|
196001
|
8.8 |
HIGH
Network
|
daifukuya
|
kagemai
|
Cross-site request forgery (CSRF) vulnerability in Kagemai 0.8.8 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
|
CWE-352
Origin Validation Error
|
CVE-2021-20687
|
2024-11-21 14:47 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196002
|
6.1 |
MEDIUM
Network
|
daifukuya
|
kagemai
|
Cross-site scripting vulnerability in Kagemai 0.8.8 allows remote attackers to inject an arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20686
|
2024-11-21 14:47 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196003
|
6.1 |
MEDIUM
Network
|
daifukuya
|
kagemai
|
Cross-site scripting vulnerability in Kagemai 0.8.8 allows remote attackers to inject an arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20685
|
2024-11-21 14:47 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196004
|
6.1 |
MEDIUM
Network
|
magazinegerz_project
|
magazinegerz
|
Cross-site scripting vulnerability in MagazinegerZ v.1.01 allows remote attackers to inject an arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20684
|
2024-11-21 14:47 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196005
|
5.4 |
MEDIUM
Network
|
basercms
|
basercms
|
Improper neutralization of JavaScript input in the blog article editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecifie…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20683
|
2024-11-21 14:47 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196006
|
7.2 |
HIGH
Network
|
basercms
|
basercms
|
baserCMS versions prior to 4.4.5 allows a remote attacker with an administrative privilege to execute arbitrary OS commands via unspecified vectors.
|
CWE-78
OS Command
|
CVE-2021-20682
|
2024-11-21 14:47 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196007
|
5.4 |
MEDIUM
Network
|
basercms
|
basercms
|
Improper neutralization of JavaScript input in the page editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vector…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20681
|
2024-11-21 14:47 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196008
|
7.5 |
HIGH
Network
|
schema-inspector_project netapp
|
schema-inspector oncommand_insight e-series_performance_analyzer
|
Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before version 2.0.0, email address validation is vulnerable to a denial-of-service atta…
|
-
|
CVE-2021-21267
|
2024-11-21 14:47 |
2021-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196009
|
8.8 |
HIGH
Network
|
google fedoraproject debian
|
chrome fedora debian_linux
|
Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-416
Use After Free
|
CVE-2021-21193
|
2024-11-21 14:47 |
2021-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196010
|
8.8 |
HIGH
Network
|
google fedoraproject debian
|
chrome fedora debian_linux
|
Heap buffer overflow in tab groups in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-21192
|
2024-11-21 14:47 |
2021-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|