|
195291
|
5.3 |
MEDIUM
Network
|
djangoproject debian fedoraproject
|
django debian_linux fedora
|
In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were no…
|
CWE-22
Path Traversal
|
CVE-2021-28658
|
2024-11-21 15:00 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195292
|
7.8 |
HIGH
Local
|
serenityos
|
serenityos
|
SerenityOS fixed as of c9f25bca048443e317f1994ba9b106f2386688c3 contains a buffer overflow vulnerability in LibTextCode through opening a crafted file.
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-28874
|
2024-11-21 15:00 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195293
|
7.8 |
HIGH
Local
|
svelte
|
svelte
|
The unofficial Svelte extension before 104.8.0 for Visual Studio Code allows attackers to execute arbitrary code via a crafted workspace configuration.
|
NVD-CWE-noinfo
|
CVE-2021-29261
|
2024-11-21 15:00 |
2021-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195294
|
7.8 |
HIGH
Local
|
vim_project
|
vim
|
VSCodeVim before 1.19.0 allows attackers to execute arbitrary code via a crafted workspace configuration.
|
NVD-CWE-noinfo
|
CVE-2021-28832
|
2024-11-21 15:00 |
2021-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195295
|
5.3 |
MEDIUM
Network
|
magpierss_project
|
magpierss
|
Because of no validation on a curl command in MagpieRSS 0.72 in the /extlib/Snoopy.class.inc file, when you send a request to the /scripts/magpie_debug.php or /scripts/magpie_simple.php page, it's po…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-28941
|
2024-11-21 15:00 |
2021-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195296
|
9.8 |
CRITICAL
Network
|
magpierss_project
|
magpierss
|
Because of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to add a extra command to the curl binary. This creates an issue on the /scripts/…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2021-28940
|
2024-11-21 15:00 |
2021-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195297
|
9.8 |
CRITICAL
Network
|
dmasoftlab
|
dma_radius_manager
|
DMA Softlab Radius Manager 4.4.0 assigns the same session cookie to every admin session. The cookie is valid when the admin is logged in, but is invalid (temporarily) during times when the admin is l…
|
CWE-287
Improper Authentication
|
CVE-2021-29012
|
2024-11-21 15:00 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195298
|
6.1 |
MEDIUM
Network
|
dmasoftlab
|
dma_radius_manager
|
DMA Softlab Radius Manager 4.4.0 is affected by Cross Site Scripting (XSS) via the description, name, or address field (under admin.php).
|
CWE-79
Cross-site Scripting
|
CVE-2021-29011
|
2024-11-21 15:00 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195299
|
6.5 |
MEDIUM
Network
|
fireeye
|
email_malware_protection_system
|
eMPS 9.0.1.923211 on the Central Management of FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the job_id parameter to the email search feature. Accordi…
|
CWE-89
SQL Injection
|
CVE-2021-28970
|
2024-11-21 15:00 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195300
|
6.5 |
MEDIUM
Network
|
fireeye
|
email_malware_protection_system
|
eMPS 9.0.1.923211 on FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort_by parameter to the email search feature. According to the vendor, the iss…
|
CWE-89
SQL Injection
|
CVE-2021-28969
|
2024-11-21 15:00 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|