Latest 7 days CVE Lists

Latest 7 days CVE Lists 피드 구독하기
This feed contains the most recent CVE cyber vulnerabilities published within the National Vulnerability Database.
업데이트: 2시간 4분 지남

CVE-2021-20351

금, 2021/03/05 - 4:15오전
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194708.

CVE-2021-27217

금, 2021/03/05 - 3:15오전
An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not correctly validate the embedded length field of an authenticated message received from the device. Out-of-bounds reads performed by aes_remove_padding() can crash the running process, depending on the memory layout. This could be used by an attacker to cause a client-side denial of service. The yubihsm-shell project is included in the YubiHSM 2 SDK product.

CVE-2021-22128

금, 2021/03/05 - 3:15오전
An improper access control vulnerability in FortiProxy SSL VPN portal 2.0.0, 1.2.9 and below versions may allow an authenticated, remote attacker to access internal service such as the ZebOS Shell on the FortiProxy appliance through the Quick Connection functionality.

CVE-2021-23126

금, 2021/03/05 - 3:15오전
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of the insecure rand() function within the process of generating the 2FA secret.

CVE-2021-23127

금, 2021/03/05 - 3:15오전
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of an insufficient length for the 2FA secret accoring to RFC 4226 of 10 bytes vs 20 bytes.

CVE-2021-23128

금, 2021/03/05 - 3:15오전
An issue was discovered in Joomla! 3.2.0 through 3.9.24. The core shipped but unused randval implementation within FOF (FOFEncryptRandval) used an potential insecure implemetation. That has now been replaced with a call to 'random_bytes()' and its backport that is shipped within random_compat.

CVE-2021-23129

금, 2021/03/05 - 3:15오전
An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of messages showed to users that could lead to xss issues.

CVE-2021-23130

금, 2021/03/05 - 3:15오전
An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of feed fields could lead to xss issues.

CVE-2021-23131

금, 2021/03/05 - 3:15오전
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Missing input validation within the template manager.

CVE-2021-23132

금, 2021/03/05 - 3:15오전
An issue was discovered in Joomla! 3.0.0 through 3.9.24. com_media allowed paths that are not intended for image uploads

CVE-2021-26027

금, 2021/03/05 - 3:15오전
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Incorrect ACL checks could allow unauthorized change of the category for an article.

CVE-2021-26028

금, 2021/03/05 - 3:15오전
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path.

CVE-2021-26029

금, 2021/03/05 - 3:15오전
An issue was discovered in Joomla! 1.6.0 through 3.9.24. Inadequate filtering of form contents could allow to overwrite the author field.

CVE-2020-15938

금, 2021/03/05 - 3:15오전
When traffic other than HTTP/S (eg: SSH traffic, etc...) traverses the FortiGate in version below 6.2.5 and below 6.4.2 on port 80/443, it is not redirected to the transparent proxy policy for processing, as it doesn't have a valid HTTP header.

CVE-2021-23344

금, 2021/03/05 - 2:15오전
The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set.

CVE-2021-23346

금, 2021/03/05 - 2:15오전
This affects the package html-parse-stringify before 2.0.1; all versions of package html-parse-stringify2. Sending certain input could cause one of the regular expressions that is used for parsing to backtrack, freezing the process.

CVE-2020-35327

금, 2021/03/05 - 1:15오전
SQL injection vulnerability was discovered in Courier Management System 1.0, which can be exploited via the ref_no (POST) parameter to admin_class.php

CVE-2020-35328

금, 2021/03/05 - 1:15오전
Courier Management System 1.0 - 'First Name' Stored XSS

CVE-2020-35329

금, 2021/03/05 - 1:15오전
Courier Management System 1.0 1.0 is affected by SQL Injection via 'MULTIPART street '.

CVE-2021-22183

금, 2021/03/05 - 12:15오전
An issue has been discovered in GitLab affecting all versions starting with 11.8. GitLab was vulnerable to a stored XSS in the epics page, which could be exploited with user interactions.

페이지