Security updates available for Adobe ColdFusion APSB21-16 | Systems running Adobe ColdFusion versions prior to
|
26 Mar 2021 | STAT12 | |
|
26 Mar 2021 | VULN182 | Elastic : Elastic Stack 7.12.0 and 6.8.15 Security Update | Systems running Elasticsearch versions prior to
|
26 Mar 2021 | VULN181 | OpenSSL : CA certificate check bypass and NULL pointer dereference | Systems running OpenSSL versions 1.1.1 prior
|
25 Mar 2021 | VULN180 | Apache : CVE-2020-1946 Apache SpamAssassin has an OS Command Injection vulnerability | Systems running Apache SpamAssassin versions prior
|
25 Mar 2021 | VULN179 | Cisco : Cisco Security Advisories Published on March 24, 2021 | Systems running Cisco Jabber Desktop and Mobile
|
25 Mar 2021 | VULN178 | Samba : Heap corruption and Out of bounds read vulnerabilities | Systems running Samba versions prior to
|
24 Mar 2021 | VULN177 | Apache : [CVE-2021-26295] RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI | Systems running Apache OFBiz versions prior to
|
24 Mar 2021 | VULN176 | WebKit : WebKitGTK and WPE WebKit Security Advisory WSA-2021-0002 | Systems running WebKitGTK, WPE WebKit versions
|
24 Mar 2021 | VULN175 | Mozilla : Security Vulnerabilities fixed in Firefox ESR 78.9 | Systems running Firefox versions prior to 87,
|
24 Mar 2021 | VULN174 | Mozilla : Security Vulnerabilities fixed in Thunderbird 78.9 | Systems running Thunderbird versions prior to
|
24 Mar 2021 | VULN173 | MariaDB : wsrep_provider and wsrep_notify_cmd system variables are writable,Export | Systems running MariaDB Server versions prior to
|
23 Mar 2021 | VULN172 | Apache : Apache PDFBox multiple vulnerabilities | Systems running Apache PDFBox versions prior to
|
23 Mar 2021 | VULN171 | Grafana : Grafana 6.7.6, 7.3.10, and 7.4.5 released with important security fixes for Grafana Enterprise | Systems running Grafana versions prior to 6.7.6,
|
22 Mar 2021 | VULN170 | Foxit : Security updates available in Foxit Reader 10.1.3 and Foxit PhantomPDF 10.1.3 | Systems running Foxit Reader, Foxit PhantomPDF
|
19 Mar 2021 | STAT11 | |
|
18 Mar 2021 | VULN169 | Xen : Xen Security Advisory CVE-2021-28687 XSA-368 v3 HVM soft-reset crashes toolstack | Systems running Xen versions 4.12 up to and
|
18 Mar 2021 | VULN168 | Shibboleth : Shibboleth SP's Template generation allows external parameters to override placeholders | Systems running Shibboleth Service Provider
|
18 Mar 2021 | VULN167 | GitLab : GitLab Critical Security Release: 13.9.4, 13.8.6, and 13.7.9 | Systems running GitLab versions prior to 13.9.4,
|
18 Mar 2021 | VULN166 | Drupal : Fast Autocomplete - Moderately critical - Access bypass -,SA-CONTRIB-2021-005 | Systems running Fast Autocomplete for Drupal
|
18 Mar 2021 | VULN165 | Jenkins : Jenkins Security Advisory 2021-03-18 | Systems running CloudBees AWS Credentials Plugin
|
18 Mar 2021 | VULN164 | Cisco : Cisco Small Business RV132W and RV134W Routers Management Interface Remote Command Execution and Denial of Service Vulnerability | Systems running RV132W ADSL2+ Wireless-N VPN
|
16 Mar 2021 | VULN163 | TYPO3 : Multiple vulnerabilities fixed in TYPO3-CORE | Systems running TYPO3-CORE versions prior to
|
15 Mar 2021 | VULN162 | Go: Go 1.16.1 and Go 1.15.9 are released | Systems running Go versions prior to 1.16.1,
|
15 Mar 2021 | VULN161 | Moodle : Multiple security vulnerabilities fixed in Moodle | Systems running Moodle versions prior to
|
12 Mar 2021 | STAT10 | |
|
12 Mar 2021 | VULN160 | Adobe : Security updates available for Adobe Animate APSB21-21 | Systems running Adobe Animate versions prior to
|
12 Mar 2021 | VULN159 | Adobe : Security updates available for Adobe Photoshop APSB21-17 | Systems running Adobe Photoshop versions prior to
|
11 Mar 2021 | VULN158 | Wireshark : wnpa-sec-2021-03 Wireshark could open unsafe URLs | Systems running Wireshark versions prior to 3.4.4,
|
11 Mar 2021 | VULN157 | Apache : Velocity Sandbox Bypass and Velocity Tools XSS Vulnerability | Systems running Apache Velocity versions prior to
|
11 Mar 2021 | VULN156 | Apache : CVE-2020-35451 Oozie local privilege escalation | Systems running Apache Oozie versions prior to
|
11 Mar 2021 | VULN155 | Aruba : SAD DNS side channel attack | Systems running Aruba Instant versions prior to
|
11 Mar 2021 | VULN154 | Aruba : Aruba Instant (IAP) Multiple Vulnerabilities | Systems running Aruba Instant versions prior to
|
10 Mar 2021 | VULN153 | Adobe : Security update available for Adobe Creative Cloud Desktop Application | Systems running Adobe Creative Cloud Desktop
|
10 Mar 2021 | VULN152 | Adobe : Security Updates Available for Adobe Framemaker APSB21-14 | Systems running Adobe Framemaker versions prior to
|
10 Mar 2021 | VULN151 | Adobe : Security updates available for Adobe Connect APSB21-19 | Systems running Adobe Connect versions prior to
|
10 Mar 2021 | VULN150 | Microsoft : Microsoft Security Update Summary for March 9, 2021 | Systems running Microsoft Office,
|
10 Mar 2021 | VULN149 | Git: malicious repositories can execute remote code while cloning | Systems running Git versions prior to 2.30.2,
|
10 Mar 2021 | VULN148 | SAP : SAP Security Patch Day – March 2021 | Systems running SAP Solution Manager,
|
9 Mar 2021 | VULN147 | APPLE : APPLE-SA-2021-03-08-1 iOS 14.4.1 and iPadOS 14.4.1 | Systems running iOS, iPadOS versions prior to
|
9 Mar 2021 | VULN146 | APPLE : APPLE-SA-2021-03-08-4 watchOS 7.3.2 | watchOS versions prior to 7.3.2.
|
9 Mar 2021 | VULN145 | APPLE : APPLE-SA-2021-03-08-2 macOS Big Sur 11.2.3 | macOS versions prior to Big Sur 11.2.3.
|
9 Mar 2021 | VULN144 | APPLE : APPLE-SA-2021-03-08-3 Safari 14.0.3 | Systems running Safari versions prior to 14.0.3.
|
5 Mar 2021 | STAT09 | |
|
5 Mar 2021 | VULN143 | Cisco : Cisco IP Phones Buffer Overflow and Denial of Service Vulnerabilities | Cisco IP Phones Firmware.
|
5 Mar 2021 | VULN142 | Atlassian : Privilege Escalation Vulnerability in Atlassian Bitbucket on Windows - CVE-2020-36233 | Windows running Atlassian Bitbucket versions 6, 7
|
5 Mar 2021 | VULN141 | Tenable : Stand-alone Security Patches Available for Tenable.sc versions 5.13.0 to 5.17.0 | Systems running Tenable.sc versions 5.13.0 up to
|
5 Mar 2021 | VULN140 | Asterisk : AST-2021-006 Crash when negotiating T.38 with a zero port | Systems running Asterisk Open Source versions prior
|
5 Mar 2021 | VULN139 | GitLab : GitLab Security Release 13.9.2, 13.8.5 and 13.7.8 | Systems running GitLab versions prior to 13.9.2,
|
5 Mar 2021 | VULN138 | Elastic : Elastic Stack 7.11.0 and 6.8.14 Security Updates | Systems running Elasticsearch versions prior to
|
4 Mar 2021 | VULN137 | Xen : netback fails to honor grant mapping errors and special config crash | Systems running Xen.
|
4 Mar 2021 | VULN136 | Fortinet : Multiple vulnerabilities fixed in FortiProxy | Systems running FortiProxy versions prior to 2.0.1,
|
4 Mar 2021 | VULN135 | GRUB : Multiple GRUB2 vulnerabilities | Systems running GRUB2.
|
4 Mar 2021 | VULN134 | OpenSSH : OpenSSH 8.5 released | Systems running OpenSSH versions prior to 8.5.
|
4 Mar 2021 | VULN133 | Microsoft : Multiple Security Updates Released for Exchange Server | Systems running Microsoft Exchange Server versions
|
4 Mar 2021 | VULN132 | Salt Project : Active SaltStack CVE Release 2021-FEB-25 | Systems running Salt versions prior to 3002.5,
|
4 Mar 2021 | VULN131 | Cisco : Multiple Cisco Products Snort Ethernet Frame Decoder Denial of Service Vulnerability | Cisco UTD Snort IPS Engine Software for IOS XE,
|
4 Mar 2021 | VULN130 | GLPI : GLPI 9.5.4 fixes multiple security vulnerabilities | Systems running GLPI versions prior to 9.5.4.
|
3 Mar 2021 | VULN129 | (Apache : Apache Tomcat h2c request mix-up and Incomplete fix for CVE-2020-9484 (RCE via session persistence)) | Systems running Apache Tomcat versions prior to
|
3 Mar 2021 | VULN128 | (VMware : VMware View Planner update addresses remote code execution vulnerability (CVE-2021-21978)) | Systems running VMware View Planner versions prior
|
3 Mar 2021 | VULN127 | Google : Google Chrome 89.0.4389.72 fixes Multiple Vulnerabilities | Systems running Google Chrome versions prior to
|
3 Mar 2021 | VULN126 | Joomla! : Multiple Vulnerabilities fixed in Joomla! | Systems running Joomla! versions prior to 3.9.25.
|
26 Feb 2021 | STAT08 | |
|
26 Feb 2021 | VULN125 | Aruba : Multiple Vulnerabilities in dnsmasq | Aruba Mobility Controllers,
|
26 Feb 2021 | VULN124 | Aruba : AirWave Management Platform Multiple Vulnerabilities | Systems running AirWave Management Platform
|
26 Feb 2021 | VULN123 | Apache : Apache XML Graphics Batik SSRF vulnerability | Systems running Apache XML Graphics Batik versions
|
26 Feb 2021 | VULN122 | Apache : Apache XML Graphics Commons SSRF vulnerability | Systems running Apache XML Graphics Commons
|
26 Feb 2021 | VULN121 | Citrix : CTX296603 Citrix Hypervisor Security Update | Systems running Citrix Hypervisor all versions.
|
26 Feb 2021 | VULN120 | Cisco : Cisco Security Advisories Published on February 24, 2021 | Systems running Cisco Application Services Engine,
|
26 Feb 2021 | VULN119 | Node.js : (Update 23-Feb-2021) Security releases available | Systems running Node.js versions 15.x, 14.x, 12.x,
|
24 Feb 2021 | VULN118 | Apache : CVE-2021-26544 Apache Livy (Incubating) is vulnerable to cross site scripting | Systems running Apache Livy versions
|
24 Feb 2021 | VULN117 | (Vmware : VMware ESXi and vCenter Server updates address multiple security vulnerabilities (CVE-2021-21972, CVE-2021-21973, CVE-2021-21974)) | Systems running VMware ESXi versions prior to
|
23 Feb 2021 | VULN116 | Mozilla : Security Vulnerabilities fixed in Firefox 86 and ESR 78.8 | Systems running Mozilla Firefox versions prior to
|
23 Feb 2021 | VULN115 | Mozilla : Security Vulnerabilities fixed in Thunderbird 78.8 | Systems running Thunderbird versions prior to
|
23 Feb 2021 | VULN114 | Jenkins : Jenkins Security Advisory 2021-02-19 | Systems running Jenkins versions prior to 2.280.
|
23 Feb 2021 | VULN113 | Django : Django security releases issued 3.1.7, 3.0.13 and 2.2.19 | Systems running Django versions prior to 3.1.7,
|
19 Feb 2021 | STAT07 | |
|
19 Feb 2021 | VULN112 | Google : Google Chrome 88.0.4324.182 fix SQL multiple security vulnerabilities | Systems running Google Chrome versions prior to
|
19 Feb 2021 | VULN111 | LimeSurvey : LimeSurvey 4.4.9 build 210219 and 3.25.14 build 210218 fix SQL injections | Systems running LimeSurvey versions prior to
|
19 Feb 2021 | VULN110 | OpenSSL : Multiple security vulnerabilities fixed in OpenSSL | Systems running OpenSSL versions prior to 1.1.1j,
|
19 Feb 2021 | VULN109 | Horde : CVE 2021-26929 XSS vulnerability in Horde_Text_Filter | Systems running Horde_Text_Filter library versions
|
19 Feb 2021 | VULN108 | Xen : Multiple security vulnerabilities fixed | Systems running Xen.
|
19 Feb 2021 | VULN107 | Apache : CVE-2021-26296 Cross-Site Request Forgery (CSRF) vulnerability in Apache MyFaces | Systems running Apache MyFaces versions 2.2.0 up
|
19 Feb 2021 | VULN106 | Apache : Privilege Escalation Attack and missed authentication check fixed | Systems running Apache Airflow versions prior to
|
19 Feb 2021 | VULN105 | SPIP : Mise à jour CRITIQUE de sécurité sortie de SPIP 3.2.9 et SPIP 3.1.15 | Systems running SPIP versions prior to 3.2.9,
|
18 Feb 2021 | VULN104 | BIND : CVE-2020-8625 A vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack | Systems running BIND versions prior to 9.11.28,
|
18 Feb 2021 | VULN103 | Cisco : Cisco AnyConnect Secure Mobility Client for Windows with VPN Posture (HostScan) Module DLL Hijacking Vulnerability | Windows running Cisco AnyConnect Secure Mobility
|
16 Feb 2021 | VULN102 | WebKitGTK and WPE WebKit : WebKitGTK and WPE WebKit Security Advisory WSA-2021-0001 | Systems running WebKitGTK, WebKit versions prior
|
12 Feb 2021 | STAT06 | |
|
12 Feb 2021 | VULN101 | GitLab : GitLab Security Release 13.8.4, 13.7.7 and 13.6.7 | Systems running GitLab versions prior to 13.8.4,
|
12 Feb 2021 | VULN100 | Open vSwitch : CVE-2020-35498 Packet parsing vulnerability | Systems running Open vSwitch versions prior to
|
12 Feb 2021 | VULN099 | PostgreSQL : PostgreSQL 13.2, 12.6, 11.11, 10.16, 9.6.21, and 9.5.25 fixes information leak and Security restrictions bypass | Sstems running PostgreSQL versions prior to 13.2,
|
12 Feb 2021 | VULN098 | Apache : CVE-2020-13949 potential DoS when processing untrusted Thrift payloads | Systems running Apache Thrift versions prior to
|
12 Feb 2021 | VULN097 | Ruby on Rails : [CVE-2021-22881] Possible Open Redirect in Host Authorization Middleware | Systems running Rails versions prior to 6.1.2.1,
|
11 Feb 2021 | VULN096 | Cisco : Cisco IOS XR Software Slow Path Forwarding Denial of Service Vulnerability | Cisco IOS XR Software.
|
11 Feb 2021 | VULN095 | (VMware : vSphere Replication updates address a command injection vulnerability (CVE-2021-21976)) | Systems running VMware vSphere Replication
|
11 Feb 2021 | VULN094 | Apache : Remote unauthenticated denial-of-service in Subversion mod_authz_svn | Systems running Apache Subversion mod_authz_svn.
|
10 Feb 2021 | VULN093 | Microsoft : Microsoft Security Update Summary for February 9, 2021 | Systems running Microsoft Windows,
|
10 Feb 2021 | VULN092 | Adobe : Security updates available for Adobe Animate APSB21-11 | Systems running Adobe Animate versions prior to
|
10 Feb 2021 | VULN091 | Adobe : Security update available for Adobe Dreamweaver APSB21-13 | Systems running Adobe Dreamweaver versions prior
|
10 Feb 2021 | VULN090 | Adobe : Security Updates Available for Adobe Illustrator APSB21-12 | Systems running Adobe Illustrator versions prior
|
10 Feb 2021 | VULN089 | Adobe : Security updates available for Adobe Photoshop APSB21-10 | Windows, macOS running Adobe Photoshop versions
|
10 Feb 2021 | VULN088 | Adobe : Security Updates Available for Magento APSB21-08 | Systems Adobe Magento Commerce, Adobe Magento Open
|
10 Feb 2021 | VULN087 | Adobe : Security update available for Adobe Acrobat and Reader APSB21-09 | Systems Adobe Acrobat, Adobe Reader versions prior
|
9 Feb 2021 | VULN086 | SAP : SAP Security Patch Day – February 2021 | Systems running SAP Business Client,
|
9 Feb 2021 | VULN085 | MISP : MISP 2.4.137 fixes XSS and Weak default password change request policy vulnerabilities | Systems running MISP versions prior to 2.4.137.
|
9 Feb 2021 | VULN084 | (MediaWiki : MediaWiki Extensions and Skins Security Release Supplement (1.31.11/1.35.1)) | Systems running MediaWiki Extensions and Skins.
|
9 Feb 2021 | VULN083 | Roundcube : Roundcube Webmail Security updates | Systems running Roundcube Webmail versions prior
|
9 Feb 2021 | VULN082 | Apache : CVE-2020-13947 - XSS in WebConsole | Systems running Apache ActiveMQ versions prior to
|
9 Feb 2021 | VULN081 | Mozilla : Security Vulnerabilities fixed in Firefox 85.0.1 and Firefox ESR 78.7.1 | Systems running Firefox versions prior to 85.0.1,
|
5 Feb 2021 | STAT05 | |
|
5 Feb 2021 | VULN080 | Google : Google Chrome 88.0.4324.150 fixes Heap buffer overflow in V8 vulnerability | Systems running Google Chrome versions prior to
|
5 Feb 2021 | VULN079 | SOLARWINDS : Serv-U File Server 15.2.2 fixes multiple new securit Vulnerabilities | Systems running Serv-U File Server versions prior
|
5 Feb 2021 | VULN078 | SOLARWINDS : Orion Platform 2020.2.4 fix multiple new Vulnerabilities | Systems running Orion Platform versions prior to
|
5 Feb 2021 | VULN077 | NPMJS : jquerry and http-proxy-middelware Malicious Packages | Systems running jquerry versions 2.0.0,
|
5 Feb 2021 | VULN076 | wpa_supplicant : wpa_supplicant P2P group information processing vulnerability | Systems running wpa_supplicant versions prior to
|
4 Feb 2021 | VULN075 | Cisco : Cisco Webex Meetings and Cisco Webex Meetings Server Software Hyperlink Injection Vulnerability | Systems running Cisco Webex Meetings versions
|
4 Feb 2021 | VULN074 | IBM : IBM QRadar SIEM is vulnerable to using components ,with known vulnerabilities | Systems running IBM QRadar SIEM versions prior to
|
4 Feb 2021 | VULN073 | SonicWall : Confirmed Zero-day vulnerability in the SonicWall SMA100 build version 10.x | SMA 100 devices firmware versions prior to
|
4 Feb 2021 | VULN072 | Fortinet : Buffer overflow vulnerabilities in FortiProxy SSL VPN | Systems running FortiProxy versions prior to
|
4 Feb 2021 | VULN071 | Fortinet : XSS vulnerability in FortiWeb | Systems running FortiWeb versions prior to 6.3.8,
|
4 Feb 2021 | VULN070 | Cisco : Cisco IOS XR Software multiple security vulnerabilities | Cisco IOS XR Software versions prior to 6.7.3,
|
4 Feb 2021 | VULN069 | Cisco : Cisco Small Business multiple security vulnerabilities | Cisco Small Business VPN Routers software.
|
3 Feb 2021 | VULN068 | Google : Google Chrome 88.0.4324.146 fixes multiple security vulnerabilities | Systems running Google Chrome versions prior to
|
3 Feb 2021 | VULN067 | Open vSwitch : Open vSwitch 2.14.1, 2.13.2, 2.12.2, 2.11.5, 2.10.6, 2.9.8, 2.8.10, 2.7.12, 2.6.9 and 2.5.11 Available | Systems running Open vSwitch versions prior to
|
3 Feb 2021 | VULN066 | Docker : Docker Engine fixes security vulnerabilities | Systems running Docker Engine versions prior to
|
2 Feb 2021 | VULN065 | Apache : [CVE-2020-17523] Apache Shiro authentication bypass | Systems running Apache Shiro versions prior to
|
2 Feb 2021 | VULN064 | Apache : [CVE-2020-17516] Apache Cassandra internode encryption enforcement vulnerability | Systems running Apache Cassandra versions prior to
|
2 Feb 2021 | VULN063 | Foxit : Security updates available in Foxit PhantomPDF Mac 4.1.3 and Foxit Reader Mac 4.1.3 | Systems running Foxit versions prior to
|
2 Feb 2021 | VULN062 | GitLab : GitLab Security Release 13.8.2, 13.7.6 and 13.6.6 | Systems running GitLab versions prior to 13.8.2,
|
2 Feb 2021 | VULN061 | APPLE : APPLE-SA-2021-02-01-1 macOS Big Sur 11.2, Security Update 2021-001, Catalina, Security Update 2021-001 Mojave | macOS running versions prior to 11.2.
|
1 Feb 2021 | VULN060 | Wireshark : Wireshark 3.4.3 fix USB HID dissector vulnerabilities | Systems running Wireshark versions prior to 3.4.3.
|
1 Feb 2021 | VULN059 | Apache : [CVE-2021-25646] Apache Druid remote code execution vulnerability | Systems running Apache Druid versions prior to
|
1 Feb 2021 | VULN058 | Apache : CVE-2020-17533 Apache Accumulo Improper Handling of Insufficient Permissions | Systems running Apache Accumulo versions prior to
|
1 Feb 2021 | VULN057 | Django : Django security releases issued 3.1.6, 3.0.12, and 2.2.18 | Systems running Django versions prior to 3.1.6,
|
29 Jan 2021 | STAT04 | |
|
29 Jan 2021 | VULN056 | Go : Go 1.15.7 and Go 1.14.14 address arbitrary code execution vulnerability | Systems running Go versions prior to 1.15.7,
|
27 Jan 2021 | VULN055 | Apache : CVE-2021-26118: Flaw in ActiveMQ Artemis OpenWire support | Systems running Apache ActiveMQ versions prior to
|
27 Jan 2021 | VULN054 | APPLE : APPLE-SA-2021-01-26-2 tvOS 14.4 | tvOS versions prior to 14.4.
|
27 Jan 2021 | VULN053 | APPLE : APPLE-SA-2021-01-26-3 watchOS 7.3 | watchOS versions prior to 7.3.
|
27 Jan 2021 | VULN052 | APPLE : APPLE-SA-2021-01-26-4 Xcode 12.4 | Systems running Xcode versions prior to 12.4.
|
27 Jan 2021 | VULN051 | APPLE : APPLE-SA-2021-01-26-1 iOS 14.4 and iPadOS 14.4 | iOS, iPadOS versions prior to 14.4.
|
27 Jan 2021 | VULN050 | Mozilla : Security Vulnerabilities fixed in Thunderbird 78.7 | Systems running Thunderbird versions prior to
|
27 Jan 2021 | VULN049 | Mozilla : Security Vulnerabilities fixed in Firefox 85 and ESR 78.7 | Systems running Firefox versions prior to 85,
|
27 Jan 2021 | VULN048 | Sudo : Buffer overflow in command line unescaping | Systems running Sudo versions prior to 1.9.5p2.
|
26 Jan 2021 | VULN047 | Jenkins : Jenkins Security Advisory 2021-01-26 | Systems running Jenkins (core) versions prior to
|
26 Jan 2021 | VULN046 | Apache : CVE-2020-17522 Mid Tier Cache Manipulation Attack in Traffic Control | Systems running Apache Traffic Control versions
|
26 Jan 2021 | VULN045 | Apache : CVE-2020-9492. Apache Hadoop Potential privilege escalation | Systems running Apache Hadoop versions prior to
|
26 Jan 2021 | VULN044 | Mutt : Mutt 2.0.5 fixes memory leaks | Systems running Mutt versions prior to 2.0.5.
|
26 Jan 2021 | VULN043 | NPMJS : discordance, sonatype and an0n-chat-lib npm Malicious packages removed | Systems running discord-fix npm package,
|
25 Jan 2021 | VULN042 | Moodle : Multiple security vulnerabilities fixed in Moodle 3.10.1, 3.9.4, 3.8.7, 3.5.16 | Systems running Moodle versions prior to 3.10.1,
|
25 Jan 2021 | VULN041 | SaltStack : Active SaltStack CVE Announced 2021-JAN-21 | Systems running Salt versions 3002 and earlier.
|
22 Jan 2021 | STAT03 | |
|
22 Jan 2021 | VULN040 | VLC : Security Bulletin VLC 3.0.12 | Systems running VLC versions prior to 3.0.12.
|
21 Jan 2021 | VULN039 | PEAR : pear/Archive_Tar 1.4.12 fix Symlink out-of-path write vulnerability in Archive_Tar | Systems running pear/Archive_Tar versions prior to
|
21 Jan 2021 | VULN038 | Drupal : Drupal core - Critical - Third-party libraries - SA-CORE-2021-001 | Systems running Drupal core versions prior to
|
21 Jan 2021 | VULN037 | Xen : IRQ vector leak on x86 | Systems running Xen versions 4.12.3, 4.12.4,
|
21 Jan 2021 | VULN036 | US-CERT : Veritas Backup Exec is vulnerable to privilege escalation due to OPENSSLDIR location | Systems running Veritas Backup Exec versions prior
|
21 Jan 2021 | VULN035 | Cisco : Cisco Security Advisories Published on January 20, 2021 | Systems running Cisco SD-WAN software;
|
20 Jan 2021 | VULN034 | Oracle : January 2021 Critical Patch Update Released | Systems running Oracle Database Server,
|
20 Jan 2021 | VULN033 | Laminas Project : XSS and RCE vectors in laminas-api-tools/api-tools-documentation-swagger | Systems running
|
19 Jan 2021 | VULN032 | Cisco : Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerabilities | Cisco Small Business RV110W, RV130, RV130W,
|
19 Jan 2021 | VULN031 | Cisco : Multiple Vulnerabilities in dnsmasq DNS Forwarder Affecting Cisco Products January 2021 | Cisco software releases running Dnsmasq DNS
|
19 Jan 2021 | VULN030 | Dnsmasq : Security and release of dnsmasq-2.83 to fix multiple vulnerabilities | Systems running Dnsmasq versions prior to 2.83.
|
18 Jan 2021 | VULN029 | Apache : CVE-2020-11997 Inconsistent restriction of connection history visibility | Systems running Apache Guacamole versions prior to
|
15 Jan 2021 | STAT02 | |
|
14 Jan 2021 | VULN028 | Apache : CVE-2021-24122 Apache Tomcat Information Disclosure | Systems running Apache Tomcat versions prior to
|
14 Jan 2021 | VULN027 | Apache : CVE-2021-23926 XMLBeans XML Entity Expansion | Systems running XMLBeans versions prior to 3.0.0,
|
14 Jan 2021 | VULN026 | Cisco : Cisco Connected Mobile Experiences Privilege Escalation Vulnerability | Systems running Cisco Connected Mobile Experiences
|
14 Jan 2021 | VULN025 | Cisco : Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Vulnerabilities | Cisco Small Business RV132W, RV160, RV160W Routers
|
14 Jan 2021 | VULN024 | Cisco : Cisco AnyConnect Secure Mobility Client for Windows DLL Injection Vulnerability | Windows running Cisco AnyConnect Secure Mobility
|
13 Jan 2021 | VULN023 | Aruba : AirWave Glass Multiple Vulnerabilities | Systems running AirWave Glass versions prior to
|
13 Jan 2021 | VULN022 | Jenkins : Jenkins Security Advisory 2021-01-13 | Systems running Jenkins (core) versions prior to
|
13 Jan 2021 | VULN021 | Microsoft : Microsoft Security Update Summary for January 12, 2021 | Systems running Microsoft Windows,
|
13 Jan 2021 | VULN020 | Node.js : January 2021 Security Releases | Systems running Node.js versions prior to 10.23.1
|
13 Jan 2021 | VULN019 | SAP : SAP Security Patch Day – December 2020 | Systems running SAP AS ABAP(DMIS),
|
12 Jan 2021 | VULN018 | Fortinet : FortiDeceptor is impacted by an OS command injection vulnerability | Systems running FortiDeceptor versions
|
12 Jan 2021 | VULN017 | Fortinet : FortiGate SSL VPN logs may display events of users in a different VDOM | Systems running FortiGate versions prior to 6.0.11,
|
12 Jan 2021 | VULN016 | Fortinet : FortiWeb unauthorized Execution of code or commands and DoS vulnerabilities | Systems running FortiWeb versions prior to 6.3.8,
|
12 Jan 2021 | VULN015 | Adobe : Security hotfix available for Adobe Captivate APSB21-06 | Windows running Adobe Captivate versions 2019 up to
|
12 Jan 2021 | VULN014 | Adobe : Security Update Available for Adobe InCopy APSB21-05 | Windows running Adobe InCopy versions prior to 16.0.
|
12 Jan 2021 | VULN013 | Adobe : Security Updates Available for Adobe Bridge APSB21-07 | Windows, macOS running Adobe Bridge versions prior
|
12 Jan 2021 | VULN012 | Adobe : Security updates available for Adobe Animate APSB21-03 | Windows, macOS running Adobe Animate versions prior
|
12 Jan 2021 | VULN011 | Adobe : Security Updates Available for Adobe Illustrator APSB21-02 | Windows, macOS running Adobe Illustrator versions
|
12 Jan 2021 | VULN010 | Adobe : Security updates available for Adobe Photoshop APSB21-01 | Windows, macOS running Adobe Photoshop versions
|
12 Jan 2021 | VULN009 | Kubernetes : CVE-2020-8570 Path Traversal bug in the Java Kubernetes Client | Systems running Kubernetes Java Client versions
|
12 Jan 2021 | VULN008 | Mozilla : Security Vulnerabilities fixed in Thunderbird 78.6.1 | Systems running Thunderbird versions prior to
|
11 Jan 2021 | VULN007 | Google : Chrome 87.0.4280.141 fixes multiple security vulnerabilities | Systems running Chrome versions prior to
|
11 Jan 2021 | VULN006 | Firefox : Security Vulnerabilities fixed in Firefox 84.0.2, Firefox for Android 84.1.3, and Firefox ESR 78.6.1 | Systems running Firefox versions prior to 84.0.2,
|
11 Jan 2021 | VULN005 | QNAP : Command Injection Vulnerability in QTS and QuTS hero | Systems runningQTS versions prior to 4.5.1.1456
|
11 Jan 2021 | VULN004 | PHP : Input validation vulnerability fixed in PHP 7.4.14, 7.3.26 | Systems running PHP versions prior to 7.4.14,
|
11 Jan 2021 | VULN003 | GitLab : GitLab Security Release: 13.7.2, 13.6.4, and 13.5.6 | Systems running GitLab versions prior to 13.7.2,
|
11 Jan 2021 | VULN002 | Dovecot : Improper Neutralization of Escape and Input Validation vulnerabilities | Systems running Dovecot versions prior to 2.3.13.
|
11 Jan 2021 | VULN001 | Sudo : Symbolic link attack in SELinux-enabled sudoedit | Systems running Sudo versions prior to 1.9.5.
|
8 Jan 2021 | STAT01 | |
|