Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2021-09-03 CVE-2021-23437 Out-of-bounds Read vulnerability in multiple products
The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
network
low complexity
python fedoraproject CWE-125
7.5
2021-09-03 CVE-2021-39192 Improper Privilege Management vulnerability in Ghost
Ghost is a Node.js content management system.
network
low complexity
ghost CWE-269
7.2
2021-09-03 CVE-2021-40490 Race Condition vulnerability in multiple products
A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13.
local
high complexity
linux fedoraproject debian netapp CWE-362
7.0
2021-09-02 CVE-2020-13929 Unspecified vulnerability in Apache Zeppelin
Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to act as another user.
network
low complexity
apache
7.5
2021-09-02 CVE-2021-22775 Unspecified vulnerability in Schneider-Electric Gp-Pro EX
A CWE-427: Uncontrolled Search Path Element vulnerability exists in GP-Pro EX,V4.09.250 and prior, that could cause local code execution with elevated privileges when installing the software.
local
low complexity
schneider-electric
7.8
2021-09-02 CVE-2021-22792 Unspecified vulnerability in Schneider-Electric products
A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (part numbers BMKC80*, all versions), Modicon Momentum Ethernet CPU (part numbers 171CBU*, all versions), PLC Simulator for EcoStruxureª Control Expert, including all Unity Pro versions (former name of EcoStruxureª Control Expert, all versions), PLC Simulator for EcoStruxureª Process Expert including all HDCS versions (former name of EcoStruxureª Process Expert, all versions), Modicon Quantum CPU (part numbers 140CPU*, all versions), Modicon Premium CPU (part numbers TSXP5*, all versions).
network
low complexity
schneider-electric
7.5
2021-09-02 CVE-2021-22793 Unspecified vulnerability in Schneider-Electric products
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exist in AccuSine PCS+ / PFV+ (Versions prior to V1.6.7) and AccuSine PCSn (Versions prior to V2.2.4) that could allow an authenticated attacker to access the device via FTP protocol.
network
low complexity
schneider-electric
7.2
2021-09-02 CVE-2021-28550 Use After Free vulnerability in Adobe products
Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Use After Free vulnerability.
network
low complexity
adobe CWE-416
8.8
2021-09-02 CVE-2021-28553 Unspecified vulnerability in Adobe products
Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Use After Free vulnerability.
network
low complexity
adobe
8.8
2021-09-02 CVE-2021-28565 Unspecified vulnerability in Adobe products
Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Out-of-bounds Read vulnerability in the PDFLibTool component.
network
low complexity
adobe
8.8