|
197081
|
4.8 |
MEDIUM
Network
|
magento
|
magento
|
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-site scripting vulnerability in the admin console. Successful exploitation could …
|
CWE-79
Cross-site Scripting
|
CVE-2021-21023
|
2024-11-21 14:47 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197082
|
5.3 |
MEDIUM
Network
|
magento
|
magento
|
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object reference (IDOR) in the product module. Successful exploitation could …
|
-
|
CVE-2021-21022
|
2024-11-21 14:47 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197083
|
8.8 |
HIGH
Network
|
adobe
|
acrobat acrobat_dc acrobat_reader acrobat_reader_dc
|
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a Use After Free vulnerability. An unauthenticated atta…
|
-
|
CVE-2021-21021
|
2024-11-21 14:47 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197084
|
5.3 |
MEDIUM
Network
|
magento
|
magento
|
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an access control bypass vulnerability in the Login as Customer module. Successful exploitation …
|
NVD-CWE-Other
|
CVE-2021-21020
|
2024-11-21 14:47 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197085
|
9.1 |
CRITICAL
Network
|
magento
|
magento
|
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the Widgets module. Successful exploitation could lead to arbitrary code execut…
|
-
|
CVE-2021-21019
|
2024-11-21 14:47 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197086
|
9.1 |
CRITICAL
Network
|
magento
|
magento
|
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the scheduled operation module. Successful exploitation could lead to a…
|
-
|
CVE-2021-21018
|
2024-11-21 14:47 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197087
|
8.8 |
HIGH
Network
|
adobe
|
acrobat acrobat_dc acrobat_reader acrobat_reader_dc
|
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthen…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-21017
|
2024-11-21 14:47 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197088
|
9.1 |
CRITICAL
Network
|
magento
|
magento
|
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the WebAPI. Successful exploitation could lead to remote code execution…
|
CWE-78
OS Command
|
CVE-2021-21016
|
2024-11-21 14:47 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197089
|
8.0 |
HIGH
Network
|
magento
|
magento
|
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an OS command injection via the customer attribute save controller. Successful exploitation coul…
|
-
|
CVE-2021-21015
|
2024-11-21 14:47 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197090
|
9.8 |
CRITICAL
Network
|
lucee
|
lucee_server
|
Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.96 there is an unaut…
|
-
|
CVE-2021-21307
|
2024-11-21 14:47 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|