Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.8

    HIGH
    CVE-2021-39173

    Cachet is an open source status page system. Prior to version 2.5.1 authenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. This issue was add... Read more

    Affected Products : catchet cachet
    • EPSS Score: %1.13
    • Published: Aug. 27, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-39172

    Cachet is an open source status page system. Prior to version 2.5.1, authenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code ex... Read more

    Affected Products : catchet cachet
    • EPSS Score: %56.66
    • Published: Aug. 27, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-39171

    Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. Prior to version 3.1.0, a malicious SAML payload can require transforms that consume significant system resources to process, thereby resulting in reduce... Read more

    Affected Products : passport-saml
    • EPSS Score: %0.36
    • Published: Aug. 27, 2021
    • Modified: Nov. 21, 2024
  • 8.0

    HIGH
    CVE-2021-39170

    Pimcore is an open source data & experience management platform. Prior to version 10.1.2, an authenticated user could add XSS code as a value of custom metadata on assets. There is a patch for this issue in Pimcore version 10.1.2. As a workaround, users m... Read more

    Affected Products : pimcore
    • EPSS Score: %0.01
    • Published: Sep. 01, 2021
    • Modified: Nov. 21, 2024
  • 8.0

    HIGH
    CVE-2021-39169

    Misskey is a decentralized microblogging platform. In versions of Misskey prior to 12.51.0, malicious actors can use the web client built-in dialog to display a malicious string, leading to cross-site scripting (XSS). XSS could compromise the API request ... Read more

    Affected Products : misskey
    • EPSS Score: %0.36
    • Published: Aug. 27, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2021-39168

    OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executor role to escalate privileges. Further details about the vulnerability will be disclosed at a later date. ... Read more

    • EPSS Score: %0.44
    • Published: Aug. 27, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2021-39167

    OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executor role to escalate privileges. Further details about the vulnerability will be disclosed at a later date. ... Read more

    Affected Products : contracts openzeppelin_contracts
    • EPSS Score: %0.44
    • Published: Aug. 27, 2021
    • Modified: Nov. 21, 2024
  • 8.0

    HIGH
    CVE-2021-39166

    Pimcore is an open source data & experience management platform. Prior to version 10.1.2, text-values were not properly escaped before printed in the version preview. This allowed XSS by authenticated users with access to the resources. This issue is patc... Read more

    Affected Products : pimcore
    • EPSS Score: %0.01
    • Published: Sep. 01, 2021
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2021-39165

    Cachet is an open source status page. With Cachet prior to and including 2.3.18, there is a SQL injection which is in the `SearchableTrait#scopeSearch()`. Attackers without authentication can utilize this vulnerability to exfiltrate sensitive data from th... Read more

    Affected Products : cachet catchet cachet
    • EPSS Score: %88.73
    • Published: Aug. 26, 2021
    • Modified: Nov. 21, 2024
  • 3.5

    LOW
    CVE-2021-39164

    Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the membership (list of members, with their display names) of a room if they know the ID of the room. The vulnerabil... Read more

    Affected Products : fedora synapse
    • EPSS Score: %0.50
    • Published: Aug. 31, 2021
    • Modified: Nov. 21, 2024
  • 3.5

    LOW
    CVE-2021-39163

    Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the name, avatar, topic and number of members of a room if they know the ID of the room. This vulnerability is limit... Read more

    Affected Products : fedora synapse
    • EPSS Score: %0.27
    • Published: Aug. 31, 2021
    • Modified: Nov. 21, 2024
  • 8.6

    HIGH
    CVE-2021-39162

    Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, can abnormally terminate if an H/2 GOAWAY and SETTINGS frame are received in the same IO event. This can lead to a DoS in the presence of untrusted *upstream* serve... Read more

    Affected Products : envoy pomerium
    • EPSS Score: %0.67
    • Published: Sep. 09, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-39161

    Discourse is an open source platform for community discussion. In affected versions category names can be used for Cross-site scripting(XSS) attacks. This is mitigated by Discourse's default Content Security Policy and this vulnerability only affects site... Read more

    Affected Products : discourse
    • EPSS Score: %0.21
    • Published: Aug. 26, 2021
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2021-39160

    nbgitpuller is a Jupyter server extension to sync a git repository one-way to a local path. Due to unsanitized input, visiting maliciously crafted links could result in arbitrary code execution in the user environment. This has been resolved in version 0.... Read more

    Affected Products : nbgitpuller
    • EPSS Score: %0.43
    • Published: Aug. 25, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-39159

    BinderHub is a kubernetes-based cloud service that allows users to share reproducible interactive computing environments from code repositories. In affected versions a remote code execution vulnerability has been identified in BinderHub, where providing B... Read more

    Affected Products : binderhub
    • EPSS Score: %1.32
    • Published: Aug. 25, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-39158

    NVCaffe's python required dependencies list used to contain `gfortran`version prior to 0.17.4, entry which does not exist in the repository pypi.org. An attacker could potentially have posted malicious files to pypi.org causing a user to install it within... Read more

    Affected Products : nvcaffe
    • EPSS Score: %0.14
    • Published: Aug. 23, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-39157

    detect-character-encoding is an open source character encoding inspection library. In detect-character-encoding v0.6.0 and earlier, data matching no charset causes the Node.js process to crash. The problem has been patched in [detect-character-encoding v0... Read more

    Affected Products : detect-character-encoding
    • EPSS Score: %0.41
    • Published: Aug. 24, 2021
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2021-39156

    Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. Istio 1.11.0, 1.10.3 and below, and 1.9.7 and below contain a remotely exploi... Read more

    Affected Products : istio
    • EPSS Score: %0.29
    • Published: Aug. 24, 2021
    • Modified: Nov. 21, 2024
  • 8.3

    HIGH
    CVE-2021-39155

    Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. According to [RFC 4343](https://datatracker.ietf.org/doc/html/rfc4343), Istio... Read more

    Affected Products : istio
    • EPSS Score: %0.21
    • Published: Aug. 24, 2021
    • Modified: Nov. 21, 2024
  • 7.1

    HIGH
    CVE-2021-39143

    Spinnaker is an open source, multi-cloud continuous delivery platform. A path traversal vulnerability was discovered in uses of TAR files by AppEngine for deployments. This uses a utility to extract files locally for deployment without validating the path... Read more

    Affected Products : spinnaker
    • EPSS Score: %0.09
    • Published: Jan. 04, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 292124 Results