Latest CVE Feed
-
6.5
MEDIUMCVE-2021-32697
neos/forms is an open source framework to build web forms. By crafting a special `GET` request containing a valid form state, a form can be submitted without invoking any validators. Form state is secured with an HMAC that is still verified. That means th... Read more
Affected Products : form- Published: Jun. 21, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-32696
The npm package "striptags" is an implementation of PHP's strip_tags in Typescript. In striptags before version 3.2.0, a type-confusion vulnerability can cause `striptags` to concatenate unsanitized strings when an array-like object is passed in as the `h... Read more
Affected Products : striptags- Published: Jun. 18, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-32695
Nextcloud Android app is the Android client for Nextcloud. In versions prior to 3.16.1, a malicious app on the same device could have gotten access to the shared preferences of the Nextcloud Android application. This required user-interaction as a victim ... Read more
- Published: Jun. 17, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-32694
Nextcloud Android app is the Android client for Nextcloud. In versions prior to 3.15.1, a malicious application on the same device is possible to crash the Nextcloud Android Client due to an uncaught exception. The vulnerability is patched in version 3.15... Read more
- Published: Jun. 17, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-32693
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. A vulnerability related to firewall authentication is in Symfony starting with version 5.3.0 and prior to 5.3.2. When an application defines multiple firewal... Read more
Affected Products : symfony- Published: Jun. 17, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-32692
Activity Watch is a free and open-source automated time tracker. Versions prior to 0.11.0 allow an attacker to execute arbitrary commands on any macOS machine with ActivityWatch running. The attacker can exploit this vulnerability by having the user visit... Read more
- Published: Dec. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32691
Apollos Apps is an open source platform for launching church-related apps. In Apollos Apps versions prior to 2.20.0, new user registrations are able to access anyone's account by only knowing their basic profile information (name, birthday, gender, etc). ... Read more
Affected Products : data-connector-rock- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-32690
Helm is a tool for managing Charts (packages of pre-configured Kubernetes resources). In versions of helm prior to 3.6.1, a vulnerability exists where the username and password credentials associated with a Helm repository could be passed on to another do... Read more
Affected Products : helm- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-32689
Nextcloud Talk is a fully on-premises audio/video and chat communication service. In versions prior to 11.2.2, if a user was able to reuse an earlier used username, they could get access to any chat message sent to the previous user with this username. Th... Read more
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-32688
Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens for authentication purposes. These tokens are supposed to be granted to a specific applications (e.g. DAV sync clients), and can also ... Read more
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-32687
Redis is an open source, in-memory database that persists on disk. An integer overflow bug affecting all versions of Redis can be exploited to corrupt the heap and potentially be used to leak arbitrary contents of the heap or trigger remote code execution... Read more
- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-32686
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In PJSIP before version 2.11.1, there are a couple of issues found in the SSL socket. ... Read more
- Published: Jul. 23, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32685
tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the browser (hashing, random, encryption, decryption, signatures, conversions), used by TogaTech.org. In versions prior to 7.0.3, the `verifyWithMessage` method of `tEnvoyNaClSigningKey` always retu... Read more
Affected Products : tenvoy- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024
-
6.2
MEDIUMCVE-2021-32684
magento-scripts contains scripts and configuration used by Create Magento App, a zero-configuration tool-chain which allows one to deploy Magento 2. In versions 1.5.1 and 1.5.2, after changing the function from synchronous to asynchronous there wasn't imp... Read more
Affected Products : magento-scripts- Published: Jun. 14, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-32683
wire-webapp is the web version of Wire, an open-source messenger. A cross-site scripting vulnerability exists in wire-webapp prior to version 2021-06-01-production.0. If a user is instructed to open an image in a new tab (right click -> open in new tab, o... Read more
Affected Products : wire-webapp- Published: Jun. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32682
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder P... Read more
Affected Products : elfinder- Published: Jun. 14, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-32681
Wagtail is an open source content management system built on Django. A cross-site scripting vulnerability exists in versions 2.13-2.13.1, versions 2.12-2.12.4, and versions prior to 2.11.8. When the `{% include_block %}` template tag is used to output the... Read more
- Published: Jun. 17, 2021
- Modified: Nov. 21, 2024
-
3.3
LOWCVE-2021-32680
Nextcloud Server is a Nextcloud package that handles data storage. In versions priot to 19.0.13, 20.0.11, and 21.0.3, Nextcloud Server audit logging functionality wasn't properly logging events for the unsetting of a share expiration date. This event is s... Read more
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-32679
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, filenames where not escaped by default in controllers using `DownloadResponse`. When a user-supplied filename was passed unsanitized into... Read more
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-32678
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, ratelimits are not applied to OCS API responses. This affects any OCS API controller (`OCSController`) using the `@BruteForceProtection` ... Read more
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024