|
195191
|
9.8 |
CRITICAL
Network
|
kill-process-by-name_project
|
kill-process-by-name
|
This affects all versions of package kill-process-by-name. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_…
|
CWE-78
OS Command
|
CVE-2021-23356
|
2024-11-21 14:51 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195192
|
9.8 |
CRITICAL
Network
|
ps-kill_project
|
ps-kill
|
This affects all versions of package ps-kill. If (attacker-controlled) user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of th…
|
CWE-78
OS Command
|
CVE-2021-23355
|
2024-11-21 14:51 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195193
|
7.5 |
HIGH
Network
|
adaltas
|
printf
|
The package printf before 0.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex string /\%(?:\(([\w_.]+)\)|([1-9]\d*)\$)?([0 +\-\]*)(\*|\d+)?(\.)?(\*|\d+)?[hlL]?([\%bscde…
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2021-23354
|
2024-11-21 14:51 |
2021-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195194
|
5.4 |
MEDIUM
Network
|
tibco
|
spotfire_server spotfire_desktop spotfire_analyst analytics_platform
|
The Spotfire client component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Desktop, and TIBCO Spotfire Server contains a vuln…
|
CWE-79
Cross-site Scripting
|
CVE-2021-23273
|
2024-11-21 14:51 |
2021-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195195
|
7.5 |
HIGH
Network
|
parall
|
jspdf
|
This affects the package jspdf before 2.3.1. ReDoS is possible via the addImage function.
|
NVD-CWE-noinfo
|
CVE-2021-23353
|
2024-11-21 14:51 |
2021-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195196
|
9.8 |
CRITICAL
Network
|
madge_project
|
madge
|
This affects the package madge before 4.0.1. It is possible to specify a custom Graphviz path via the graphVizPath option parameter which when the .image(), .svg() or .dot() functions are called, is …
|
CWE-89
SQL Injection
|
CVE-2021-23352
|
2024-11-21 14:51 |
2021-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195197
|
4.9 |
MEDIUM
Network
|
go-proxyproto_project fedoraproject
|
go-proxyproto fedora
|
The package github.com/pires/go-proxyproto before 0.5.0 are vulnerable to Denial of Service (DoS) via the parseVersion1() function. The reader in this package is a default bufio.Reader wrapping a net…
|
NVD-CWE-noinfo
|
CVE-2021-23351
|
2024-11-21 14:51 |
2021-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195198
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 3.0.0 through 3.9.24. com_media allowed paths that are not intended for image uploads
|
NVD-CWE-noinfo
|
CVE-2021-23132
|
2024-11-21 14:51 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195199
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Missing input validation within the template manager.
|
CWE-20
Improper Input Validation
|
CVE-2021-23131
|
2024-11-21 14:51 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195200
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of feed fields could lead to xss issues.
|
CWE-79
Cross-site Scripting
|
CVE-2021-23130
|
2024-11-21 14:51 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|