Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.1

    MEDIUM
    CVE-2021-25922

    In OpenEMR, versions 4.2.0 to 6.0.0 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly. An attacker could trick a user to click on a malicious url and execute malicious code.... Read more

    Affected Products : openemr
    • EPSS Score: %1.67
    • Published: Mar. 22, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-25913

    Prototype pollution vulnerability in 'set-or-get' version 1.0.0 through 1.2.10 allows an attacker to cause a denial of service and may lead to remote code execution.... Read more

    Affected Products : set-or-get
    • EPSS Score: %2.95
    • Published: Feb. 08, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-25912

    Prototype pollution vulnerability in 'dotty' versions 0.0.1 through 0.1.0 allows attackers to cause a denial of service and may lead to remote code execution.... Read more

    Affected Products : dotty
    • EPSS Score: %2.95
    • Published: Feb. 02, 2021
    • Modified: Nov. 21, 2024
  • 8.0

    HIGH
    CVE-2021-25910

    Improper Authentication vulnerability in the cookie parameter of ZIV AUTOMATION 4CCT-EA6-334126BF allows a local attacker to perform modifications in several parameters of the affected device as an authenticated user.... Read more

    • EPSS Score: %0.07
    • Published: Jan. 29, 2021
    • Modified: Nov. 21, 2024
  • 8.6

    HIGH
    CVE-2021-25909

    ZIV Automation 4CCT-EA6-334126BF firmware version 3.23.80.27.36371, allows an unauthenticated, remote attacker to cause a denial of service condition on the device. An attacker could exploit this vulnerability by sending specific packets to the port 7919.... Read more

    • EPSS Score: %0.42
    • Published: Jan. 29, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-25908

    An issue was discovered in the fil-ocl crate through 2021-01-04 for Rust. From<EventList> can lead to a double free.... Read more

    Affected Products : fil-ocl
    • EPSS Score: %0.33
    • Published: Jan. 26, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-25907

    An issue was discovered in the containers crate before 0.9.11 for Rust. When a panic occurs, a util::{mutate,mutate2} double drop can be performed.... Read more

    Affected Products : containers
    • EPSS Score: %0.42
    • Published: Jan. 26, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-25906

    An issue was discovered in the basic_dsp_matrix crate before 0.9.2 for Rust. When a TransformContent panic occurs, a double drop can be performed.... Read more

    Affected Products : basic_dsp_matrix
    • EPSS Score: %0.33
    • Published: Jan. 26, 2021
    • Modified: Nov. 21, 2024
  • 9.1

    CRITICAL
    CVE-2021-25905

    An issue was discovered in the bra crate before 0.1.1 for Rust. It lacks soundness because it can read uninitialized memory.... Read more

    Affected Products : bra
    • EPSS Score: %0.43
    • Published: Jan. 26, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-25904

    An issue was discovered in the av-data crate before 0.3.0 for Rust. A raw pointer is dereferenced, leading to a read of an arbitrary memory address, sometimes causing a segfault.... Read more

    Affected Products : av-data
    • EPSS Score: %0.39
    • Published: Jan. 26, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-25903

    An issue was discovered in the cache crate through 2021-01-01 for Rust. A raw pointer is dereferenced.... Read more

    Affected Products : cache
    • EPSS Score: %0.39
    • Published: Jan. 26, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-25902

    An issue was discovered in the glsl-layout crate before 0.4.0 for Rust. When a panic occurs, map_array can perform a double drop.... Read more

    Affected Products : glsl-layout
    • EPSS Score: %0.33
    • Published: Jan. 26, 2021
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-25901

    An issue was discovered in the lazy-init crate through 2021-01-17 for Rust. Lazy lacks a Send bound, leading to a data race.... Read more

    Affected Products : lazy-init
    • EPSS Score: %0.30
    • Published: Jan. 26, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-25900

    An issue was discovered in the smallvec crate before 0.6.14 and 1.x before 1.6.1 for Rust. There is a heap-based buffer overflow in SmallVec::insert_many.... Read more

    Affected Products : smallvec
    • EPSS Score: %0.55
    • Published: Jan. 26, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-25899

    An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. An unauthenticated attacker can send a crafted HTTP request to perform a blind time-based SQL Injection. The vulnerable parameter is param1.... Read more

    Affected Products : aurall_rec_monitor
    • EPSS Score: %85.35
    • Published: Apr. 23, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-25898

    An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. Passwords are stored in unencrypted source-code text files. This was noted when accessing the svc-login.php file. The value is used to authenticate a high-privileged user upon aut... Read more

    • EPSS Score: %0.14
    • Published: Apr. 23, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-25894

    Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the /magnoliaPublic/travel/members/login.html mgnlUserId parameter.... Read more

    Affected Products : magnolia_cms
    • EPSS Score: %0.40
    • Published: Apr. 02, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-25893

    Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the setText parameter of /magnoliaAuthor/.magnolia/.... Read more

    Affected Products : magnolia_cms
    • EPSS Score: %0.38
    • Published: Apr. 02, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-25878

    AVideo/YouPHPTube 10.0 and prior is affected by multiple reflected Cross Script Scripting vulnerabilities via the videoName parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.... Read more

    Affected Products : youphptube
    • EPSS Score: %0.44
    • Published: Nov. 01, 2021
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2021-25877

    AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write files on filesystem using flag and code variables in file save.php.... Read more

    Affected Products : youphptube
    • EPSS Score: %1.20
    • Published: Nov. 01, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 291394 Results