Latest CVE Feed
-
9.8
CRITICALCVE-2021-25992
In Ifme, versions 1.0.0 to v.7.33.2 don’t properly invalidate a user’s session even after the user initiated logout. It makes it possible for an attacker to reuse the admin cookies either via local/network access or by other hypothetical attacks.... Read more
Affected Products : ifme- EPSS Score: %0.38
- Published: Feb. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25952
Prototype pollution vulnerability in ‘just-safe-set’ versions 1.0.0 through 2.2.1 allows an attacker to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : just-safe-set- EPSS Score: %2.95
- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25947
Prototype pollution vulnerability in 'nestie' versions 0.0.0 through 1.0.0 allows an attacker to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : nestie- EPSS Score: %2.54
- Published: Jun. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25946
Prototype pollution vulnerability in `nconf-toml` versions 0.0.1 through 0.0.2 allows an attacker to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : nconf-toml- EPSS Score: %2.95
- Published: May. 25, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25928
Prototype pollution vulnerability in 'safe-obj' versions 1.0.0 through 1.0.2 allows an attacker to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : safe-obj- EPSS Score: %3.35
- Published: Apr. 26, 2021
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2021-25914
Prototype pollution vulnerability in 'object-collider' versions 1.0.0 through 1.0.3 allows attacker to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : object-collider- EPSS Score: %3.23
- Published: Mar. 01, 2021
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2021-25912
Prototype pollution vulnerability in 'dotty' versions 0.0.1 through 0.1.0 allows attackers to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : dotty- EPSS Score: %2.95
- Published: Feb. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25915
Prototype pollution vulnerability in 'changeset' versions 0.0.1 through 0.2.5 allows an attacker to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : changeset- EPSS Score: %2.95
- Published: Mar. 09, 2021
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2021-25827
Emby Server < 4.7.12.0 is vulnerable to a login bypass attack by setting the X-Forwarded-For header to a local IP-address.... Read more
Affected Products : emby- EPSS Score: %0.30
- Published: Jun. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25944
Prototype pollution vulnerability in 'deep-defaults' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : deep-defaults- EPSS Score: %2.54
- Published: May. 25, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25927
Prototype pollution vulnerability in 'safe-flat' versions 2.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : safe-flat- EPSS Score: %3.23
- Published: Apr. 26, 2021
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2021-25770
In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution.... Read more
Affected Products : youtrack- EPSS Score: %0.02
- Published: Feb. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25668
A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT PRO (All versions < 5.5.1), SCALANCE X202-2 IRT (All versions < 5.5.1), SCALANCE X202-2P IRT (incl. SIPLU... Read more
Affected Products : scalance_x200-4p_irt_firmware scalance_x201-3p_irt_firmware scalance_x201-3p_irt_pro_firmware scalance_x202-2p_irt_firmware scalance_x202-2p_irt_pro_firmware scalance_xf201-3p_irt_firmware scalance_xf202-2p_irt_firmware scalance_xf204-2ba_irt_firmware scalance_x202-2_irt_firmware scalance_x204_irt_firmware +48 more products- EPSS Score: %0.54
- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25434
Improper input validation vulnerability in Tizen bootloader prior to Firmware update JUL-2021 Release allows arbitrary code execution using param partition in wireless firmware download mode.... Read more
Affected Products : tizen- EPSS Score: %1.10
- Published: Jul. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25436
Improper input validation vulnerability in Tizen FOTA service prior to Firmware update JUL-2021 Release allows arbitrary code execution via Samsung Accessory Protocol.... Read more
Affected Products : tizen- EPSS Score: %1.10
- Published: Jul. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25385
An improper input validation vulnerability in sdfffd_parse_chunk_PROP() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.... Read more
- EPSS Score: %0.19
- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25384
An improper input validation vulnerability in sdfffd_parse_chunk_PROP() with Sample Rate Chunk in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.... Read more
- EPSS Score: %0.15
- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25386
An improper input validation vulnerability in sdfffd_parse_chunk_FVER() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.... Read more
- EPSS Score: %0.19
- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25283
An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks.... Read more
- EPSS Score: %7.44
- Published: Feb. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25281
An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the master.... Read more
- EPSS Score: %94.01
- Published: Feb. 27, 2021
- Modified: Nov. 21, 2024