|
195141
|
9.8 |
CRITICAL
Network
|
portkiller_project
|
portkiller
|
This affects all versions of package portkiller. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process ex…
|
CWE-78
OS Command
|
CVE-2021-23379
|
2024-11-21 14:51 |
2021-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195142
|
9.8 |
CRITICAL
Network
|
picotts_project
|
picotts
|
This affects all versions of package picotts. If attacker-controlled user input is given to the say function, it is possible for an attacker to execute arbitrary commands. This is due to use of the c…
|
CWE-78
OS Command
|
CVE-2021-23378
|
2024-11-21 14:51 |
2021-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195143
|
9.8 |
CRITICAL
Network
|
onion-oled-js_project
|
onion-oled-js
|
This affects all versions of package onion-oled-js. If attacker-controlled user input is given to the scroll function, it is possible for an attacker to execute arbitrary commands. This is due to use…
|
CWE-78
OS Command
|
CVE-2021-23377
|
2024-11-21 14:51 |
2021-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195144
|
9.8 |
CRITICAL
Network
|
ffmpegdotjs_project
|
ffmpegdotjs
|
This affects all versions of package ffmpegdotjs. If attacker-controlled user input is given to the trimvideo function, it is possible for an attacker to execute arbitrary commands. This is due to us…
|
CWE-78
OS Command
|
CVE-2021-23376
|
2024-11-21 14:51 |
2021-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195145
|
9.8 |
CRITICAL
Network
|
psnode_project
|
psnode
|
This affects all versions of package psnode. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the c…
|
CWE-78
OS Command
|
CVE-2021-23375
|
2024-11-21 14:51 |
2021-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195146
|
9.8 |
CRITICAL
Network
|
ps-visitor_project
|
ps-visitor
|
This affects all versions of package ps-visitor. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of t…
|
CWE-78
OS Command
|
CVE-2021-23374
|
2024-11-21 14:51 |
2021-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195147
|
7.0 |
HIGH
Local
|
linux fedoraproject debian netapp broadcom
|
linux_kernel fedora debian_linux cloud_backup solidfire_\&_hci_management_node brocade_fabric_operating_system h410c_firmware h300s_firmware h500s_firmware h700s_firmwa…
|
A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_des…
|
CWE-362
Race Condition
|
CVE-2021-23133
|
2024-11-21 14:51 |
2021-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195148
|
7.5 |
HIGH
Network
|
mongo-express_project
|
mongo-express
|
All versions of package mongo-express are vulnerable to Denial of Service (DoS) when exporting an empty collection as CSV, due to an unhandled exception, leading to a crash.
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2021-23372
|
2024-11-21 14:51 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195149
|
10.0 |
CRITICAL
Network
|
eaton
|
intelligent_power_manager
|
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated remote code execution vulnerability. IPM software does not sanitize the date provided via coverterCheckList action…
|
CWE-94
Code Injection
|
CVE-2021-23281
|
2024-11-21 14:51 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195150
|
9.9 |
CRITICAL
Network
|
eaton
|
intelligent_power_manager intelligent_power_manager_virtual_appliance intelligent_power_protector
|
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. IPM’s maps_srv.js allows an attacker to upload a malicious NodeJS file using up…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-23280
|
2024-11-21 14:51 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|