|
196281
|
8.2 |
HIGH
Local
|
parallels
|
parallels_desktop
|
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.1-49141. An attacker must first obtain the ability to execute high-privileged code…
|
-
|
CVE-2021-27278
|
2024-11-21 14:57 |
2021-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196282
|
7.8 |
HIGH
Local
|
solarwinds
|
orion_platform
|
This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Orion Virtual Infrastructure Monitor 2020.2. An attacker must first obtain the ability to exec…
|
-
|
CVE-2021-27277
|
2024-11-21 14:57 |
2021-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196283
|
5.4 |
MEDIUM
Network
|
casap_automated_enrollment_system_project
|
casap_automated_enrollment_system
|
CASAP Automated Enrollment System version 1.0 contains a cross-site scripting (XSS) vulnerability through the Students > Edit > ROUTE parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27129
|
2024-11-21 14:57 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196284
|
8.8 |
HIGH
Network
|
mendix
|
mendix
|
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.19), Mendix Applications using Mendix 8 (All versions < V8.17.0), Mendix Applications using Mendix 8 (V…
|
-
|
CVE-2021-27394
|
2024-11-21 14:57 |
2021-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196285
|
7.2 |
HIGH
Network
|
altn
|
mdaemon
|
An issue was discovered in MDaemon before 20.0.4. Administrators can use Remote Administration to exploit an Arbitrary File Write vulnerability. An attacker is able to create new files in any locatio…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2021-27183
|
2024-11-21 14:57 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196286
|
8.8 |
HIGH
Network
|
altn
|
mdaemon
|
An issue was discovered in MDaemon before 20.0.4. There is an IFRAME injection vulnerability in Webmail (aka WorldClient). It can be exploited via an email message. It allows an attacker to perform a…
|
CWE-74
Injection
|
CVE-2021-27182
|
2024-11-21 14:57 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196287
|
8.8 |
HIGH
Network
|
altn
|
mdaemon
|
An issue was discovered in MDaemon before 20.0.4. Remote Administration allows an attacker to perform a fixation of the anti-CSRF token. In order to exploit this issue, the user has to click on a mal…
|
CWE-352
Origin Validation Error
|
CVE-2021-27181
|
2024-11-21 14:57 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196288
|
6.1 |
MEDIUM
Network
|
altn
|
mdaemon
|
An issue was discovered in MDaemon before 20.0.4. There is Reflected XSS in Webmail (aka WorldClient). It can be exploited via a GET request. It allows performing any action with the privileges of th…
|
CWE-79
Cross-site Scripting
|
CVE-2021-27180
|
2024-11-21 14:57 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196289
|
3.2 |
LOW
Local
|
parallels
|
parallels_desktop
|
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 16.0.1-48919. An attacker must first obtain the ability to execute high-priv…
|
-
|
CVE-2021-27260
|
2024-11-21 14:57 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196290
|
7.8 |
HIGH
Local
|
parallels
|
parallels_desktop
|
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.0.1-48919. An attacker must first obtain the ability to execute low-privileged code …
|
-
|
CVE-2021-27259
|
2024-11-21 14:57 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|