|
195071
|
6.1 |
MEDIUM
Network
|
videojs fedoraproject
|
video.js fedora
|
This affects the package video.js before 7.14.3. The src attribute of track tag allows to bypass HTML escaping and execute arbitrary code.
|
CWE-79
Cross-site Scripting
|
CVE-2021-23414
|
2024-11-21 14:51 |
2021-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195072
|
5.3 |
MEDIUM
Network
|
jszip_project
|
jszip
|
This affects the package jszip before 3.7.0. Crafting a new zip file with filenames set to Object prototype values (e.g __proto__, toString, etc) results in a returned object with a modified prototyp…
|
NVD-CWE-noinfo
|
CVE-2021-23413
|
2024-11-21 14:51 |
2021-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195073
|
9.8 |
CRITICAL
Network
|
gitlogplus_project
|
gitlogplus
|
All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes are appended to the command to be executed without sanitization.
|
CWE-78
OS Command
|
CVE-2021-23412
|
2024-11-21 14:51 |
2021-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195074
|
4.3 |
MEDIUM
Network
|
graphhopper
|
graphhopper
|
This affects the package com.graphhopper:graphhopper-web-bundle before 3.2, from 4.0-pre1 and before 4.0. The URL parser could be tricked into adding or modifying properties of Object.prototype using…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-23408
|
2024-11-21 14:51 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195075
|
6.1 |
MEDIUM
Network
|
anchorme_project
|
anchorme
|
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the main functionality. It accepts input that can result in the output (an anchor a tag) containing undesirable Java…
|
CWE-79
Cross-site Scripting
|
CVE-2021-23411
|
2024-11-21 14:51 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195076
|
7.5 |
HIGH
Network
|
go-proxyproto_project
|
go-proxyproto
|
The package github.com/pires/go-proxyproto before 0.6.0 are vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header.
|
NVD-CWE-noinfo
|
CVE-2021-23409
|
2024-11-21 14:51 |
2021-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195077
|
7.5 |
HIGH
Network
|
elfinder.net.core_project
|
elfinder.net.core
|
This affects the package elFinder.Net.Core from 0 and before 1.2.4. The user-controlled file name is not properly sanitized before it is used to create a file system path.
|
CWE-22
Path Traversal
|
CVE-2021-23407
|
2024-11-21 14:51 |
2021-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195078
|
9.8 |
CRITICAL
Network
|
totaljs
|
total4
|
The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
|
CWE-94
Code Injection
|
CVE-2021-23390
|
2024-11-21 14:51 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195079
|
9.8 |
CRITICAL
Network
|
totaljs
|
total.js
|
The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
|
CWE-94
Code Injection
|
CVE-2021-23389
|
2024-11-21 14:51 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195080
|
8.8 |
HIGH
Network
|
pimcore
|
pimcore
|
This affects the package pimcore/pimcore before 10.0.7. This issue exists due to the absence of check on the storeId parameter in the method collectionsActionGet and groupsActionGet method within the…
|
CWE-89
SQL Injection
|
CVE-2021-23405
|
2024-11-21 14:51 |
2021-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|