|
196071
|
4.8 |
MEDIUM
Network
|
dynpg
|
dynpg
|
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allow remote attacker to inject javascript via URI in /index.php.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27530
|
2024-11-21 14:58 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196072
|
4.8 |
MEDIUM
Network
|
dynpg
|
dynpg
|
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "limit" parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27529
|
2024-11-21 14:58 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196073
|
4.8 |
MEDIUM
Network
|
dynpg
|
dynpg
|
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "refID" parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27528
|
2024-11-21 14:58 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196074
|
4.8 |
MEDIUM
Network
|
dynpg
|
dynpg
|
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "valueID" parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27527
|
2024-11-21 14:58 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196075
|
4.8 |
MEDIUM
Network
|
dynpg
|
dynpg
|
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "page" parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27526
|
2024-11-21 14:58 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196076
|
3.3 |
LOW
Local
|
sap
|
3d_visual_enterprise_viewer
|
When a user opens manipulated Autodesk 3D Studio for MS-DOS (.3DS) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailabl…
|
NVD-CWE-noinfo
|
CVE-2021-27596
|
2024-11-21 14:58 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196077
|
3.3 |
LOW
Local
|
sap
|
3d_visual_enterprise_viewer
|
When a user opens manipulated Portable Document Format (.PDF) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to …
|
NVD-CWE-noinfo
|
CVE-2021-27595
|
2024-11-21 14:58 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196078
|
3.3 |
LOW
Local
|
sap
|
3d_visual_enterprise_viewer
|
When a user opens manipulated Windows Bitmap (.BMP) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user u…
|
NVD-CWE-noinfo
|
CVE-2021-27594
|
2024-11-21 14:58 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196079
|
3.3 |
LOW
Local
|
sap
|
3d_visual_enterprise_viewer
|
When a user opens manipulated Graphics Interchange Format (.GIF) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable …
|
NVD-CWE-noinfo
|
CVE-2021-27593
|
2024-11-21 14:58 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196080
|
7.1 |
HIGH
Network
|
grafana
|
grafana
|
Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.
|
NVD-CWE-noinfo
|
CVE-2021-27962
|
2024-11-21 14:58 |
2021-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|