|
197741
|
8.8 |
HIGH
Network
|
acemetrix
|
jquery-deparam
|
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-deparam 0.5.1 allows a malicious user to inject properties into Object.prototype.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-20087
|
2024-11-21 14:45 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197742
|
8.8 |
HIGH
Network
|
jquery-sparkle_project
|
jquery-sparkle
|
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-sparkle 1.5.2-beta allows a malicious user to inject properties into Object.prototype.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-20084
|
2024-11-21 14:45 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197743
|
4.9 |
MEDIUM
Network
|
sonicwall
|
email_security hosted_email_security
|
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
|
CWE-22
Path Traversal
|
CVE-2021-20023
|
2024-11-21 14:45 |
2021-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197744
|
9.8 |
CRITICAL
Network
|
sonicwall
|
global_management_system
|
A command execution vulnerability in SonicWall GMS 9.3 allows a remote unauthenticated attacker to locally escalate privilege to root.
|
CWE-287
Improper Authentication
|
CVE-2021-20020
|
2024-11-21 14:45 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197745
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_servicedesk_plus
|
Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a remote, unauthenticated attacker to conduct persiste…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20080
|
2024-11-21 14:45 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197746
|
7.2 |
HIGH
Network
|
sonicwall
|
email_security hosted_email_security
|
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-20022
|
2024-11-21 14:45 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197747
|
9.8 |
CRITICAL
Network
|
sonicwall
|
email_security hosted_email_security
|
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
|
CWE-269
Improper Privilege Management
|
CVE-2021-20021
|
2024-11-21 14:45 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197748
|
7.8 |
HIGH
Local
|
qualcomm
|
aqt1000_firmware pm8005_firmware pm855_firmware pm855p_firmware pm8998_firmware pmi8998_firmware qat3550_firmware qca1062_firmware qca1064_firmware qca2066_firmware qca6…
|
Memory corruption due to improper input validation while processing IO control which is nonstandard in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapd…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-1892
|
2024-11-21 14:45 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197749
|
8.8 |
HIGH
Network
|
apple debian fedoraproject
|
safari iphone_os watchos tvos macos ipados debian_linux fedora
|
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 14.4.1 and iPadOS 14.4.1, Safari 14.0.3 (v. 14610.4.3.1.7 and 15610.4.3.1.7), watchOS 7.3.2, macOS Big Sur…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-1844
|
2024-11-21 14:45 |
2021-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197750
|
9.8 |
CRITICAL
Network
|
apple
|
mac_os_x iphone_os tvos watchos ipad_os macos
|
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS …
|
NVD-CWE-noinfo
|
CVE-2021-1818
|
2024-11-21 14:45 |
2021-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|