|
195511
|
7.5 |
HIGH
Network
|
buffalo
|
wsr-2533dhpl2-bk_firmware wsr-2533dhp3-bk_firmware
|
The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict access to sensitive information from an unauthorized actor.
|
CWE-287
Improper Authentication
|
CVE-2021-20092
|
2024-11-21 14:45 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195512
|
8.8 |
HIGH
Network
|
buffalo
|
wsr-2533dhpl2-bk_firmware wsr-2533dhp3-bk_firmware
|
The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly sanitize user input. An authenticated remote attacker could leverage thi…
|
NVD-CWE-noinfo
|
CVE-2021-20091
|
2024-11-21 14:45 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195513
|
9.8 |
CRITICAL
Network
|
buffalo
|
wsr-2533dhpl2-bk_firmware wsr-2533dhp3-bk_firmware
|
A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass…
|
CWE-22
Path Traversal
|
CVE-2021-20090
|
2024-11-21 14:45 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195514
|
8.8 |
HIGH
Network
|
purl_project
|
purl
|
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in purl 2.3.2 allows a malicious user to inject properties into Object.prototype.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-20089
|
2024-11-21 14:45 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195515
|
8.8 |
HIGH
Network
|
jquery-bbq_project
|
jquery-bbq
|
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-bbq 1.2.1 allows a malicious user to inject properties into Object.prototype.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-20086
|
2024-11-21 14:45 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195516
|
8.8 |
HIGH
Network
|
backbone-query-parameters_project
|
backbone-query-parameters
|
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in backbone-query-parameters 0.4.0 allows a malicious user to inject properties into Object.prototype.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-20085
|
2024-11-21 14:45 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195517
|
8.8 |
HIGH
Network
|
jquery-plugin-query-object_project
|
jquery-plugin-query-object
|
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object 2.2.3 allows a malicious user to inject properties into Object.prototype.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-20083
|
2024-11-21 14:45 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195518
|
8.8 |
HIGH
Network
|
mootools
|
mootools-more
|
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in mootools-more 1.6.0 allows a malicious user to inject properties into Object.prototype.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-20088
|
2024-11-21 14:45 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195519
|
8.8 |
HIGH
Network
|
acemetrix
|
jquery-deparam
|
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-deparam 0.5.1 allows a malicious user to inject properties into Object.prototype.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-20087
|
2024-11-21 14:45 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195520
|
8.8 |
HIGH
Network
|
jquery-sparkle_project
|
jquery-sparkle
|
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-sparkle 1.5.2-beta allows a malicious user to inject properties into Object.prototype.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-20084
|
2024-11-21 14:45 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|