|
194891
|
5.4 |
MEDIUM
Network
|
concretecms
|
concrete_cms
|
A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security Research Team"
|
CWE-352
Origin Validation Error
|
CVE-2021-22953
|
2024-11-21 14:51 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194892
|
8.8 |
HIGH
Network
|
ui
|
unifi_talk
|
A vulnerability found in UniFi Talk application V1.12.3 and earlier permits a malicious actor who has already gained access to a network to subsequently control Talk device(s) assigned to said networ…
|
NVD-CWE-noinfo
|
CVE-2021-22952
|
2024-11-21 14:51 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194893
|
6.5 |
MEDIUM
Network
|
concretecms
|
concrete_cms
|
Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be deleted.Credit for discovery: "Solar Security Research Team"
|
CWE-352
Origin Validation Error
|
CVE-2021-22950
|
2024-11-21 14:51 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194894
|
5.4 |
MEDIUM
Network
|
concretecms
|
concrete_cms
|
A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security CMS Researc…
|
CWE-352
Origin Validation Error
|
CVE-2021-22949
|
2024-11-21 14:51 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194895
|
7.1 |
HIGH
Network
|
revive-adserver
|
revive_adserver
|
Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some circumstances, an attacker could theoretically be …
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2021-22948
|
2024-11-21 14:51 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194896
|
9.8 |
CRITICAL
Network
|
client
|
jointjs
|
This affects the package jointjs before 3.4.2. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 when the user-provided keys used in the path parameter are arrays in the setByPath…
|
CWE-843
Type Confusion
|
CVE-2021-23444
|
2024-11-21 14:51 |
2021-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194897
|
6.1 |
MEDIUM
Network
|
adonisjs
|
edge
|
This affects the package edge.js before 5.3.2. A type confusion vulnerability can be used to bypass input sanitization when the input to be rendered is an array (instead of a string or a SafeValue), …
|
CWE-843
Type Confusion
|
CVE-2021-23443
|
2024-11-21 14:51 |
2021-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194898
|
9.8 |
CRITICAL
Network
|
cookiex-deep_project
|
cookiex-deep
|
This affects all versions of package @cookiex/deep. The global proto object can be polluted using the __proto__ object.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-23442
|
2024-11-21 14:51 |
2021-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194899
|
8.8 |
HIGH
Network
|
f5
|
big-ip_application_security_manager big-ip_advanced_web_application_firewall
|
On version 16.0.x before 16.0.1.2, insufficient permission checks may allow authenticated users with guest privileges to perform Server-Side Request Forgery (SSRF) attacks through F5 Advanced Web App…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-23029
|
2024-11-21 14:51 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194900
|
6.1 |
MEDIUM
Network
|
f5
|
big-ip_application_security_manager big-ip_advanced_web_application_firewall big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_ddos_hybrid_defender big-ip_applicatio…
|
On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, and 14.1.x before 14.1.4.3, a DOM based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration u…
|
CWE-79
Cross-site Scripting
|
CVE-2021-23027
|
2024-11-21 14:51 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|