|
195091
|
9.8 |
CRITICAL
Network
|
set-deep-prop_project
|
set-deep-prop
|
All versions of package set-deep-prop are vulnerable to Prototype Pollution via the main functionality.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-23373
|
2024-11-21 14:51 |
2022-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195092
|
8.8 |
HIGH
Network
|
jfrog
|
artifactory
|
JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versio…
|
CWE-352
Origin Validation Error
|
CVE-2021-23163
|
2024-11-21 14:51 |
2022-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195093
|
8.8 |
HIGH
Network
|
craftercms
|
crafter_cms
|
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker static methods.
|
CWE-913
Improper Control of Dynamically-Managed Code Resources
|
CVE-2021-23267
|
2024-11-21 14:51 |
2022-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195094
|
4.3 |
MEDIUM
Network
|
craftercms
|
crafter_cms
|
An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2021-23266
|
2024-11-21 14:51 |
2022-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195095
|
4.3 |
MEDIUM
Network
|
craftercms
|
crafter_cms
|
A logged-in and authenticated user with a Reviewer Role may lock a content item.
|
NVD-CWE-noinfo
|
CVE-2021-23265
|
2024-11-21 14:51 |
2022-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195096
|
9.8 |
CRITICAL
Network
|
twelvemonkeys_project
|
twelvemonkeys
|
The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injection due to an insecurely initialized XML parser for reading XMP Metadata. An atta…
|
CWE-611
XXE
|
CVE-2021-23792
|
2024-11-21 14:51 |
2022-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195097
|
9.8 |
CRITICAL
Network
|
thinkphp
|
thinkphp
|
The package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unserialize method in the Driver class.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-23592
|
2024-11-21 14:51 |
2022-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195098
|
6.5 |
MEDIUM
Network
|
f5
|
nginx_ingress_controller
|
On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not apply to Ingress objects. Note: Software versions whic…
|
NVD-CWE-Other
|
CVE-2021-23055
|
2024-11-21 14:51 |
2022-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195099
|
5.4 |
MEDIUM
Network
|
eaton
|
intelligent_power_protector
|
Eaton Intelligent Power Protector (IPP) prior to version 1.69 is vulnerable to stored Cross Site Scripting. The vulnerability exists due to insufficient validation of user input and improper encoding…
|
CWE-79
Cross-site Scripting
|
CVE-2021-23283
|
2024-11-21 14:51 |
2022-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195100
|
8.0 |
HIGH
Adjacent
|
eaton
|
intelligent_power_manager
|
Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to CSV Formula Injection. This issue affects: Eaton Intelligent Power Ma…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2021-23286
|
2024-11-21 14:51 |
2022-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|