|
196131
|
3.5 |
LOW
Network
|
atlassian
|
data_center jira jira_server jira_data_center
|
The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymo…
|
CWE-352
Origin Validation Error
|
CVE-2021-26071
|
2024-11-21 14:55 |
2021-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196132
|
6.1 |
MEDIUM
Network
|
open-emr
|
openemr
|
In OpenEMR, versions 4.2.0 to 6.0.0 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly. An attacker could trick a user to click on a malicious url a…
|
CWE-79
Cross-site Scripting
|
CVE-2021-25922
|
2024-11-21 14:55 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196133
|
5.4 |
MEDIUM
Network
|
open-emr
|
openemr
|
In OpenEMR, versions 2.7.3-rc1 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly in the `Allergies` section. An attacker could lure an admin …
|
CWE-79
Cross-site Scripting
|
CVE-2021-25921
|
2024-11-21 14:55 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196134
|
6.5 |
MEDIUM
Network
|
open-emr
|
openemr
|
In OpenEMR, versions v2.7.2-rc1 to 6.0.0 are vulnerable to Improper Access Control when creating a new user, which leads to a malicious user able to read and send sensitive messages on behalf of the …
|
CWE-178
Improper Handling of Case Sensitivity
|
CVE-2021-25920
|
2024-11-21 14:55 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196135
|
4.8 |
MEDIUM
Network
|
open-emr
|
openemr
|
In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly. A highly privileged attacker could inject arbitrary code into i…
|
CWE-79
Cross-site Scripting
|
CVE-2021-25919
|
2024-11-21 14:55 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196136
|
4.8 |
MEDIUM
Network
|
open-emr
|
openemr
|
In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the TOTP Authentication method page. A highly pr…
|
CWE-79
Cross-site Scripting
|
CVE-2021-25918
|
2024-11-21 14:55 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196137
|
4.8 |
MEDIUM
Network
|
open-emr
|
openemr
|
In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the U2F USB Device authentication method page. A…
|
CWE-79
Cross-site Scripting
|
CVE-2021-25917
|
2024-11-21 14:55 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196138
|
7.2 |
HIGH
Network
|
atlassian
|
data_center jira jira_server
|
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `mak…
|
CWE-287
Improper Authentication
|
CVE-2021-26070
|
2024-11-21 14:55 |
2021-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196139
|
5.3 |
MEDIUM
Network
|
atlassian
|
jira data_center jira_server jira_data_center
|
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to download temporary files and enumerate project keys via an Information Disclosure vulnerability in…
|
CWE-74
Injection
|
CVE-2021-26069
|
2024-11-21 14:55 |
2021-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196140
|
5.3 |
MEDIUM
Network
|
jetbrains
|
phpstorm
|
In JetBrains PhpStorm before 2020.3, source code could be added to debug logs.
|
NVD-CWE-noinfo
|
CVE-2021-25764
|
2024-11-21 14:55 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|