|
197901
|
8.8 |
HIGH
Network
|
mootools
|
mootools-more
|
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in mootools-more 1.6.0 allows a malicious user to inject properties into Object.prototype.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-20088
|
2024-11-21 14:45 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197902
|
8.8 |
HIGH
Network
|
acemetrix
|
jquery-deparam
|
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-deparam 0.5.1 allows a malicious user to inject properties into Object.prototype.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-20087
|
2024-11-21 14:45 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197903
|
8.8 |
HIGH
Network
|
jquery-sparkle_project
|
jquery-sparkle
|
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-sparkle 1.5.2-beta allows a malicious user to inject properties into Object.prototype.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-20084
|
2024-11-21 14:45 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197904
|
4.9 |
MEDIUM
Network
|
sonicwall
|
email_security hosted_email_security
|
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
|
CWE-22
Path Traversal
|
CVE-2021-20023
|
2024-11-21 14:45 |
2021-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197905
|
9.8 |
CRITICAL
Network
|
sonicwall
|
global_management_system
|
A command execution vulnerability in SonicWall GMS 9.3 allows a remote unauthenticated attacker to locally escalate privilege to root.
|
CWE-287
Improper Authentication
|
CVE-2021-20020
|
2024-11-21 14:45 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197906
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_servicedesk_plus
|
Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a remote, unauthenticated attacker to conduct persiste…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20080
|
2024-11-21 14:45 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197907
|
7.2 |
HIGH
Network
|
sonicwall
|
email_security hosted_email_security
|
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-20022
|
2024-11-21 14:45 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197908
|
9.8 |
CRITICAL
Network
|
sonicwall
|
email_security hosted_email_security
|
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
|
CWE-269
Improper Privilege Management
|
CVE-2021-20021
|
2024-11-21 14:45 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197909
|
7.8 |
HIGH
Local
|
qualcomm
|
aqt1000_firmware pm8005_firmware pm855_firmware pm855p_firmware pm8998_firmware pmi8998_firmware qat3550_firmware qca1062_firmware qca1064_firmware qca2066_firmware qca6…
|
Memory corruption due to improper input validation while processing IO control which is nonstandard in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapd…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-1892
|
2024-11-21 14:45 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197910
|
8.8 |
HIGH
Network
|
apple debian fedoraproject
|
safari iphone_os watchos tvos macos ipados debian_linux fedora
|
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 14.4.1 and iPadOS 14.4.1, Safari 14.0.3 (v. 14610.4.3.1.7 and 15610.4.3.1.7), watchOS 7.3.2, macOS Big Sur…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-1844
|
2024-11-21 14:45 |
2021-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|