Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2021-21278

    RSSHub is an open source, easy to use, and extensible RSS feed generator. In RSSHub before version 7f1c430 (non-semantic versioning) there is a risk of code injection. Some routes use `eval` or `Function constructor`, which may be injected by the target s... Read more

    Affected Products : rsshub
    • EPSS Score: %0.45
    • Published: Jan. 26, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-21277

    angular-expressions is "angular's nicest part extracted as a standalone module for the browser and node". In angular-expressions before version 1.1.2 there is a vulnerability which allows Remote Code Execution if you call "expressions.compile(userControll... Read more

    Affected Products : angular-expressions
    • EPSS Score: %0.72
    • Published: Feb. 01, 2021
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2021-21276

    Polr is an open source URL shortener. in Polr before version 2.3.0, a vulnerability in the setup process allows attackers to gain admin access to site instances, even if they do not possess an existing account. This vulnerability exists regardless of user... Read more

    Affected Products : polr
    • EPSS Score: %18.53
    • Published: Feb. 01, 2021
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-21275

    The MediaWiki "Report" extension has a Cross-Site Request Forgery (CSRF) vulnerability. Before fixed version, there was no protection against CSRF checks on Special:Report, so requests to report a revision could be forged. The problem has been fixed in co... Read more

    • EPSS Score: %0.18
    • Published: Jan. 25, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-21274

    Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, a malicious homeserver could redirect requests to their .well... Read more

    Affected Products : fedora synapse
    • EPSS Score: %0.58
    • Published: Feb. 26, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-21273

    Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, requests to user provided domains were not restricted to exte... Read more

    Affected Products : fedora synapse
    • EPSS Score: %0.39
    • Published: Feb. 26, 2021
    • Modified: Nov. 21, 2024
  • 7.7

    HIGH
    CVE-2021-21272

    ORAS is open source software which enables a way to push OCI Artifacts to OCI Conformant registries. ORAS is both a CLI for initial testing and a Go Module. In ORAS from version 0.4.0 and before version 0.9.0, there is a "zip-slip" vulnerability. The dire... Read more

    Affected Products : oras
    • EPSS Score: %0.22
    • Published: Jan. 25, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-21271

    Tendermint Core is an open source Byzantine Fault Tolerant (BFT) middleware that takes a state transition machine - written in any programming language - and securely replicates it on many machines. Tendermint Core v0.34.0 introduced a new way of handling... Read more

    Affected Products : tendermint
    • EPSS Score: %0.57
    • Published: Jan. 26, 2021
    • Modified: Nov. 21, 2024
  • 6.2

    MEDIUM
    CVE-2021-21270

    OctopusDSC is a PowerShell module with DSC resources that can be used to install and configure an Octopus Deploy Server and Tentacle agent. In OctopusDSC version 4.0.977 and earlier a customer API key used to connect to Octopus Server is exposed via loggi... Read more

    Affected Products : octopusdsc
    • EPSS Score: %0.04
    • Published: Jan. 22, 2021
    • Modified: Nov. 21, 2024
  • 7.7

    HIGH
    CVE-2021-21269

    Keymaker is a Mastodon Community Finder based Matrix Community serverlist page Server. In Keymaker before version 0.2.0, the assets endpoint did not check for the extension. The rust `join` method without checking user input might have made it abe to do a... Read more

    Affected Products : keymaker
    • EPSS Score: %0.36
    • Published: Jan. 20, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-21267

    Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before version 2.0.0, email address validation is vulnerable to a denial-of-service attack where some input (for example `[email protected].... Read more

    • EPSS Score: %0.87
    • Published: Mar. 19, 2021
    • Modified: Nov. 21, 2024
  • 6.4

    MEDIUM
    CVE-2021-21266

    openHAB is a vendor and technology agnostic open source automation software for your home. In openHAB before versions 2.5.12 and 3.0.1 the XML external entity (XXE) attack allows attackers in the same network as the openHAB instance to retrieve internal i... Read more

    Affected Products : openhab
    • EPSS Score: %0.25
    • Published: Feb. 01, 2021
    • Modified: Nov. 21, 2024
  • 5.2

    MEDIUM
    CVE-2021-21264

    October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-26231 (fixed in 1.0.470/471 and 1.1.1) was discovered that has the same impact as CVE-2020-26231 & CVE-2020-15247. An authenticated backend u... Read more

    Affected Products : october
    • EPSS Score: %0.05
    • Published: May. 03, 2021
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-21263

    Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit applies to the illuminate/database package which is used by Laravel. If a request is crafted where a fiel... Read more

    Affected Products : laravel framework
    • EPSS Score: %2.18
    • Published: Jan. 19, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-21261

    Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` service that can allow sandboxed applications to execute arbitrary code on the host system (a sandbox escape)... Read more

    Affected Products : debian_linux flatpak
    • EPSS Score: %0.05
    • Published: Jan. 14, 2021
    • Modified: Nov. 21, 2024
  • 7.6

    HIGH
    CVE-2021-21260

    Online Invoicing System (OIS) is open source software which is a lean invoicing system for small businesses, consultants and freelancers created using AppGini. In OIS version 4.0 there is a stored XSS which can enables an attacker takeover of the admin ac... Read more

    Affected Products : online_invoicing_system
    • EPSS Score: %0.21
    • Published: Jan. 22, 2021
    • Modified: Nov. 21, 2024
  • 7.4

    HIGH
    CVE-2021-21259

    HedgeDoc is open source software which lets you create real-time collaborative markdown notes. In HedgeDoc before version 1.7.2, an attacker can inject arbitrary JavaScript into a HedgeDoc note, which is executed when the note is viewed in slide mode. Dep... Read more

    Affected Products : hedgedoc
    • EPSS Score: %0.27
    • Published: Jan. 22, 2021
    • Modified: Nov. 21, 2024
  • 6.8

    MEDIUM
    CVE-2021-21258

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI from version 9.5.0 and before version 9.5.4, there is a cross-site scripting injection vulnerability... Read more

    Affected Products : glpi
    • EPSS Score: %0.28
    • Published: Mar. 02, 2021
    • Modified: Nov. 21, 2024
  • 8.2

    HIGH
    CVE-2021-21257

    Contiki-NG is an open-source, cross-platform operating system for internet of things devices. The RPL-Classic and RPL-Lite implementations in the Contiki-NG operating system versions prior to 4.6 do not validate the address pointer in the RPL source routi... Read more

    Affected Products : contiki-ng
    • EPSS Score: %0.33
    • Published: Jun. 18, 2021
    • Modified: Nov. 21, 2024
  • 5.8

    MEDIUM
    CVE-2021-21255

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI version 9.5.3, it was possible to switch entities with IDOR from a logged in user. This is fixed in ... Read more

    Affected Products : glpi
    • EPSS Score: %0.28
    • Published: Mar. 02, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 291014 Results