Latest CVE Feed
-
4.3
MEDIUMCVE-2021-41273
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. Due to improperly configured CSRF protections on two routes, a malicious user could execute a CSRF-based attack against the following endpoints: Sending a test ema... Read more
Affected Products : panel- Published: Nov. 17, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41272
Besu is an Ethereum client written in Java. Starting in version 21.10.0, changes in the implementation of the SHL, SHR, and SAR operations resulted in the introduction of a signed type coercion error in values that represent negative values for 32 bit sig... Read more
Affected Products : besu- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-41271
Discourse is a platform for community discussion. In affected versions a maliciously crafted request could cause an error response to be cached by intermediate proxies. This could cause a loss of confidentiality for some content. This issue is patched in ... Read more
Affected Products : discourse- Published: Nov. 15, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-41270
Symfony/Serializer handles serializing and deserializing data structures for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Symfony versions 4.1.0 before 4.4.35 and versions 5.0.0 before 5.3.12 are vulnerab... Read more
- Published: Nov. 24, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-41269
cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for them. In affected versions A template Injection was identified in cron-utils enabling attackers to inject arbitrary Java EL expressions, ... Read more
Affected Products : cron-utils- Published: Nov. 15, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-41268
Symfony/SecurityBundle is the security system for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Since the rework of the Remember me cookie in version 5.3.0, the cookie is not invalidated when the user chan... Read more
Affected Products : symfony- Published: Nov. 24, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-41267
Symfony/Http-Kernel is the HTTP kernel component for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Headers that are not part of the "trusted_headers" allowed list are ignored and protect users from "Cache ... Read more
Affected Products : symfony- Published: Nov. 24, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41266
Minio console is a graphical user interface for the for MinIO operator. Minio itself is a multi-cloud object storage project. Affected versions are subject to an authentication bypass issue in the Operator Console when an external IDP is enabled. All user... Read more
- Published: Nov. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41264
OpenZeppelin Contracts is a library for smart contract development. In affected versions upgradeable contracts using `UUPSUpgradeable` may be vulnerable to an attack affecting uninitialized implementation contracts. A fix is included in version 4.3.2 of `... Read more
- Published: Nov. 12, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-41263
rails_multisite provides multi-db support for Rails applications. In affected versions this vulnerability impacts any Rails applications using `rails_multisite` alongside Rails' signed/encrypted cookies. Depending on how the application makes use of these... Read more
Affected Products : rails_multisite- Published: Nov. 15, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-41262
Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 are subject to SQL injection attacks by users with "member" privilege. Users are advised to upgrade to version 0.9.6 as... Read more
Affected Products : galette- Published: Dec. 16, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-41261
Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 are subject to stored cross site scripting attacks via the preferences footer. The preference footer can only be altere... Read more
Affected Products : galette- Published: Dec. 16, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-41260
Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 do not check for Cross Site Request Forgery attacks. All users are advised to upgrade to 0.9.6 as soon as possible. The... Read more
Affected Products : galette- Published: Dec. 16, 2021
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2021-41258
Kirby is an open source file structured CMS. In affected versions Kirby's blocks field stores structured data for each block. This data is then used in block snippets to convert the blocks to HTML for use in your templates. We recommend to escape HTML spe... Read more
Affected Products : kirby- Published: Nov. 16, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-41256
nextcloud news-android is an Android client for the Nextcloud news/feed reader app. In affected versions the Nextcloud News for Android app has a security issue by which a malicious application installed on the same device can send it an arbitrary Intent ... Read more
Affected Products : news- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-41254
kustomize-controller is a Kubernetes operator, specialized in running continuous delivery pipelines for infrastructure and workloads defined with Kubernetes manifests and assembled with Kustomize. Users that can create Kubernetes Secrets, Service Accounts... Read more
Affected Products : kustomize-controller- Published: Nov. 12, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-41253
Zydis is an x86/x86-64 disassembler library. Users of Zydis versions v3.2.0 and older that use the string functions provided in `zycore` in order to append untrusted user data to the formatter buffer within their custom formatter hooks can run into heap b... Read more
Affected Products : zydis- Published: Nov. 08, 2021
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2021-41252
Kirby is an open source file structured CMS ### Impact Kirby's writer field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwis... Read more
Affected Products : kirby- Published: Nov. 16, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-41251
@sap-cloud-sdk/core contains the core functionality of the SAP Cloud SDK as well as the SAP Business Technology Platform abstractions. This affects applications on SAP Business Technology Platform that use the SAP Cloud SDK and enabled caching of destinat... Read more
Affected Products : cloud_sdk- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-41250
Python discord bot is the community bot for the Python Discord community. In affected versions when a non-blacklisted URL and an otherwise triggering filter token is included in the same message the token filter does not trigger. This means that by includ... Read more
Affected Products : bot- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024