|
196531
|
9.8 |
CRITICAL
Network
|
oppo
|
quick_app
|
A command injection vulerability found in quick game engine allows arbitrary remote code in quick app. Allows remote attacke0rs to gain arbitrary code execution in quick game engine
|
CWE-77
Command Injection
|
CVE-2021-23247
|
2024-11-21 14:51 |
2022-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196532
|
7.2 |
HIGH
Network
|
bosch
|
autodome_ip_4000i_firmware autodome_ip_5000i_firmware autodome_ip_starlight_5000i_firmware autodome_ip_starlight_7000i_firmware dinion_ip_3000i_firmware dinion_ip_bullet_4000i_firmware…
|
A specially crafted TCP/IP packet may cause the camera recovery image web interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only…
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-23851
|
2024-11-21 14:51 |
2022-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196533
|
7.2 |
HIGH
Network
|
bosch
|
autodome_ip_4000i_firmware autodome_ip_5000i_firmware autodome_ip_starlight_5000i_firmware autodome_ip_starlight_7000i_firmware dinion_ip_3000i_firmware dinion_ip_bullet_4000i_firmware…
|
A specially crafted TCP/IP packet may cause a camera recovery image telnet interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can onl…
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-23850
|
2024-11-21 14:51 |
2022-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196534
|
4.8 |
MEDIUM
Network
|
ampforwp
|
accelerated_mobile_pages
|
Multiple Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) vulnerabilities discovered in AMP for WP – Accelerated Mobile Pages WordPress plugin (versions <= 1.0.77.32).
|
-
|
CVE-2021-23209
|
2024-11-21 14:51 |
2022-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196535
|
4.8 |
MEDIUM
Network
|
ampforwp
|
accelerated_mobile_pages
|
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in AMP for WP – Accelerated Mobile Pages plugin <= 1.0.77.31 versions.
|
-
|
CVE-2021-23150
|
2024-11-21 14:51 |
2022-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196536
|
6.5 |
MEDIUM
Network
|
argencoders-notevil_project notevil_project
|
argencoders-notevil notevil
|
This affects all versions of package notevil; all versions of package argencoders-notevil. It is vulnerable to Sandbox Escape leading to Prototype pollution. The package fails to restrict access to t…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-23771
|
2024-11-21 14:51 |
2022-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196537
|
9.8 |
CRITICAL
Network
|
git_project
|
git
|
All versions of package git are vulnerable to Remote Code Execution (RCE) due to missing sanitization in the Git.git method, which allows execution of OS commands rather than just git commands. Steps…
|
CWE-78
OS Command
|
CVE-2021-23632
|
2024-11-21 14:51 |
2022-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196538
|
8.0 |
HIGH
Network
|
guake-project
|
guake
|
The package guake before 3.8.5 are vulnerable to Exposed Dangerous Method or Function due to the exposure of execute_command and execute_command_by_uuid methods via the d-bus interface, which makes i…
|
NVD-CWE-Other
|
CVE-2021-23556
|
2024-11-21 14:51 |
2022-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196539
|
6.1 |
MEDIUM
Network
|
paypal fedoraproject
|
braintree\/sanitize-url fedora
|
The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.
|
CWE-79
Cross-site Scripting
|
CVE-2021-23648
|
2024-11-21 14:51 |
2022-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196540
|
9.8 |
CRITICAL
Network
|
htmldoc_project
|
htmldoc
|
A flaw was found in htmldoc before v1.9.12. Heap buffer overflow in pspdf_prepare_outpages(), in ps-pdf.cxx may lead to execute arbitrary code and denial of service.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-23165
|
2024-11-21 14:51 |
2022-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|