Latest CVE Feed
-
9.8
CRITICALCVE-2021-45331
An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for the 2FA can be submitted correctly more than once.... Read more
Affected Products : gitea- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45330
An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse.... Read more
Affected Products : gitea- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-45329
Cross Site Scripting (XSS) vulnerability exists in Gitea before 1.5.1 via the repository settings inside the external wiki/issue tracker URL field.... Read more
Affected Products : gitea- Published: Feb. 08, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-45328
Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.... Read more
Affected Products : gitea- Published: Feb. 08, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45327
Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. which could let a remote malisious user execute arbitrary code.... Read more
Affected Products : gitea- Published: Feb. 08, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-45326
Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state altering POST requests.... Read more
Affected Products : gitea- Published: Feb. 08, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45325
Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL.... Read more
Affected Products : gitea- Published: Feb. 08, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-45310
Sangoma Technologies Corporation Switchvox Version 102409 is affected by an information disclosure vulnerability due to an improper access restriction. Users information such as first name, last name, acount id, server uuid, email address, profile image, ... Read more
Affected Products : switchvox- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45297
An infinite loop vulnerability exists in Gpac 1.0.1 in gf_get_bit_size.... Read more
Affected Products : gpac- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45293
A Denial of Service vulnerability exists in Binaryen 103 due to an Invalid memory address dereference in wasm::WasmBinaryBuilder::visitLet.... Read more
- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45292
The gf_isom_hint_rtp_read function in GPAC 1.0.1 allows attackers to cause a denial of service (Invalid memory address dereference) via a crafted file in the MP4Box command.... Read more
Affected Products : gpac- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45291
The gf_dump_setup function in GPAC 1.0.1 allows malicoius users to cause a denial of service (Invalid memory address dereference) via a crafted file in the MP4Box command.... Read more
Affected Products : gpac- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45290
A Denial of Service vulnerability exits in Binaryen 103 due to an assertion abort in wasm::handle_unreachable.... Read more
- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45289
A vulnerability exists in GPAC 1.0.1 due to an omission of security-relevant Information, which could cause a Denial of Service. The program terminates with signal SIGKILL.... Read more
Affected Products : gpac- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45288
A Double Free vulnerability exists in filedump.c in GPAC 1.0.1, which could cause a Denail of Service via a crafted file in the MP4Box command.... Read more
Affected Products : gpac- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-45286
Directory Traversal vulnerability exists in ZZCMS 2021 via the skin parameter in 1) index.php, 2) bottom.php, and 3) top_index.php.... Read more
Affected Products : zzcms- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-45281
QuickBox Pro v2.4.8 contains a cross-site scripting (XSS) vulnerability at "adminuseredit.php?usertoedit=XSS", as the user supplied input for the value of this parameter is not properly sanitized.... Read more
Affected Products : quickbox- Published: Feb. 07, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-45268
A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading a maliciously add-on with crafted PHP file. NOTE: the vendor disputes t... Read more
- Published: Feb. 03, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45267
An invalid memory address dereference vulnerability exists in gpac 1.1.0 via the svg_node_start function, which causes a segmentation fault and application crash.... Read more
Affected Products : gpac- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45266
A null pointer dereference vulnerability exists in gpac 1.1.0 via the lsr_read_anim_values_ex function, which causes a segmentation fault and application crash.... Read more
Affected Products : gpac- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024