Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.8

    HIGH
    CVE-2021-29454

    Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.42 and 4.0.2, template authors could run arbitrary PHP code by crafting a malicious math string. If a math string was... Read more

    Affected Products : fedora debian_linux smarty
    • EPSS Score: %0.42
    • Published: Jan. 10, 2022
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-29453

    matrix-media-repo is an open-source multi-domain media repository for Matrix. Versions 1.2.6 and earlier of matrix-media-repo do not properly handle malicious images which are crafted to be small in file size, but large in complexity. A malicious user cou... Read more

    Affected Products : matrix-media-repo matrix-media-repo
    • EPSS Score: %0.32
    • Published: Apr. 19, 2021
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2021-29452

    a12n-server is an npm package which aims to provide a simple authentication system. A new HAL-Form was added to allow editing users in version 0.18.0. This feature should only have been accessible to admins. Unfortunately, privileges were incorrectly chec... Read more

    Affected Products : a12n-server
    • EPSS Score: %0.25
    • Published: Apr. 16, 2021
    • Modified: Nov. 21, 2024
  • 9.1

    CRITICAL
    CVE-2021-29451

    Portofino is an open source web development framework. Portofino before version 5.2.1 did not properly verify the signature of JSON Web Tokens. This allows forging a valid JWT. The issue will be patched in the upcoming 5.2.1 release.... Read more

    Affected Products : portofino
    • EPSS Score: %0.20
    • Published: Apr. 16, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-29450

    Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. This has been patched in WordPress 5.7.1, along with the o... Read more

    Affected Products : debian_linux wordpress
    • EPSS Score: %1.59
    • Published: Apr. 15, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-29449

    Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discovered in version 5.2.4 of Pi-hole core. See the referenced GitHub security advisory for details.... Read more

    Affected Products : pi-hole
    • EPSS Score: %11.36
    • Published: Apr. 14, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-29448

    Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious actor with the network access to DNS server. See the referenced GitHub sec... Read more

    Affected Products : pi-hole web_interface ftldns
    • EPSS Score: %0.30
    • Published: Apr. 15, 2021
    • Modified: Nov. 21, 2024
  • 7.1

    HIGH
    CVE-2021-29447

    Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is pos... Read more

    Affected Products : debian_linux wordpress
    • EPSS Score: %89.76
    • Published: Apr. 15, 2021
    • Modified: Nov. 21, 2024
  • 5.9

    MEDIUM
    CVE-2021-29446

    jose-node-cjs-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verificatio... Read more

    Affected Products : jose-node-cjs-runtime
    • EPSS Score: %0.39
    • Published: Apr. 16, 2021
    • Modified: Nov. 21, 2024
  • 5.9

    MEDIUM
    CVE-2021-29445

    jose-node-esm-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verificatio... Read more

    Affected Products : jose-node-cjs-runtime
    • EPSS Score: %0.39
    • Published: Apr. 16, 2021
    • Modified: Nov. 21, 2024
  • 5.9

    MEDIUM
    CVE-2021-29444

    jose-browser-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification... Read more

    Affected Products : jose-node-cjs-runtime
    • EPSS Score: %0.39
    • Published: Apr. 16, 2021
    • Modified: Nov. 21, 2024
  • 5.9

    MEDIUM
    CVE-2021-29443

    jose is an npm library providing a number of cryptographic operations. In vulnerable versions AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if eithe... Read more

    Affected Products : jose jose-node-cjs-runtime
    • EPSS Score: %0.32
    • Published: Apr. 16, 2021
    • Modified: Nov. 21, 2024
  • 8.6

    HIGH
    CVE-2021-29442

    Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, the ConfigOpsController lets the user perform management operations like querying the database or even wiping it out. While... Read more

    Affected Products : nacos
    • EPSS Score: %94.00
    • Published: Apr. 27, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-29441

    Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, when configured to use authentication (-Dnacos.core.auth.enabled=true) Nacos uses the AuthFilter servlet filter to enforce ... Read more

    Affected Products : nacos
    • EPSS Score: %94.05
    • Published: Apr. 27, 2021
    • Modified: Nov. 21, 2024
  • 8.4

    HIGH
    CVE-2021-29440

    Grav is a file based Web-platform. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. As the Twig processor runs unsandboxed, this behavior can be used to gain arbitrary code exec... Read more

    Affected Products : grav
    • EPSS Score: %20.26
    • Published: Apr. 13, 2021
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-29439

    The Grav admin plugin prior to version 1.10.11 does not correctly verify caller's privileges. As a consequence, users with the permission `admin.login` can install third-party plugins and their dependencies. By installing the right plugin, an attacker can... Read more

    Affected Products : grav_admin
    • EPSS Score: %0.32
    • Published: Apr. 13, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-29438

    The Nextcloud dialogs library (npm package @nextcloud/dialogs) before 3.1.2 insufficiently escaped text input passed to a toast. If your application displays toasts with user-supplied input, this could lead to a XSS vulnerability. The vulnerability has be... Read more

    Affected Products : nextcloud\/dialogs
    • EPSS Score: %0.22
    • Published: Apr. 13, 2021
    • Modified: Nov. 21, 2024
  • 8.0

    HIGH
    CVE-2021-29437

    ScratchOAuth2 is an Oauth implementation for Scratch. Any ScratchOAuth2-related data normally accessible and modifiable by a user can be read and modified by a third party. 1. Scratch user visits 3rd party site. 2. 3rd party site asks user for Scratch use... Read more

    Affected Products : scratchoauth2
    • EPSS Score: %0.27
    • Published: Apr. 13, 2021
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2021-29436

    Anuko Time Tracker is an open source, web-based time tracking application written in PHP. In Time Tracker before version 1.19.27.5431 a Cross site request forgery (CSRF) vulnerability existed. The nature of CSRF is that a logged on user may be tricked by ... Read more

    Affected Products : time_tracker
    • EPSS Score: %0.22
    • Published: Apr. 13, 2021
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2021-29435

    trestle-auth is an authentication plugin for the Trestle admin framework. A vulnerability in trestle-auth versions 0.4.0 and 0.4.1 allows an attacker to create a form that will bypass Rails' built-in CSRF protection when submitted by a victim with a trest... Read more

    Affected Products : trestle-auth
    • EPSS Score: %0.14
    • Published: Apr. 13, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 291551 Results