Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.1

    MEDIUM
    CVE-2021-30151

    Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.... Read more

    Affected Products : debian_linux sidekiq
    • EPSS Score: %19.11
    • Published: Apr. 06, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-30150

    Composr 10.0.36 allows XSS in an XML script.... Read more

    Affected Products : composr composr_cms
    • EPSS Score: %0.32
    • Published: Apr. 06, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-30149

    Composr 10.0.36 allows upload and execution of PHP files.... Read more

    Affected Products : composr composr_cms
    • EPSS Score: %15.52
    • Published: Apr. 06, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-30147

    DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.... Read more

    Affected Products : radius_manager
    • EPSS Score: %0.40
    • Published: Apr. 07, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-30146

    Seafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality."... Read more

    Affected Products : seafile seafile_server
    • EPSS Score: %0.48
    • Published: Apr. 06, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-30145

    A format string vulnerability in mpv through 0.33.0 allows user-assisted remote attackers to achieve code execution via a crafted m3u playlist file.... Read more

    Affected Products : mpv
    • EPSS Score: %4.48
    • Published: May. 18, 2021
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2021-30144

    The Dashboard plugin through 1.0.2 for GLPI allows remote low-privileged users to bypass access control on viewing information about the last ten events, the connected users, and the users in the tech category. For example, plugins/dashboard/front/main2.p... Read more

    Affected Products : glpi_dashboard dashboard
    • EPSS Score: %0.12
    • Published: Apr. 06, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-30141

    Module/Settings/UserExport.php in Friendica through 2021.01 allows settings/userexport to be used by anonymous users, as demonstrated by an attempted access to an array offset on a value of type null, and excessive memory consumption. NOTE: the vendor sta... Read more

    Affected Products : friendica
    • EPSS Score: %0.36
    • Published: Apr. 05, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-30140

    LiquidFiles 3.4.15 has stored XSS through the "send email" functionality when sending a file via email to an administrator. When a file has no extension and contains malicious HTML / JavaScript content (such as SVG with HTML content), the payload is execu... Read more

    Affected Products : liquidfiles
    • EPSS Score: %1.12
    • Published: Apr. 06, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-30139

    In Alpine Linux apk-tools before 2.12.5, the tarball parser allows a buffer overflow and crash.... Read more

    Affected Products : apk-tools
    • EPSS Score: %0.20
    • Published: Apr. 21, 2021
    • Modified: Nov. 21, 2024
  • 8.2

    HIGH
    CVE-2021-30137

    Assyst 10 SP7.5 has authenticated XXE leading to SSRF via XML unmarshalling. The application allows users to send JSON or XML data to the server. It was possible to inject malicious XML data through several access points.... Read more

    Affected Products : assyst
    • EPSS Score: %0.16
    • Published: Sep. 15, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-30133

    A cross-site scripting (XSS) vulnerability in CloverDX Server 5.9.0, CloverDX 5.8.1, CloverDX 5.7.0, and earlier allows remote attackers to inject arbitrary web script or HTML via the sessionToken parameter of multiple methods in Simple HTTP API. This is ... Read more

    Affected Products : cloverdx
    • EPSS Score: %0.23
    • Published: Jun. 09, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-30132

    Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges.... Read more

    Affected Products : cloudera_manager
    • EPSS Score: %0.53
    • Published: Nov. 08, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-30130

    phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification.... Read more

    Affected Products : debian_linux phpseclib
    • EPSS Score: %0.16
    • Published: Apr. 06, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-30129

    A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apa... Read more

    • EPSS Score: %0.23
    • Published: Jul. 12, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2021-30128

    Apache OFBiz has unsafe deserialization prior to 17.12.07 version... Read more

    Affected Products : ofbiz
    • EPSS Score: %93.35
    • Published: Apr. 27, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-30127

    TerraMaster F2-210 devices through 2021-04-03 use UPnP to make the admin web server accessible over the Internet on TCP port 8181, which is arguably inconsistent with the "It is only available on the local network" documentation. NOTE: manually editing /e... Read more

    Affected Products : f2-210_firmware f2-210
    • EPSS Score: %0.24
    • Published: Apr. 03, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-30126

    Lightmeter ControlCenter 1.1.0 through 1.5.x before 1.5.1 allows anyone who knows the URL of a publicly available Lightmeter instance to access application settings, possibly including an SMTP password and a Slack access token, via a settings HTTP query.... Read more

    Affected Products : controlcenter
    • EPSS Score: %0.21
    • Published: Apr. 02, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-30125

    Jamf Pro before 10.28.0 allows XSS related to inventory history, aka PI-009376.... Read more

    Affected Products : jamf
    • EPSS Score: %0.28
    • Published: Apr. 02, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-30124

    The unofficial vscode-phpmd (aka PHP Mess Detector) extension before 1.3.0 for Visual Studio Code allows remote attackers to execute arbitrary code via a crafted phpmd.command value in a workspace folder.... Read more

    Affected Products : vscode-phpmd
    • EPSS Score: %2.74
    • Published: Jul. 30, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 291562 Results