|
195571
|
8.2 |
HIGH
Network
|
matrix fedoraproject
|
synapse fedora
|
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.27.0, the p…
|
CWE-79
Cross-site Scripting
|
CVE-2021-21332
|
2024-11-21 14:48 |
2021-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195572
|
9.8 |
CRITICAL
Network
|
kongchuanhujiao_project
|
kongchuanhujiao
|
In github.com/kongchuanhujiao/server before version 1.3.21 there is an authentication Bypass by Primary Weakness vulnerability. All users are impacted. This is fixed in version 1.3.21.
|
CWE-287
Improper Authentication
|
CVE-2021-21403
|
2024-11-21 14:48 |
2021-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195573
|
9.8 |
CRITICAL
Network
|
genivia oracle
|
gsoap communications_lsms communications_diameter_signaling_router tekelec_virtual_operating_environment communications_eagle_lnp_application_processor communications_eagle_application…
|
A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an H…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2021-21783
|
2024-11-21 14:48 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195574
|
9.8 |
CRITICAL
Network
|
apkleaks_project
|
apkleaks
|
APKLeaks is an open-source project for scanning APK file for URIs, endpoints & secrets. APKLeaks prior to v2.0.3 allows remote attackers to execute arbitrary OS commands via package name inside appli…
|
-
|
CVE-2021-21386
|
2024-11-21 14:48 |
2021-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195575
|
7.4 |
HIGH
Network
|
mifos
|
mifos-mobile
|
Mifos-Mobile Android Application for MifosX is an Android Application built on top of the MifosX Self-Service platform. Mifos-Mobile before commit e505f62 disables HTTPS hostname verification of its …
|
-
|
CVE-2021-21385
|
2024-11-21 14:48 |
2021-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195576
|
8.8 |
HIGH
Network
|
xwiki
|
xwiki
|
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of XWiki Platform (and only those with the Ratings API installed), the Ra…
|
CWE-89
SQL Injection
|
CVE-2021-21380
|
2024-11-21 14:48 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195577
|
6.5 |
MEDIUM
Network
|
jellyfin
|
jellyfin
|
Jellyfin is a Free Software Media System. In Jellyfin before version 10.7.1, with certain endpoints, well crafted requests will allow arbitrary file read from a Jellyfin server's file system. This is…
|
-
|
CVE-2021-21402
|
2024-11-21 14:48 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195578
|
7.1 |
HIGH
Network
|
nanopb_project
|
nanopb
|
Nanopb is a small code-size Protocol Buffers implementation in ansi C. In Nanopb before versions 0.3.9.8 and 0.4.5, decoding a specifically formed message can cause invalid `free()` or `realloc()` ca…
|
-
|
CVE-2021-21401
|
2024-11-21 14:48 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195579
|
5.4 |
MEDIUM
Network
|
openmicroscopy
|
omero.web
|
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL after performing login or switching the group contex…
|
-
|
CVE-2021-21377
|
2024-11-21 14:48 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195580
|
6.5 |
MEDIUM
Network
|
openmicroscopy
|
omero.web
|
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the current user such as their id, name and the groups t…
|
-
|
CVE-2021-21376
|
2024-11-21 14:48 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|