- EPSS 94.36%
- Published 10.12.2021 10:15:09
- Last modified 27.10.2025 17:40:33
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An atta...
CVE-2021-4048
- EPSS 0.37%
- Published 08.12.2021 22:15:10
- Last modified 21.11.2024 06:36:47
An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application u...
CVE-2021-44420
- EPSS 0.13%
- Published 08.12.2021 00:15:07
- Last modified 21.11.2024 06:30:56
In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.
CVE-2021-44686
- EPSS 0.33%
- Published 07.12.2021 00:15:08
- Last modified 21.11.2024 06:31:23
calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in html_preprocess_rules in ebooks/conversion/preprocess.py.
CVE-2021-4069
- EPSS 0.2%
- Published 06.12.2021 12:15:07
- Last modified 21.11.2024 06:36:50
vim is vulnerable to Use After Free
CVE-2021-3984
- EPSS 0.22%
- Published 01.12.2021 11:15:07
- Last modified 21.11.2024 06:23:18
vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-4019
- EPSS 0.1%
- Published 01.12.2021 10:15:07
- Last modified 21.11.2024 06:36:44
vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-3802
- EPSS 0.04%
- Published 29.11.2021 16:15:07
- Last modified 21.11.2024 06:22:28
A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability.
CVE-2021-44225
- EPSS 0.05%
- Published 26.11.2021 00:15:10
- Last modified 21.11.2024 06:30:37
In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system ...
- EPSS 0.87%
- Published 24.11.2021 19:15:07
- Last modified 21.11.2024 06:25:56
Symfony/Serializer handles serializing and deserializing data structures for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Symfony versions 4.1.0 before 4.4.35 and versions 5.0.0 before 5.3.12 are vul...