Latest CVE Feed
-
7.5
HIGHCVE-2021-21373
Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a list of Nimble packages over HTTPS by default. In case of error it falls back to a non-TLS URL http://irclog... Read more
Affected Products : nim- EPSS Score: %0.16
- Published: Mar. 26, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-21372
Nimble is a package manager for the Nim programming language. In Nim release version before versions 1.2.10 and 1.4.4, Nimble doCmd is used in different places and can be leveraged to execute arbitrary commands. An attacker can craft a malicious entry in ... Read more
Affected Products : nim- EPSS Score: %1.12
- Published: Mar. 26, 2021
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-21371
Tenable for Jira Cloud is an open source project designed to pull Tenable.io vulnerability data, then generate Jira Tasks and sub-tasks based on the vulnerabilities' current state. It published in pypi as "tenable-jira-cloud". In tenable-jira-cloud before... Read more
Affected Products : jira_cloud- EPSS Score: %0.08
- Published: Mar. 10, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-21370
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that content elements of type _menu_ are vulnerable to cross-site scripting when their referenced item... Read more
Affected Products : typo3- EPSS Score: %0.34
- Published: Mar. 23, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-21369
Hyperledger Besu is an open-source, MainNet compatible, Ethereum client written in Java. In Besu before version 1.5.1 there is a denial-of-service vulnerability involving the HTTP JSON-RPC API service. If username and password authentication is enabled fo... Read more
Affected Products : besu- EPSS Score: %0.58
- Published: Mar. 09, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-21368
msgpack5 is a msgpack v5 implementation for node.js and the browser. In msgpack5 before versions 3.6.1, 4.5.1, and 5.2.1 there is a "Prototype Poisoning" vulnerability. When msgpack5 decodes a map containing a key "__proto__", it assigns the decoded value... Read more
Affected Products : msgpack5- EPSS Score: %1.20
- Published: Mar. 12, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-21367
Switchboard Bluetooth Plug for elementary OS from version 2.3.0 and before version version 2.3.5 has an incorrect authorization vulnerability. When the Bluetooth plug is running (in discoverable mode), Bluetooth service requests and pairing requests are a... Read more
- EPSS Score: %0.14
- Published: Mar. 12, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-21366
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.4.0 and older do not correctly preserve system identifiers, FPIs or namespaces when repeatedly parsing and serializing maliciously ... Read more
- EPSS Score: %0.57
- Published: Mar. 12, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-21365
Bootstrap Package is a theme for TYPO3. It has been discovered that rendering content in the website frontend is vulnerable to cross-site scripting. A valid backend user account is needed to exploit this vulnerability. Users of the extension, who have ove... Read more
Affected Products : typo3- EPSS Score: %0.34
- Published: Apr. 27, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-21364
swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger definition. In swagger-codegen before version 2.4.19, on Uni... Read more
Affected Products : swagger-codegen- EPSS Score: %0.08
- Published: Mar. 11, 2021
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2021-21363
swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger definition. In swagger-codegen before version 2.4.19, on Uni... Read more
Affected Products : swagger-codegen- EPSS Score: %0.04
- Published: Mar. 11, 2021
- Modified: Nov. 21, 2024
-
7.7
HIGHCVE-2021-21362
MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage service. In MinIO before version RELEASE.2021-03-04T00-53-13Z it is possible to bypass a readOnly policy by creating a temporary 'mc shar... Read more
Affected Products : minio- EPSS Score: %0.08
- Published: Mar. 08, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-21361
The `com.bmuschko:gradle-vagrant-plugin` Gradle plugin contains an information disclosure vulnerability due to the logging of the system environment variables. When this Gradle plugin is executed in public CI/CD, this can lead to sensitive credentials bei... Read more
Affected Products : vagrant- EPSS Score: %0.12
- Published: Mar. 09, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-21360
Products.GenericSetup is a mini-framework for expressing the configured state of a Zope Site as a set of filesystem artifacts. In Products.GenericSetup before version 2.1.1 there is an information disclosure vulnerability - anonymous visitors may view log... Read more
Affected Products : products.genericsetup- EPSS Score: %0.34
- Published: Mar. 09, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-21359
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.25, 10.4.14, 11.1.1 requesting invalid or non-existing resources via HTTP triggers the page error handler which again could retrieve content to be shown as error... Read more
Affected Products : typo3- EPSS Score: %2.56
- Published: Mar. 23, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-21358
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that the Form Designer backend module of the Form Framework is vulnerable to cross-site scripting. A valid backend user accoun... Read more
Affected Products : typo3- EPSS Score: %0.38
- Published: Mar. 23, 2021
- Modified: Nov. 21, 2024
-
8.3
HIGHCVE-2021-21357
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1 due to improper input validation, attackers can by-pass restrictions of predefined options and submit arbitrary data in the Form Desi... Read more
Affected Products : typo3- EPSS Score: %1.12
- Published: Mar. 23, 2021
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-21355
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1, due to the lack of ensuring file extensions belong to configured allowed mime-types, attackers can upload arbitrary data with arbitr... Read more
Affected Products : typo3- EPSS Score: %0.42
- Published: Mar. 23, 2021
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2021-21354
Pollbot is open source software which "frees its human masters from the toilsome task of polling for the state of things during the Firefox release process." In Pollbot before version 1.4.4 there is an open redirection vulnerability in the path of "https:... Read more
Affected Products : pollbot- EPSS Score: %0.57
- Published: Mar. 08, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-21352
Anuko Time Tracker is an open source, web-based time tracking application written in PHP. In TimeTracker before version 1.19.24.5415 tokens used in password reset feature in Time Tracker are based on system time and, therefore, are predictable. This opens... Read more
Affected Products : time_tracker- EPSS Score: %0.42
- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024