|
195141
|
5.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_modules leak names of unpublished and/or inaccessible modules.
|
CWE-862
Missing Authorization
|
CVE-2021-23123
|
2024-11-21 14:51 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195142
|
7.8 |
HIGH
Local
|
sudo_project netapp fedoraproject
|
sudo solidfire hci_management_node fedora
|
selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary …
|
CWE-59
Link Following
|
CVE-2021-23240
|
2024-11-21 14:51 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195143
|
2.5 |
LOW
Local
|
sudo_project netapp fedoraproject debian
|
sudo cloud_backup solidfire hci_management_node fedora debian_linux
|
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled…
|
CWE-59
Link Following
|
CVE-2021-23239
|
2024-11-21 14:51 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195144
|
5.3 |
MEDIUM
Network
|
opera
|
opera_mini
|
Opera Mini for Android below 53.1 displays URL left-aligned in the address field. This allows a malicious attacker to craft a URL with a long domain name, e.g. www.safe.opera.com.attacker.com. With t…
|
NVD-CWE-Other
|
CVE-2021-23253
|
2024-11-21 14:51 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195145
|
5.3 |
MEDIUM
Network
|
mercusys
|
mercury_x18g_firmware
|
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpd.json URI.
|
CWE-22
Path Traversal
|
CVE-2021-23242
|
2024-11-21 14:51 |
2021-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195146
|
5.3 |
MEDIUM
Network
|
mercusys
|
mercury_x18g_firmware
|
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication bypass) to the web server, as demonstrated by the /loginLess…
|
CWE-22
Path Traversal
|
CVE-2021-23241
|
2024-11-21 14:51 |
2021-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195147
|
- |
|
-
|
-
|
A potential vulnerability has been identified for OpenText Operations Bridge Reporter. The vulnerability could be exploited to inject malicious SQL queries. An attack requires to be an authenticate…
|
-
|
CVE-2021-22508
|
2024-11-21 14:50 |
2024-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195148
|
7.8 |
HIGH
Local
|
ti
|
real-time_operating_system simplelink_cc26xx_software_development_kit simplelink_cc13xx_software_development_kit simplelink_cc32xx_software_development_kit simplelink_msp432e411y simpl…
|
Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulne…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2021-22636
|
2024-11-21 14:50 |
2023-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195149
|
7.5 |
HIGH
Network
|
schneider-electric
|
modicon_m340_bmxp341000_firmware modicon_m340_bmxp342000_firmware modicon_m340_bmxp342010_firmware modicon_m340_bmxp3420102_firmware modicon_m340_bmxp342020_firmware modicon_m340_bmxp3…
|
A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information stored on the memory of the controller when communicating over the Modbus TCP protocol. Aff…
|
-
|
CVE-2021-22786
|
2024-11-21 14:50 |
2023-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195150
|
7.5 |
HIGH
Network
|
cassianetworks
|
access_controller
|
An attacker may be able to use minify route with a relative path to view any file on the Cassia Networks Access Controller prior to 2.0.1.
|
CWE-22
Path Traversal
|
CVE-2021-22685
|
2024-11-21 14:50 |
2022-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|