Latest CVE Feed
-
9.1
CRITICALCVE-2021-21308
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 the soft logout system is not complete and an attacker is able to foreign request and executes customer commands. The problem is fixed in 1.7.7.2... Read more
Affected Products : prestashop- EPSS Score: %0.37
- Published: Feb. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21307
Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.96 there is an unauthenticated remote code exploit. This is fixed in version... Read more
Affected Products : lucee_server- EPSS Score: %92.21
- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-21306
Marked is an open-source markdown parser and compiler (npm package "marked"). In marked from version 1.1.1 and before version 2.0.0, there is a Regular expression Denial of Service vulnerability. This vulnerability can affect anyone who runs user generate... Read more
Affected Products : marked- EPSS Score: %0.60
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-21305
CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1, there is a code injection vulnerability. The "#manipulate!" method inappropriately evals... Read more
Affected Products : carrierwave- EPSS Score: %3.57
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21304
Dynamoose is an open-source modeling tool for Amazon's DynamoDB. In Dynamoose from version 2.0.0 and before version 2.7.0 there was a prototype pollution vulnerability in the internal utility method "lib/utils/object/set.ts". This method is used throughou... Read more
Affected Products : dynamoose- EPSS Score: %0.64
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-21303
Helm is open-source software which is essentially "The Kubernetes Package Manager". Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. In Helm from version 3.0 and before version 3.5.2, there a few cases where ... Read more
Affected Products : helm- EPSS Score: %0.17
- Published: Feb. 05, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-21302
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by using shop search keywords via the admin panel. The problem is fixed in 1.7.7.2... Read more
Affected Products : prestashop- EPSS Score: %0.47
- Published: Feb. 26, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-21301
Wire is an open-source collaboration platform. In Wire for iOS (iPhone and iPad) before version 3.75 there is a vulnerability where the video capture isn't stopped in a scenario where a user first has their camera enabled and then disables it. It's a priv... Read more
Affected Products : wire- EPSS Score: %0.39
- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2021-21300
Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as Git LFS, may cause just-checked out script to be execut... Read more
- EPSS Score: %70.68
- Published: Mar. 09, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-21299
hyper is an open-source HTTP library for Rust (crates.io). In hyper from version 0.12.0 and before versions 0.13.10 and 0.14.3 there is a vulnerability that can enable a request smuggling attack. The HTTP server code had a flaw that incorrectly understand... Read more
Affected Products : hyper- EPSS Score: %0.58
- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-21298
Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier has a vulnerability which allows arbitrary path traversal via the Projects API. If the Projects feature is enabled, a user with `projects.read`... Read more
Affected Products : node-red- EPSS Score: %0.36
- Published: Feb. 26, 2021
- Modified: Nov. 21, 2024
-
7.7
HIGHCVE-2021-21297
Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier contains a Prototype Pollution vulnerability in the admin API. A badly formed request can modify the prototype of the default JavaScript Object... Read more
Affected Products : node-red- EPSS Score: %0.33
- Published: Feb. 26, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2021-21296
Fleet is an open source osquery manager. In Fleet before version 3.7.0 a malicious actor with a valid node key can send a badly formatted request that causes the Fleet server to exit, resulting in denial of service. This is possible only while a live quer... Read more
Affected Products : fleet- EPSS Score: %0.57
- Published: Feb. 10, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-21295
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability ... Read more
- EPSS Score: %2.08
- Published: Mar. 09, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-21294
Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Http4s before versions 0.21.17, 0.22.0-M2, and 1.0.0-M14 have a vulnerability which can lead to a denial-of-service. Blaze-core, a library underlying http4s-blaze-serv... Read more
Affected Products : http4s- EPSS Score: %0.53
- Published: Feb. 02, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-21293
blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. All servers running blaze-core before version 0.14.15 are affected by a vulnerability in which unbounded connection acceptance leads to file handle exhaustion. Blaze... Read more
Affected Products : blaze- EPSS Score: %0.41
- Published: Feb. 02, 2021
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2021-21292
Traccar is an open source GPS tracking system. In Traccar before version 4.12 there is an unquoted Windows binary path vulnerability. Only Windows versions are impacted. Attacker needs write access to the filesystem on the host machine. If Java path inclu... Read more
- EPSS Score: %0.06
- Published: Feb. 02, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-21291
OAuth2 Proxy is an open-source reverse proxy and static file server that provides authentication using Providers (Google, GitHub, and others) to validate accounts by email, domain or group. In OAuth2 Proxy before version 7.0.0, for users that use the whit... Read more
Affected Products : oauth2_proxy- EPSS Score: %0.24
- Published: Feb. 02, 2021
- Modified: Nov. 21, 2024
-
6.2
MEDIUMCVE-2021-21290
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involvin... Read more
- EPSS Score: %0.02
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
8.3
HIGHCVE-2021-21289
Mechanize is an open-source ruby library that makes automated web interaction easy. In Mechanize from version 2.0.0 and before version 2.7.7 there is a command injection vulnerability. Affected versions of mechanize allow for OS commands to be injected us... Read more
- EPSS Score: %2.50
- Published: Feb. 02, 2021
- Modified: Nov. 21, 2024