CVEs (354)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apache FedoraprojectOracle19Banking Corporate Lending Process Management Banking Credit Facilities Process ManagementBanking Supply Chain Finance+16 moreNov 21, 2024 Mar 19, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions. |
3Fedoraproject OraclePython3Fedora Peoplesoft Enterprise PeopletoolsUrllib3Nov 21, 2024 Mar 15, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn't given via proxy_confi...Show more |
5Fedoraproject NetappNodejs+2 more13Active Iq Unified Manager E Series Performance AnalyzerFedora+10 moreNov 21, 2024 Mar 3, 2021 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is r...Show more |
5Fedoraproject NetappNodejs+2 more9E Series Performance Analyzer FedoraGraalvm+6 moreNov 21, 2024 Mar 3, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If...Show more |
2Json Smart Project Oracle7Communications Cloud Native Core Policy Json Smart V1Json Smart V2+4 moreNov 21, 2024 Feb 23, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not ca...Show more |
7Apple DebianNetapp+4 more23Business Intelligence Communications Cloud Native Core PolicyDebian Linux+20 moreNov 21, 2024 Feb 16, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle a...Show more |
4Lodash NetappOracle+1 more23Active Iq Unified Manager Banking Corporate Lending Process ManagementBanking Credit Facilities Process Management+20 moreNov 21, 2024 Feb 15, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. |
3Lodash OracleSiemens19Banking Corporate Lending Process Management Banking Credit Facilities Process ManagementBanking Extensibility Workbench+16 moreNov 21, 2024 Feb 15, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. |
1Oracle 1Peoplesoft Enterprise Peopletools Nov 21, 2024 Jan 20, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search). Supported versions that are affected are 8.56, 8.57 and 8.58. Difficult to exploit vulnerability allows una...Show more |
1Oracle 1Peoplesoft Enterprise Peopletools Nov 21, 2024 Jan 20, 2021 N/A· v4 8.4 HIGH· v3 4.6 MEDIUM· v2 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticat...Show more |
1Oracle 1Peoplesoft Enterprise Peopletools Nov 21, 2024 Jan 20, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticat...Show more |
4Apache DebianNetapp+1 more7Debian Linux Middleware Common Libraries And ToolsOncommand Unified Manager Core Package+4 moreNov 21, 2024 Jan 14, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBean...Show more |
3Apache BouncycastleOracle20Banking Corporate Lending Process Management Banking Credit Facilities Process ManagementBanking Extensibility Workbench+17 moreMay 12, 2025 Dec 18, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate th...Show more |
8Apple DebianFedoraproject+5 more17Clustered Data Ontap Communications Billing And Revenue ManagementCommunications Cloud Native Core Policy+14 moreNov 21, 2024 Dec 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response. |
9Apple DebianFedoraproject+6 more22Clustered Data Ontap Communications Billing And Revenue ManagementCommunications Cloud Native Core Policy+19 moreApr 16, 2026 Dec 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing. |
9Apple DebianFedoraproject+6 more22Clustered Data Ontap Communications Billing And Revenue ManagementCommunications Cloud Native Core Policy+19 moreApr 16, 2026 Dec 14, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherw...Show more |
4Google NetappOracle+1 more13Active Iq Unified Manager Commerce Guided SearchCommunications Cloud Native Core Network Repository Function+10 moreFeb 23, 2026 Dec 10, 2020 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.F...Show more |
8Debian FedoraprojectNetapp+5 more44Active Iq Unified Manager Aff A250 FirmwareApi Gateway+41 moreMay 29, 2026 Dec 8, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of...Show more |
4Apache NetappOracle+1 more17Active Iq Unified Manager Commerce Guided SearchCommunications Cloud Native Core Service Communication Proxy+14 moreDec 1, 2025 Dec 2, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request executio...Show more |
2Ckeditor Oracle9Agile Plm Application ExpressBanking Party Management+6 moreNov 21, 2024 Nov 12, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor...Show more |