Latest CVE Feed
-
5.4
MEDIUMCVE-2021-25934
In OpenNMS Horizon, versions opennms-18.0.0-1 through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.7-1 are vulnerable... Read more
- EPSS Score: %0.28
- Published: May. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25932
In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerab... Read more
- EPSS Score: %0.26
- Published: Jun. 01, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-25924
In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup` endpoint. An attacker can trick a victim to click on a malicious link which could change backup configurations or... Read more
Affected Products : gocd- EPSS Score: %0.93
- Published: Apr. 01, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-25923
In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of the victim user’s password, he can leverage it to an acco... Read more
Affected Products : openemr- EPSS Score: %0.06
- Published: Jun. 24, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25922
In OpenEMR, versions 4.2.0 to 6.0.0 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly. An attacker could trick a user to click on a malicious url and execute malicious code.... Read more
Affected Products : openemr- EPSS Score: %1.67
- Published: Mar. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25913
Prototype pollution vulnerability in 'set-or-get' version 1.0.0 through 1.2.10 allows an attacker to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : set-or-get- EPSS Score: %2.95
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25912
Prototype pollution vulnerability in 'dotty' versions 0.0.1 through 0.1.0 allows attackers to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : dotty- EPSS Score: %2.95
- Published: Feb. 02, 2021
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2021-25910
Improper Authentication vulnerability in the cookie parameter of ZIV AUTOMATION 4CCT-EA6-334126BF allows a local attacker to perform modifications in several parameters of the affected device as an authenticated user.... Read more
- EPSS Score: %0.07
- Published: Jan. 29, 2021
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-25909
ZIV Automation 4CCT-EA6-334126BF firmware version 3.23.80.27.36371, allows an unauthenticated, remote attacker to cause a denial of service condition on the device. An attacker could exploit this vulnerability by sending specific packets to the port 7919.... Read more
- EPSS Score: %0.42
- Published: Jan. 29, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-25908
An issue was discovered in the fil-ocl crate through 2021-01-04 for Rust. From<EventList> can lead to a double free.... Read more
Affected Products : fil-ocl- EPSS Score: %0.33
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25907
An issue was discovered in the containers crate before 0.9.11 for Rust. When a panic occurs, a util::{mutate,mutate2} double drop can be performed.... Read more
Affected Products : containers- EPSS Score: %0.42
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-25906
An issue was discovered in the basic_dsp_matrix crate before 0.9.2 for Rust. When a TransformContent panic occurs, a double drop can be performed.... Read more
Affected Products : basic_dsp_matrix- EPSS Score: %0.33
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-25905
An issue was discovered in the bra crate before 0.1.1 for Rust. It lacks soundness because it can read uninitialized memory.... Read more
Affected Products : bra- EPSS Score: %0.43
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-25904
An issue was discovered in the av-data crate before 0.3.0 for Rust. A raw pointer is dereferenced, leading to a read of an arbitrary memory address, sometimes causing a segfault.... Read more
Affected Products : av-data- EPSS Score: %0.39
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-25903
An issue was discovered in the cache crate through 2021-01-01 for Rust. A raw pointer is dereferenced.... Read more
Affected Products : cache- EPSS Score: %0.39
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-25902
An issue was discovered in the glsl-layout crate before 0.4.0 for Rust. When a panic occurs, map_array can perform a double drop.... Read more
Affected Products : glsl-layout- EPSS Score: %0.33
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-25901
An issue was discovered in the lazy-init crate through 2021-01-17 for Rust. Lazy lacks a Send bound, leading to a data race.... Read more
Affected Products : lazy-init- EPSS Score: %0.30
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25900
An issue was discovered in the smallvec crate before 0.6.14 and 1.x before 1.6.1 for Rust. There is a heap-based buffer overflow in SmallVec::insert_many.... Read more
Affected Products : smallvec- EPSS Score: %0.55
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-25899
An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. An unauthenticated attacker can send a crafted HTTP request to perform a blind time-based SQL Injection. The vulnerable parameter is param1.... Read more
Affected Products : aurall_rec_monitor- EPSS Score: %85.35
- Published: Apr. 23, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-25898
An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. Passwords are stored in unencrypted source-code text files. This was noted when accessing the svc-login.php file. The value is used to authenticate a high-privileged user upon aut... Read more
- EPSS Score: %0.14
- Published: Apr. 23, 2021
- Modified: Nov. 21, 2024