Latest CVE Feed
-
4.8
MEDIUMCVE-2021-23838
An issue was discovered in flatCore before 2.0.0 build 139. A reflected XSS vulnerability was identified in the media_filter HTTP request body parameter for the acp interface. The affected parameter accepts malicious client-side script without proper inpu... Read more
- EPSS Score: %0.34
- Published: Jan. 15, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-23837
An issue was discovered in flatCore before 2.0.0 build 139. A time-based blind SQL injection was identified in the selected_folder HTTP request body parameter for the acp interface. The affected parameter (which retrieves the file contents of the specifie... Read more
- EPSS Score: %0.78
- Published: Jan. 15, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-23836
An issue was discovered in flatCore before 2.0.0 build 139. A stored XSS vulnerability was identified in the prefs_smtp_psw HTTP request body parameter for the acp interface. An admin user can inject malicious client-side script into the affected paramete... Read more
- EPSS Score: %0.40
- Published: Jan. 15, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-23835
An issue was discovered in flatCore before 2.0.0 build 139. A local file disclosure vulnerability was identified in the docs_file HTTP request body parameter for the acp interface. This can be exploited with admin access rights. The affected parameter (wh... Read more
- EPSS Score: %1.64
- Published: Jan. 15, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-23827
Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps directories. It fails to effectively clear cached picture... Read more
- EPSS Score: %0.08
- Published: Feb. 23, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-23824
This affects the package Crow before 0.3+4. When using attributes without quotes in the template, an attacker can manipulate the input to introduce additional attributes, potentially executing code. This may lead to a Cross-site Scripting (XSS) vulnerabil... Read more
Affected Products : crow- EPSS Score: %0.29
- Published: Jan. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23820
This affects all versions of package json-pointer. A type confusion vulnerability can lead to a bypass of CVE-2020-7709 when the pointer components are arrays.... Read more
- EPSS Score: %0.20
- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23803
This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the security of the application. When the template is set to allow/disallow the use of certain functions, adding control characters (x00-x08) afte... Read more
Affected Products : latte- EPSS Score: %0.41
- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23797
All versions of package http-server-node are vulnerable to Directory Traversal via use of --path-as-is.... Read more
Affected Products : http-server-node- EPSS Score: %0.64
- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23792
The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injection due to an insecurely initialized XML parser for reading XMP Metadata. An attacker can exploit this vulnerability if they are able to ... Read more
Affected Products : twelvemonkeys- EPSS Score: %0.28
- Published: May. 06, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-23784
This affects the package tempura before 0.4.0. If the input to the esc function is of type object (i.e an array) it is returned without being escaped/sanitized, leading to a potential Cross-Site Scripting vulnerability.... Read more
Affected Products : tempura- EPSS Score: %0.33
- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-23772
This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The unsafe handling of file names during upload using UploadFormFiles method may enable attackers to write to arbitrary locations outside th... Read more
- EPSS Score: %0.66
- Published: Dec. 24, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-23771
This affects all versions of package notevil; all versions of package argencoders-notevil. It is vulnerable to Sandbox Escape leading to Prototype pollution. The package fails to restrict access to the main context, allowing an attacker to add or modify a... Read more
- EPSS Score: %0.29
- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23760
The package keyget from 0.0.0 are vulnerable to Prototype Pollution via the methods set, push, and at which could allow an attacker to cause a denial of service and may lead to remote code execution. **Note:** This vulnerability derives from an incomplete... Read more
Affected Products : keyget- EPSS Score: %2.42
- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23758
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.... Read more
Affected Products : ajaxpro.2- EPSS Score: %87.78
- Published: Dec. 03, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-23732
This affects all versions of package docker-cli-js. If the command parameter of the Docker.command method can at least be partially controlled by a user, they will be in a position to execute any arbitrary OS commands on the host system.... Read more
Affected Products : docker-cli-js- EPSS Score: %0.84
- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-23727
This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow m... Read more
- EPSS Score: %2.02
- Published: Dec. 29, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-23718
The package ssrf-agent before 1.0.5 are vulnerable to Server-side Request Forgery (SSRF) via the defaultIpChecker function. It fails to properly validate if the IP requested is private.... Read more
Affected Products : ssrf-agent- EPSS Score: %0.35
- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23702
The package object-extend from 0.0.0 are vulnerable to Prototype Pollution via object-extend.... Read more
Affected Products : object-extend- EPSS Score: %0.38
- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23700
All versions of package merge-deep2 are vulnerable to Prototype Pollution via the mergeDeep() function.... Read more
Affected Products : merge-deep2- EPSS Score: %0.48
- Published: Dec. 10, 2021
- Modified: Nov. 21, 2024