|
194991
|
10.0 |
CRITICAL
Network
|
vm2_project
|
vm2
|
This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitrary code on the host machine.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-23449
|
2024-11-21 14:51 |
2021-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194992
|
9.8 |
CRITICAL
Network
|
glasswire
|
glasswire
|
A code injection vulnerability exists within the firewall software of GlassWire v2.1.167 that could lead to arbitrary code execution from a file in the user path on first execution.
|
CWE-94
Code Injection
|
CVE-2021-22961
|
2024-11-21 14:51 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194993
|
6.1 |
MEDIUM
Network
|
fastify
|
fastify-static
|
A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbitrary websites via a double slash // followed by a domain: http://localhost:3000…
|
CWE-601
Open Redirect
|
CVE-2021-22963
|
2024-11-21 14:51 |
2021-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194994
|
8.8 |
HIGH
Network
|
fastify
|
fastify-static
|
A redirect vulnerability in the `fastify-static` module version >= 4.2.4 and < 4.4.1 allows remote attackers to redirect Mozilla Firefox users to arbitrary websites via a double slash `//` followed b…
|
CWE-601
Open Redirect
|
CVE-2021-22964
|
2024-11-21 14:51 |
2021-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194995
|
9.8 |
CRITICAL
Network
|
config-handler_project
|
config-handler
|
All versions of package config-handler are vulnerable to Prototype Pollution when loading config files.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-23448
|
2024-11-21 14:51 |
2021-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194996
|
6.1 |
MEDIUM
Network
|
teddy_project
|
teddy
|
This affects the package teddy before 0.5.9. A type confusion vulnerability can be used to bypass input sanitization when the model content is an array (instead of a string).
|
CWE-843
Type Confusion
|
CVE-2021-23447
|
2024-11-21 14:51 |
2021-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194997
|
9.8 |
CRITICAL
Network
|
concretecms
|
concrete_cms
|
A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the limitations in place for localhost allowing interaction wit…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-22958
|
2024-11-21 14:51 |
2021-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194998
|
6.1 |
MEDIUM
Network
|
bosch
|
rexroth_indramotion_mlc_l20_firmware rexroth_indramotion_mlc_l40_firmware
|
The web server is vulnerable to reflected XSS and therefore an attacker might be able to execute scripts on a client’s computer by sending the client a manipulated URL.
|
CWE-79
Cross-site Scripting
|
CVE-2021-23856
|
2024-11-21 14:51 |
2021-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194999
|
7.5 |
HIGH
Network
|
bosch
|
rexroth_indramotion_xlc_firmware rexroth_indramotion_mlc_firmware
|
The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a weak hashing algorithm and therefore allow an attacker to determine the password by using…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2021-23855
|
2024-11-21 14:51 |
2021-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195000
|
7.5 |
HIGH
Network
|
bosch
|
rexroth_indramotion_mlc_l20_firmware rexroth_indramotion_mlc_l40_firmware rexroth_indramotion_mlc_l25_firmware rexroth_indramotion_mlc_l45_firmware rexroth_indramotion_mlc_l65_firmware
|
Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-23858
|
2024-11-21 14:51 |
2021-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|