Latest CVE Feed
-
7.8
HIGHCVE-2021-23521
This affects the package juce-framework/JUCE before 6.1.5. This vulnerability is triggered when a malicious archive is crafted with an entry containing a symbolic link. When extracted, the symbolic link is followed outside of the target dir allowing writi... Read more
Affected Products : juce- EPSS Score: %0.08
- Published: Jan. 31, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23520
The package juce-framework/juce before 6.1.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) via the ZipFile::uncompressEntry function in juce_ZipFile.cpp. This vulnerability is triggered when the archive is extracted upon calling... Read more
Affected Products : juce- EPSS Score: %0.74
- Published: Jan. 31, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23518
The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the... Read more
- EPSS Score: %0.13
- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-23514
This affects the package Crow before 0.3+4. It is possible to traverse directories to fetch arbitrary files from the server.... Read more
Affected Products : crow- EPSS Score: %0.48
- Published: Jan. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23509
This affects the package json-ptr before 3.0.0. A type confusion vulnerability can lead to a bypass of CVE-2020-7766 when the user-provided keys used in the pointer parameter are arrays.... Read more
Affected Products : json-ptr- EPSS Score: %1.75
- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23507
The package object-path-set before 1.0.2 are vulnerable to Prototype Pollution via the setPath method, as it allows an attacker to merge object prototypes into it. *Note:* This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/... Read more
Affected Products : object-path-set- EPSS Score: %0.50
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23497
This affects the package @strikeentco/set before 1.0.2. It allows an attacker to cause a denial of service and may lead to remote code execution. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-STRIKEEN... Read more
Affected Products : set- EPSS Score: %3.25
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-23495
The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter.... Read more
Affected Products : karma- EPSS Score: %0.26
- Published: Feb. 25, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-23490
The package parse-link-header before 2.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the checkHeader function.... Read more
Affected Products : parse-link-header- EPSS Score: %0.41
- Published: Dec. 24, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23484
The package zip-local before 0.3.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) which can lead to an extraction of a crafted file outside the intended extraction directory.... Read more
Affected Products : zip-local- EPSS Score: %0.59
- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-23472
This affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is ... Read more
Affected Products : bootstrap_table- EPSS Score: %0.58
- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23470
This affects the package putil-merge before 3.8.0. The merge() function does not check the values passed into the argument. An attacker can supply a malicious value by adjusting the value to include the constructor property. Note: This vulnerability deriv... Read more
Affected Products : putil-merge- EPSS Score: %1.46
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-23463
The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML() method. If it e... Read more
Affected Products : h2- EPSS Score: %0.12
- Published: Dec. 10, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-23460
The package min-dash before 3.8.1 are vulnerable to Prototype Pollution via the set method due to missing enforcement of key types.... Read more
Affected Products : min-dash- EPSS Score: %0.54
- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23452
This affects all versions of package x-assign. The global proto object can be polluted using the __proto__ object.... Read more
Affected Products : x-assign- EPSS Score: %0.56
- Published: Oct. 20, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23451
The package otp-generator before 3.0.0 are vulnerable to Insecure Randomness due to insecure generation of random one-time passwords, which may allow a brute-force attack.... Read more
Affected Products : otp-generator- EPSS Score: %0.36
- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23450
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.... Read more
Affected Products : debian_linux weblogic_server communications_policy_management primavera_unifier dojo- EPSS Score: %2.41
- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-23449
This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitrary code on the host machine.... Read more
Affected Products : vm2- EPSS Score: %0.60
- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23448
All versions of package config-handler are vulnerable to Prototype Pollution when loading config files.... Read more
Affected Products : config-handler- EPSS Score: %0.44
- Published: Oct. 11, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-23447
This affects the package teddy before 0.5.9. A type confusion vulnerability can be used to bypass input sanitization when the model content is an array (instead of a string).... Read more
Affected Products : teddy- EPSS Score: %0.30
- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024