Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2021-21267

    Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before version 2.0.0, email address validation is vulnerable to a denial-of-service attack where some input (for example `[email protected].... Read more

    • EPSS Score: %0.87
    • Published: Mar. 19, 2021
    • Modified: Nov. 21, 2024
  • 6.4

    MEDIUM
    CVE-2021-21266

    openHAB is a vendor and technology agnostic open source automation software for your home. In openHAB before versions 2.5.12 and 3.0.1 the XML external entity (XXE) attack allows attackers in the same network as the openHAB instance to retrieve internal i... Read more

    Affected Products : openhab
    • EPSS Score: %0.25
    • Published: Feb. 01, 2021
    • Modified: Nov. 21, 2024
  • 5.2

    MEDIUM
    CVE-2021-21264

    October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-26231 (fixed in 1.0.470/471 and 1.1.1) was discovered that has the same impact as CVE-2020-26231 & CVE-2020-15247. An authenticated backend u... Read more

    Affected Products : october
    • EPSS Score: %0.05
    • Published: May. 03, 2021
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-21263

    Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit applies to the illuminate/database package which is used by Laravel. If a request is crafted where a fiel... Read more

    Affected Products : laravel framework
    • EPSS Score: %2.18
    • Published: Jan. 19, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-21261

    Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` service that can allow sandboxed applications to execute arbitrary code on the host system (a sandbox escape)... Read more

    Affected Products : debian_linux flatpak
    • EPSS Score: %0.05
    • Published: Jan. 14, 2021
    • Modified: Nov. 21, 2024
  • 7.6

    HIGH
    CVE-2021-21260

    Online Invoicing System (OIS) is open source software which is a lean invoicing system for small businesses, consultants and freelancers created using AppGini. In OIS version 4.0 there is a stored XSS which can enables an attacker takeover of the admin ac... Read more

    Affected Products : online_invoicing_system
    • EPSS Score: %0.21
    • Published: Jan. 22, 2021
    • Modified: Nov. 21, 2024
  • 7.4

    HIGH
    CVE-2021-21259

    HedgeDoc is open source software which lets you create real-time collaborative markdown notes. In HedgeDoc before version 1.7.2, an attacker can inject arbitrary JavaScript into a HedgeDoc note, which is executed when the note is viewed in slide mode. Dep... Read more

    Affected Products : hedgedoc
    • EPSS Score: %0.27
    • Published: Jan. 22, 2021
    • Modified: Nov. 21, 2024
  • 6.8

    MEDIUM
    CVE-2021-21258

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI from version 9.5.0 and before version 9.5.4, there is a cross-site scripting injection vulnerability... Read more

    Affected Products : glpi
    • EPSS Score: %0.28
    • Published: Mar. 02, 2021
    • Modified: Nov. 21, 2024
  • 8.2

    HIGH
    CVE-2021-21257

    Contiki-NG is an open-source, cross-platform operating system for internet of things devices. The RPL-Classic and RPL-Lite implementations in the Contiki-NG operating system versions prior to 4.6 do not validate the address pointer in the RPL source routi... Read more

    Affected Products : contiki-ng
    • EPSS Score: %0.33
    • Published: Jun. 18, 2021
    • Modified: Nov. 21, 2024
  • 5.8

    MEDIUM
    CVE-2021-21255

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI version 9.5.3, it was possible to switch entities with IDOR from a logged in user. This is fixed in ... Read more

    Affected Products : glpi
    • EPSS Score: %0.28
    • Published: Mar. 02, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-21254

    CKEditor 5 is an open source rich text editor framework with a modular architecture. The CKEditor 5 Markdown plugin (@ckeditor/ckeditor5-markdown-gfm) before version 25.0.0 has a regex denial of service (ReDoS) vulnerability. The vulnerability allowed to ... Read more

    Affected Products : ckeditor5
    • EPSS Score: %0.37
    • Published: Jan. 29, 2021
    • Modified: Nov. 21, 2024
  • 5.8

    MEDIUM
    CVE-2021-21253

    OnlineVotingSystem is an open source project hosted on GitHub. OnlineVotingSystem before version 1.1.2 hashes user passwords without a salt, which is vulnerable to dictionary attacks. Therefore there is a threat of security breach in the voting system. Wi... Read more

    Affected Products : onlinevotingsystem
    • EPSS Score: %0.17
    • Published: Jan. 21, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-21252

    The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jquery-validation". jquery-validation before version 1.19.3 contains one or more regular expressions that are vulnerable to ReDoS (Regular... Read more

    Affected Products : snapcenter jquery_validation
    • EPSS Score: %0.42
    • Published: Jan. 13, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-21251

    OneDev is an all-in-one devops platform. In OneDev before version 4.0.3 there is a critical "zip slip" vulnerability. This issue may lead to arbitrary file write. The KubernetesResource REST endpoint untars user controlled data from the request body using... Read more

    Affected Products : onedev
    • EPSS Score: %0.71
    • Published: Jan. 15, 2021
    • Modified: Nov. 21, 2024
  • 7.7

    HIGH
    CVE-2021-21250

    OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which may lead to arbitrary file read. When BuildSpec is provided in XML format, the spec is processed by XmlBuildSpecMigrator.migrate(buildSpecStri... Read more

    Affected Products : onedev
    • EPSS Score: %0.29
    • Published: Jan. 15, 2021
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2021-21249

    OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is an issue involving YAML parsing which can lead to post-auth remote code execution. In order to parse and process YAML files, OneDev uses SnakeYaml which by default (when not... Read more

    Affected Products : onedev
    • EPSS Score: %1.33
    • Published: Jan. 15, 2021
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2021-21248

    OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability involving the build endpoint parameters. InputSpec is used to define parameters of a Build spec. It does so by using dynamically generated Groovy cl... Read more

    Affected Products : onedev
    • EPSS Score: %0.43
    • Published: Jan. 15, 2021
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2021-21247

    OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the application's BasePage registers an AJAX event listener (`AbstractPostAjaxBehavior`) in all pages other than the login page. This listener decodes and deserializes the `data` que... Read more

    Affected Products : onedev
    • EPSS Score: %0.31
    • Published: Jan. 15, 2021
    • Modified: Nov. 21, 2024
  • 8.6

    HIGH
    CVE-2021-21246

    OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the REST UserResource endpoint performs a security check to make sure that only administrators can list user details. However for the `/users/{id}` endpoint there are no security che... Read more

    Affected Products : onedev
    • EPSS Score: %1.21
    • Published: Jan. 15, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2021-21245

    OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user controlled data (`request.getInputStream()`) to a user specified location (`request.getHeader("File-Name")`). This issue may lead to arbitrary... Read more

    Affected Products : onedev
    • EPSS Score: %0.34
    • Published: Jan. 15, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 291024 Results