|
196901
|
7.5 |
HIGH
Network
|
apache netapp
|
myfaces oncommand_insight
|
In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site reque…
|
CWE-352
Origin Validation Error
|
CVE-2021-26296
|
2024-11-21 14:56 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196902
|
6.1 |
MEDIUM
Network
|
openenergymonitor
|
emoncms
|
Modules/input/Views/schedule.php in Emoncms through 10.2.7 allows XSS via the node parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-26716
|
2024-11-21 14:56 |
2021-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196903
|
5.4 |
MEDIUM
Network
|
apache
|
livy
|
Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicious user could use this flaw to access logs and results of other users' sessions…
|
CWE-79
Cross-site Scripting
|
CVE-2021-26544
|
2024-11-21 14:56 |
2021-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196904
|
6.1 |
MEDIUM
Network
|
chamilo
|
chamilo
|
Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.php?type= URI.
|
CWE-79
Cross-site Scripting
|
CVE-2021-26746
|
2024-11-21 14:56 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196905
|
9.8 |
CRITICAL
Network
|
netis-systems
|
wf2780_firmware wf2411_firmware
|
Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.
|
CWE-78
OS Command
|
CVE-2021-26747
|
2024-11-21 14:56 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196906
|
7.5 |
HIGH
Network
|
digium
|
certified_asterisk asterisk
|
Incorrect access controls in res_srtp.c in Sangoma Asterisk 13.38.1, 16.16.0, 17.9.1, and 18.2.0 and Certified Asterisk 16.8-cert5 allow a remote unauthenticated attacker to prematurely terminate sec…
|
NVD-CWE-Other
|
CVE-2021-26712
|
2024-11-21 14:56 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196907
|
7.5 |
HIGH
Network
|
digium
|
certified_asterisk asterisk
|
An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6. When re-negotiating for T.38, if the initial remo…
|
NVD-CWE-noinfo
|
CVE-2021-26717
|
2024-11-21 14:56 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196908
|
7.8 |
HIGH
Local
|
avahi debian
|
avahi debian_linux
|
avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbit…
|
CWE-59
Link Following
|
CVE-2021-26720
|
2024-11-21 14:56 |
2021-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196909
|
9.8 |
CRITICAL
Network
|
phpgurukul
|
car_rental_portal
|
PHPGurukul Car Rental Project version 2.0 suffers from a remote shell upload vulnerability in changeimage1.php.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-26809
|
2024-11-21 14:56 |
2021-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196910
|
5.3 |
MEDIUM
Network
|
apache
|
airflow
|
The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to hit that endpoint. This is low-severity issue as th…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-26697
|
2024-11-21 14:56 |
2021-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|