Latest CVE Feed
-
6.1
MEDIUMCVE-2021-21273
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, requests to user provided domains were not restricted to exte... Read more
- EPSS Score: %0.39
- Published: Feb. 26, 2021
- Modified: Nov. 21, 2024
-
7.7
HIGHCVE-2021-21272
ORAS is open source software which enables a way to push OCI Artifacts to OCI Conformant registries. ORAS is both a CLI for initial testing and a Go Module. In ORAS from version 0.4.0 and before version 0.9.0, there is a "zip-slip" vulnerability. The dire... Read more
Affected Products : oras- EPSS Score: %0.22
- Published: Jan. 25, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-21271
Tendermint Core is an open source Byzantine Fault Tolerant (BFT) middleware that takes a state transition machine - written in any programming language - and securely replicates it on many machines. Tendermint Core v0.34.0 introduced a new way of handling... Read more
Affected Products : tendermint- EPSS Score: %0.57
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
6.2
MEDIUMCVE-2021-21270
OctopusDSC is a PowerShell module with DSC resources that can be used to install and configure an Octopus Deploy Server and Tentacle agent. In OctopusDSC version 4.0.977 and earlier a customer API key used to connect to Octopus Server is exposed via loggi... Read more
Affected Products : octopusdsc- EPSS Score: %0.04
- Published: Jan. 22, 2021
- Modified: Nov. 21, 2024
-
7.7
HIGHCVE-2021-21269
Keymaker is a Mastodon Community Finder based Matrix Community serverlist page Server. In Keymaker before version 0.2.0, the assets endpoint did not check for the extension. The rust `join` method without checking user input might have made it abe to do a... Read more
Affected Products : keymaker- EPSS Score: %0.36
- Published: Jan. 20, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-21267
Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before version 2.0.0, email address validation is vulnerable to a denial-of-service attack where some input (for example `[email protected].... Read more
- EPSS Score: %0.87
- Published: Mar. 19, 2021
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2021-21266
openHAB is a vendor and technology agnostic open source automation software for your home. In openHAB before versions 2.5.12 and 3.0.1 the XML external entity (XXE) attack allows attackers in the same network as the openHAB instance to retrieve internal i... Read more
Affected Products : openhab- EPSS Score: %0.25
- Published: Feb. 01, 2021
- Modified: Nov. 21, 2024
-
5.2
MEDIUMCVE-2021-21264
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-26231 (fixed in 1.0.470/471 and 1.1.1) was discovered that has the same impact as CVE-2020-26231 & CVE-2020-15247. An authenticated backend u... Read more
Affected Products : october- EPSS Score: %0.05
- Published: May. 03, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-21263
Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit applies to the illuminate/database package which is used by Laravel. If a request is crafted where a fiel... Read more
- EPSS Score: %2.18
- Published: Jan. 19, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-21261
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` service that can allow sandboxed applications to execute arbitrary code on the host system (a sandbox escape)... Read more
- EPSS Score: %0.05
- Published: Jan. 14, 2021
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2021-21260
Online Invoicing System (OIS) is open source software which is a lean invoicing system for small businesses, consultants and freelancers created using AppGini. In OIS version 4.0 there is a stored XSS which can enables an attacker takeover of the admin ac... Read more
Affected Products : online_invoicing_system- EPSS Score: %0.21
- Published: Jan. 22, 2021
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2021-21259
HedgeDoc is open source software which lets you create real-time collaborative markdown notes. In HedgeDoc before version 1.7.2, an attacker can inject arbitrary JavaScript into a HedgeDoc note, which is executed when the note is viewed in slide mode. Dep... Read more
Affected Products : hedgedoc- EPSS Score: %0.27
- Published: Jan. 22, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-21258
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI from version 9.5.0 and before version 9.5.4, there is a cross-site scripting injection vulnerability... Read more
Affected Products : glpi- EPSS Score: %0.28
- Published: Mar. 02, 2021
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2021-21257
Contiki-NG is an open-source, cross-platform operating system for internet of things devices. The RPL-Classic and RPL-Lite implementations in the Contiki-NG operating system versions prior to 4.6 do not validate the address pointer in the RPL source routi... Read more
Affected Products : contiki-ng- EPSS Score: %0.33
- Published: Jun. 18, 2021
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2021-21255
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI version 9.5.3, it was possible to switch entities with IDOR from a logged in user. This is fixed in ... Read more
Affected Products : glpi- EPSS Score: %0.28
- Published: Mar. 02, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-21254
CKEditor 5 is an open source rich text editor framework with a modular architecture. The CKEditor 5 Markdown plugin (@ckeditor/ckeditor5-markdown-gfm) before version 25.0.0 has a regex denial of service (ReDoS) vulnerability. The vulnerability allowed to ... Read more
Affected Products : ckeditor5- EPSS Score: %0.37
- Published: Jan. 29, 2021
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2021-21253
OnlineVotingSystem is an open source project hosted on GitHub. OnlineVotingSystem before version 1.1.2 hashes user passwords without a salt, which is vulnerable to dictionary attacks. Therefore there is a threat of security breach in the voting system. Wi... Read more
Affected Products : onlinevotingsystem- EPSS Score: %0.17
- Published: Jan. 21, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-21252
The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jquery-validation". jquery-validation before version 1.19.3 contains one or more regular expressions that are vulnerable to ReDoS (Regular... Read more
- EPSS Score: %0.42
- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-21251
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3 there is a critical "zip slip" vulnerability. This issue may lead to arbitrary file write. The KubernetesResource REST endpoint untars user controlled data from the request body using... Read more
Affected Products : onedev- EPSS Score: %0.71
- Published: Jan. 15, 2021
- Modified: Nov. 21, 2024
-
7.7
HIGHCVE-2021-21250
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which may lead to arbitrary file read. When BuildSpec is provided in XML format, the spec is processed by XmlBuildSpecMigrator.migrate(buildSpecStri... Read more
Affected Products : onedev- EPSS Score: %0.29
- Published: Jan. 15, 2021
- Modified: Nov. 21, 2024