CVE-2021-27358
- EPSS 78.27%
- Published 18.03.2021 20:15:13
- Last modified 21.11.2024 05:57:50
The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.
CVE-2021-20231
- EPSS 0.92%
- Published 12.03.2021 19:15:13
- Last modified 21.11.2024 05:46:10
A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.
CVE-2021-22884
- EPSS 0.27%
- Published 03.03.2021 18:15:14
- Last modified 21.11.2024 05:50:50
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over ne...
CVE-2021-22883
- EPSS 87.36%
- Published 03.03.2021 18:15:14
- Last modified 21.11.2024 05:50:49
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is con...
CVE-2021-27219
- EPSS 0.34%
- Published 15.02.2021 17:15:13
- Last modified 21.11.2024 05:57:37
An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could potentially lead to memory corrupti...
CVE-2021-27218
- EPSS 5.06%
- Published 15.02.2021 17:15:13
- Last modified 21.11.2024 05:57:37
An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If g_byte_array_new_take() was called with a buffer of 4GB or more on a 64-bit platform, the length would be truncated modulo 2**32, causing unintended length truncation.
CVE-2020-14782
- EPSS 0.14%
- Published 21.10.2020 15:15:18
- Last modified 27.05.2025 16:40:51
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthe...
CVE-2020-11110
- EPSS 67.64%
- Published 27.07.2020 13:15:11
- Last modified 21.11.2024 04:56:48
Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.
CVE-2020-14664
- EPSS 1.94%
- Published 15.07.2020 18:15:31
- Last modified 21.11.2024 05:03:50
Vulnerability in the Java SE product of Oracle Java SE (component: JavaFX). The supported version that is affected is Java SE: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to com...
- EPSS 0.46%
- Published 15.07.2020 18:15:27
- Last modified 27.05.2025 16:33:09
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenti...