|
195091
|
9.8 |
CRITICAL
Network
|
totaljs
|
total.js
|
The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set.
|
CWE-94
Code Injection
|
CVE-2021-23344
|
2024-11-21 14:51 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195092
|
4.8 |
MEDIUM
Network
|
argoproj
|
argo_cd
|
The package github.com/argoproj/argo-cd/cmd before 1.7.13, from 1.8.0 and before 1.8.6 are vulnerable to Cross-site Scripting (XSS) the SSO provider connected to Argo CD would have to send back a mal…
|
CWE-79
Cross-site Scripting
|
CVE-2021-23347
|
2024-11-21 14:51 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195093
|
5.3 |
MEDIUM
Network
|
thecodingmachine
|
gotenberg
|
All versions of package github.com/thecodingmachine/gotenberg are vulnerable to Server-side Request Forgery (SSRF) via the /convert/html endpoint when the src attribute of an HTML element refers to a…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-23345
|
2024-11-21 14:51 |
2021-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195094
|
5.5 |
MEDIUM
Local
|
keybase
|
keybase
|
Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps d…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2021-23827
|
2024-11-21 14:51 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195095
|
6.1 |
MEDIUM
Network
|
docsifyjs
|
docsify
|
This affects the package docsify before 4.12.0. It is possible to bypass the remediation done by CVE-2020-7680 and execute malicious JavaScript through the following methods 1) When parsing HTML from…
|
CWE-79
Cross-site Scripting
|
CVE-2021-23342
|
2024-11-21 14:51 |
2021-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195096
|
7.5 |
HIGH
Network
|
prismjs
|
prism
|
The package prismjs before 1.23.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the prism-asciidoc, prism-rest, prism-tap and prism-eiffel components.
|
NVD-CWE-noinfo
|
CVE-2021-23341
|
2024-11-21 14:51 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195097
|
7.1 |
HIGH
Network
|
pimcore
|
pimcore
|
This affects the package pimcore/pimcore before 6.8.8. A Local FIle Inclusion vulnerability exists in the downloadCsvAction function of the CustomReportController class (bundles/AdminBundle/Controlle…
|
CWE-22
Path Traversal
|
CVE-2021-23340
|
2024-11-21 14:51 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195098
|
6.5 |
MEDIUM
Network
|
lightbend
|
akka-http
|
This affects all versions before 10.1.14 and from 10.2.0 to 10.2.4 of package com.typesafe.akka:akka-http-core. It allows multiple Transfer-Encoding headers.
|
CWE-444
HTTP Request Smuggling
|
CVE-2021-23339
|
2024-11-21 14:51 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195099
|
5.9 |
MEDIUM
Network
|
openssl debian tenable apple netapp oracle siemens
|
openssl debian_linux tenable.sc nessus_network_monitor macos iphone_os safari ipados snapcenter oncommand_workflow_automation oncommand_insight business_intelligence<…
|
The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails …
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-23841
|
2024-11-21 14:51 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195100
|
7.5 |
HIGH
Network
|
openssl debian tenable oracle mcafee fujitsu nodejs
|
openssl debian_linux nessus_network_monitor log_correlation_engine business_intelligence jd_edwards_world_security enterprise_manager_for_storage_management enterprise_manager_op…
|
Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integ…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2021-23840
|
2024-11-21 14:51 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|