|
194961
|
7.8 |
HIGH
Local
|
we-con
|
levistudiou
|
WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute code.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-23157
|
2024-11-21 14:51 |
2022-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194962
|
7.8 |
HIGH
Local
|
we-con
|
levistudiou
|
WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute code.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-23138
|
2024-11-21 14:51 |
2022-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194963
|
8.8 |
HIGH
Network
|
php_everywhere_project
|
php_everywhere
|
Cross-Site Request Forgery (CSRF) vulnerability in Alexander Fuchs PHP Everywhere plugin <= 2.0.2 versions.
|
-
|
CVE-2021-23227
|
2024-11-21 14:51 |
2022-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194964
|
6.1 |
MEDIUM
Network
|
crowcpp
|
crow
|
This affects the package Crow before 0.3+4. When using attributes without quotes in the template, an attacker can manipulate the input to introduce additional attributes, potentially executing code. …
|
CWE-79
Cross-site Scripting
|
CVE-2021-23824
|
2024-11-21 14:51 |
2022-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194965
|
7.5 |
HIGH
Network
|
crowcpp
|
crow
|
This affects the package Crow before 0.3+4. It is possible to traverse directories to fetch arbitrary files from the server.
|
CWE-22
Path Traversal
|
CVE-2021-23514
|
2024-11-21 14:51 |
2022-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194966
|
7.5 |
HIGH
Network
|
mirantis
|
mirantis_container_runtime
|
When running with FIPS mode enabled, Mirantis Container Runtime 20.10.8 leaks memory during TLS Handshakes which could be abused to cause a denial of service.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2021-23218
|
2024-11-21 14:51 |
2022-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194967
|
7.8 |
HIGH
Local
|
mirantis
|
lens
|
In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided arguments which are then executed in the user's shell. Arguments can be provided wh…
|
CWE-78
OS Command
|
CVE-2021-23154
|
2024-11-21 14:51 |
2022-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194968
|
10.0 |
CRITICAL
Network
|
agoric
|
realms-shim
|
All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-23594
|
2024-11-21 14:51 |
2022-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194969
|
9.8 |
CRITICAL
Network
|
eggjs
|
extend2
|
The package extend2 before 1.0.1 are vulnerable to Prototype Pollution via the extend function due to unsafe recursive merge.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-23568
|
2024-11-21 14:51 |
2022-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194970
|
9.8 |
CRITICAL
Network
|
agoric
|
realms-shim
|
All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-23543
|
2024-11-21 14:51 |
2022-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|