MicrocoCVEs & Vulnerabilities
2 CVEs affecting Microco products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
bluemonday 2
CVE-2021-42576CRITICAL
The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Python (in pybluemonday), does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.
18 Oct 2021
9.8
CVSS
CVE-2021-29272MEDIUM
bluemonday before 1.0.5 allows XSS because certain Go lowercasing converts an uppercase Cyrillic character, defeating a protection mechanism against the "script" string.
27 Mar 2021
6.1
CVSS
← PrevPage 1 / 1Next →