Latest CVE Feed
-
6.1
MEDIUMCVE-2021-22888
Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `status` parameter of campaign-zone-zones.php. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifical... Read more
Affected Products : revive_adserver- EPSS Score: %0.82
- Published: Mar. 25, 2021
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2021-22887
A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can compromise the BI... Read more
Affected Products : psa-5000_firmware psa-7000_firmware x10slh-f_firmware x10sll-f_firmware x10slm-f_firmware x10sll\+f_firmware x10slm\+-f_firmware x10slm\+ln4f_firmware x10sla-f_firmware x10sl7-f_firmware +14 more products- EPSS Score: %0.06
- Published: Mar. 16, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-22886
Rocket.Chat before 3.11, 3.10.5, 3.9.7, 3.8.8 is vulnerable to persistent cross-site scripting (XSS) using nested markdown tags allowing a remote attacker to inject arbitrary JavaScript in a message. This flaw leads to arbitrary file read and RCE on Rocke... Read more
Affected Products : rocket.chat- EPSS Score: %0.46
- Published: Mar. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-22885
A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.... Read more
- EPSS Score: %0.97
- Published: May. 27, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-22884
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network... Read more
- EPSS Score: %0.27
- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-22883
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configur... Read more
- EPSS Score: %87.36
- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-22882
UniFi Protect before v1.17.1 allows an attacker to use spoofed cameras to perform a denial-of-service attack that may cause the UniFi Protect controller to crash.... Read more
- EPSS Score: %0.59
- Published: Feb. 23, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-22881
The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action... Read more
- EPSS Score: %6.85
- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-22880
The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the `money` type of the PostgreSQL adapter in Act... Read more
- EPSS Score: %5.88
- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-22879
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.... Read more
- EPSS Score: %1.01
- Published: Apr. 14, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-22878
Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `OC.Notification.show`.... Read more
- EPSS Score: %0.37
- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-22877
A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration when not already configured yet.... Read more
- EPSS Score: %0.46
- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-22875
Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in stats.php via the `setPerPage` parameter.... Read more
Affected Products : revive_adserver- EPSS Score: %0.70
- Published: Jan. 28, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-22874
Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in userlog-index.php via the `period_preset` parameter.... Read more
Affected Products : revive_adserver- EPSS Score: %0.70
- Published: Jan. 28, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-22873
Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php delivery scripts. Such open redirects had previously been available by design to allow third party ad servers to track ... Read more
Affected Products : revive_adserver- EPSS Score: %66.61
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-22872
Revive Adserver before 5.1.0 is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the publicly accessible afr.php delivery script. While this issue was previously addressed in modern browsers as CVE-2020-8115, some older browsers (e.g... Read more
Affected Products : revive_adserver- EPSS Score: %1.94
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-22871
Revive Adserver before 5.1.0 permits any user with a manager account to store possibly malicious content in the URL website property, which is then displayed unsanitized in the affiliate-preview.php tag generation screen, leading to a persistent cross-sit... Read more
Affected Products : revive_adserver- EPSS Score: %0.94
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-22870
A path traversal vulnerability was identified in GitHub Pages builds on GitHub Enterprise Server that could allow an attacker to read system files. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on... Read more
Affected Products : enterprise_server- EPSS Score: %0.46
- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22869
An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not have had access to. This affects customers using self-hosted runner groups for access control. A repository ... Read more
Affected Products : enterprise_server- EPSS Score: %0.39
- Published: Sep. 24, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-22868
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to read f... Read more
Affected Products : enterprise_server- EPSS Score: %0.28
- Published: Sep. 24, 2021
- Modified: Nov. 21, 2024