|
197411
|
6.1 |
MEDIUM
Network
|
ec-cube
|
ec-cube
|
Cross-site scripting vulnerability in EC-CUBE 4.0.0 to 4.0.5 allows a remote attacker to inject a specially crafted script in the specific input field of the EC web site which is created using EC-CUB…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20717
|
2024-11-21 14:47 |
2021-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197412
|
5.2 |
MEDIUM
Local
|
octobercms
|
october
|
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-26231 (fixed in 1.0.470/471 and 1.1.1) was discovered that has the same impact as CVE…
|
NVD-CWE-Other
|
CVE-2021-21264
|
2024-11-21 14:47 |
2021-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197413
|
8.8 |
HIGH
Network
|
google fedoraproject debian
|
chrome fedora debian_linux
|
Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-21233
|
2024-11-21 14:47 |
2021-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197414
|
8.8 |
HIGH
Network
|
google fedoraproject debian
|
chrome fedora debian_linux
|
Use after free in Dev Tools in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-416
Use After Free
|
CVE-2021-21232
|
2024-11-21 14:47 |
2021-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197415
|
8.8 |
HIGH
Network
|
google debian fedoraproject
|
chrome debian_linux fedora
|
Insufficient data validation in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-21231
|
2024-11-21 14:47 |
2021-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197416
|
8.8 |
HIGH
Network
|
google fedoraproject debian
|
chrome fedora debian_linux
|
Type confusion in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-843
Type Confusion
|
CVE-2021-21230
|
2024-11-21 14:47 |
2021-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197417
|
6.5 |
MEDIUM
Network
|
google debian fedoraproject
|
chrome debian_linux fedora
|
Incorrect security UI in downloads in Google Chrome on Android prior to 90.0.4430.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
|
CWE-346
Origin Validation Error
|
CVE-2021-21229
|
2024-11-21 14:47 |
2021-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197418
|
4.3 |
MEDIUM
Network
|
google debian fedoraproject
|
chrome debian_linux fedora
|
Insufficient policy enforcement in extensions in Google Chrome prior to 90.0.4430.93 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a …
|
CWE-863
Incorrect Authorization
|
CVE-2021-21228
|
2024-11-21 14:47 |
2021-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197419
|
8.8 |
HIGH
Network
|
google fedoraproject debian
|
chrome fedora debian_linux
|
Insufficient data validation in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-21227
|
2024-11-21 14:47 |
2021-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197420
|
9.8 |
CRITICAL
Network
|
buffalo
|
bhr-4rv_firmware fs-g54_firmware wbr2-b11_firmware wbr2-g54_firmware wbr2-g54-kd_firmware wbr-b11_firmware wbr-g54_firmware wbr-g54l_firmware whr2-a54g54_firmware whr2-g54_…
|
Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 and prior, WBR2-B11 firmware Ver.2.32 and prior, WBR2-G54 firmware Ver.2.32 and…
|
NVD-CWE-Other
|
CVE-2021-20716
|
2024-11-21 14:47 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|