|
195811
|
6.1 |
MEDIUM
Network
|
csphere
|
clansphere
|
Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "language" parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27310
|
2024-11-21 14:57 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195812
|
6.1 |
MEDIUM
Network
|
csphere
|
clansphere
|
Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "module" parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27309
|
2024-11-21 14:57 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195813
|
4.8 |
MEDIUM
Network
|
4homepages
|
4images
|
A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to inject JavaScript via the "redirect" parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27308
|
2024-11-21 14:57 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195814
|
7.5 |
HIGH
Network
|
netapp
|
cloud_manager
|
Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability which could allow a remote attacker to cause a Denial of Service (DoS).
|
NVD-CWE-noinfo
|
CVE-2021-26992
|
2024-11-21 14:57 |
2021-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195815
|
7.5 |
HIGH
Network
|
netapp
|
cloud_manager
|
Cloud Manager versions prior to 3.9.4 contain an insecure Cross-Origin Resource Sharing (CORS) policy which could allow a remote attacker to interact with Cloud Manager.
|
NVD-CWE-noinfo
|
CVE-2021-26991
|
2024-11-21 14:57 |
2021-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195816
|
9.1 |
CRITICAL
Network
|
netapp
|
cloud_manager
|
Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability that could allow a remote attacker to overwrite arbitrary system files.
|
CWE-862
Missing Authorization
|
CVE-2021-26990
|
2024-11-21 14:57 |
2021-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195817
|
8.1 |
HIGH
Network
|
mikrotik
|
routeros
|
MikroTik RouterOS 6.47.9 allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /export command. NOTE: the vendor's position is that this is intended behavior becau…
|
NVD-CWE-noinfo
|
CVE-2021-27221
|
2024-11-21 14:57 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195818
|
6.1 |
MEDIUM
Network
|
advantech
|
webaccess\/scada
|
WebAccess/SCADA Versions 9.0 and prior is vulnerable to cross-site scripting, which may allow an attacker to send malicious JavaScript code to an unsuspecting user, which could result in hijacking of…
|
CWE-79
Cross-site Scripting
|
CVE-2021-27436
|
2024-11-21 14:57 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195819
|
7.5 |
HIGH
Network
|
grafana netapp
|
grafana e-series_performance_analyzer
|
The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.
|
NVD-CWE-noinfo
|
CVE-2021-27358
|
2024-11-21 14:57 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195820
|
7.5 |
HIGH
Network
|
konghq
|
kong_gateway
|
An improper access control vulnerability in the JWT plugin in Kong Gateway prior to 2.3.2.0 allows unauthenticated users access to authenticated routes without a valid token JWT.
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2021-27306
|
2024-11-21 14:57 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|