|
194081
|
5.4 |
MEDIUM
Network
|
remoteclinic
|
remote_clinic
|
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Full Name field on register-patient.php.
|
CWE-79
Cross-site Scripting
|
CVE-2021-30030
|
2024-11-21 15:03 |
2021-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194082
|
6.1 |
MEDIUM
Network
|
wikimedia
|
parsoid
|
An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2. An attacker can send crafted wikitext that Utils/WTUtils.php will transform by using a <meta> tag, bypassing sanit…
|
CWE-79
Cross-site Scripting
|
CVE-2021-30458
|
2024-11-21 15:03 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194083
|
4.3 |
MEDIUM
Network
|
mediawiki debian fedoraproject
|
mediawiki debian_linux fedora
|
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Users can bypass intended restrictions on deleting pages in certain "fast double move" situations. MovePag…
|
NVD-CWE-noinfo
|
CVE-2021-30159
|
2024-11-21 15:03 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194084
|
4.3 |
MEDIUM
Network
|
mediawiki fedoraproject
|
mediawiki fedora
|
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Special:Contributions can leak that a "hidden" user exists.
|
CWE-200
Information Exposure
|
CVE-2021-30156
|
2024-11-21 15:03 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194085
|
4.3 |
MEDIUM
Network
|
mediawiki debian fedoraproject
|
mediawiki debian_linux fedora
|
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. ContentModelChange does not check if a user has correct permissions to create and set the content model of…
|
CWE-862
Missing Authorization
|
CVE-2021-30155
|
2024-11-21 15:03 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194086
|
4.3 |
MEDIUM
Network
|
mediawiki debian fedoraproject
|
mediawiki debian_linux fedora
|
An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki API to "protect" a page, a user is currently able to protect to a higher level th…
|
CWE-269
Improper Privilege Management
|
CVE-2021-30152
|
2024-11-21 15:03 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194087
|
7.8 |
HIGH
Local
|
vestacp
|
control_panel
|
VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY value from user.conf under the /usr/local/vesta/data…
|
CWE-59
Link Following
|
CVE-2021-30463
|
2024-11-21 15:03 |
2021-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194088
|
7.2 |
HIGH
Network
|
vestacp
|
vesta_control_panel
|
VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require a password to run /usr/local/vesta/bin scripts.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-30462
|
2024-11-21 15:03 |
2021-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194089
|
6.5 |
MEDIUM
Network
|
web-school
|
enterprise_resource_planning
|
Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a voucher payment request through module/accounting/voucher/create. The applica…
|
CWE-352
Origin Validation Error
|
CVE-2021-30114
|
2024-11-21 15:03 |
2021-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194090
|
6.1 |
MEDIUM
Network
|
web-school
|
enterprise_resource_planning
|
A blind XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in event name and description fields. An attacker can inject a JavaScript code that will be stored in the page. If any visito…
|
CWE-79
Cross-site Scripting
|
CVE-2021-30113
|
2024-11-21 15:03 |
2021-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|