|
195011
|
9.8 |
CRITICAL
Network
|
client
|
jointjs
|
This affects the package jointjs before 3.4.2. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 when the user-provided keys used in the path parameter are arrays in the setByPath…
|
CWE-843
Type Confusion
|
CVE-2021-23444
|
2024-11-21 14:51 |
2021-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195012
|
6.1 |
MEDIUM
Network
|
adonisjs
|
edge
|
This affects the package edge.js before 5.3.2. A type confusion vulnerability can be used to bypass input sanitization when the input to be rendered is an array (instead of a string or a SafeValue), …
|
CWE-843
Type Confusion
|
CVE-2021-23443
|
2024-11-21 14:51 |
2021-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195013
|
9.8 |
CRITICAL
Network
|
cookiex-deep_project
|
cookiex-deep
|
This affects all versions of package @cookiex/deep. The global proto object can be polluted using the __proto__ object.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-23442
|
2024-11-21 14:51 |
2021-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195014
|
8.8 |
HIGH
Network
|
f5
|
big-ip_application_security_manager big-ip_advanced_web_application_firewall
|
On version 16.0.x before 16.0.1.2, insufficient permission checks may allow authenticated users with guest privileges to perform Server-Side Request Forgery (SSRF) attacks through F5 Advanced Web App…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-23029
|
2024-11-21 14:51 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195015
|
6.1 |
MEDIUM
Network
|
f5
|
big-ip_application_security_manager big-ip_advanced_web_application_firewall big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_ddos_hybrid_defender big-ip_applicatio…
|
On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, and 14.1.x before 14.1.4.3, a DOM based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration u…
|
CWE-79
Cross-site Scripting
|
CVE-2021-23027
|
2024-11-21 14:51 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195016
|
8.8 |
HIGH
Network
|
f5
|
big-iq_centralized_management big-ip_access_policy_manager big-ip_application_security_manager big-ip_advanced_web_application_firewall big-ip_advanced_firewall_manager big-ip_analytic…
|
BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x and all versions of BIG-IQ 8.x, 7.x, and 6.x are vul…
|
CWE-352
Origin Validation Error
|
CVE-2021-23026
|
2024-11-21 14:51 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195017
|
7.5 |
HIGH
Network
|
f5
|
big-ip_application_security_manager big-ip_advanced_web_application_firewall
|
On BIG-IP Advanced WAF and BIG-IP ASM version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all versions of 12.1.x, when a WebSocket profile is c…
|
CWE-20
Improper Input Validation
|
CVE-2021-23030
|
2024-11-21 14:51 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195018
|
7.5 |
HIGH
Network
|
f5
|
big-ip_application_security_manager big-ip_advanced_web_application_firewall
|
On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, and 13.1.x before 13.1.4, when JSON content profiles are configured for URLs as part of an F5 Advanced Web Applicati…
|
CWE-20
Improper Input Validation
|
CVE-2021-23028
|
2024-11-21 14:51 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195019
|
8.8 |
HIGH
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system …
|
On version 15.1.x before 15.1.0.5, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all versions of 12.1.x and 11.6.x, an authenticated remote command execution vulnerability exists in the BIG-IP …
|
CWE-78
OS Command
|
CVE-2021-23025
|
2024-11-21 14:51 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195020
|
7.5 |
HIGH
Network
|
f5
|
big-ip_advanced_web_application_firewall big-ip_application_security_manager big-ip_datasafe
|
On version 16.0.x before 16.0.1.2, when a BIG-IP ASM and DataSafe profile are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Not…
|
CWE-20
Improper Input Validation
|
CVE-2021-23036
|
2024-11-21 14:51 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|