Latest CVE Feed
-
7.6
HIGHCVE-2021-39202
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the widgets editor introduced in WordPress 5.8 beta 1 has improper handling of HTML input in the Custom HTML fea... Read more
Affected Products : wordpress- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2021-39201
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor. This byp... Read more
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-39200
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions, which can include data like nonces.... Read more
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-39199
remark-html is an open source nodejs library which compiles Markdown to HTML. In affected versions the documentation of remark-html has mentioned that it was safe by default. In practice the default was never safe and had to be opted into. That is, user i... Read more
Affected Products : remark-html- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2021-39198
OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an attacker is able to disqualify any Lead with a Cross-Site Request Forgery (CSRF) attack. There are no worka... Read more
Affected Products : client_relationship_management- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-39197
better_errors is an open source replacement for the standard Rails error page with more information rich error pages. It is also usable outside of Rails in any Rack app as Rack middleware. better_errors prior to 2.8.0 did not implement CSRF protection for... Read more
Affected Products : better_errors- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
7.7
HIGHCVE-2021-39196
pcapture is an open source dumpcap web service interface . In affected versions this vulnerability allows an authenticated but unprivileged user to use the REST API to capture and download packets with no capture filter and without adequate permissions. T... Read more
Affected Products : pcapture- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
7.7
HIGHCVE-2021-39195
Misskey is an open source, decentralized microblogging platform. In affected versions a Server-Side Request Forgery vulnerability exists in "Upload from URL" and remote attachment handling. This could result in the disclosure of non-public information wit... Read more
Affected Products : misskey- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-39194
kaml is an open source implementation of the YAML format with support for kotlinx.serialization. In affected versions attackers that could provide arbitrary YAML input to an application that uses kaml could cause the application to endlessly loop while pa... Read more
Affected Products : kaml- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-39193
Frontier is Substrate's Ethereum compatibility layer. Prior to commit number 0b962f218f0cdd796dadfe26c3f09e68f7861b26, a bug in `pallet-ethereum` can cause invalid transactions to be included in the Ethereum block state in `pallet-ethereum` due to not val... Read more
Affected Products : frontier- Published: Sep. 03, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-39192
Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.0 and 4.9.4 allows all authenticated users (including contributors) to view admin-level API keys via the integrations API endpoint, lea... Read more
Affected Products : ghost- Published: Sep. 03, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-39191
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9.4, the 3rd-party init SSO func... Read more
- Published: Sep. 03, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-39190
The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3.0, the Configuration page is publicly accessible in read-only mode. This issue is patched in version 2.3.0. No known workarounds exist... Read more
Affected Products : system_center_configuration_manager- Published: Sep. 22, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-39189
Pimcore is an open source data & experience management platform. In versions prior to 10.1.3, it is possible to enumerate usernames via the forgot password functionality. This issue is fixed in version 10.1.3. As a workaround, one may apply the available ... Read more
Affected Products : pimcore- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-39187
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version 4.10.3, Parse Server crashes when if a query request contains an invalid value for the `explain` option. This is due to a bug in the M... Read more
Affected Products : parse-server- Published: Sep. 02, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-39186
GlobalNewFiles is a MediaWiki extension maintained by Miraheze. Prior to commit number cee254e1b158cdb0ddbea716b1d3edc31fa4fb5d, the username column of the GlobalNewFiles special page is vulnerable to a stored XSS. Commit number cee254e1b158cdb0ddbea716b1... Read more
Affected Products : globalnewfiles- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-39185
Http4s is a minimal, idiomatic Scala interface for HTTP services. In http4s versions 0.21.26 and prior, 0.22.0 through 0.22.2, 0.23.0, 0.23.1, and 1.0.0-M1 through 1.0.0-M24, the default CORS configuration is vulnerable to an origin reflection attack. The... Read more
Affected Products : http4s- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-39184
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, 12.1.0, and 13.3.0 allows a sandboxed renderer to request a "thumbnail" image of an arbitrary file on the ... Read more
Affected Products : electron- Published: Oct. 12, 2021
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2021-39183
Owncast is an open source, self-hosted live video streaming and chat server. In affected versions inline scripts are executed when Javascript is parsed via a paste action. This issue is patched in 0.0.9 by blocking unsafe-inline Content Security Policy an... Read more
Affected Products : owncast- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-39182
EnroCrypt is a Python module for encryption and hashing. Prior to version 1.1.4, EnroCrypt used the MD5 hashing algorithm in the hashing file. Beginners who are unfamiliar with hashes can face problems as MD5 is considered an insecure hashing algorithm. T... Read more
Affected Products : enrocrypt- Published: Nov. 08, 2021
- Modified: Nov. 21, 2024