|
194261
|
4.8 |
MEDIUM
Network
|
seopanel
|
seo_panel
|
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via alerts.php and the "from_time" parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-28420
|
2024-11-21 14:59 |
2021-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194262
|
7.2 |
HIGH
Network
|
seopanel
|
seo_panel
|
The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads to the ability to retrieve all databases.
|
CWE-89
SQL Injection
|
CVE-2021-28419
|
2024-11-21 14:59 |
2021-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194263
|
4.8 |
MEDIUM
Network
|
seopanel
|
seo_panel
|
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and the "category" parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-28418
|
2024-11-21 14:59 |
2021-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194264
|
4.8 |
MEDIUM
Network
|
seopanel
|
seo_panel
|
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and the "search_name" parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-28417
|
2024-11-21 14:59 |
2021-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194265
|
9.8 |
CRITICAL
Network
|
vhs_project
|
vhs
|
The vhs (aka VHS: Fluid ViewHelpers) extension before 5.1.1 for TYPO3 allows SQL injection via isLanguageViewHelper.
|
CWE-89
SQL Injection
|
CVE-2021-28381
|
2024-11-21 14:59 |
2021-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194266
|
5.4 |
MEDIUM
Network
|
aimeos_project
|
aimeos
|
The aimeos (aka Aimeos shop and e-commerce framework) extension before 19.10.12 and 20.x before 20.10.5 for TYPO3 allows XSS via a backend user account.
|
CWE-79
Cross-site Scripting
|
CVE-2021-28380
|
2024-11-21 14:59 |
2021-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194267
|
7.5 |
HIGH
Network
|
online_ordering_system_project
|
online_ordering_system
|
Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure.
|
CWE-89
SQL Injection
|
CVE-2021-28295
|
2024-11-21 14:59 |
2021-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194268
|
9.8 |
CRITICAL
Network
|
online_ordering_system_project
|
online_ordering_system
|
Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE).
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-28294
|
2024-11-21 14:59 |
2021-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194269
|
7.5 |
HIGH
Network
|
varnish-cache fedoraproject
|
varnish-modules varnish-modules_klarlack fedora
|
Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations. This does not affect organizations that only install the Varnish Ca…
|
CWE-476 CWE-617
NULL Pointer Dereference Reachable Assertion
|
CVE-2021-28543
|
2024-11-21 14:59 |
2021-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194270
|
6.5 |
MEDIUM
Network
|
python fedoraproject oracle
|
urllib3 fedora peoplesoft_enterprise_peopletools
|
The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn't …
|
CWE-295
Improper Certificate Validation
|
CVE-2021-28363
|
2024-11-21 14:59 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|