Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2021-32263

    ok-file-formats through 2021-04-29 has a heap-based buffer overflow in the ok_csv_circular_buffer_read function in ok_csv.c.... Read more

    Affected Products : ok-file-formats
    • EPSS Score: %0.21
    • Published: Aug. 24, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-32256

    An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.... Read more

    Affected Products : binutils
    • EPSS Score: %0.12
    • Published: Jul. 18, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-32245

    In PageKit v1.0.18, a user can upload SVG files in the file upload portion of the CMS. These SVG files can contain malicious scripts. This file will be uploaded to the system and it will not be stripped or filtered. The user can create a link on the websi... Read more

    Affected Products : pagekit
    • EPSS Score: %0.19
    • Published: Jun. 16, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-32244

    Cross Site Scripting (XSS) in Moodle 3.10.3 allows remote attackers to execute arbitrary web script or HTML via the "Description" field.... Read more

    Affected Products : moodle
    • EPSS Score: %0.13
    • Published: Jun. 16, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-32243

    FOGProject v1.5.9 is affected by a File Upload RCE (Authenticated).... Read more

    Affected Products : fogproject
    • EPSS Score: %0.47
    • Published: Jun. 16, 2021
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2021-32238

    Epic Games / Psyonix Rocket League <=1.95 is affected by Buffer Overflow. Stack-based buffer overflow occurs when Rocket League handles UPK object files that can result in code execution and denial of service scenario.... Read more

    Affected Products : rocket_league
    • EPSS Score: %0.63
    • Published: May. 18, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-32234

    SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows remote code execution.... Read more

    Affected Products : smartermail
    • EPSS Score: %3.07
    • Published: Nov. 17, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-32233

    SmarterTools SmarterMail before Build 7776 allows XSS.... Read more

    Affected Products : smartermail
    • EPSS Score: %0.28
    • Published: Jul. 06, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-32202

    In CS-Cart version 4.11.1, it is possible to induce copy-paste XSS by manipulating the "post description" filed in the blog post creation page.... Read more

    Affected Products : cs-cart
    • EPSS Score: %0.24
    • Published: Sep. 14, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-32198

    EmTec ZOC through 8.02.4 allows remote servers to cause a denial of service (Windows GUI hang) by telling the ZOC window to change its title repeatedly at high speed, which results in many SetWindowTextA or SetWindowTextW calls. In other words, it does no... Read more

    Affected Products : zoc
    • EPSS Score: %0.57
    • Published: Jun. 06, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-32172

    Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.... Read more

    Affected Products : maian_cart
    • EPSS Score: %70.44
    • Published: Oct. 07, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-32162

    A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 through the File Manager feature.... Read more

    Affected Products : webmin
    • EPSS Score: %8.02
    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-32161

    A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the File Manager feature.... Read more

    Affected Products : webmin
    • EPSS Score: %8.09
    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-32160

    A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the Add Users feature.... Read more

    Affected Products : webmin
    • EPSS Score: %8.09
    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-32159

    A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Upload and Download feature.... Read more

    Affected Products : webmin
    • EPSS Score: %8.02
    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-32158

    A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Upload and Download feature.... Read more

    Affected Products : webmin
    • EPSS Score: %8.09
    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2021-32157

    A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.... Read more

    Affected Products : webmin
    • EPSS Score: %25.28
    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-32156

    A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.... Read more

    Affected Products : webmin
    • EPSS Score: %8.02
    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2021-32139

    The gf_isom_vp_config_get function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.... Read more

    Affected Products : gpac
    • EPSS Score: %0.09
    • Published: Sep. 13, 2021
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2021-32138

    The DumpTrackInfo function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.... Read more

    Affected Products : gpac
    • EPSS Score: %0.09
    • Published: Sep. 13, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 292318 Results