Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2021-10-05 CVE-2021-39226 Missing Authorization vulnerability in multiple products
Grafana is an open source data visualization platform.
network
low complexity
grafana fedoraproject CWE-862
7.3
2021-10-05 CVE-2021-35491 Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine
A Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine through 4.8.11+5 allows a remote attacker to delete a user account via the /enginemanager/server/user/delete.htm userName parameter.
network
low complexity
wowza CWE-352
8.1
2021-10-05 CVE-2021-41286 Improper Authentication vulnerability in Omikron Multicash 4.00.008
Omikron MultiCash Desktop 4.00.008.SP5 relies on a client-side authentication mechanism.
local
low complexity
omikron CWE-287
7.8
2021-10-05 CVE-2021-41554 Missing Authorization vulnerability in Archibus web Central 21.3.3.815
ARCHIBUS Web Central 21.3.3.815 (a version from 2014) does not properly validate requests for access to data and functionality in these affected endpoints: /archibus/schema/ab-edit-users.axvw, /archibus/schema/ab-data-dictionary-table.axvw, /archibus/schema/ab-schema-add-field.axvw, /archibus/schema/ab-core/views/process-navigator/ab-my-user-profile.axvw.
network
low complexity
archibus CWE-862
8.8
2021-10-05 CVE-2021-39867 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.
network
low complexity
gitlab CWE-918
8.1
2021-10-05 CVE-2021-39893 Missing Authorization vulnerability in Gitlab
A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.
network
low complexity
gitlab CWE-862
7.5
2021-10-05 CVE-2021-35504 Injection vulnerability in Afian Filerun
Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the ffmpeg binary.
network
low complexity
afian CWE-74
7.2
2021-10-05 CVE-2021-35505 Injection vulnerability in Afian Filerun
Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the magick binary.
network
low complexity
afian CWE-74
7.2
2021-10-05 CVE-2021-41524 NULL Pointer Dereference vulnerability in multiple products
While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server.
network
low complexity
apache fedoraproject oracle netapp CWE-476
7.5
2021-10-05 CVE-2021-41773 Path Traversal vulnerability in multiple products
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49.
network
low complexity
apache fedoraproject oracle netapp CWE-22
7.5