Latest CVE Feed
-
9.1
CRITICALCVE-2021-32825
bblfshd is an open source self-hosted server for source code parsing. In bblfshd before commit 4265465b9b6fb5663c30ee43806126012066aad4 there is a "zipslip" vulnerability. The unsafe handling of symbolic links in an unpacking routine may enable attackers ... Read more
Affected Products : bblfshd- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32824
Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arbitrary bean manipulation in the Telnet handler. The Dubbo main service port can be used to access a Telnet... Read more
Affected Products : dubbo- Published: Jan. 03, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-32823
In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions it is very slow for certain classes in BinData to be created. For example BinData::Bit100000, BinData::Bit100001, BinData::Bit100002, B... Read more
- Published: Jun. 24, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-32822
The npm hbs package is an Express view engine wrapper for Handlebars. Depending on usage, users of hbs may be vulnerable to a file disclosure vulnerability. There is currently no patch for this vulnerability. hbs mixes pure template data with engine confi... Read more
Affected Products : hbs- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-32821
MooTools is a collection of JavaScript utilities for JavaScript developers. All known versions include a CSS selector parser that is vulnerable to Regular Expression Denial of Service (ReDoS). An attack requires that an attacker can inject a string into a... Read more
Affected Products : mootools- Published: Jan. 03, 2023
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-32820
Express-handlebars is a Handlebars view engine for Express. Express-handlebars mixes pure template data with engine configuration options through the Express render API. More specifically, the layout parameter may trigger file disclosure vulnerabilities i... Read more
Affected Products : express_handlebars- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-32819
Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options remote ... Read more
Affected Products : squirrelly- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
7.7
HIGHCVE-2021-32818
haml-coffee is a JavaScript templating solution. haml-coffee mixes pure template data with engine configuration options through the Express render API. More specifically, haml-coffee supports overriding a series of HTML helper functions through its config... Read more
Affected Products : haml-coffee- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-32817
express-hbs is an Express handlebars template engine. express-hbs mixes pure template data with engine configuration options through the Express render API. More specifically, the layout parameter may trigger file disclosure vulnerabilities in downstream ... Read more
Affected Products : express_handlebars- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-32816
ProtonMail Web Client is the official AngularJS web client for the ProtonMail secure email service. ProtonMail Web Client before version 3.16.60 has a regular expression denial-of-service vulnerability. This was fixed in commit 6687fb. There is a full rep... Read more
Affected Products : protonmail- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-32815
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The assertion failure is triggered when Exiv2 is used to modify the metadata of a crafted image file. An attacker could potentially ... Read more
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2021-32814
Skytable is a NoSQL database with automated snapshots and TLS. Versions prior to 0.5.1 are vulnerable to a a directory traversal attack enabling remotely connected clients to destroy and/or manipulate critical files on the host's file system. This securit... Read more
Affected Products : skytable- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-32813
Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.4.13, there exists a potential header vulnerability in Traefik's handling of the Connection header. Active exploitation of this issue is unlikely, as it requires that a removed header ... Read more
Affected Products : traefik- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-32812
Monkshu is an enterprise application server for mobile apps (iOS and Android), responsive HTML 5 apps, and JSON API services. In version 2.90 and earlier, there is a reflected cross-site scripting vulnerability in frontend HTTP server. The attacker can se... Read more
Affected Products : monkshu- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-32811
Zope is an open-source web application server. Zope versions prior to versions 4.6.3 and 5.3 have a remote code execution security issue. In order to be affected, one must use Python 3 for one's Zope deployment, run Zope 4 below version 4.6.3 or Zope 5 be... Read more
- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32810
crossbeam-deque is a package of work-stealing deques for building task schedulers when programming in Rust. In versions prior to 0.7.4 and 0.8.0, the result of the race condition is that one or more tasks in the worker queue can be popped twice instead of... Read more
- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-32809
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality us... Read more
- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2021-32808
ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed wi... Read more
- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-32807
The module `AccessControl` defines security policies for Python code used in restricted code within Zope applications. Restricted code is any code that resides in Zope's object database, such as the contents of `Script (Python)` objects. The policies defi... Read more
Affected Products : accesscontrol- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-32806
Products.isurlinportal is a replacement for isURLInPortal method in Plone. Versions of Products.isurlinportal prior to 1.2.0 have an Open Redirect vulnerability. Various parts of Plone use the 'is url in portal' check for security, mostly to see if it is ... Read more
Affected Products : isurlinportal- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024