|
195201
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of messages showed to users that could lead to xss issues.
|
CWE-79
Cross-site Scripting
|
CVE-2021-23129
|
2024-11-21 14:51 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195202
|
9.1 |
CRITICAL
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 3.2.0 through 3.9.24. The core shipped but unused randval implementation within FOF (FOFEncryptRandval) used an potential insecure implemetation. That has now been …
|
NVD-CWE-noinfo
|
CVE-2021-23128
|
2024-11-21 14:51 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195203
|
9.1 |
CRITICAL
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of an insufficient length for the 2FA secret accoring to RFC 4226 of 10 bytes vs 20 bytes.
|
NVD-CWE-noinfo
|
CVE-2021-23127
|
2024-11-21 14:51 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195204
|
5.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of the insecure rand() function within the process of generating the 2FA secret.
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2021-23126
|
2024-11-21 14:51 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195205
|
5.3 |
MEDIUM
Network
|
html-parse-stringify_project
|
html-parse-stringify
|
This affects the package html-parse-stringify before 2.0.1; all versions of package html-parse-stringify2. Sending certain input could cause one of the regular expressions that is used for parsing to…
|
NVD-CWE-Other
|
CVE-2021-23346
|
2024-11-21 14:51 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195206
|
9.8 |
CRITICAL
Network
|
totaljs
|
total.js
|
The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set.
|
CWE-94
Code Injection
|
CVE-2021-23344
|
2024-11-21 14:51 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195207
|
4.8 |
MEDIUM
Network
|
argoproj
|
argo_cd
|
The package github.com/argoproj/argo-cd/cmd before 1.7.13, from 1.8.0 and before 1.8.6 are vulnerable to Cross-site Scripting (XSS) the SSO provider connected to Argo CD would have to send back a mal…
|
CWE-79
Cross-site Scripting
|
CVE-2021-23347
|
2024-11-21 14:51 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195208
|
5.3 |
MEDIUM
Network
|
thecodingmachine
|
gotenberg
|
All versions of package github.com/thecodingmachine/gotenberg are vulnerable to Server-side Request Forgery (SSRF) via the /convert/html endpoint when the src attribute of an HTML element refers to a…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-23345
|
2024-11-21 14:51 |
2021-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195209
|
5.5 |
MEDIUM
Local
|
keybase
|
keybase
|
Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps d…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2021-23827
|
2024-11-21 14:51 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195210
|
6.1 |
MEDIUM
Network
|
docsifyjs
|
docsify
|
This affects the package docsify before 4.12.0. It is possible to bypass the remediation done by CVE-2020-7680 and execute malicious JavaScript through the following methods 1) When parsing HTML from…
|
CWE-79
Cross-site Scripting
|
CVE-2021-23342
|
2024-11-21 14:51 |
2021-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|