|
196091
|
7.2 |
HIGH
Network
|
mybb
|
mybb
|
SQL Injection vulnerability in MyBB before 1.8.26 via the Copy Forum feature in Forum Management. (issue 2 of 3).
|
CWE-89
SQL Injection
|
CVE-2021-27947
|
2024-11-21 14:58 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196092
|
8.8 |
HIGH
Network
|
mybb
|
mybb
|
SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3).
|
CWE-89
SQL Injection
|
CVE-2021-27946
|
2024-11-21 14:58 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196093
|
8.8 |
HIGH
Network
|
mybb
|
mybb
|
SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.
|
CWE-89
SQL Injection
|
CVE-2021-27890
|
2024-11-21 14:58 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196094
|
6.1 |
MEDIUM
Network
|
mybb
|
mybb
|
Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27889
|
2024-11-21 14:58 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196095
|
9.8 |
CRITICAL
Network
|
shopxo
|
shopxo
|
A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which is uploaded after modifying the phar suffix.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-27817
|
2024-11-21 14:58 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196096
|
6.1 |
MEDIUM
Network
|
openmaint
|
openmaint
|
Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via any "Add" sections, such as Add Card Building & Flo…
|
CWE-79
Cross-site Scripting
|
CVE-2021-27695
|
2024-11-21 14:58 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196097
|
7.0 |
HIGH
Local
|
ssh
|
tectia_client tectia_connectsecure tectia_server
|
SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions. ConnectSecure on Windows is affected.
|
NVD-CWE-noinfo
|
CVE-2021-27893
|
2024-11-21 14:58 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196098
|
7.8 |
HIGH
Local
|
ssh
|
tectia_client tectia_connectsecure tectia_server
|
SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation. ConnectSecure on Windows is affected.
|
NVD-CWE-noinfo
|
CVE-2021-27892
|
2024-11-21 14:58 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196099
|
8.8 |
HIGH
Network
|
ssh
|
tectia_client tectia_connectsecure tectia_server
|
SSH Tectia Client and Server before 6.4.19 on Windows have weak key generation. ConnectSecure on Windows is affected.
|
NVD-CWE-noinfo
|
CVE-2021-27891
|
2024-11-21 14:58 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196100
|
7.5 |
HIGH
Network
|
apache
|
openmeetings
|
If was found that the NetTest web service can be used to overload the bandwidth of a Apache OpenMeetings server. This issue was addressed in Apache OpenMeetings 6.0.0
|
NVD-CWE-noinfo
|
CVE-2021-27576
|
2024-11-21 14:58 |
2021-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|