Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2021-03-18 CVE-2021-21383 Cross-site Scripting vulnerability in Requarks Wiki.Js
Wiki.js an open-source wiki app built on Node.js.
network
requarks CWE-79
3.5
2021-03-18 CVE-2020-27827 Resource Exhaustion vulnerability in multiple products
A flaw was found in multiple versions of OpenvSwitch.
7.5
2021-03-18 CVE-2020-26155 Incorrect Permission Assignment for Critical Resource vulnerability in Utimaco products
Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0.
4.4
2021-03-18 CVE-2021-28796 Cross-site Scripting vulnerability in Increments Qiita::Markdown
Increments Qiita::Markdown before 0.33.0 allows XSS in transformers.
network
increments CWE-79
4.3
2021-03-18 CVE-2021-28794 Unspecified vulnerability in Shellcheck Project Shellcheck
The unofficial ShellCheck extension before 0.13.4 for Visual Studio Code mishandles shellcheck.executablePath.
network
low complexity
shellcheck-project
7.5
2021-03-18 CVE-2021-28792 Unspecified vulnerability in Swift Development Environment Project Swift Development Environment
The unofficial Swift Development Environment extension before 2.12.1 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted sourcekit-lsp.serverPath, swift.languageServerPath, swift.path.sourcekite, swift.path.sourcekiteDockerMode, swift.path.swift_driver_bin, or swift.path.shell configuration value that triggers execution upon opening the workspace.
6.8
2021-03-18 CVE-2021-28791 Unspecified vulnerability in Swiftformat Project Swiftformat
The unofficial SwiftFormat extension before 1.3.7 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted swiftformat.path configuration value that triggers execution upon opening the workspace.
6.8
2021-03-18 CVE-2021-28790 Unspecified vulnerability in Swiftlint Project Swiftlint
The unofficial SwiftLint extension before 1.4.5 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted swiftlint.path configuration value that triggers execution upon opening the workspace.
6.8
2021-03-18 CVE-2021-28789 Unspecified vulnerability in Apple-Swift-Format Project Apple-Swift-Format
The unofficial apple/swift-format extension before 1.1.2 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted apple-swift-format.path configuration value that triggers execution upon opening the workspace.
6.8
2021-03-18 CVE-2021-28145 Cross-site Scripting vulnerability in Concretecms Concrete CMS
Concrete CMS (formerly concrete5) before 8.5.5 allows remote authenticated users to conduct XSS attacks via a crafted survey block.
3.5