• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2021-23432
2021-08-31
N/A
9.8 CRITICAL
This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge()
CVE-2021-23431
2021-08-31
N/A
8.8 HIGH
The package joplin before 2.3.2 are vulnerable to Cross-site Request Forgery (CSRF) due to missing CSRF checks in various forms.
CVE-2021-23430
2021-08-31
N/A
7.5 HIGH
All versions of package startserver are vulnerable to Directory Traversal due to missing sanitization.
CVE-2021-2343
2021-07-22
N/A
4.3 MEDIUM
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Workflow accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
CVE-2021-23429
2021-08-31
N/A
7.5 HIGH
All versions of package transpile are vulnerable to Denial of Service (DoS) due to a lack of input sanitization or whitelisting, coupled with improper exception handling in the .to() function.
CVE-2021-23428
2022-06-28
N/A
9.8 CRITICAL
This affects all versions of package elFinder.NetCore. The Path.Combine(...) method is used to create an absolute file path. Due to missing sanitation of the user input and a missing check of the generated path its possible to escape the Files directory via path traversal
CVE-2021-23427
2022-07-12
N/A
9.8 CRITICAL
This affects all versions of package elFinder.NetCore. The ExtractAsync function within the FileSystem is vulnerable to arbitrary extraction due to insufficient validation.
CVE-2021-23426
2021-09-09
N/A
7.5 HIGH
This affects all versions of package Proto. It is possible to inject pollute the object property of an application using Proto by leveraging the merge function.
CVE-2021-23425
2022-01-18
N/A
5.3 MEDIUM
All versions of package trim-off-newlines are vulnerable to Regular Expression Denial of Service (ReDoS) via string processing.
CVE-2021-23424
2022-08-04
N/A
7.5 HIGH
This affects all versions of package ansi-html. If an attacker provides a malicious string, it will get stuck processing the input for an extremely long time.
« Previous 1 … 8,397 8,398 8,399 8,400 8,401 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE