|
195671
|
4.6 |
MEDIUM
Network
|
jenkins
|
active_choices
|
Jenkins Active Choices Plugin 2.5.2 and earlier does not escape reference parameter values, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure …
|
CWE-79
Cross-site Scripting
|
CVE-2021-21616
|
2024-11-21 14:48 |
2021-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195672
|
5.3 |
MEDIUM
Network
|
brave
|
brave
|
Brave is an open source web browser with a focus on privacy and security. In Brave versions 1.17.73-1.20.103, the CNAME adblocking feature added in Brave 1.17.73 accidentally initiated DNS requests t…
|
-
|
CVE-2021-21323
|
2024-11-21 14:48 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195673
|
6.0 |
MEDIUM
Local
|
dell
|
emc_powerprotect_cyber_recovery
|
Dell EMC PowerProtect Cyber Recovery, version 19.7.0.1, contains an Information Disclosure vulnerability. A locally authenticated high privileged Cyber Recovery user may potentially exploit this vuln…
|
CWE-200
Information Exposure
|
CVE-2021-21512
|
2024-11-21 14:48 |
2021-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195674
|
5.4 |
MEDIUM
Network
|
apereo
|
opencast
|
Opencast is a free, open-source platform to support the management of educational audio and video content. In Opencast before version 9.2 there is a vulnerability in which publishing an episode with …
|
-
|
CVE-2021-21318
|
2024-11-21 14:48 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195675
|
5.3 |
MEDIUM
Network
|
uap-core_project
|
uap-core
|
uap-core in an open-source npm package which contains the core of BrowserScope's original user agent string parser. In uap-core before version 0.11.0, some regexes are vulnerable to regular expressio…
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2021-21317
|
2024-11-21 14:48 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195676
|
7.8 |
HIGH
Local
|
less-openui5_project
|
less-openui5
|
less-openui5 is an npm package which enables building OpenUI5 themes with Less.js. In less-openui5 before version 0.10., when processing theming resources (i.e. `*.less` files) with less-openui5 that…
|
-
|
CVE-2021-21316
|
2024-11-21 14:48 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195677
|
7.8 |
HIGH
Local
|
systeminformation apache
|
systeminformation cordova
|
The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation b…
|
CWE-78
OS Command
|
CVE-2021-21315
|
2024-11-21 14:48 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195678
|
8.1 |
HIGH
Network
|
dell
|
emc_avamar_server emc_integrated_data_protection_appliance
|
Dell EMC Avamar Server, versions 19.3 and 19.4 contain an Improper Authorization vulnerability in the web UI. A remote low privileged attacker could potentially exploit this vulnerability, to gain un…
|
NVD-CWE-Other
|
CVE-2021-21511
|
2024-11-21 14:48 |
2021-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195679
|
7.5 |
HIGH
Network
|
php debian netapp oracle
|
php debian_linux clustered_data_ontap communications_diameter_signaling_router
|
In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP server could return malformed XML data as a respo…
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-21702
|
2024-11-21 14:48 |
2021-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195680
|
9.8 |
CRITICAL
Network
|
dell
|
emc_powerscale_onefs
|
Dell PowerScale OneFS versions 8.1.0 – 9.1.0 contain a "use of SSH key past account expiration" vulnerability. A user on the network with the ISI_PRIV_AUTH_SSH RBAC privilege that has an expired acco…
|
CWE-287
Improper Authentication
|
CVE-2021-21502
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|