|
195391
|
7.8 |
HIGH
Local
|
microsoft
|
excel office_web_apps office_online_server office 365_apps
|
Microsoft Excel Remote Code Execution Vulnerability
|
CWE-416
Use After Free
|
CVE-2021-24067
|
2024-11-21 14:52 |
2021-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195392
|
8.8 |
HIGH
Network
|
microsoft
|
sharepoint_foundation sharepoint_enterprise_server sharepoint_server
|
Microsoft SharePoint Remote Code Execution Vulnerability
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-24066
|
2024-11-21 14:52 |
2021-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195393
|
9.8 |
CRITICAL
Network
|
botan_project
|
botan
|
In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, base58, base64, and hex).
|
NVD-CWE-noinfo
|
CVE-2021-24115
|
2024-11-21 14:52 |
2021-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195394
|
8.8 |
HIGH
Network
|
mcafee
|
web_gateway
|
Privilege escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.8 allows an authenticated user to gain elevated privileges through the User Interface and execute commands on the appliance…
|
NVD-CWE-Other
|
CVE-2021-23885
|
2024-11-21 14:52 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195395
|
9.1 |
CRITICAL
Network
|
apache netapp
|
nutch snap_creator_framework
|
An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web se…
|
CWE-611
XXE
|
CVE-2021-23901
|
2024-11-21 14:52 |
2021-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195396
|
9.1 |
CRITICAL
Network
|
apache netapp debian oracle
|
xmlbeans snap_creator_framework snapmanager oncommand_unified_manager_core_package debian_linux peoplesoft_enterprise_peopletools middleware_common_libraries_and_tools
|
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion att…
|
CWE-776
XML Entity Expansion
|
CVE-2021-23926
|
2024-11-21 14:52 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195397
|
5.9 |
MEDIUM
Network
|
apache debian oracle
|
tomcat debian_linux agile_plm
|
When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to …
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2021-24122
|
2024-11-21 14:52 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195398
|
7.5 |
HIGH
Network
|
owasp
|
json-sanitizer
|
OWASP json-sanitizer before 1.2.2 can output invalid JSON or throw an undeclared exception for crafted input. This may lead to denial of service if the application is not prepared to handle these sit…
|
NVD-CWE-noinfo
|
CVE-2021-23900
|
2024-11-21 14:52 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195399
|
9.8 |
CRITICAL
Network
|
owasp
|
json-sanitizer
|
OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input. This allows an attacker to inject arbitrary HTML or XML into embedding documents.
|
CWE-611
XXE
|
CVE-2021-23899
|
2024-11-21 14:52 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195400
|
6.1 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite through 7.10.4 allows XSS via the subject of a task.
|
CWE-79
Cross-site Scripting
|
CVE-2021-23936
|
2024-11-21 14:52 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|