Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-5972 1 Sukimalab 1 Online Lesson Booking 2022-07-29 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Online Lesson Booking 0.8.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2019-5970 1 Sukimalab 1 Attendance Manager 2022-07-29 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Attendance Manager 0.5.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2021-27908 1 Acquia 1 Mautic 2022-07-29 2.1 LOW 4.4 MEDIUM
In all versions prior to Mautic 3.3.2, secret parameters such as database credentials could be exposed publicly by an authorized admin user through leveraging Symfony parameter syntax in any of the free text fields in Mautic’s configuration that are used in publicly facing parts of the application.
CVE-2021-28129 1 Apache 1 Openoffice 2022-07-29 4.6 MEDIUM 7.8 HIGH
While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupid of 500. This both caused issues with desktop integration and could allow a crafted attack on files owned by that user or group if they exist. Users who installed the Apache OpenOffice 4.1.8 DEB packaging should upgrade to the latest version of Apache OpenOffice.
CVE-2021-3820 1 Inflect Project 1 Inflect 2022-07-29 5.0 MEDIUM 7.5 HIGH
inflect is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-3810 1 Coder 1 Code-server 2022-07-29 7.8 HIGH 7.5 HIGH
code-server is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-3804 1 Taro 1 Taro 2022-07-29 7.8 HIGH 7.5 HIGH
taro is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-3803 1 Nth-check Project 1 Nth-check 2022-07-29 5.0 MEDIUM 7.5 HIGH
nth-check is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-3795 1 Semver-regex Project 1 Semver-regex 2022-07-29 5.0 MEDIUM 7.5 HIGH
semver-regex is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-3801 1 Prismjs 1 Prism 2022-07-29 4.3 MEDIUM 6.5 MEDIUM
prism is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-3794 1 Vuelidate Project 1 Vuelidate 2022-07-29 5.0 MEDIUM 7.5 HIGH
vuelidate is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-3777 1 Tmpl Project 1 Tmpl 2022-07-29 7.8 HIGH 7.5 HIGH
nodejs-tmpl is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-3645 1 Merge Project 1 Merge 2022-07-29 7.5 HIGH 9.8 CRITICAL
merge is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2021-3766 1 Objection Project 1 Objection 2022-07-29 7.5 HIGH 9.8 CRITICAL
objection.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2021-3666 1 Xml Body Parser Project 1 Xml Body Parser 2022-07-29 7.5 HIGH 9.8 CRITICAL
body-parser-xml is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2021-28499 1 Arista 2 7130, Metamako Operating System 2022-07-29 2.1 LOW 5.5 MEDIUM
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user account passwords set in clear text could leak to users without any password. This issue affects: Arista Metamako Operating System MOS-0.18 and post releases in the MOS-0.1x train All releases in the MOS-0.2x train MOS-0.31.1 and prior releases in the MOS-0.3x train
CVE-2022-2071 1 Name Directory Project 1 Name Directory 2022-07-29 N/A 6.1 MEDIUM
The Name Directory WordPress plugin before 1.25.4 does not have CSRF check when importing names, and is also lacking sanitisation as well as escaping in some of the imported data, which could allow attackers to make a logged in admin import arbitrary names with XSS payloads in them.
CVE-2022-1551 1 Smartypantsplugins 1 Sp Project \& Document Manager 2022-07-29 N/A 6.5 MEDIUM
The SP Project & Document Manager WordPress plugin through 4.57 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.
CVE-2021-3822 1 Jsoneditoronline 1 Jsoneditor 2022-07-29 5.0 MEDIUM 7.5 HIGH
jsoneditor is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-3765 1 Validator Project 1 Validator 2022-07-29 5.0 MEDIUM 7.5 HIGH
validator.js is vulnerable to Inefficient Regular Expression Complexity