Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In September 2021
Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.
CVSS Score
9.8
EPSS Score
0.003
Published
2021-09-22
CVE-2021-36260
Known exploited
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.
CVSS Score
9.8
EPSS Score
0.944
Published
2021-09-22
MaianAffiliate v1.0 allows an authenticated administrative user to save an XSS to the database.
CVSS Score
4.8
EPSS Score
0.003
Published
2021-09-22
A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special template characters. This flaw allows attackers to perform command injection, which discloses sensitive information. The highest threat from this vulnerability is to confidentiality and integrity.
CVSS Score
7.1
EPSS Score
0.004
Published
2021-09-22
The Telefication WordPress plugin is vulnerable to Open Proxy and Server-Side Request Forgery via the ~/bypass.php file due to a user-supplied URL request value that gets called by a curl requests. This affects versions up to, and including, 1.8.0.
CVSS Score
5.8
EPSS Score
0.002
Published
2021-09-22
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.
CVSS Score
5.9
EPSS Score
0.009
Published
2021-09-22
In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on systems that already trust each other based on certificate verification.
CVSS Score
9.8
EPSS Score
0.014
Published
2021-09-22
In the Amazon AWS WorkSpaces client 3.0.10 through 3.1.8 on Windows, argument injection in the workspaces:// URI handler can lead to remote code execution because of the Chromium Embedded Framework (CEF) --gpu-launcher argument. This is fixed in 3.1.9.
CVSS Score
8.8
EPSS Score
0.285
Published
2021-09-22
Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface.
CVSS Score
7.5
EPSS Score
0.139
Published
2021-09-22
An issue was discovered in gpac 0.8.0. The OD_ReadUTF8String function in odf_code.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted media file.
CVSS Score
5.5
EPSS Score
0.002
Published
2021-09-22


Contact Us

Shodan ® - All rights reserved