|
194111
|
7.1 |
HIGH
Local
|
google
|
android
|
An issue was discovered on LG mobile devices with Android OS 4.4 through 11 software. Attackers can leverage ISMS services to bypass access control on specific content providers. The LG ID is LVE-SMP…
|
NVD-CWE-Other
|
CVE-2021-30162
|
2024-11-21 15:03 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194112
|
5.5 |
MEDIUM
Local
|
google
|
android
|
An issue was discovered on LG mobile devices with Android OS 11 software. Attackers can bypass the lockscreen protection mechanism after an incoming call has been terminated. The LG ID is LVE-SMP-210…
|
NVD-CWE-noinfo
|
CVE-2021-30161
|
2024-11-21 15:03 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194113
|
5.3 |
MEDIUM
Network
|
mediawiki debian fedoraproject
|
mediawiki debian_linux fedora
|
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user mi…
|
CWE-287
Improper Authentication
|
CVE-2021-30158
|
2024-11-21 15:03 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194114
|
6.1 |
MEDIUM
Network
|
mediawiki debian fedoraproject
|
mediawiki debian_linux fedora
|
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special pages such as Special:RecentChanges and Special:Watchlist, some of the rcfilters-fi…
|
CWE-79
Cross-site Scripting
|
CVE-2021-30157
|
2024-11-21 15:03 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194115
|
6.1 |
MEDIUM
Network
|
mediawiki debian fedoraproject
|
mediawiki debian_linux fedora
|
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Special:NewFiles, all the mediastatistics-header-* messages are output in HTML unescaped, leading to XS…
|
CWE-79
Cross-site Scripting
|
CVE-2021-30154
|
2024-11-21 15:03 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194116
|
6.1 |
MEDIUM
Network
|
contribsys debian
|
sidekiq debian_linux
|
Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.
|
CWE-79
Cross-site Scripting
|
CVE-2021-30151
|
2024-11-21 15:03 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194117
|
6.1 |
MEDIUM
Network
|
ocproducts
|
composr
|
Composr 10.0.36 allows XSS in an XML script.
|
CWE-79
Cross-site Scripting
|
CVE-2021-30150
|
2024-11-21 15:03 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194118
|
9.8 |
CRITICAL
Network
|
ocproducts
|
composr
|
Composr 10.0.36 allows upload and execution of PHP files.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-30149
|
2024-11-21 15:03 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194119
|
4.3 |
MEDIUM
Network
|
glpi-project
|
dashboard
|
The Dashboard plugin through 1.0.2 for GLPI allows remote low-privileged users to bypass access control on viewing information about the last ten events, the connected users, and the users in the tec…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2021-30144
|
2024-11-21 15:03 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194120
|
7.5 |
HIGH
Network
|
friendica
|
friendica
|
Module/Settings/UserExport.php in Friendica through 2021.01 allows settings/userexport to be used by anonymous users, as demonstrated by an attempted access to an array offset on a value of type null…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2021-30141
|
2024-11-21 15:03 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|