Latest CVE Feed
-
8.8
HIGHCVE-2021-32743
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions prior to 2.11.10 and from version 2.12.0 through version 2.12.4, some of the Icinga 2 fe... Read more
- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-32742
Vapor is a web framework for Swift. In versions 4.47.1 and prior, bug in the `Data.init(base32Encoded:)` function opens up the potential for exposing server memory and/or crashing the server (Denial of Service) for applications where untrusted data can en... Read more
- Published: Jul. 09, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-32741
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public share link mount endpoint. This may have allowed an attacker to enumerate potentially valid... Read more
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-32740
Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. An uncontrolled resource consumption vulnerability exists after version 2.3.0 through version 2.7.0. Within the URI template implementation in ... Read more
- Published: Jul. 06, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-32739
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. From version 2.4.0 through version 2.12.4, a vulnerability exists that may allow privilege escalatio... Read more
- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-32738
js-stellar-sdk is a Javascript library for communicating with a Stellar Horizon server. The `Utils.readChallengeTx` function used in SEP-10 Stellar Web Authentication states in its function documentation that it reads and validates the challenge transacti... Read more
Affected Products : js-stellar-sdk- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024
-
8.4
HIGHCVE-2021-32737
Sulu is an open-source PHP content management system based on the Symfony framework. In versions of Sulu prior to 1.6.41, it is possible for a logged in admin user to add a script injection (cross-site-scripting) in the collection title. The problem is pa... Read more
Affected Products : sulu- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-32736
think-helper defines a set of helper functions for ThinkJS. In versions of think-helper prior to 1.1.3, the software receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not pr... Read more
Affected Products : think-helper- Published: Jun. 30, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-32735
Kirby is a content management system. In Kirby CMS versions 3.5.5 and 3.5.6, the Panel's `ListItem` component (used in the pages and files section for example) displayed HTML in page titles as it is. This could be used for cross-site scripting (XSS) attac... Read more
Affected Products : kirby- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-32734
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, the Nextcloud Text application shipped with Nextcloud Server returned verbatim exception messages to the user. This could result in a full... Read more
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-32733
Nextcloud Text is a collaborative document editing application that uses Markdown. A cross-site scripting vulnerability is present in versions prior to 19.0.13, 20.0.11, and 21.0.3. The Nextcloud Text application shipped with Nextcloud server used a `text... Read more
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-32732
### Impact It's possible to know if a user has or not an account in a wiki related to an email address, and which username(s) is actually tied to that email by forging a request to the Forgot username page. Note that since this page does not have a CSRF c... Read more
Affected Products : xwiki- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-32731
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Between (and including) versions 13.1RC1 and 13.1, the reset password form reveals the email address of users just by giving their username. The probl... Read more
Affected Products : xwiki- Published: Jul. 01, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-32730
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A cross-site request forgery vulnerability exists in versions prior to 12.10.5, and in versions 13.0 through 13.1. It's possible for forge an URL that... Read more
Affected Products : xwiki- Published: Jul. 01, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-32729
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A vulnerability exists in versions prior to 12.6.88, 12.10.4, and 13.0. The script service method used to reset the authentication failures record can... Read more
Affected Products : xwiki- Published: Jul. 01, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-32728
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. Clients using the Nextcloud end-to-end encryption feature download the public and private key via an API endpoint. In versions prior to 3.3.0, the Nextcloud... Read more
- Published: Aug. 18, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-32727
Nextcloud Android Client is the Android client for Nextcloud. Clients using the Nextcloud end-to-end encryption feature download the public and private key via an API endpoint. In versions prior to 3.16.1, the Nextcloud Android client skipped a step that ... Read more
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32726
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted after a user has been deleted. If a victim reused an earlier used username, the previous user could gain ... Read more
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-32725
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, default share permissions were not being respected for federated reshares of files and folders. The issue was fixed in versions 19.0.13, 2... Read more
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2021-32724
check-spelling is a github action which provides CI spell checking. In affected versions and for a repository with the [check-spelling action](https://github.com/marketplace/actions/check-spelling) enabled that triggers on `pull_request_target` (or `sched... Read more
Affected Products : check-spelling- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024