|
196171
|
7.5 |
HIGH
Network
|
markdown2_project fedoraproject
|
markdown2 fedora
|
markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacker provides a malicious string, it can make markdown2 processing difficult or de…
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2021-26813
|
2024-11-21 14:56 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196172
|
6.6 |
MEDIUM
Network
|
microsoft
|
exchange_server
|
Microsoft Exchange Server Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2021-26854
|
2024-11-21 14:56 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196173
|
9.1 |
CRITICAL
Network
|
microsoft
|
exchange_server
|
Microsoft Exchange Server Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2021-26412
|
2024-11-21 14:56 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196174
|
8.8 |
HIGH
Network
|
eprints
|
eprints
|
EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/toolbox/toolbox URI.
|
CWE-78
OS Command
|
CVE-2021-26704
|
2024-11-21 14:56 |
2021-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196175
|
9.8 |
CRITICAL
Network
|
eprints
|
eprints
|
EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase URI.
|
CWE-611
XXE
|
CVE-2021-26703
|
2024-11-21 14:56 |
2021-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196176
|
6.1 |
MEDIUM
Network
|
eprints
|
eprints
|
EPrints 3.4.2 exposes a reflected XSS opportunity in the dataset parameter to the cgi/dataset_dictionary URI.
|
CWE-79
Cross-site Scripting
|
CVE-2021-26702
|
2024-11-21 14:56 |
2021-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196177
|
9.8 |
CRITICAL
Network
|
eprints
|
eprints
|
EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI.
|
CWE-78
OS Command
|
CVE-2021-26476
|
2024-11-21 14:56 |
2021-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196178
|
6.1 |
MEDIUM
Network
|
eprints
|
eprints
|
EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI.
|
CWE-79
Cross-site Scripting
|
CVE-2021-26475
|
2024-11-21 14:56 |
2021-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196179
|
7.8 |
HIGH
Local
|
synology faad2_project
|
diskstation_manager vs960hd_firmware skynas_firmware diskstation_manager_unified_controller faad2
|
Stack-based buffer overflow vulnerability in frontend/main.c in faad2 before 2.2.7.1 allow local attackers to execute arbitrary code via filename and pathname options.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-26567
|
2024-11-21 14:56 |
2021-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196180
|
9.0 |
CRITICAL
Network
|
synology
|
diskstation_manager vs960hd_firmware skynas_firmware diskstation_manager_unified_controller
|
Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary comman…
|
CWE-200
Information Exposure
|
CVE-2021-26566
|
2024-11-21 14:56 |
2021-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|