|
195491
|
5.4 |
MEDIUM
Network
|
monicahq
|
monica
|
The Contact page in Monica 2.19.1 allows stored XSS via the Middle Name field.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27369
|
2024-11-21 14:57 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195492
|
5.4 |
MEDIUM
Network
|
monicahq
|
monica
|
The Contact page in Monica 2.19.1 allows stored XSS via the First Name field.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27368
|
2024-11-21 14:57 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195493
|
5.3 |
MEDIUM
Network
|
telegram
|
telegram
|
The Terminate Session feature in the Telegram application through 7.2.1 for Android, and through 2.4.7 for Windows and UNIX, fails to invalidate a recently active session.
|
CWE-613
Insufficient Session Expiration
|
CVE-2021-27351
|
2024-11-21 14:57 |
2021-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195494
|
6.5 |
MEDIUM
Network
|
yeastar
|
neogate_tg400_firmware
|
Yeastar NeoGate TG400 91.3.0.3 devices are affected by Directory Traversal. An authenticated user can decrypt firmware and can read sensitive information, such as a password or decryption key.
|
CWE-22
Path Traversal
|
CVE-2021-27328
|
2024-11-21 14:57 |
2021-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195495
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_adselfservice_plus
|
A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP req…
|
CWE-79 CWE-918
Cross-site Scripting Server-Side Request Forgery (SSRF)
|
CVE-2021-27214
|
2024-11-21 14:57 |
2021-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195496
|
7.5 |
HIGH
Network
|
scrapbox-parser_project
|
scrapbox-parser
|
A ReDoS (regular expression denial of service) flaw was found in the @progfay/scrapbox-parser package before 6.0.3 for Node.js.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2021-27405
|
2024-11-21 14:57 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195497
|
6.1 |
MEDIUM
Network
|
asus
|
askey_rtf8115vw_firmware
|
Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow injection of a Host HTTP header.
|
CWE-601
Open Redirect
|
CVE-2021-27404
|
2024-11-21 14:57 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195498
|
6.1 |
MEDIUM
Network
|
asus
|
askey_rtf8115vw_firmware
|
Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow cgi-bin/te_acceso_router.cgi curWebPage XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27403
|
2024-11-21 14:57 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195499
|
5.9 |
MEDIUM
Network
|
digium
|
certified_asterisk asterisk
|
An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.x through 18.2.0, and Certified Asterisk through 1…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2021-26906
|
2024-11-21 14:57 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195500
|
9.8 |
CRITICAL
Network
|
kollectapp
|
kollect
|
KollectApps before 4.8.16c is affected by insecure Java deserialization, leading to Remote Code Execution via a ysoserial.payloads.CommonsCollections parameter.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-27335
|
2024-11-21 14:57 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|