CVE-2025-30756
- EPSS 0.02%
- Published 15.07.2025 19:27:31
- Last modified 25.07.2025 16:12:51
Vulnerability in Oracle REST Data Services (component: General). The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle REST Data Services...
CVE-2021-41184
- EPSS 22.09%
- Published 26.10.2021 15:15:10
- Last modified 21.11.2024 06:25:42
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string v...
CVE-2021-41183
- EPSS 2.34%
- Published 26.10.2021 15:15:10
- Last modified 21.11.2024 06:25:42
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The v...
CVE-2021-41182
- EPSS 22.27%
- Published 26.10.2021 15:15:10
- Last modified 21.11.2024 06:25:41
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any str...
CVE-2021-32014
- EPSS 0.21%
- Published 19.07.2021 14:15:08
- Last modified 21.11.2024 06:06:42
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js.
CVE-2021-32013
- EPSS 0.21%
- Published 19.07.2021 14:15:08
- Last modified 21.11.2024 06:06:42
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 2 of 2).
CVE-2021-32012
- EPSS 0.21%
- Published 19.07.2021 14:15:08
- Last modified 21.11.2024 06:06:42
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 1 of 2).
CVE-2021-34429
- EPSS 93.8%
- Published 15.07.2021 17:15:08
- Last modified 21.11.2024 06:10:23
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerabilit...
CVE-2021-34428
- EPSS 0.51%
- Published 22.06.2021 15:15:16
- Last modified 21.11.2024 06:10:23
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and mul...
CVE-2021-28169
- EPSS 92.42%
- Published 09.06.2021 02:15:06
- Last modified 21.11.2024 05:59:14
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to `/concat?/%2557EB-INF/web.xml...