Latest CVE Feed
-
7.5
HIGHCVE-2021-32778
Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions envoy’s procedure for resetting a HTTP/2 stream has O(N^2) complexity, leading to high CPU utilization when a large numbe... Read more
Affected Products : envoy- Published: Aug. 24, 2021
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-32777
Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions when ext-authz extension is sending request headers to the external authorization service it must merge multiple value he... Read more
Affected Products : envoy- Published: Aug. 24, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-32776
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows servers no cleanup is done on CSRF tokens. This issue is fixed in versions 2.7.4 and 3.0.0.... Read more
Affected Products : itop- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
7.7
HIGHCVE-2021-32775
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, a non admin user can get access to many class/field values through GroupBy Dashlet error message. This issue is fixed in versions 2.7.4 and 3.0.0.... Read more
Affected Products : itop- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-32774
DataDump is a MediaWiki extension that provides dumps of wikis. Prior to commit 67a82b76e186925330b89ace9c5fd893a300830b, DataDump had no protection against CSRF attacks so requests to generate or delete dumps could be forged. The vulnerability was patche... Read more
Affected Products : datadump- Published: Jul. 20, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-32773
Racket is a general-purpose programming language and an ecosystem for language-oriented programming. In versions prior to 8.2, code evaluated using the Racket sandbox could cause system modules to incorrectly use attacker-created modules instead of their ... Read more
Affected Products : racket- Published: Jul. 20, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-32772
Poddycast is a podcast app made with Electron. Prior to version 0.8.1, an attacker can create a podcast or episode with malicious characters and execute commands on the client machine. The application does not clean the HTML characters of the podcast info... Read more
Affected Products : poddycast- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-32771
Contiki-NG is an open-source, cross-platform operating system for IoT devices. In affected versions it is possible to cause a buffer overflow when copying an IPv6 address prefix in the RPL-Classic implementation in Contiki-NG. In order to trigger the vuln... Read more
Affected Products : contiki-ng- Published: Aug. 04, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-32770
Gatsby is a framework for building websites. The gatsby-source-wordpress plugin prior to versions 4.0.8 and 5.9.2 leaks .htaccess HTTP Basic Authentication variables into the app.js bundle during build-time. Users who are not initializing basic authentica... Read more
- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-32769
Micronaut is a JVM-based, full stack Java framework designed for building JVM applications. A path traversal vulnerability exists in versions prior to 2.5.9. With a basic configuration, it is possible to access any file from a filesystem, using "/../../" ... Read more
Affected Products : micronaut- Published: Jul. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-32768
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions failing to properly parse, sanitize and encode malicious rich-text content, the content rendering process in the website frontend is vulnerabl... Read more
Affected Products : typo3- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-32767
TYPO3 is an open source PHP based web content management system. In versions 9.0.0 through 9.5.27, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0, user credentials may been logged as plain-text. This occurs when explicitly using log level debug, which ... Read more
Affected Products : typo3- Published: Jul. 20, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-32766
Nextcloud Text is an open source plaintext editing application which ships with the nextcloud server. In affected versions the Nextcloud Text application returned different error messages depending on whether a folder existed in a public link share. This ... Read more
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-32765
Hiredis is a minimalistic C client library for the Redis database. In affected versions Hiredis is vulnurable to integer overflow if provided maliciously crafted or corrupted `RESP` `mult-bulk` protocol data. When parsing `multi-bulk` (array-like) replies... Read more
- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-32764
Discourse is an open-source discussion platform. In Discourse versions 2.7.5 and prior, parsing and rendering of YouTube Oneboxes can be susceptible to XSS attacks. This vulnerability only affects sites which have modified or disabled Discourse's default ... Read more
Affected Products : discourse- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-32763
OpenProject is open-source, web-based project management software. In versions prior to 11.3.3, the `MessagesController` class of OpenProject has a `quote` method that implements the logic behind the Quote button in the discussion forums, and it uses a re... Read more
Affected Products : openproject- Published: Jul. 20, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-32762
Redis is an open source, in-memory database that persists on disk. The redis-cli command line tool and redis-sentinel service may be vulnerable to integer overflow when parsing specially crafted large multi-bulk network replies. This is a result of a vuln... Read more
- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-32761
Redis is an in-memory database that persists on disk. A vulnerability involving out-of-bounds read and integer overflow to buffer overflow exists starting with version 2.2 and prior to versions 5.0.13, 6.0.15, and 6.2.5. On 32-bit systems, Redis `*BIT*` c... Read more
- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-32760
containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Cha... Read more
- Published: Jul. 19, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-32759
OpenMage magento-lts is an alternative to the Magento CE official releases. Due to missing sanitation in data flow in versions prior to 19.4.15 and 20.0.13, it was possible for admin users to upload arbitrary executable files to the server. OpenMage versi... Read more
Affected Products : magento- Published: Aug. 27, 2021
- Modified: Nov. 21, 2024