|
195171
|
9.8 |
CRITICAL
Network
|
myscada
|
mypro
|
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
|
-
|
CVE-2021-23198
|
2024-11-21 14:51 |
2021-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195172
|
8.2 |
HIGH
Local
|
nvidia
|
geforce_experience
|
NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply individual user access controls for users on the same device, which, with user inte…
|
CWE-863
Incorrect Authorization
|
CVE-2021-23175
|
2024-11-21 14:51 |
2021-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195173
|
6.1 |
MEDIUM
Network
|
deltaww
|
diaenergie
|
DIAEnergie Version 1.7.5 and prior is vulnerable to a reflected cross-site scripting attack through error pages that are returned by “.NET Request.QueryString”.
|
-
|
CVE-2021-23228
|
2024-11-21 14:51 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195174
|
9.8 |
CRITICAL
Network
|
nette
|
latte
|
This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the security of the application. When the template is set to allow/disallow the use of cer…
|
CWE-863
Incorrect Authorization
|
CVE-2021-23803
|
2024-11-21 14:51 |
2021-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195175
|
9.8 |
CRITICAL
Network
|
http-server-node_project
|
http-server-node
|
All versions of package http-server-node are vulnerable to Directory Traversal via use of --path-as-is.
|
CWE-22
Path Traversal
|
CVE-2021-23797
|
2024-11-21 14:51 |
2021-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195176
|
9.8 |
CRITICAL
Network
|
linuxfoundation oracle debian
|
dojo primavera_unifier weblogic_server communications_policy_management debian_linux
|
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-23450
|
2024-11-21 14:51 |
2021-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195177
|
8.8 |
HIGH
Network
|
unisharp
|
laravel-filemanager
|
This affects the package unisharp/laravel-filemanager from 0.0.0. The upload() function does not sufficiently validate the file type when uploading. An attacker may be able to reproduce the following…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-23814
|
2024-11-21 14:51 |
2021-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195178
|
9.8 |
CRITICAL
Network
|
merge-deep2_project
|
merge-deep2
|
All versions of package merge-deep2 are vulnerable to Prototype Pollution via the mergeDeep() function.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-23700
|
2024-11-21 14:51 |
2021-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195179
|
9.8 |
CRITICAL
Network
|
sey_project
|
sey
|
All versions of package sey are vulnerable to Prototype Pollution via the deepmerge() function.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-23663
|
2024-11-21 14:51 |
2021-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195180
|
9.8 |
CRITICAL
Network
|
markdown_to_pdf_project
|
markdown_to_pdf
|
The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter content, without disabling the JS engine.
|
NVD-CWE-noinfo
|
CVE-2021-23639
|
2024-11-21 14:51 |
2021-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|