CVE-2021-43816
- EPSS 0.15%
 - Published 05.01.2022 19:15:08
 - Last modified 21.11.2024 06:29:51
 
containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), an unprivileged pod scheduled t...
CVE-2021-45115
- EPSS 0.39%
 - Published 05.01.2022 00:15:07
 - Last modified 21.11.2024 06:31:59
 
An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. UserAttributeSimilarityValidator incurred significant overhead in evaluating a submitted password that was artificially large in relation to the comparison ...
CVE-2021-45116
- EPSS 0.26%
 - Published 05.01.2022 00:15:07
 - Last modified 22.05.2025 19:15:27
 
An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. Due to leveraging the Django Template Language's variable resolution logic, the dictsort template filter was potentially vulnerable to information disclosur...
CVE-2021-45452
- EPSS 0.34%
 - Published 05.01.2022 00:15:07
 - Last modified 21.11.2024 06:32:14
 
Storage.save in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1 allows directory traversal if crafted filenames are directly passed to it.
CVE-2021-3842
- EPSS 0.41%
 - Published 04.01.2022 15:15:07
 - Last modified 21.11.2024 06:22:36
 
nltk is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-41819
- EPSS 0.45%
 - Published 01.01.2022 06:15:07
 - Last modified 22.05.2025 15:15:54
 
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
CVE-2021-41817
- EPSS 0.36%
 - Published 01.01.2022 05:15:08
 - Last modified 21.11.2024 06:26:48
 
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
CVE-2021-45942
- EPSS 0.16%
 - Published 01.01.2022 01:15:09
 - Last modified 21.11.2024 06:33:19
 
OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.
CVE-2021-45943
- EPSS 0.3%
 - Published 01.01.2022 01:15:09
 - Last modified 21.11.2024 06:33:19
 
GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and PCIDSK::CPCIDSKBinarySegment::CPCIDSKBinarySegment).
CVE-2021-45930
- EPSS 0.13%
 - Published 01.01.2022 01:15:08
 - Last modified 21.11.2024 06:33:17
 
Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-of-bounds write in QtPrivate::QCommonArrayOps<QPainterPath::Element>::growAppend (called from QPainterPath::addPath and QPathClipper::intersect).