|
197161
|
9.8 |
CRITICAL
Network
|
onedev_project
|
onedev
|
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods that deserialize untrusted data from the request body. These endpoints do not e…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-21243
|
2024-11-21 14:47 |
2021-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197162
|
8.1 |
HIGH
Network
|
adobe
|
magento
|
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR) in the customer API module. Successful exploitati…
|
-
|
CVE-2021-21013
|
2024-11-21 14:47 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197163
|
5.3 |
MEDIUM
Network
|
adobe
|
magento_open_source magento_commerce
|
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR) in the checkout module. Successful exploitation c…
|
-
|
CVE-2021-21012
|
2024-11-21 14:47 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197164
|
7.0 |
HIGH
Local
|
adobe
|
captivate
|
Adobe Captivate 2019 version 11.5.1.499 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalation. An attacker with permissions to write t…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2021-21011
|
2024-11-21 14:47 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197165
|
7.0 |
HIGH
Local
|
adobe
|
incopy
|
InCopy version 15.1.1 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation…
|
-
|
CVE-2021-21010
|
2024-11-21 14:47 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197166
|
8.6 |
HIGH
Network
|
adobe
|
campaign_classic
|
Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.1.7 (and earlier) are affected by a server-side re…
|
-
|
CVE-2021-21009
|
2024-11-21 14:47 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197167
|
7.0 |
HIGH
Local
|
adobe
|
animate
|
Adobe Animate version 21.0 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Exploitation of this issu…
|
-
|
CVE-2021-21008
|
2024-11-21 14:47 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197168
|
7.0 |
HIGH
Local
|
adobe
|
illustrator
|
Adobe Illustrator version 25.0 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Exploitation of this …
|
-
|
CVE-2021-21007
|
2024-11-21 14:47 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197169
|
8.6 |
HIGH
Local
|
adobe
|
photoshop
|
Adobe Photoshop version 22.1 (and earlier) is affected by a heap buffer overflow vulnerability when handling a specially crafted font file. Successful exploitation could lead to arbitrary code execut…
|
-
|
CVE-2021-21006
|
2024-11-21 14:47 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197170
|
5.3 |
MEDIUM
Network
|
laravel
|
laravel
|
Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit applies to the illuminate/database package which …
|
CWE-89
SQL Injection
|
CVE-2021-21263
|
2024-11-21 14:47 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|