Latest CVE Feed
-
9.8
CRITICALCVE-2021-39214
mitmproxy is an interactive, SSL/TLS-capable intercepting proxy. In mitmproxy 7.0.2 and below, a malicious client or server is able to perform HTTP request smuggling attacks through mitmproxy. This means that a malicious client/server could smuggle a requ... Read more
Affected Products : mitmproxy- EPSS Score: %0.19
- Published: Sep. 16, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-39213
GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest enabled is vulnerable to API bypass with custom header injection. This issue is fixed in version 9.5.6. One may disable API Res... Read more
Affected Products : glpi- EPSS Score: %0.35
- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-39212
ImageMagick is free software delivered as a ready-to-run binary distribution or as source code that you may use, copy, modify, and distribute in both open and proprietary applications. In affected versions and in certain cases, Postscript files could be r... Read more
Affected Products : imagemagick- EPSS Score: %0.02
- Published: Sep. 13, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-39211
GLPI is a free Asset and IT management software package. Starting in version 9.2 and prior to version 9.5.6, the telemetry endpoint discloses GLPI and server information. This issue is fixed in version 9.5.6. As a workaround, remove the file `ajax/telemet... Read more
Affected Products : glpi- EPSS Score: %54.40
- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-39210
GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses the "remember me" feature) is accessible by scripts. A malicious plugin that could steal this cookie would... Read more
Affected Products : glpi- EPSS Score: %0.33
- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-39209
GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, a user who is logged in to GLPI can bypass Cross-Site Request Forgery (CSRF) protection in many places. This could allow a malicious actor to perform many actions on GLPI... Read more
Affected Products : glpi- EPSS Score: %0.14
- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-39208
SharpCompress is a fully managed C# library to deal with many compression types and formats. Versions prior to 0.29.0 are vulnerable to partial path traversal. SharpCompress recreates a hierarchy of directories under destinationDirectory if ExtractFullPat... Read more
Affected Products : sharpcompress- EPSS Score: %0.43
- Published: Sep. 16, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-39207
parlai is a framework for training and evaluating AI models on a variety of openly available dialogue datasets. In affected versions the package is vulnerable to YAML deserialization attack caused by unsafe loading which leads to Arbitary code execution. ... Read more
Affected Products : parlai- EPSS Score: %1.35
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-39206
Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, contains two authorization related vulnerabilities CVE-2021-32777 and CVE-2021-32779. This may lead to incorrect routing or authorization policy decisions. With spe... Read more
- EPSS Score: %0.16
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-39205
Jitsi Meet is an open source video conferencing application. Versions prior to 2.0.6173 are vulnerable to client-side cross-site scripting via injecting properties into JSON objects that were not properly escaped. There are no known incidents related to t... Read more
Affected Products : jitsi_meet- EPSS Score: %0.41
- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-39204
Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, incorrectly handles resetting of HTTP/2 streams with excessive complexity. This can lead to high CPU utilization when a large number of streams are reset. This can ... Read more
- EPSS Score: %0.41
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-39203
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authenticated users who don't have permission to view private post types/data can bypass restrictions in the blo... Read more
Affected Products : wordpress- EPSS Score: %0.80
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2021-39202
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the widgets editor introduced in WordPress 5.8 beta 1 has improper handling of HTML input in the Custom HTML fea... Read more
Affected Products : wordpress- EPSS Score: %0.90
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2021-39201
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor. This byp... Read more
- EPSS Score: %0.20
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-39200
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions, which can include data like nonces.... Read more
- EPSS Score: %1.28
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-39199
remark-html is an open source nodejs library which compiles Markdown to HTML. In affected versions the documentation of remark-html has mentioned that it was safe by default. In practice the default was never safe and had to be opted into. That is, user i... Read more
Affected Products : remark-html- EPSS Score: %0.33
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2021-39198
OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an attacker is able to disqualify any Lead with a Cross-Site Request Forgery (CSRF) attack. There are no worka... Read more
Affected Products : client_relationship_management- EPSS Score: %0.11
- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-39197
better_errors is an open source replacement for the standard Rails error page with more information rich error pages. It is also usable outside of Rails in any Rack app as Rack middleware. better_errors prior to 2.8.0 did not implement CSRF protection for... Read more
Affected Products : better_errors- EPSS Score: %0.21
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
7.7
HIGHCVE-2021-39196
pcapture is an open source dumpcap web service interface . In affected versions this vulnerability allows an authenticated but unprivileged user to use the REST API to capture and download packets with no capture filter and without adequate permissions. T... Read more
Affected Products : pcapture- EPSS Score: %0.21
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
7.7
HIGHCVE-2021-39195
Misskey is an open source, decentralized microblogging platform. In affected versions a Server-Side Request Forgery vulnerability exists in "Upload from URL" and remote attachment handling. This could result in the disclosure of non-public information wit... Read more
Affected Products : misskey- EPSS Score: %0.24
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024