|
196981
|
7.2 |
HIGH
Network
|
prisma
|
prisma
|
Prisma is an open source ORM for Node.js & TypeScript. As of today, we are not aware of any Prisma users or external consumers of the `@prisma/sdk` package who are affected by this security vulnerabi…
|
-
|
CVE-2021-21414
|
2024-11-21 14:48 |
2021-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196982
|
6.5 |
MEDIUM
Network
|
ckeditor
|
ckeditor5-widget ckeditor5-paste-from-office ckeditor5-media-embed ckeditor5-markdown-gfm ckeditor5-list ckeditor5-image ckeditor5-font ckeditor5-engine
|
CKEditor 5 provides a WYSIWYG editing solution. This CVE affects the following npm packages: ckeditor5-engine, ckeditor5-font, ckeditor5-image, ckeditor5-list, ckeditor5-markdown-gfm, ckeditor5-media…
|
-
|
CVE-2021-21391
|
2024-11-21 14:48 |
2021-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196983
|
3.3 |
LOW
Local
|
openapi-generator
|
openapi_generator
|
OpenAPI Generator allows generation of API client libraries, server stubs, documentation and configuration automatically given an OpenAPI Spec. Using `File.createTempFile` in JDK will result in creat…
|
-
|
CVE-2021-21429
|
2024-11-21 14:48 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196984
|
5.4 |
MEDIUM
Network
|
typo3
|
typo3
|
Bootstrap Package is a theme for TYPO3. It has been discovered that rendering content in the website frontend is vulnerable to cross-site scripting. A valid backend user account is needed to exploit …
|
-
|
CVE-2021-21365
|
2024-11-21 14:48 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196985
|
7.2 |
HIGH
Network
|
openmage
|
magento
|
Magento-lts is a long-term support alternative to Magento Community Edition (CE). A vulnerability in magento-lts versions before 19.4.13 and 20.0.9 potentially allows an administrator unauthorized ac…
|
-
|
CVE-2021-21427
|
2024-11-21 14:48 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196986
|
9.8 |
CRITICAL
Network
|
openmage
|
magento
|
Magento-lts is a long-term support alternative to Magento Community Edition (CE). In magento-lts versions 19.4.12 and prior and 20.0.8 and prior, there is a vulnerability caused by the unsecured dese…
|
-
|
CVE-2021-21426
|
2024-11-21 14:48 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196987
|
4.3 |
MEDIUM
Network
|
jenkins
|
cloudbees_cd
|
Jenkins CloudBees CD Plugin 1.1.21 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Item/Read permission to schedule builds of projects without having Item…
|
-
|
CVE-2021-21647
|
2024-11-21 14:48 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196988
|
8.8 |
HIGH
Network
|
jenkins
|
templating_engine
|
Jenkins Templating Engine Plugin 2.1 and earlier does not protect its pipeline configurations using Script Security Plugin, allowing attackers with Job/Configure permission to execute arbitrary code …
|
-
|
CVE-2021-21646
|
2024-11-21 14:48 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196989
|
4.3 |
MEDIUM
Network
|
jenkins
|
config_file_provider
|
Jenkins Config File Provider Plugin 3.7.0 and earlier does not perform permission checks in several HTTP endpoints, attackers with Overall/Read permission to enumerate configuration file IDs.
|
-
|
CVE-2021-21645
|
2024-11-21 14:48 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196990
|
5.4 |
MEDIUM
Network
|
jenkins
|
config_file_provider
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attackers to delete configuration files corresponding to an attacker-specified ID.
|
CWE-352
Origin Validation Error
|
CVE-2021-21644
|
2024-11-21 14:48 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|