Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2021-06-08 CVE-2021-22212 Use of a Broken or Risky Cryptographic Algorithm vulnerability in multiple products
ntpkeygen can generate keys that ntpd fails to parse.
network
high complexity
ntpsec fedoraproject CWE-327
7.4
2021-06-08 CVE-2021-22116 Improper Input Validation vulnerability in multiple products
RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection endpoint.
network
low complexity
vmware debian CWE-20
7.5
2021-06-08 CVE-2021-23169 A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1.
network
low complexity
openexr fedoraproject
8.8
2021-06-08 CVE-2021-33560 Information Exposure Through Discrepancy vulnerability in multiple products
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately.
network
low complexity
gnupg debian fedoraproject oracle CWE-203
7.5
2021-06-08 CVE-2021-23392 Unspecified vulnerability in Locutus
The package locutus before 2.0.15 are vulnerable to Regular Expression Denial of Service (ReDoS) via the gopher_parsedir function.
network
low complexity
locutus
7.5
2021-06-08 CVE-2021-28810 Unspecified vulnerability in Qnap Roon Server
If exploited, this vulnerability allows an attacker to access resources which are not otherwise accessible without proper authentication.
network
low complexity
qnap
7.5
2021-06-08 CVE-2021-28811 Command Injection vulnerability in Roonlabs Roon Server 20210201
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands.
network
low complexity
roonlabs CWE-77
7.2
2021-06-07 CVE-2021-3277 Unrestricted Upload of File with Dangerous Type vulnerability in Nagios XI
Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rename functionality in custom-includes component, which leads to remote code execution by uploading php files.
network
low complexity
nagios CWE-434
7.2
2021-06-07 CVE-2020-25716 Unspecified vulnerability in Redhat Cloudforms
A flaw was found in Cloudforms.
network
low complexity
redhat
8.1
2021-06-07 CVE-2021-20259 Unspecified vulnerability in Theforeman Foremanfogproxmox
A flaw was found in the Foreman project.
local
low complexity
theforeman
7.8