Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2021-23521

    This affects the package juce-framework/JUCE before 6.1.5. This vulnerability is triggered when a malicious archive is crafted with an entry containing a symbolic link. When extracted, the symbolic link is followed outside of the target dir allowing writi... Read more

    Affected Products : juce
    • EPSS Score: %0.08
    • Published: Jan. 31, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-23520

    The package juce-framework/juce before 6.1.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) via the ZipFile::uncompressEntry function in juce_ZipFile.cpp. This vulnerability is triggered when the archive is extracted upon calling... Read more

    Affected Products : juce
    • EPSS Score: %0.74
    • Published: Jan. 31, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-23518

    The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the... Read more

    Affected Products : debian_linux cached-path-relative
    • EPSS Score: %0.13
    • Published: Jan. 21, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-23514

    This affects the package Crow before 0.3+4. It is possible to traverse directories to fetch arbitrary files from the server.... Read more

    Affected Products : crow
    • EPSS Score: %0.48
    • Published: Jan. 13, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-23509

    This affects the package json-ptr before 3.0.0. A type confusion vulnerability can lead to a bypass of CVE-2020-7766 when the user-provided keys used in the pointer parameter are arrays.... Read more

    Affected Products : json-ptr
    • EPSS Score: %1.75
    • Published: Nov. 03, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-23507

    The package object-path-set before 1.0.2 are vulnerable to Prototype Pollution via the setPath method, as it allows an attacker to merge object prototypes into it. *Note:* This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/... Read more

    Affected Products : object-path-set
    • EPSS Score: %0.50
    • Published: Feb. 04, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-23497

    This affects the package @strikeentco/set before 1.0.2. It allows an attacker to cause a denial of service and may lead to remote code execution. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-STRIKEEN... Read more

    Affected Products : set
    • EPSS Score: %3.25
    • Published: Feb. 04, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-23495

    The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter.... Read more

    Affected Products : karma
    • EPSS Score: %0.26
    • Published: Feb. 25, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-23490

    The package parse-link-header before 2.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the checkHeader function.... Read more

    Affected Products : parse-link-header
    • EPSS Score: %0.41
    • Published: Dec. 24, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-23484

    The package zip-local before 0.3.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) which can lead to an extraction of a crafted file outside the intended extraction directory.... Read more

    Affected Products : zip-local
    • EPSS Score: %0.59
    • Published: Jan. 28, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-23472

    This affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is ... Read more

    Affected Products : bootstrap_table
    • EPSS Score: %0.58
    • Published: Nov. 03, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-23470

    This affects the package putil-merge before 3.8.0. The merge() function does not check the values passed into the argument. An attacker can supply a malicious value by adjusting the value to include the constructor property. Note: This vulnerability deriv... Read more

    Affected Products : putil-merge
    • EPSS Score: %1.46
    • Published: Feb. 04, 2022
    • Modified: Nov. 21, 2024
  • 9.1

    CRITICAL
    CVE-2021-23463

    The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML() method. If it e... Read more

    Affected Products : h2
    • EPSS Score: %0.12
    • Published: Dec. 10, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-23460

    The package min-dash before 3.8.1 are vulnerable to Prototype Pollution via the set method due to missing enforcement of key types.... Read more

    Affected Products : min-dash
    • EPSS Score: %0.54
    • Published: Jan. 21, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-23452

    This affects all versions of package x-assign. The global proto object can be polluted using the __proto__ object.... Read more

    Affected Products : x-assign
    • EPSS Score: %0.56
    • Published: Oct. 20, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-23451

    The package otp-generator before 3.0.0 are vulnerable to Insecure Randomness due to insecure generation of random one-time passwords, which may allow a brute-force attack.... Read more

    Affected Products : otp-generator
    • EPSS Score: %0.36
    • Published: Jul. 25, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-23450

    All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.... Read more

    • EPSS Score: %2.41
    • Published: Dec. 17, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2021-23449

    This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitrary code on the host machine.... Read more

    Affected Products : vm2
    • EPSS Score: %0.60
    • Published: Oct. 18, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-23448

    All versions of package config-handler are vulnerable to Prototype Pollution when loading config files.... Read more

    Affected Products : config-handler
    • EPSS Score: %0.44
    • Published: Oct. 11, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-23447

    This affects the package teddy before 0.5.9. A type confusion vulnerability can be used to bypass input sanitization when the model content is an array (instead of a string).... Read more

    Affected Products : teddy
    • EPSS Score: %0.30
    • Published: Oct. 07, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 290940 Results