Latest CVE Feed
-
6.8
MEDIUMCVE-2021-21319
Galette is a membership management web application geared towards non profit organizations. In versions prior to 0.9.5, malicious javascript code can be stored to be displayed later on self subscription page. The self subscription feature can be disabled ... Read more
Affected Products : galette- EPSS Score: %0.88
- Published: Oct. 25, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-21318
Opencast is a free, open-source platform to support the management of educational audio and video content. In Opencast before version 9.2 there is a vulnerability in which publishing an episode with strict access rules will overwrite the currently set ser... Read more
Affected Products : opencast- EPSS Score: %0.19
- Published: Feb. 18, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-21317
uap-core in an open-source npm package which contains the core of BrowserScope's original user agent string parser. In uap-core before version 0.11.0, some regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture g... Read more
Affected Products : uap-core- EPSS Score: %1.48
- Published: Feb. 16, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-21316
less-openui5 is an npm package which enables building OpenUI5 themes with Less.js. In less-openui5 before version 0.10., when processing theming resources (i.e. `*.less` files) with less-openui5 that originate from an untrusted source, those resources mig... Read more
Affected Products : less-openui5- EPSS Score: %0.30
- Published: Feb. 16, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-21314
GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In GLPI before verison 9.5.4, there is an XSS vulnerability involving a logged in user while updating a ticket... Read more
Affected Products : glpi- EPSS Score: %0.32
- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-21313
GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In GLPI before verison 9.5.4, there is a vulnerability in the /ajax/common.tabs.php endpoint, indeed, at least... Read more
Affected Products : glpi- EPSS Score: %0.39
- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-21312
GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In GLPI before verison 9.5.4, there is a vulnerability within the document upload function (Home > Management ... Read more
Affected Products : glpi- EPSS Score: %0.32
- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-21311
Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This... Read more
- EPSS Score: %86.40
- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-21310
NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. In next-auth before version 3.3.0 there is a token verification vulnerability. Implementations using the Prisma database adapter in conjunction with the Email prov... Read more
Affected Products : next-auth- EPSS Score: %0.37
- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-21309
Redis is an open-source, in-memory database that persists on disk. In affected versions of Redis an integer overflow bug in 32-bit Redis version 4.0 or newer could be exploited to corrupt the heap and potentially result with remote code execution. Redis 4... Read more
- EPSS Score: %0.53
- Published: Feb. 26, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-21308
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 the soft logout system is not complete and an attacker is able to foreign request and executes customer commands. The problem is fixed in 1.7.7.2... Read more
Affected Products : prestashop- EPSS Score: %0.37
- Published: Feb. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21307
Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.96 there is an unauthenticated remote code exploit. This is fixed in version... Read more
Affected Products : lucee_server- EPSS Score: %92.21
- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-21306
Marked is an open-source markdown parser and compiler (npm package "marked"). In marked from version 1.1.1 and before version 2.0.0, there is a Regular expression Denial of Service vulnerability. This vulnerability can affect anyone who runs user generate... Read more
Affected Products : marked- EPSS Score: %0.60
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-21305
CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1, there is a code injection vulnerability. The "#manipulate!" method inappropriately evals... Read more
Affected Products : carrierwave- EPSS Score: %3.57
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21304
Dynamoose is an open-source modeling tool for Amazon's DynamoDB. In Dynamoose from version 2.0.0 and before version 2.7.0 there was a prototype pollution vulnerability in the internal utility method "lib/utils/object/set.ts". This method is used throughou... Read more
Affected Products : dynamoose- EPSS Score: %0.64
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-21303
Helm is open-source software which is essentially "The Kubernetes Package Manager". Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. In Helm from version 3.0 and before version 3.5.2, there a few cases where ... Read more
Affected Products : helm- EPSS Score: %0.17
- Published: Feb. 05, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-21302
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by using shop search keywords via the admin panel. The problem is fixed in 1.7.7.2... Read more
Affected Products : prestashop- EPSS Score: %0.47
- Published: Feb. 26, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-21301
Wire is an open-source collaboration platform. In Wire for iOS (iPhone and iPad) before version 3.75 there is a vulnerability where the video capture isn't stopped in a scenario where a user first has their camera enabled and then disables it. It's a priv... Read more
Affected Products : wire- EPSS Score: %0.39
- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2021-21300
Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as Git LFS, may cause just-checked out script to be execut... Read more
- EPSS Score: %70.68
- Published: Mar. 09, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-21299
hyper is an open-source HTTP library for Rust (crates.io). In hyper from version 0.12.0 and before versions 0.13.10 and 0.14.3 there is a vulnerability that can enable a request smuggling attack. The HTTP server code had a flaw that incorrectly understand... Read more
Affected Products : hyper- EPSS Score: %0.58
- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024