CVE-2021-32677
- EPSS 0.12%
- Veröffentlicht 09.06.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:30
FastAPI is a web framework for building APIs with Python 3.6+ based on standard Python type hints. FastAPI versions lower than 0.65.2 that used cookies for authentication in path operations that received JSON payloads sent by browsers were vulnerable...
CVE-2021-26314
- EPSS 0.1%
- Veröffentlicht 09.06.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 05:56:04
Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and may result...
CVE-2021-33829
- EPSS 47.62%
- Veröffentlicht 09.06.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:09:38
A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.
- EPSS 5.13%
- Veröffentlicht 08.06.2021 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:06:35
ASP.NET Core Denial of Service Vulnerability
CVE-2021-31807
- EPSS 47.57%
- Veröffentlicht 08.06.2021 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:06:15
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests. The issue trigger is a header that can be expected to...
CVE-2021-33203
- EPSS 0.33%
- Veröffentlicht 08.06.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:08:30
Django before 2.2.24, 3.x before 3.1.12, and 3.2.x before 3.2.4 has a potential directory traversal via django.contrib.admindocs. Staff members could use the TemplateDetailView view to check the existence of arbitrary files. Additionally, if (and onl...
CVE-2021-33571
- EPSS 0.02%
- Veröffentlicht 08.06.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:09:06
In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. This may allow a bypass of access control that is based o...
CVE-2021-22212
- EPSS 0.14%
- Veröffentlicht 08.06.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 05:49:43
ntpkeygen can generate keys that ntpd fails to parse. NTPsec 1.2.0 allows ntpkeygen to generate keys with '#' characters. ntpd then either pads, shortens the key, or fails to load these keys entirely, depending on the key type and the placement of th...
CVE-2021-3564
- EPSS 0.02%
- Veröffentlicht 08.06.2021 12:15:11
- Zuletzt bearbeitet 21.11.2024 06:21:51
A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This flaw affects all the Linux ke...
CVE-2021-23169
- EPSS 0.18%
- Veröffentlicht 08.06.2021 12:15:10
- Zuletzt bearbeitet 21.11.2024 05:51:19
A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1. An attacker could use this flaw to execute arbitrary code with the permissions of the user running the application compiled against OpenEXR.