|
196131
|
5.3 |
MEDIUM
Network
|
magento
|
magento
|
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an access control bypass vulnerability in the Login as Customer module. Successful exploitation …
|
NVD-CWE-Other
|
CVE-2021-21020
|
2024-11-21 14:47 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196132
|
9.1 |
CRITICAL
Network
|
magento
|
magento
|
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the Widgets module. Successful exploitation could lead to arbitrary code execut…
|
-
|
CVE-2021-21019
|
2024-11-21 14:47 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196133
|
9.1 |
CRITICAL
Network
|
magento
|
magento
|
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the scheduled operation module. Successful exploitation could lead to a…
|
-
|
CVE-2021-21018
|
2024-11-21 14:47 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196134
|
8.8 |
HIGH
Network
|
adobe
|
acrobat acrobat_dc acrobat_reader acrobat_reader_dc
|
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthen…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-21017
|
2024-11-21 14:47 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196135
|
9.1 |
CRITICAL
Network
|
magento
|
magento
|
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the WebAPI. Successful exploitation could lead to remote code execution…
|
CWE-78
OS Command
|
CVE-2021-21016
|
2024-11-21 14:47 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196136
|
8.0 |
HIGH
Network
|
magento
|
magento
|
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an OS command injection via the customer attribute save controller. Successful exploitation coul…
|
-
|
CVE-2021-21015
|
2024-11-21 14:47 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196137
|
9.8 |
CRITICAL
Network
|
lucee
|
lucee_server
|
Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.96 there is an unaut…
|
-
|
CVE-2021-21307
|
2024-11-21 14:47 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196138
|
4.3 |
MEDIUM
Network
|
wire
|
wire
|
Wire is an open-source collaboration platform. In Wire for iOS (iPhone and iPad) before version 3.75 there is a vulnerability where the video capture isn't stopped in a scenario where a user first ha…
|
-
|
CVE-2021-21301
|
2024-11-21 14:47 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196139
|
8.1 |
HIGH
Network
|
hyper
|
hyper
|
hyper is an open-source HTTP library for Rust (crates.io). In hyper from version 0.12.0 and before versions 0.13.10 and 0.14.3 there is a vulnerability that can enable a request smuggling attack. The…
|
-
|
CVE-2021-21299
|
2024-11-21 14:47 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196140
|
2.7 |
LOW
Network
|
fleetdm
|
fleet
|
Fleet is an open source osquery manager. In Fleet before version 3.7.0 a malicious actor with a valid node key can send a badly formatted request that causes the Fleet server to exit, resulting in de…
|
NVD-CWE-Other
|
CVE-2021-21296
|
2024-11-21 14:47 |
2021-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|