|
195061
|
5.9 |
MEDIUM
Network
|
apache debian oracle
|
tomcat debian_linux agile_plm
|
When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to …
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2021-24122
|
2024-11-21 14:52 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195062
|
7.5 |
HIGH
Network
|
owasp
|
json-sanitizer
|
OWASP json-sanitizer before 1.2.2 can output invalid JSON or throw an undeclared exception for crafted input. This may lead to denial of service if the application is not prepared to handle these sit…
|
NVD-CWE-noinfo
|
CVE-2021-23900
|
2024-11-21 14:52 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195063
|
9.8 |
CRITICAL
Network
|
owasp
|
json-sanitizer
|
OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input. This allows an attacker to inject arbitrary HTML or XML into embedding documents.
|
CWE-611
XXE
|
CVE-2021-23899
|
2024-11-21 14:52 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195064
|
6.1 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite through 7.10.4 allows XSS via the subject of a task.
|
CWE-79
Cross-site Scripting
|
CVE-2021-23936
|
2024-11-21 14:52 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195065
|
6.1 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite through 7.10.4 allows XSS via an appointment in which the location contains JavaScript code.
|
CWE-79
Cross-site Scripting
|
CVE-2021-23935
|
2024-11-21 14:52 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195066
|
6.1 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite through 7.10.4 allows XSS via a contact whose name contains JavaScript code.
|
CWE-79
Cross-site Scripting
|
CVE-2021-23934
|
2024-11-21 14:52 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195067
|
6.1 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite through 7.10.4 allows XSS via JavaScript in a Note referenced by a mail:// URL.
|
CWE-79
Cross-site Scripting
|
CVE-2021-23933
|
2024-11-21 14:52 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195068
|
6.1 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite through 7.10.4 allows XSS via an inline image with a crafted filename.
|
CWE-79
Cross-site Scripting
|
CVE-2021-23932
|
2024-11-21 14:52 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195069
|
6.1 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite through 7.10.4 allows XSS via an inline binary file.
|
CWE-79
Cross-site Scripting
|
CVE-2021-23931
|
2024-11-21 14:52 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195070
|
6.1 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite through 7.10.4 allows XSS via use of the conversion API for a distributedFile.
|
CWE-79
Cross-site Scripting
|
CVE-2021-23930
|
2024-11-21 14:52 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|