|
194221
|
9.8 |
CRITICAL
Network
|
wordpress
|
requests
|
Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been patched and users of `Requests` 1.6.0, 1.6.1 and 1.7.0 should update to version …
|
-
|
CVE-2021-29476
|
2024-11-21 15:01 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194222
|
8.8 |
HIGH
Network
|
getcomposer debian fedoraproject
|
composer debian_linux fedora
|
Composer is a dependency manager for PHP. URLs for Mercurial repositories in the root composer.json and package source download URLs are not sanitized correctly. Specifically crafted URL values allow…
|
-
|
CVE-2021-29472
|
2024-11-21 15:01 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194223
|
7.5 |
HIGH
Network
|
alibaba
|
nacos
|
Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, the ConfigOpsController lets the user perform management operations…
|
-
|
CVE-2021-29442
|
2024-11-21 15:01 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194224
|
7.8 |
HIGH
Local
|
ibm
|
spectrum_scale
|
IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper val…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2021-29667
|
2024-11-21 15:01 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194225
|
5.4 |
MEDIUM
Network
|
ibm
|
spectrum_scale
|
IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alterin…
|
CWE-79
Cross-site Scripting
|
CVE-2021-29666
|
2024-11-21 15:01 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194226
|
9.8 |
CRITICAL
Network
|
alibaba
|
nacos
|
Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, when configured to use authentication (-Dnacos.core.auth.enabled=tr…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2021-29441
|
2024-11-21 15:01 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194227
|
5.4 |
MEDIUM
Network
|
getkirby
|
kirby
|
Kirby is an open source CMS. An editor with write access to the Kirby Panel can upload an SVG file that contains harmful content like `<script>` tags. The direct link to that file can be sent to othe…
|
-
|
CVE-2021-29460
|
2024-11-21 15:01 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194228
|
5.8 |
MEDIUM
Network
|
hedgedoc
|
hedgedoc
|
HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker can read arbitrary `.md` files from the server's filesystem due to an improper input validation, which…
|
CWE-22
Path Traversal
|
CVE-2021-29474
|
2024-11-21 15:01 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194229
|
10.0 |
CRITICAL
Network
|
hedgedoc
|
hedgedoc
|
HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker is able to receive arbitrary files from the file system when exporting a note to PDF. Since the code i…
|
CWE-94 CWE-918
Code Injection Server-Side Request Forgery (SSRF)
|
CVE-2021-29475
|
2024-11-21 15:01 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194230
|
7.5 |
HIGH
Network
|
ibm
|
spectrum_protect_plus
|
IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 200258.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2021-29694
|
2024-11-21 15:01 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|