Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.3

    MEDIUM
    CVE-2021-21288

    CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1 the download feature has an SSRF vulnerability, allowing attacks to provide DNS entries o... Read more

    Affected Products : carrierwave
    • EPSS Score: %0.20
    • Published: Feb. 08, 2021
    • Modified: Nov. 21, 2024
  • 7.7

    HIGH
    CVE-2021-21287

    MinIO is a High Performance Object Storage released under Apache License v2.0. In MinIO before version RELEASE.2021-01-30T00-20-58Z there is a server-side request forgery vulnerability. The target application may have functionality for importing data from... Read more

    Affected Products : minio
    • EPSS Score: %92.68
    • Published: Feb. 01, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-21286

    AVideo Platform is an open-source Audio and Video platform. It is similar to a self-hosted YouTube. In AVideo Platform before version 10.2 there is an authorization bypass vulnerability which enables an ordinary user to get admin control. This is fixed in... Read more

    Affected Products : avideo
    • EPSS Score: %0.26
    • Published: Feb. 01, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-21285

    In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the dockerd daemon. Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing.... Read more

    • EPSS Score: %0.14
    • Published: Feb. 02, 2021
    • Modified: Nov. 21, 2024
  • 6.8

    MEDIUM
    CVE-2021-21284

    In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access to remapped root allows privilege escalation to real root. When using "--userns-remap", if the root user in the remapped namespace has ... Read more

    • EPSS Score: %0.03
    • Published: Feb. 02, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-21283

    Flarum is an open source discussion platform for websites. The "Flarum Sticky" extension versions 0.1.0-beta.14 and 0.1.0-beta.15 has a cross-site scripting vulnerability. A change in release beta 14 of the Sticky extension caused the plain text content o... Read more

    Affected Products : sticky
    • EPSS Score: %0.35
    • Published: Jan. 26, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-21282

    Contiki-NG is an open-source, cross-platform operating system for internet of things devices. In versions prior to 4.5, buffer overflow can be triggered by an input packet when using either of Contiki-NG's two RPL implementations in source-routing mode. T... Read more

    Affected Products : contiki-ng
    • EPSS Score: %0.44
    • Published: Jun. 18, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-21281

    Contiki-NG is an open-source, cross-platform operating system for internet of things devices. A buffer overflow vulnerability exists in Contiki-NG versions prior to 4.6. After establishing a TCP socket using the tcp-socket library, it is possible for the ... Read more

    Affected Products : contiki-ng
    • EPSS Score: %0.44
    • Published: Jun. 18, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-21280

    Contiki-NG is an open-source, cross-platform operating system for internet of things devices. It is possible to cause an out-of-bounds write in versions of Contiki-NG prior to 4.6 when transmitting a 6LoWPAN packet with a chain of extension headers. Unfor... Read more

    Affected Products : contiki-ng
    • EPSS Score: %0.41
    • Published: Jun. 18, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-21279

    Contiki-NG is an open-source, cross-platform operating system for internet of things devices. In verions prior to 4.6, an attacker can perform a denial-of-service attack by triggering an infinite loop in the processing of IPv6 neighbor solicitation (NS) m... Read more

    Affected Products : contiki-ng
    • EPSS Score: %0.30
    • Published: Jun. 18, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-21278

    RSSHub is an open source, easy to use, and extensible RSS feed generator. In RSSHub before version 7f1c430 (non-semantic versioning) there is a risk of code injection. Some routes use `eval` or `Function constructor`, which may be injected by the target s... Read more

    Affected Products : rsshub
    • EPSS Score: %0.45
    • Published: Jan. 26, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-21277

    angular-expressions is "angular's nicest part extracted as a standalone module for the browser and node". In angular-expressions before version 1.1.2 there is a vulnerability which allows Remote Code Execution if you call "expressions.compile(userControll... Read more

    Affected Products : angular-expressions
    • EPSS Score: %0.72
    • Published: Feb. 01, 2021
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2021-21276

    Polr is an open source URL shortener. in Polr before version 2.3.0, a vulnerability in the setup process allows attackers to gain admin access to site instances, even if they do not possess an existing account. This vulnerability exists regardless of user... Read more

    Affected Products : polr
    • EPSS Score: %18.53
    • Published: Feb. 01, 2021
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-21275

    The MediaWiki "Report" extension has a Cross-Site Request Forgery (CSRF) vulnerability. Before fixed version, there was no protection against CSRF checks on Special:Report, so requests to report a revision could be forged. The problem has been fixed in co... Read more

    • EPSS Score: %0.18
    • Published: Jan. 25, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-21274

    Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, a malicious homeserver could redirect requests to their .well... Read more

    Affected Products : fedora synapse
    • EPSS Score: %0.58
    • Published: Feb. 26, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-21273

    Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, requests to user provided domains were not restricted to exte... Read more

    Affected Products : fedora synapse
    • EPSS Score: %0.39
    • Published: Feb. 26, 2021
    • Modified: Nov. 21, 2024
  • 7.7

    HIGH
    CVE-2021-21272

    ORAS is open source software which enables a way to push OCI Artifacts to OCI Conformant registries. ORAS is both a CLI for initial testing and a Go Module. In ORAS from version 0.4.0 and before version 0.9.0, there is a "zip-slip" vulnerability. The dire... Read more

    Affected Products : oras
    • EPSS Score: %0.22
    • Published: Jan. 25, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-21271

    Tendermint Core is an open source Byzantine Fault Tolerant (BFT) middleware that takes a state transition machine - written in any programming language - and securely replicates it on many machines. Tendermint Core v0.34.0 introduced a new way of handling... Read more

    Affected Products : tendermint
    • EPSS Score: %0.57
    • Published: Jan. 26, 2021
    • Modified: Nov. 21, 2024
  • 6.2

    MEDIUM
    CVE-2021-21270

    OctopusDSC is a PowerShell module with DSC resources that can be used to install and configure an Octopus Deploy Server and Tentacle agent. In OctopusDSC version 4.0.977 and earlier a customer API key used to connect to Octopus Server is exposed via loggi... Read more

    Affected Products : octopusdsc
    • EPSS Score: %0.04
    • Published: Jan. 22, 2021
    • Modified: Nov. 21, 2024
  • 7.7

    HIGH
    CVE-2021-21269

    Keymaker is a Mastodon Community Finder based Matrix Community serverlist page Server. In Keymaker before version 0.2.0, the assets endpoint did not check for the extension. The rust `join` method without checking user input might have made it abe to do a... Read more

    Affected Products : keymaker
    • EPSS Score: %0.36
    • Published: Jan. 20, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 291024 Results