|
195611
|
8.8 |
HIGH
Network
|
jquery-bbq_project
|
jquery-bbq
|
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-bbq 1.2.1 allows a malicious user to inject properties into Object.prototype.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-20086
|
2024-11-21 14:45 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195612
|
8.8 |
HIGH
Network
|
backbone-query-parameters_project
|
backbone-query-parameters
|
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in backbone-query-parameters 0.4.0 allows a malicious user to inject properties into Object.prototype.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-20085
|
2024-11-21 14:45 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195613
|
8.8 |
HIGH
Network
|
jquery-plugin-query-object_project
|
jquery-plugin-query-object
|
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object 2.2.3 allows a malicious user to inject properties into Object.prototype.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-20083
|
2024-11-21 14:45 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195614
|
8.8 |
HIGH
Network
|
mootools
|
mootools-more
|
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in mootools-more 1.6.0 allows a malicious user to inject properties into Object.prototype.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-20088
|
2024-11-21 14:45 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195615
|
8.8 |
HIGH
Network
|
acemetrix
|
jquery-deparam
|
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-deparam 0.5.1 allows a malicious user to inject properties into Object.prototype.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-20087
|
2024-11-21 14:45 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195616
|
8.8 |
HIGH
Network
|
jquery-sparkle_project
|
jquery-sparkle
|
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-sparkle 1.5.2-beta allows a malicious user to inject properties into Object.prototype.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-20084
|
2024-11-21 14:45 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195617
|
4.9 |
MEDIUM
Network
|
sonicwall
|
email_security hosted_email_security
|
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
|
CWE-22
Path Traversal
|
CVE-2021-20023
|
2024-11-21 14:45 |
2021-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195618
|
9.8 |
CRITICAL
Network
|
sonicwall
|
global_management_system
|
A command execution vulnerability in SonicWall GMS 9.3 allows a remote unauthenticated attacker to locally escalate privilege to root.
|
CWE-287
Improper Authentication
|
CVE-2021-20020
|
2024-11-21 14:45 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195619
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_servicedesk_plus
|
Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a remote, unauthenticated attacker to conduct persiste…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20080
|
2024-11-21 14:45 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195620
|
7.2 |
HIGH
Network
|
sonicwall
|
email_security hosted_email_security
|
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-20022
|
2024-11-21 14:45 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|