|
194951
|
8.8 |
HIGH
Network
|
tiny
|
plupload
|
This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a user to upload this kind of file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-23562
|
2024-11-21 14:51 |
2021-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194952
|
9.1 |
CRITICAL
Network
|
craftercms
|
crafter_cms
|
Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete search indexes.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2021-23264
|
2024-11-21 14:51 |
2021-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194953
|
7.5 |
HIGH
Network
|
craftercms
|
crafter_cms
|
Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and some of the files in /.git/* (non-binary).
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2021-23263
|
2024-11-21 14:51 |
2021-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194954
|
7.2 |
HIGH
Network
|
craftercms
|
crafter_cms
|
Authenticated administrators may modify the main YAML configuration file and load a Java class resulting in RCE.
|
CWE-913
Improper Control of Dynamically-Managed Code Resources
|
CVE-2021-23262
|
2024-11-21 14:51 |
2021-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194955
|
4.9 |
MEDIUM
Network
|
craftercms
|
crafter_cms
|
Authenticated administrators may override the system configuration file and cause a denial of service.
|
NVD-CWE-Other
|
CVE-2021-23261
|
2024-11-21 14:51 |
2021-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194956
|
5.4 |
MEDIUM
Network
|
craftercms
|
crafter_cms
|
Authenticated users with Site roles may inject XSS scripts via file names that will execute in the browser for this and other users of the same site.
|
CWE-79
Cross-site Scripting
|
CVE-2021-23260
|
2024-11-21 14:51 |
2021-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194957
|
7.2 |
HIGH
Network
|
craftercms
|
crafter_cms
|
Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib to render a webpage. The groovy script does not have security restrictions, wh…
|
CWE-913
Improper Control of Dynamically-Managed Code Resources
|
CVE-2021-23259
|
2024-11-21 14:51 |
2021-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194958
|
7.2 |
HIGH
Network
|
craftercms
|
crafter_cms
|
Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans. SPEL Expression does not have security restrictions, which will cause attackers t…
|
CWE-913
Improper Control of Dynamically-Managed Code Resources
|
CVE-2021-23258
|
2024-11-21 14:51 |
2021-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194959
|
9.8 |
CRITICAL
Network
|
html-to-csv_project
|
html-to-csv
|
This affects all versions of package html-to-csv. When there is a formula embedded in a HTML page, it gets accepted without any validation and the same would be pushed while converting it into a CSV …
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2021-23654
|
2024-11-21 14:51 |
2021-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194960
|
8.8 |
HIGH
Network
|
ui
|
unifi_protect
|
A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allows a malicious actor who has convinced a privileged user to access a URL with ma…
|
NVD-CWE-noinfo
|
CVE-2021-22957
|
2024-11-21 14:51 |
2021-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|