|
195911
|
5.4 |
MEDIUM
Network
|
textpattern
|
textpattern
|
A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attackers to execute arbitrary code via a crafted payload entered …
|
CWE-79
Cross-site Scripting
|
CVE-2021-28002
|
2024-11-21 14:58 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195912
|
5.4 |
MEDIUM
Network
|
textpattern
|
textpattern
|
A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to execute arbitrary code via a crafted payload entered into the U…
|
CWE-79
Cross-site Scripting
|
CVE-2021-28001
|
2024-11-21 14:58 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195913
|
4.8 |
MEDIUM
Network
|
local_services_search_engine_management_system_project
|
local_services_search_engine_management_system
|
A persistent cross-site scripting vulnerability was discovered in Local Services Search Engine Management System Project 1.0 which allows remote attackers to execute arbitrary code via crafted payloa…
|
CWE-79
Cross-site Scripting
|
CVE-2021-28000
|
2024-11-21 14:58 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195914
|
4.9 |
MEDIUM
Network
|
local_services_search_engine_management_system_project
|
local_services_search_engine_management_system
|
A SQL injection vulnerability was discovered in the editid parameter in Local Services Search Engine Management System Project 1.0. This vulnerability gives admin users the ability to dump all data f…
|
CWE-89
SQL Injection
|
CVE-2021-27999
|
2024-11-21 14:58 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195915
|
4.8 |
MEDIUM
Network
|
phpgurukul
|
vehicle_parking_management_system
|
A persistent cross site scripting (XSS) vulnerability in the Add Categories module of Vehicle Parking Management System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted pay…
|
CWE-79
Cross-site Scripting
|
CVE-2021-27822
|
2024-11-21 14:58 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195916
|
7.5 |
HIGH
Network
|
hcc-embedded
|
nichestack
|
The web server in InterNiche NicheStack through 4.0.1 allows remote attackers to cause a denial of service (infinite loop and networking outage) via an unexpected valid HTTP request such as OPTIONS. …
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2021-27565
|
2024-11-21 14:58 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195917
|
9.1 |
CRITICAL
Network
|
hcltechsw
|
hcl_commerce
|
" Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"
|
CWE-611
XXE
|
CVE-2021-27741
|
2024-11-21 14:58 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195918
|
7.8 |
HIGH
Local
|
broadcom
|
fabric_operating_system
|
A vulnerability in the authentication mechanism of Brocade Fabric OS versions before Brocade Fabric OS v.9.0.1a, v8.2.3a and v7.4.2h could allow a user to Login with empty password, and invalid passw…
|
CWE-287
Improper Authentication
|
CVE-2021-27794
|
2024-11-21 14:58 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195919
|
5.3 |
MEDIUM
Network
|
broadcom
|
fabric_operating_system
|
ntermittent authorization failure in aaa tacacs+ with Brocade Fabric OS versions before Brocade Fabric OS v9.0.1b and after 9.0.0, also in Brocade Fabric OS before Brocade Fabric OS v8.2.3a and after…
|
CWE-863
Incorrect Authorization
|
CVE-2021-27793
|
2024-11-21 14:58 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195920
|
7.8 |
HIGH
Local
|
broadcom
|
fabric_operating_system
|
The request handling functions in web management interface of Brocade Fabric OS versions before v9.0.1a, v8.2.3a, and v7.4.2h do not properly handle malformed user input, resulting in a service crash…
|
NVD-CWE-noinfo
|
CVE-2021-27792
|
2024-11-21 14:58 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|