|
195121
|
6.1 |
MEDIUM
Network
|
anchorme_project
|
anchorme
|
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the main functionality. It accepts input that can result in the output (an anchor a tag) containing undesirable Java…
|
CWE-79
Cross-site Scripting
|
CVE-2021-23411
|
2024-11-21 14:51 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195122
|
7.5 |
HIGH
Network
|
go-proxyproto_project
|
go-proxyproto
|
The package github.com/pires/go-proxyproto before 0.6.0 are vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header.
|
NVD-CWE-noinfo
|
CVE-2021-23409
|
2024-11-21 14:51 |
2021-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195123
|
7.5 |
HIGH
Network
|
elfinder.net.core_project
|
elfinder.net.core
|
This affects the package elFinder.Net.Core from 0 and before 1.2.4. The user-controlled file name is not properly sanitized before it is used to create a file system path.
|
CWE-22
Path Traversal
|
CVE-2021-23407
|
2024-11-21 14:51 |
2021-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195124
|
9.8 |
CRITICAL
Network
|
totaljs
|
total4
|
The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
|
CWE-94
Code Injection
|
CVE-2021-23390
|
2024-11-21 14:51 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195125
|
9.8 |
CRITICAL
Network
|
totaljs
|
total.js
|
The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
|
CWE-94
Code Injection
|
CVE-2021-23389
|
2024-11-21 14:51 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195126
|
8.8 |
HIGH
Network
|
pimcore
|
pimcore
|
This affects the package pimcore/pimcore before 10.0.7. This issue exists due to the absence of check on the storeId parameter in the method collectionsActionGet and groupsActionGet method within the…
|
CWE-89
SQL Injection
|
CVE-2021-23405
|
2024-11-21 14:51 |
2021-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195127
|
6.1 |
MEDIUM
Network
|
flask-user_project
|
flask-user
|
This affects all versions of package Flask-User. When using the make_safe_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slas…
|
CWE-601
Open Redirect
|
CVE-2021-23401
|
2024-11-21 14:51 |
2021-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195128
|
9.8 |
CRITICAL
Network
|
ts-nodash_project
|
ts-nodash
|
All versions of package ts-nodash are vulnerable to Prototype Pollution via the Merge() function due to lack of validation input.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-23403
|
2024-11-21 14:51 |
2021-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195129
|
9.8 |
CRITICAL
Network
|
record-like-deep-assign_project
|
record-like-deep-assign
|
All versions of package record-like-deep-assign are vulnerable to Prototype Pollution via the main functionality.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-23402
|
2024-11-21 14:51 |
2021-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195130
|
7.8 |
HIGH
Local
|
tibco
|
spotfire_server spotfire_statistics_services spotfire_analytics_platform enterprise_runtime_for_r
|
The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server E…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2021-23275
|
2024-11-21 14:51 |
2021-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|