Latest CVE Feed
-
8.0
HIGHCVE-2021-29427
In Gradle from version 5.1 and before version 7.0 there is a vulnerability which can lead to information disclosure and/or dependency poisoning. Repository content filtering is a security control Gradle introduced to help users specify what repositories a... Read more
- EPSS Score: %0.56
- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2021-29425
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not f... Read more
Affected Products : debian_linux active_iq_unified_manager weblogic_server access_manager communications_policy_management agile_engineering_data_management commerce_guided_search communications_pricing_design_center communications_cloud_native_core_network_repository_function primavera_unifier +50 more products- EPSS Score: %0.26
- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29424
The Net::Netmask module before 2.0000 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.... Read more
- EPSS Score: %0.08
- Published: Apr. 06, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29421
models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.... Read more
- EPSS Score: %0.37
- Published: Apr. 01, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-29418
The netmask package before 2.0.1 for Node.js mishandles certain unexpected characters in an IP address string, such as an octal digit of 9. This (in some situations) allows attackers to bypass access control that is based on IP addresses. NOTE: this issue... Read more
Affected Products : netmask- EPSS Score: %0.02
- Published: Mar. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-29417
gitjacker before 0.1.0 allows remote attackers to execute arbitrary code via a crafted .git directory because of directory traversal.... Read more
Affected Products : gitjacker- EPSS Score: %5.34
- Published: Mar. 29, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-29416
An issue was discovered in PortSwigger Burp Suite before 2021.2. During viewing of a malicious request, it can be manipulated into issuing a request that does not respect its upstream proxy configuration. This could leak NetNTLM hashes on Windows systems ... Read more
Affected Products : burp_suite- EPSS Score: %0.31
- Published: Mar. 29, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-29415
The elliptic curve cryptography (ECC) hardware accelerator, part of the ARM® TrustZone® CryptoCell 310, contained in the NordicSemiconductor nRF52840 through 2021-03-29 has a non-constant time ECDSA implemenation. This allows an adversary to recover the p... Read more
- EPSS Score: %0.08
- Published: May. 21, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-29414
STMicroelectronics STM32L4 devices through 2021-03-29 have incorrect physical access control.... Read more
Affected Products : stm32cubel4_firmware stm32l412c8 stm32l412cb stm32l412k8 stm32l412kb stm32l412r8 stm32l412rb stm32l412t8 stm32l412tb stm32l422cb +85 more products- EPSS Score: %0.15
- Published: May. 21, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-29400
A cross-site request forgery (CSRF) vulnerability in the My SMTP Contact v1.1.1 plugin for GetSimple CMS allows remote attackers to change the SMTP settings of the contact forms for the webpages of the CMS after an authenticated admin visits a malicious t... Read more
Affected Products : my_smtp_contact- EPSS Score: %0.11
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-29399
XMB is vulnerable to cross-site scripting (XSS) due to inadequate filtering of BBCode input. This bug affects all versions of XMB. All XMB installations must be updated to versions 1.9.12.03 or 1.9.11.16.... Read more
- EPSS Score: %0.40
- Published: Apr. 19, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-29398
Directory traversal in /northstar/Common/NorthFileManager/fileManagerObjects.jsp Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to browse and list the directories across the entire filesystem of the host of th... Read more
Affected Products : northstar_club_management- EPSS Score: %1.11
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29397
Cleartext Transmission of Sensitive Information in /northstar/Admin/login.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote local user to intercept users credentials transmitted in cleartext over HTTP.... Read more
Affected Products : northstar_club_management- EPSS Score: %0.18
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-29396
Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to use various functionalities without authentication.... Read more
Affected Products : northstar_club_management- EPSS Score: %1.40
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29395
Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary files, including JSP source code, across the filesystem of the host of the web ... Read more
Affected Products : northstar_club_management- EPSS Score: %1.17
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-29394
Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated users to change the password of any targeted user accounts via lack of proper authorization in the user-contro... Read more
Affected Products : northstar_club_management- EPSS Score: %0.15
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-29393
Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to inject and execute arbitrary system commands via the unsanitized user-controlled "command" and "comm... Read more
Affected Products : northstar_club_management- EPSS Score: %14.16
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-29390
libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.... Read more
- EPSS Score: %0.05
- Published: Aug. 22, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29388
A stored cross-site scripting (XSS) vulnerability in SourceCodester Budget Management System 1.0 allows users to inject and store arbitrary JavaScript code in index.php via vulnerable field 'Budget Title'.... Read more
Affected Products : budget_management_system- EPSS Score: %0.18
- Published: Apr. 28, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29387
Multiple stored cross-site scripting (XSS) vulnerabilities in Sourcecodester Equipment Inventory System 1.0 allow remote attackers to inject arbitrary javascript via any "Add" sections, such as Add Item , Employee and Position or others in the Name Parame... Read more
Affected Products : equipment_inventory_system- EPSS Score: %0.13
- Published: Apr. 28, 2021
- Modified: Nov. 21, 2024