553 Commits

Author SHA1 Message Date
CVE Team
0045fa7568
"-Synchronized-Data." 2021-11-16 10:01:04 +00:00
hagaiwech
1370dd68c9
Add CVE-2021-25985
FactorJS - Insufficient Session Expiration Leads to a Local Account Takeover
Committed by: Hagai Wechsler
2021-11-16 11:40:58 +02:00
hagaiwech
a7e5670f34
Add CVE-2021-25984
FactorJS - Stored Cross-Site Scripting (XSS) in Post Reply Functionality
Committed by: Hagai Wechsler
2021-11-16 11:36:44 +02:00
hagaiwech
918ace797b
Add CVE-2021-25983
FactorJS - Reflected Cross-Site Scripting (XSS) in Tags and Categories Functionality
Committed by: Hagai Wechsler
2021-11-16 11:34:26 +02:00
hagaiwech
eaa8530183
Add CVE-2021-25982
FactorJS - Reflected Cross-Site Scripting (XSS) in Search Functionality
Committed by: Hagai Wechsler
2021-11-16 11:31:56 +02:00
hagaiwech
64478ccb0b
Add CVE-2021-25940
ArangoDB - Insufficient Session Expiration after Password Change
Committed by: Hagai Wechsler
2021-11-16 11:20:25 +02:00
hagaiwech
50b79fb658
Add CVE-2021-25965
Calibre-web - Admin Account Takeover via Cross-Site Request Forgery (CSRF)
Committed by: Hagai Wechsler
2021-11-16 11:09:47 +02:00
hagaiwech
425b9ac487
Add CVE-2021-25976
Piranha CMS - Site-wide Cross-Site Request Forgery (CSRF)
Committed by: Hagai Wechsler
2021-11-16 11:03:23 +02:00
CVE Team
04da7a6f0e
"-Synchronized-Data." 2021-11-11 08:01:08 +00:00
hagaiwech
8a68f79c30
Add CVE-2021-25980
Talkyard - Host-Header Injection Leads to Account Takeover
Committed by: Hagai Wechsler
2021-11-11 09:09:20 +02:00
CVE Team
9e841b7247
"-Synchronized-Data." 2021-11-11 03:00:55 +00:00
CVE Team
54d09a78e4
"-Synchronized-Data." 2021-11-10 20:00:58 +00:00
CVE Team
31a2254456
"-Synchronized-Data." 2021-11-10 12:01:04 +00:00
hagaiwech
1958438698
Add CVE-2021-25975
Publify - Stored Cross-Site Scripting (XSS) due to Unrestricted File Upload
Committed by: Hagai Wechsler
2021-11-10 13:03:51 +02:00
hagaiwech
1d1437d3d7
Add CVE-2021-25974
Publify - Stored Cross-Site Scripting (XSS) in Editor
Committed by: Hagai Wechsler
2021-11-10 12:59:25 +02:00
CVE Team
91e3573566
"-Synchronized-Data." 2021-11-10 10:00:56 +00:00
MSRC
df296d9e01 November 2021 Patch Tuesday 2021-11-09 16:46:54 -08:00
Siemens ProductCERT
d86e94a524 Siemens AD-2021-11 2021-11-09 12:22:21 +01:00
CVE Team
36cdf34403
"-Synchronized-Data." 2021-11-08 15:01:04 +00:00
Daniel Elkabes
1aa30aa677
Add CVE-2021-25979
Apostrophe - Insufficient Session Expiration
Committed by: Daniel Elkabes
2021-11-08 16:15:09 +02:00
Daniel Elkabes
512bae039a
Merge branch 'CVEProject:master' into master 2021-11-08 16:11:41 +02:00
CVE Team
3d3f4ec159
"-Synchronized-Data." 2021-11-07 18:01:05 +00:00
CVE Team
26489f2936
Auto-merge PR#3425
Auto-merge PR#3425
2021-11-07 12:15:17 -05:00
Daniel Elkabes
2932e968da
Add CVE-2021-25978
Add CVE-2021-25977
Committed by: Daniel Elkabes
2021-11-07 19:09:04 +02:00
Daniel Elkabes
d4743e1a03
Revert 2021-11-07 19:07:01 +02:00
Daniel Elkabes
6b7303286d
Add CVE-2021-25978
Apostrophe - XSS
Committed by: Daniel Elkabes
2021-11-07 18:51:38 +02:00
CVE Team
948e87572d
"-Synchronized-Data." 2021-11-05 03:00:59 +00:00
CVE Team
bd7bbeb91e
"-Synchronized-Data." 2021-11-04 04:00:55 +00:00
CVE Team
5005be1076
Auto-merge PR#3309
Auto-merge PR#3309
2021-11-02 06:20:11 -04:00
CVE Team
703a7561e0
"-Synchronized-Data." 2021-11-02 07:01:03 +00:00
hagaiwech
11317ab190
Add CVE-2021-25973
Publify - Improper Authorization Leads to Guest Signup Restriction Bypass
Committed by: Hagai Wechsler
2021-11-02 08:48:52 +02:00
CVE Team
9b35672b68
"-Synchronized-Data." 2021-11-02 04:00:55 +00:00
hagaiwech
dcf6a85a95
Update CVE-2021-25971
CVE was mistakenly uploaded with wrong CVSS and CWE.
It is now modified to the intended values.
This was coordinated with the NVD team
Committed by: Hagai Wechsler
2021-11-01 16:55:40 +02:00
CVE Team
a12df3d74f
"-Synchronized-Data." 2021-11-01 12:01:02 +00:00
CVE Team
dc975ec9d8
"-Synchronized-Data." 2021-10-29 05:01:04 +00:00
CVE Team
a7ab6bca0f
Auto-merge PR#3295
Auto-merge PR#3295
2021-10-29 00:05:17 -04:00
CVE Team
8d54368f95
"-Synchronized-Data." 2021-10-29 03:00:56 +00:00
CJ Cullen
784f75340c
Merge branch 'CVEProject:master' into master 2021-10-28 13:53:13 -07:00
CJ Cullen
9e32c131ca
Fill in details for CVE-2021-25742. (#10)
* Fill in details for CVE-2021-25742.

* Update 2021/25xxx/CVE-2021-25742.json

Co-authored-by: Tim Allclair <timallclair@gmail.com>

Co-authored-by: Tim Allclair <timallclair@gmail.com>
2021-10-28 13:45:45 -07:00
Michał Kępień
2e158c4656 [ISC] document BIND9 CVE-2021-25219 2021-10-27 23:05:16 +02:00
CVE Team
7c24b6ed6b
"-Synchronized-Data." 2021-10-25 14:01:01 +00:00
hagaiwech
4edc78fe21
Add CVE-2021-25977
Piranha CMS - Stored XSS in Page Title
Committed by: Hagai Wechsler and Miriam Iomin
2021-10-25 16:03:31 +03:00
CVE Team
903b226043
"-Synchronized-Data." 2021-10-20 12:01:08 +00:00
hagaiwech
a36b53314c
Add CVE-2021-25972
Camaleon CMS - Server-Side Request Forgery (SSRF) in Media Upload Feature
Committed by: Hagai Wechsler
2021-10-20 14:50:39 +03:00
hagaiwech
a08d61ed3b
Add CVE-2021-25971
Camaleon CMS - SVG File Upload Creates DoS for Media Upload Feature
Committed by: Hagai Wechsler
2021-10-20 14:45:46 +03:00
hagaiwech
470948e7bc
Add CVE-2021-25970
Camaleon CMS - Insufficient Session Expiration after Password Change
Committed by: Hagai Wechsler
2021-10-20 14:40:54 +03:00
hagaiwech
b7a6fa8d9e
Add CVE-2021-25969
Camaleon CMS - Stored Cross-Site Scripting (XSS) in Comments
Committed by: Hagai Wechsler
2021-10-20 14:33:13 +03:00
CVE Team
6b2a2a6de9
"-Synchronized-Data." 2021-10-20 11:02:08 +00:00
Bill Situ
93f3910443 Oracle 2021 Oracle CPU third party CVEs update
On branch cna/Oracle/CPU2021Oct3rd
 Changes to be committed:
	modified:   2014/0xxx/CVE-2014-0107.json
	modified:   2014/3xxx/CVE-2014-3004.json
	modified:   2016/0xxx/CVE-2016-0762.json
	modified:   2016/1000xxx/CVE-2016-1000031.json
	modified:   2016/2xxx/CVE-2016-2183.json
	modified:   2016/5xxx/CVE-2016-5018.json
	modified:   2016/6xxx/CVE-2016-6794.json
	modified:   2016/6xxx/CVE-2016-6796.json
	modified:   2016/6xxx/CVE-2016-6797.json
	modified:   2017/5xxx/CVE-2017-5645.json
	modified:   2017/9xxx/CVE-2017-9841.json
	modified:   2018/10xxx/CVE-2018-10237.json
	modified:   2018/11xxx/CVE-2018-11039.json
	modified:   2018/11xxx/CVE-2018-11040.json
	modified:   2018/14xxx/CVE-2018-14550.json
	modified:   2018/15xxx/CVE-2018-15756.json
	modified:   2018/1xxx/CVE-2018-1257.json
	modified:   2018/1xxx/CVE-2018-1258.json
	modified:   2018/1xxx/CVE-2018-1270.json
	modified:   2018/1xxx/CVE-2018-1271.json
	modified:   2018/1xxx/CVE-2018-1272.json
	modified:   2018/1xxx/CVE-2018-1275.json
	modified:   2018/20xxx/CVE-2018-20031.json
	modified:   2018/20xxx/CVE-2018-20032.json
	modified:   2018/20xxx/CVE-2018-20033.json
	modified:   2018/20xxx/CVE-2018-20034.json
	modified:   2018/20xxx/CVE-2018-20843.json
	modified:   2018/8xxx/CVE-2018-8032.json
	modified:   2018/8xxx/CVE-2018-8088.json
	modified:   2019/0xxx/CVE-2019-0227.json
	modified:   2019/0xxx/CVE-2019-0228.json
	modified:   2019/0xxx/CVE-2019-0230.json
	modified:   2019/0xxx/CVE-2019-0233.json
	modified:   2019/10xxx/CVE-2019-10082.json
	modified:   2019/10xxx/CVE-2019-10086.json
	modified:   2019/11xxx/CVE-2019-11358.json
	modified:   2019/12xxx/CVE-2019-12400.json
	modified:   2019/12xxx/CVE-2019-12402.json
	modified:   2019/12xxx/CVE-2019-12415.json
	modified:   2019/13xxx/CVE-2019-13990.json
	modified:   2019/16xxx/CVE-2019-16775.json
	modified:   2019/17xxx/CVE-2019-17195.json
	modified:   2019/17xxx/CVE-2019-17566.json
	modified:   2019/17xxx/CVE-2019-17567.json
	modified:   2019/20xxx/CVE-2019-20388.json
	modified:   2019/3xxx/CVE-2019-3738.json
	modified:   2019/3xxx/CVE-2019-3739.json
	modified:   2019/3xxx/CVE-2019-3740.json
	modified:   2019/5xxx/CVE-2019-5427.json
	modified:   2019/7xxx/CVE-2019-7317.json
	modified:   2020/10xxx/CVE-2020-10543.json
	modified:   2020/10xxx/CVE-2020-10672.json
	modified:   2020/10xxx/CVE-2020-10673.json
	modified:   2020/10xxx/CVE-2020-10683.json
	modified:   2020/10xxx/CVE-2020-10878.json
	modified:   2020/10xxx/CVE-2020-10968.json
	modified:   2020/10xxx/CVE-2020-10969.json
	modified:   2020/11xxx/CVE-2020-11022.json
	modified:   2020/11xxx/CVE-2020-11023.json
	modified:   2020/11xxx/CVE-2020-11111.json
	modified:   2020/11xxx/CVE-2020-11112.json
	modified:   2020/11xxx/CVE-2020-11113.json
	modified:   2020/11xxx/CVE-2020-11979.json
	modified:   2020/11xxx/CVE-2020-11987.json
	modified:   2020/11xxx/CVE-2020-11988.json
	modified:   2020/11xxx/CVE-2020-11994.json
	modified:   2020/11xxx/CVE-2020-11998.json
	modified:   2020/12xxx/CVE-2020-12723.json
	modified:   2020/13xxx/CVE-2020-13935.json
	modified:   2020/13xxx/CVE-2020-13947.json
	modified:   2020/13xxx/CVE-2020-13950.json
	modified:   2020/13xxx/CVE-2020-13954.json
	modified:   2020/13xxx/CVE-2020-13956.json
	modified:   2020/14xxx/CVE-2020-14060.json
	modified:   2020/14xxx/CVE-2020-14061.json
	modified:   2020/14xxx/CVE-2020-14062.json
	modified:   2020/14xxx/CVE-2020-14195.json
	modified:   2020/15xxx/CVE-2020-15824.json
	modified:   2020/17xxx/CVE-2020-17521.json
	modified:   2020/17xxx/CVE-2020-17530.json
	modified:   2020/1xxx/CVE-2020-1945.json
	modified:   2020/1xxx/CVE-2020-1967.json
	modified:   2020/1xxx/CVE-2020-1968.json
	modified:   2020/1xxx/CVE-2020-1971.json
	modified:   2020/24xxx/CVE-2020-24616.json
	modified:   2020/24xxx/CVE-2020-24750.json
	modified:   2020/24xxx/CVE-2020-24977.json
	modified:   2020/25xxx/CVE-2020-25648.json
	modified:   2020/25xxx/CVE-2020-25649.json
	modified:   2020/26xxx/CVE-2020-26116.json
	modified:   2020/26xxx/CVE-2020-26137.json
	modified:   2020/26xxx/CVE-2020-26217.json
	modified:   2020/27xxx/CVE-2020-27193.json
	modified:   2020/27xxx/CVE-2020-27216.json
	modified:   2020/27xxx/CVE-2020-27218.json
	modified:   2020/27xxx/CVE-2020-27824.json
	modified:   2020/28xxx/CVE-2020-28052.json
	modified:   2020/28xxx/CVE-2020-28500.json
	modified:   2020/28xxx/CVE-2020-28928.json
	modified:   2020/29xxx/CVE-2020-29661.json
	modified:   2020/35xxx/CVE-2020-35452.json
	modified:   2020/35xxx/CVE-2020-35490.json
	modified:   2020/35xxx/CVE-2020-35491.json
	modified:   2020/35xxx/CVE-2020-35728.json
	modified:   2020/36xxx/CVE-2020-36179.json
	modified:   2020/36xxx/CVE-2020-36180.json
	modified:   2020/36xxx/CVE-2020-36181.json
	modified:   2020/36xxx/CVE-2020-36182.json
	modified:   2020/36xxx/CVE-2020-36183.json
	modified:   2020/36xxx/CVE-2020-36184.json
	modified:   2020/36xxx/CVE-2020-36185.json
	modified:   2020/36xxx/CVE-2020-36186.json
	modified:   2020/36xxx/CVE-2020-36187.json
	modified:   2020/36xxx/CVE-2020-36188.json
	modified:   2020/36xxx/CVE-2020-36189.json
	modified:   2020/5xxx/CVE-2020-5258.json
	modified:   2020/5xxx/CVE-2020-5397.json
	modified:   2020/5xxx/CVE-2020-5398.json
	modified:   2020/5xxx/CVE-2020-5413.json
	modified:   2020/5xxx/CVE-2020-5421.json
	modified:   2020/6xxx/CVE-2020-6950.json
	modified:   2020/7xxx/CVE-2020-7065.json
	modified:   2020/7xxx/CVE-2020-7069.json
	modified:   2020/7xxx/CVE-2020-7070.json
	modified:   2020/7xxx/CVE-2020-7071.json
	modified:   2020/7xxx/CVE-2020-7226.json
	modified:   2020/7xxx/CVE-2020-7595.json
	modified:   2020/8xxx/CVE-2020-8203.json
	modified:   2020/8xxx/CVE-2020-8277.json
	modified:   2020/8xxx/CVE-2020-8622.json
	modified:   2020/8xxx/CVE-2020-8908.json
	modified:   2020/9xxx/CVE-2020-9281.json
	modified:   2020/9xxx/CVE-2020-9484.json
	modified:   2020/9xxx/CVE-2020-9488.json
	modified:   2020/9xxx/CVE-2020-9546.json
	modified:   2020/9xxx/CVE-2020-9547.json
	modified:   2020/9xxx/CVE-2020-9548.json
	modified:   2021/20xxx/CVE-2021-20227.json
	modified:   2021/20xxx/CVE-2021-20265.json
	modified:   2021/20xxx/CVE-2021-20270.json
	modified:   2021/21xxx/CVE-2021-21290.json
	modified:   2021/21xxx/CVE-2021-21341.json
	modified:   2021/21xxx/CVE-2021-21342.json
	modified:   2021/21xxx/CVE-2021-21343.json
	modified:   2021/21xxx/CVE-2021-21344.json
	modified:   2021/21xxx/CVE-2021-21345.json
	modified:   2021/21xxx/CVE-2021-21346.json
	modified:   2021/21xxx/CVE-2021-21347.json
	modified:   2021/21xxx/CVE-2021-21348.json
	modified:   2021/21xxx/CVE-2021-21349.json
	modified:   2021/21xxx/CVE-2021-21350.json
	modified:   2021/21xxx/CVE-2021-21351.json
	modified:   2021/21xxx/CVE-2021-21409.json
	modified:   2021/21xxx/CVE-2021-21702.json
	modified:   2021/21xxx/CVE-2021-21783.json
	modified:   2021/22xxx/CVE-2021-22112.json
	modified:   2021/22xxx/CVE-2021-22118.json
	modified:   2021/22xxx/CVE-2021-22207.json
	modified:   2021/22xxx/CVE-2021-22222.json
	modified:   2021/22xxx/CVE-2021-22696.json
	modified:   2021/22xxx/CVE-2021-22883.json
	modified:   2021/22xxx/CVE-2021-22884.json
	modified:   2021/22xxx/CVE-2021-22922.json
	modified:   2021/22xxx/CVE-2021-22923.json
	modified:   2021/22xxx/CVE-2021-22924.json
	modified:   2021/22xxx/CVE-2021-22925.json
	modified:   2021/22xxx/CVE-2021-22926.json
	modified:   2021/22xxx/CVE-2021-22931.json
	modified:   2021/22xxx/CVE-2021-22939.json
	modified:   2021/22xxx/CVE-2021-22940.json
	modified:   2021/22xxx/CVE-2021-22945.json
	modified:   2021/22xxx/CVE-2021-22946.json
	modified:   2021/22xxx/CVE-2021-22947.json
	modified:   2021/23xxx/CVE-2021-23017.json
	modified:   2021/23xxx/CVE-2021-23336.json
	modified:   2021/23xxx/CVE-2021-23337.json
	modified:   2021/23xxx/CVE-2021-23839.json
	modified:   2021/23xxx/CVE-2021-23840.json
	modified:   2021/23xxx/CVE-2021-23841.json
	modified:   2021/23xxx/CVE-2021-23926.json
	modified:   2021/25xxx/CVE-2021-25122.json
	modified:   2021/25xxx/CVE-2021-25215.json
	modified:   2021/25xxx/CVE-2021-25329.json
	modified:   2021/26xxx/CVE-2021-26117.json
	modified:   2021/26xxx/CVE-2021-26271.json
	modified:   2021/26xxx/CVE-2021-26272.json
	modified:   2021/26xxx/CVE-2021-26690.json
	modified:   2021/26xxx/CVE-2021-26691.json
	modified:   2021/27xxx/CVE-2021-27290.json
	modified:   2021/27xxx/CVE-2021-27364.json
	modified:   2021/27xxx/CVE-2021-27365.json
	modified:   2021/27xxx/CVE-2021-27807.json
	modified:   2021/27xxx/CVE-2021-27906.json
	modified:   2021/28xxx/CVE-2021-28163.json
	modified:   2021/28xxx/CVE-2021-28164.json
	modified:   2021/28xxx/CVE-2021-28165.json
	modified:   2021/28xxx/CVE-2021-28169.json
	modified:   2021/28xxx/CVE-2021-28363.json
	modified:   2021/28xxx/CVE-2021-28657.json
	modified:   2021/28xxx/CVE-2021-28957.json
	modified:   2021/29xxx/CVE-2021-29425.json
	modified:   2021/29xxx/CVE-2021-29505.json
	modified:   2021/29xxx/CVE-2021-29921.json
	modified:   2021/2xxx/CVE-2021-2341.json
	modified:   2021/2xxx/CVE-2021-2369.json
	modified:   2021/2xxx/CVE-2021-2388.json
	modified:   2021/2xxx/CVE-2021-2432.json
	modified:   2021/30xxx/CVE-2021-30468.json
	modified:   2021/30xxx/CVE-2021-30640.json
	modified:   2021/30xxx/CVE-2021-30641.json
	modified:   2021/31xxx/CVE-2021-31618.json
	modified:   2021/31xxx/CVE-2021-31811.json
	modified:   2021/31xxx/CVE-2021-31812.json
	modified:   2021/32xxx/CVE-2021-32803.json
	modified:   2021/32xxx/CVE-2021-32804.json
	modified:   2021/32xxx/CVE-2021-32808.json
	modified:   2021/32xxx/CVE-2021-32809.json
	modified:   2021/33xxx/CVE-2021-33037.json
	modified:   2021/33xxx/CVE-2021-33503.json
	modified:   2021/33xxx/CVE-2021-33560.json
	modified:   2021/34xxx/CVE-2021-34428.json
	modified:   2021/34xxx/CVE-2021-34558.json
	modified:   2021/35xxx/CVE-2021-35043.json
	modified:   2021/35xxx/CVE-2021-35515.json
	modified:   2021/35xxx/CVE-2021-35516.json
	modified:   2021/35xxx/CVE-2021-35517.json
	modified:   2021/36xxx/CVE-2021-36090.json
	modified:   2021/36xxx/CVE-2021-36222.json
	modified:   2021/36xxx/CVE-2021-36373.json
	modified:   2021/36xxx/CVE-2021-36374.json
	modified:   2021/37xxx/CVE-2021-37695.json
	modified:   2021/37xxx/CVE-2021-37701.json
	modified:   2021/37xxx/CVE-2021-37712.json
	modified:   2021/37xxx/CVE-2021-37713.json
	modified:   2021/39xxx/CVE-2021-39134.json
	modified:   2021/39xxx/CVE-2021-39135.json
	modified:   2021/3xxx/CVE-2021-3156.json
	modified:   2021/3xxx/CVE-2021-3177.json
	modified:   2021/3xxx/CVE-2021-3426.json
	modified:   2021/3xxx/CVE-2021-3449.json
	modified:   2021/3xxx/CVE-2021-3450.json
	modified:   2021/3xxx/CVE-2021-3517.json
	modified:   2021/3xxx/CVE-2021-3518.json
	modified:   2021/3xxx/CVE-2021-3520.json
	modified:   2021/3xxx/CVE-2021-3522.json
	modified:   2021/3xxx/CVE-2021-3537.json
	modified:   2021/3xxx/CVE-2021-3711.json
	modified:   2021/3xxx/CVE-2021-3712.json
2021-10-19 14:23:14 -07:00
CVE Team
e83f7e9843
"-Synchronized-Data." 2021-10-19 09:01:01 +00:00