CVE-2022-21664
- EPSS 3.75%
- Veröffentlicht 06.01.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:45:11
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed. This has been patc...
CVE-2022-21661
- EPSS 90.9%
- Veröffentlicht 06.01.2022 23:15:07
- Zuletzt bearbeitet 19.08.2025 16:35:50
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a c...
CVE-2021-46141
- EPSS 0.12%
- Veröffentlicht 06.01.2022 04:15:06
- Zuletzt bearbeitet 21.11.2024 06:33:40
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
CVE-2021-46142
- EPSS 0.12%
- Veröffentlicht 06.01.2022 04:15:06
- Zuletzt bearbeitet 21.11.2024 06:33:40
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
CVE-2021-43816
- EPSS 0.15%
- Veröffentlicht 05.01.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:29:51
containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), an unprivileged pod scheduled t...
CVE-2021-45115
- EPSS 0.42%
- Veröffentlicht 05.01.2022 00:15:07
- Zuletzt bearbeitet 21.11.2024 06:31:59
An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. UserAttributeSimilarityValidator incurred significant overhead in evaluating a submitted password that was artificially large in relation to the comparison ...
CVE-2021-45116
- EPSS 0.36%
- Veröffentlicht 05.01.2022 00:15:07
- Zuletzt bearbeitet 22.05.2025 19:15:27
An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. Due to leveraging the Django Template Language's variable resolution logic, the dictsort template filter was potentially vulnerable to information disclosur...
CVE-2021-45452
- EPSS 0.29%
- Veröffentlicht 05.01.2022 00:15:07
- Zuletzt bearbeitet 21.11.2024 06:32:14
Storage.save in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1 allows directory traversal if crafted filenames are directly passed to it.
CVE-2021-3842
- EPSS 0.41%
- Veröffentlicht 04.01.2022 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:22:36
nltk is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-41819
- EPSS 0.69%
- Veröffentlicht 01.01.2022 06:15:07
- Zuletzt bearbeitet 22.05.2025 15:15:54
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.