Latest CVE Feed
-
7.5
HIGHCVE-2021-26308
An issue was discovered in the marc crate before 2.0.0 for Rust. A user-provided Read implementation can gain access to the old contents of newly allocated memory, violating soundness.... Read more
Affected Products : marc- EPSS Score: %0.29
- Published: Jan. 29, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-26307
An issue was discovered in the raw-cpuid crate before 9.0.0 for Rust. It allows __cpuid_count() calls even if the processor does not support the CPUID instruction, which is unsound and causes a deterministic crash.... Read more
Affected Products : raw-cpuid- EPSS Score: %0.05
- Published: Jan. 29, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-26306
An issue was discovered in the raw-cpuid crate before 9.0.0 for Rust. It has unsound transmute calls within as_string() methods.... Read more
Affected Products : raw-cpuid- EPSS Score: %0.39
- Published: Jan. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26305
An issue was discovered in Deserializer::read_vec in the cdr crate before 0.2.4 for Rust. A user-provided Read implementation can gain access to the old contents of newly allocated heap memory, violating soundness.... Read more
Affected Products : cdr- EPSS Score: %0.50
- Published: Jan. 29, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-26304
PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the add-expense.php Item parameter.... Read more
Affected Products : daily_expense_tracker_system- EPSS Score: %0.18
- Published: Jan. 29, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26303
PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the user-profile.php Full Name field.... Read more
Affected Products : daily_expense_tracker_system- EPSS Score: %0.21
- Published: Jan. 29, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-26296
In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is ... Read more
- EPSS Score: %0.32
- Published: Feb. 19, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26295
Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.... Read more
Affected Products : ofbiz- EPSS Score: %94.26
- Published: Mar. 22, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-26294
An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal to read files (such as a data/settings/settings.xml file containing admin panel credentials), as demonstrated by dav/server.php/files/... Read more
- EPSS Score: %87.18
- Published: Mar. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26293
An issue was discovered in AfterLogic Aurora through 8.5.3 and WebMail Pro through 8.5.3, when DAV is enabled. They allow directory traversal to create new files (such as an executable file under the web root). This is related to DAVServer.php in 8.x and ... Read more
- EPSS Score: %50.70
- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-26291
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a p... Read more
- EPSS Score: %45.48
- Published: Apr. 23, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26277
The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to perform privileged actions.... Read more
- EPSS Score: %0.33
- Published: Feb. 17, 2023
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-26276
scripts/cli.js in the GoDaddy node-config-shield (aka Config Shield) package before 0.2.2 for Node.js calls eval when processing a set command. NOTE: the vendor reportedly states that this is not a vulnerability. The set command was not intended for use w... Read more
Affected Products : node-config-shield- EPSS Score: %0.24
- Published: Jan. 27, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-26275
The eslint-fixer package through 0.1.5 for Node.js allows command injection via shell metacharacters to the fix function. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. The ozum/eslint-fixer GitHub repositor... Read more
Affected Products : eslint-fixer- EPSS Score: %5.59
- Published: Mar. 19, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-26274
The Agent in NinjaRMM 5.0.909 has Insecure Permissions.... Read more
Affected Products : ninjarmm- EPSS Score: %0.04
- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26273
The Agent in NinjaRMM 5.0.909 has Incorrect Access Control.... Read more
Affected Products : ninjarmm- EPSS Score: %0.14
- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-26272
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).... Read more
- EPSS Score: %0.20
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-26271
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).... Read more
- EPSS Score: %0.64
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-26267
cPanel before 92.0.9 allows a MySQL user (who has an old-style password hash) to bypass suspension (SEC-579).... Read more
Affected Products : cpanel- EPSS Score: %0.24
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-26266
cPanel before 92.0.9 allows a Reseller to bypass the suspension lock (SEC-578).... Read more
Affected Products : cpanel- EPSS Score: %0.24
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024