|
195051
|
9.8 |
CRITICAL
Network
|
elfinder.netcore_project
|
elfinder.netcore
|
This affects all versions of package elFinder.NetCore. The ExtractAsync function within the FileSystem is vulnerable to arbitrary extraction due to insufficient validation.
|
CWE-22
Path Traversal
|
CVE-2021-23427
|
2024-11-21 14:51 |
2021-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195052
|
7.5 |
HIGH
Network
|
proto_project
|
proto
|
This affects all versions of package Proto. It is possible to inject pollute the object property of an application using Proto by leveraging the merge function.
|
NVD-CWE-Other
|
CVE-2021-23426
|
2024-11-21 14:51 |
2021-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195053
|
8.6 |
HIGH
Network
|
object-path_project debian
|
object-path debian_linux
|
This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components used in the path parameter are arrays. In particular…
|
CWE-843
Type Confusion
|
CVE-2021-23434
|
2024-11-21 14:51 |
2021-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195054
|
9.8 |
CRITICAL
Network
|
mootools_project
|
mootools
|
This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge()
|
NVD-CWE-noinfo
|
CVE-2021-23432
|
2024-11-21 14:51 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195055
|
8.8 |
HIGH
Network
|
joplinapp
|
joplin
|
The package joplin before 2.3.2 are vulnerable to Cross-site Request Forgery (CSRF) due to missing CSRF checks in various forms.
|
CWE-352
Origin Validation Error
|
CVE-2021-23431
|
2024-11-21 14:51 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195056
|
7.5 |
HIGH
Network
|
startserver_project
|
startserver
|
All versions of package startserver are vulnerable to Directory Traversal due to missing sanitization.
|
CWE-22
Path Traversal
|
CVE-2021-23430
|
2024-11-21 14:51 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195057
|
7.5 |
HIGH
Network
|
transpile_project
|
transpile
|
All versions of package transpile are vulnerable to Denial of Service (DoS) due to a lack of input sanitization or whitelisting, coupled with improper exception handling in the .to() function.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2021-23429
|
2024-11-21 14:51 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195058
|
9.8 |
CRITICAL
Network
|
pac-resolver_project
|
pac-resolver
|
This affects the package pac-resolver before 5.0.0. This can occur when used with untrusted input, due to unsafe PAC file handling. **NOTE:** The fix for this vulnerability is applied in the node-deg…
|
NVD-CWE-noinfo
|
CVE-2021-23406
|
2024-11-21 14:51 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195059
|
5.3 |
MEDIUM
Network
|
trim-off-newlines_project
|
trim-off-newlines
|
All versions of package trim-off-newlines are vulnerable to Regular Expression Denial of Service (ReDoS) via string processing.
|
NVD-CWE-noinfo
|
CVE-2021-23425
|
2024-11-21 14:51 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195060
|
7.5 |
HIGH
Network
|
ansi-html_project
|
ansi-html
|
This affects all versions of package ansi-html. If an attacker provides a malicious string, it will get stuck processing the input for an extremely long time.
|
NVD-CWE-noinfo
|
CVE-2021-23424
|
2024-11-21 14:51 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|