Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.6

    HIGH
    CVE-2021-39184

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, 12.1.0, and 13.3.0 allows a sandboxed renderer to request a "thumbnail" image of an arbitrary file on the ... Read more

    Affected Products : electron
    • Published: Oct. 12, 2021
    • Modified: Nov. 21, 2024
  • 8.2

    HIGH
    CVE-2021-39183

    Owncast is an open source, self-hosted live video streaming and chat server. In affected versions inline scripts are executed when Javascript is parsed via a paste action. This issue is patched in 0.0.9 by blocking unsafe-inline Content Security Policy an... Read more

    Affected Products : owncast
    • Published: Dec. 14, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-39182

    EnroCrypt is a Python module for encryption and hashing. Prior to version 1.1.4, EnroCrypt used the MD5 hashing algorithm in the hashing file. Beginners who are unfamiliar with hashes can face problems as MD5 is considered an insecure hashing algorithm. T... Read more

    Affected Products : enrocrypt
    • Published: Nov. 08, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-39181

    OpenOlat is a web-based learning management system (LMS). Prior to version 15.3.18, 15.5.3, and 16.0.0, using a prepared import XML file (e.g. a course) any class on the Java classpath can be instantiated, including spring AOP bean factories. This can be ... Read more

    Affected Products : openolat
    • Published: Sep. 01, 2021
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2021-39180

    OpenOLAT is a web-based learning management system (LMS). A path traversal vulnerability exists in versions prior to 15.3.18, 15.5.3, and 16.0.0. Using a specially prepared ZIP file, it is possible to overwrite any file that is writable by the application... Read more

    Affected Products : openolat
    • Published: Aug. 31, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-39179

    DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL Injection vulnerability in the Tracker component in DHIS2 Server allows authenticated remote attackers to execute arbitrary SQL commands via unspe... Read more

    Affected Products : dhis_2
    • Published: Oct. 29, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-39178

    Next.js is a React framework. Versions of Next.js between 10.0.0 and 11.0.0 contain a cross-site scripting vulnerability. In order for an instance to be affected by the vulnerability, the `next.config.js` file must have `images.domains` array assigned and... Read more

    Affected Products : next.js
    • Published: Aug. 31, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-39177

    Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Versions of Geyser prior to 1.4.2-SNAPSHOT allow anyone that can connect to the server to forge a LoginPacket with manipulated JWT token allowing impersonation as any user.... Read more

    Affected Products : geyser
    • Published: Aug. 30, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-39176

    detect-character-encoding is a package for detecting character encoding using ICU. In detect-character-encoding v0.3.0 and earlier, allocated memory is not released. The problem has been patched in detect-character-encoding v0.3.1.... Read more

    Affected Products : detect-character-encoding
    • Published: Aug. 31, 2021
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2021-39175

    HedgeDoc is a platform to write and share markdown. In versions prior to 1.9.0, an unauthenticated attacker can inject arbitrary JavaScript into the speaker-notes of the slide-mode feature by embedding an iframe hosting the malicious code into the slides ... Read more

    Affected Products : hedgedoc
    • Published: Aug. 30, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-39174

    Cachet is an open source status page system. Prior to version 2.5.1, authenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret (`APP_KEY`) and various... Read more

    Affected Products : catchet cachet
    • Published: Aug. 28, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-39173

    Cachet is an open source status page system. Prior to version 2.5.1 authenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. This issue was add... Read more

    Affected Products : catchet cachet
    • Published: Aug. 27, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-39172

    Cachet is an open source status page system. Prior to version 2.5.1, authenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code ex... Read more

    Affected Products : catchet cachet
    • Published: Aug. 27, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-39171

    Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. Prior to version 3.1.0, a malicious SAML payload can require transforms that consume significant system resources to process, thereby resulting in reduce... Read more

    Affected Products : passport-saml
    • Published: Aug. 27, 2021
    • Modified: Nov. 21, 2024
  • 8.0

    HIGH
    CVE-2021-39170

    Pimcore is an open source data & experience management platform. Prior to version 10.1.2, an authenticated user could add XSS code as a value of custom metadata on assets. There is a patch for this issue in Pimcore version 10.1.2. As a workaround, users m... Read more

    Affected Products : pimcore
    • Published: Sep. 01, 2021
    • Modified: Nov. 21, 2024
  • 8.0

    HIGH
    CVE-2021-39169

    Misskey is a decentralized microblogging platform. In versions of Misskey prior to 12.51.0, malicious actors can use the web client built-in dialog to display a malicious string, leading to cross-site scripting (XSS). XSS could compromise the API request ... Read more

    Affected Products : misskey
    • Published: Aug. 27, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2021-39168

    OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executor role to escalate privileges. Further details about the vulnerability will be disclosed at a later date. ... Read more

    • Published: Aug. 27, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2021-39167

    OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executor role to escalate privileges. Further details about the vulnerability will be disclosed at a later date. ... Read more

    Affected Products : contracts openzeppelin_contracts
    • Published: Aug. 27, 2021
    • Modified: Nov. 21, 2024
  • 8.0

    HIGH
    CVE-2021-39166

    Pimcore is an open source data & experience management platform. Prior to version 10.1.2, text-values were not properly escaped before printed in the version preview. This allowed XSS by authenticated users with access to the resources. This issue is patc... Read more

    Affected Products : pimcore
    • Published: Sep. 01, 2021
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2021-39165

    Cachet is an open source status page. With Cachet prior to and including 2.3.18, there is a SQL injection which is in the `SearchableTrait#scopeSearch()`. Attackers without authentication can utilize this vulnerability to exfiltrate sensitive data from th... Read more

    Affected Products : cachet catchet cachet
    • Published: Aug. 26, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 292913 Results